- hosts: all become: true vars_files: - ../inventory/group_vars/all.yaml roles: - role: base tags: [base] - role: sops_agent tags: [sops] - role: custodian_agent # injects ~/.ssh/id_custodian_agent.pub into authorized_keys tags: [custodian_agent] - role: swapfile # provisions swap file (size + swappiness from host_vars) tags: [swap] - role: resource_limits # nproc PAM caps + systemd user slice memory limits tags: [resource_limits] # - role: wireguard # enable if you configure WireGuard variables