One XML per app under templates/, ca_profile.xml at the root, as the
Community Applications starter lays it out.
The ihasmail template runs the published multi-arch image read-only
with /tmp in memory, and as Unraid's nobody user (99:100) because that
is the owner Unraid gives a freshly created appdata folder; the image's
own user could not write the session file there. The appdata path is
optional: clear it, blank SESSION_FILE and set IMMUTABLE=1 for a
container with no writable path at all.