The role takes a host as AlmaLinux ships it and leaves nftables owning the
firewall with firewalld masked, a ban service reading the proxy's audit log,
the panel's Quadlets installed, and the backup on a nightly timer. What
differs between deployments — the site name, the addresses administration is
accepted from — comes from the inventory, not from the units.
The scenario runs the real playbook against a real systemd in an AlmaLinux 10
container, twice, and the second run changes nothing. Running it found two
faults worth having: fail2ban refuses to start when the log it watches does
not exist yet, which is every new host, and logrotate will not take a numeric
id where a name belongs, so the proxy's logs were never being rotated at all.
A container is not a machine: reboot recovery, certificates, SELinux labelling
and real packet filtering still need a run against one.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>