Remove OpenVPN. Add pubkeys to the institute "client" command args.
Replaced "revoked" with "clients" in private/members.yml.
Use a PostUp command to install peer private keys from the local
/etc/wireguard/private-key file, thus keeping it out of the WireGuard™
and Ansible configurations. Moved e.g Secret/gate-wg0.conf to
private/. Provide the example private keys in a table (as they appear
nowhere else!). Treat gate-wg0.conf and front-wg0.conf like
members.yml: do not tangle them and thus wipe out a test state(?).