For the record, I recalled that /etc/tmpfiles.d/knot-resolver.conf would
be another place to modify.
This would've been much easier with
https://gitlab.nic.cz/knot/knot-resolver/-/merge_requests/1056
as the ownership changes would happen automatically and tmpfiles
wouldn't be needed. (Unfortunately, as stated there, some distributions
don't have sufficiently new systemd, so overall it would generally be
more trouble than worth so far - perhaps in a few years.)
--Vladimir