Ansible hardened HAProxy 3.0 reverse-proxy edge for Debian 13

Deploys a DMZ HAProxy 3.0 reverse proxy fronting Immich and Ente Photos in the
server subnet. Roles: proxmox_vm (VM clone + cloud-init), os_base, tailscale
(management mesh), haproxy_edge (HAProxy + ACME/Cloudflare DNS-01 certificates),
and an app-specific fail2ban haproxy-http jail. Firewall and hardening come from
the shared collections: base_firewall (public 80/443 + management SSH) via
acidnetworks.base_debian, and the full security layer via
acidnetworks.hardening_debian over a hardened_hosts supergroup. Ships prod,
staging, and Vagrant inventories; secrets in ansible-vault.