If the share dir contains rpms in /share/rpms, install those, instead of using the plugin from the container.
Switch to kerberos aut and also ship ssl.conf, adapted to serve at localhost and the fqdn, instead of creating it via sed.
Use quay.io/osbuild/koji:v1 and remove db schema generation, now done in run-koji.cotnainer.sh. Ensure /mnt/koji has the right permission, but don't create it, since it is a volume and bind-mounted in.