Clone major upgrade fails at 'check': the upgrade container omits databaseContainer.containerConfig volumes (TLS cert)

Problem

Clone major upgrade fails at the check stage on any instance whose databaseContainer.containerConfig adds volumes — which is the normal setup when TLS is on:

Upgrade was not applied. The clone is still running on PostgreSQL 16.
Cause: pg_upgrade failed with exit code 10 before converting anything

pg_upgrade_clone.log only reports could not connect to source postmaster. The real cause is in pg_upgrade_server.log, which the engine deletes with data_new on rollback:

FATAL:  could not load server certificate file "/var/lib/postgresql/cert/server.crt": No such file or directory
LOG:  database system is shut down
pg_ctl: could not start server

Cause

The clone's postgresql.dblab.snapshot.conf has ssl = 'on' with ssl_cert_file = '/var/lib/postgresql/cert/server.crt'. Clone containers receive that path through databaseContainer.containerConfig (volume: /var/lib/dblab/cert:/var/lib/postgresql/cert), which RunContainer turns into containerFlags and appends to docker run (engine/internal/provision/docker/docker.go:69-73,84).

RunUpgradeContainer builds its docker run from createDefaultVolumes/getMountVolumes only and never appends c.ContainerConf (docker.go:151-161). pg_upgrade therefore starts the old-major postmaster in a container with no cert mounted, it exits at startup, --check cannot connect, and the script exits 10.

Reproduced and bisected on demo.dblab.dev (engine v4.2.0-20260911-0242)

Same clone, cleanly shut down, one variable changed:

run volumes result
A engine's current set could not connect to source postmaster, exit 1
B same + -v /var/lib/dblab/cert:/var/lib/postgresql/cert:ro *Clusters are compatible*, exit 0

Fix

Append c.ContainerConf flags to the upgrade container's docker run, the way RunContainer already does.

Still present on master.