@NebulaTide generally, yes. after the years, my post 3rd stage is either execution of some quick shell scripts or ansible for getting all of the usual aspects in place. perhaps I'll make a public repo for these arrangements and call it something like "stage4.gentoo.rfc1918.systems"... right now they're somewhere in rfc1918.sh but certbot wildcard expired or something (they stopped sending automated emails for renewals a while ago)