"I have persistent docker.sock permission/connection failures inside a Debian 13.2 VM running on Proxmox VE (latest QEMU updates). The Docker service runs, but Portainer cannot connect to it (fails when clicking 'local'). All standard fixes (GID, privileged, API checks) have failed. Is this a known Kernel Security Context (AppArmor/SELinux) conflict specific to Debian 13/Bookworm guests on Proxmox that requires a non-standard VM configuration tweak, or is this environment fundamentally incompatible with the default Docker socket connection?"