/etc/trojan-go/tls/ after certbot obtains the certificatetrojan-config.json.j2 to use /etc/trojan-go/tls/ for cert and key pathsCapabilityBoundingSet=CAP_NET_BIND_SERVICE to trojan.service.j2ansible-playbook site.yml --syntax-check to confirm playbook parses