@bvitnik It worked as hoped, after an iteration or two. I opted for using jinja templating with setting template vars up top and using in standardized fashion below. But... I can see that cloud configs will not be easy to manage and scale for complex tasks. If you need to write a file or two, configure LDAP authN using sssd, the prometheus node_exporter, etc., the scripts can get lengthy. Given how difficult they are to debug (cloud-init schema --config-file <config.yaml> --annotate is helpful, but more challenging with jinja templates), it would seem something else should supplement a basic config.
Now I'm considering ansible-pull from an on-network git repo -- I don't think I have the scale to warrant a control instance and I can't quite warm up to the idea of an SSH key with sudo access everywhere. Admittedly the security concern just shifts to the repo, especially if periodic pulls will happen. In your opinion am I going in the right direction or should I be considering other config management options too? My goal is to deploy VMs with a set of docker containers (I'll use podman) in a repeatable fashion. Thanks again for your patience with a DevOps noob.