- Store smime_private_key in encrypted vault - Add playbook tasks: create cert directory + deploy private key with 0600 permissions - Certificate public already in git at config/cert/certificate.pem Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>