Thanks. Can someone clarify if “strict” confinement + “personal-files” plug is enough for read/write access to the configuration file, or I do need the “classic” confinement? I tried building the snap locally with the config shown in the OP, but it still does not have permission. Not sure if I am doing something wrong.