The deploy user runs scripts as root via passwordless sudo, avoiding ownership conflicts with Docker-mounted volumes.