Organize the bridge fleet Ansible repository with clear separation between inventory, roles, and playbooks:
bridge-fleet/
inventory/
production.yml # Active bridge hosts
staging.yml # Test instances
roles/
tor-bridge/
tasks/main.yml
templates/torrc.j2
handlers/main.yml
monitoring/
tasks/main.yml
security-hardening/
tasks/main.yml
playbooks/
provision-bridge.yml
rotate-bridge.yml
update-all.yml
emergency-shutdown.yml
vars/
vault.yml # Encrypted credentials
common.yml # Shared configuration
Store the repository in a private git repository with encrypted secrets managed through Ansible Vault. This structure allows any operator with the vault password to provision, update, or rotate bridges from any machine with Ansible installed, without requiring direct SSH access to individual bridge servers during normal operations.