This is nicer for us, since this avoids sharing a secret. Also put certificate directories in `certs` sub-directory for better organization.
become
/etc/ansible_certs
/certs