Container fails with 'read-only file system' when K8s tries to mount a secret into /etc/kafka/secrets alongside the ConfigMap at /etc/kafka. Switch to subPath mount of server.properties directly.