Authentik migrations need to CREATE SCHEMA (not just tables in public schema). This requires GRANT CREATE ON DATABASE, not just schema-level permissions. Added to PostSync Job: - GRANT CREATE ON DATABASE authentik TO authentik - GRANT CREATE ON DATABASE temporal TO temporal - GRANT CREATE ON DATABASE temporal_visibility TO temporal App user can grant these (it owns the databases).