Goal: make kelp able to provision AWS hosts the way the controller does, then deploy an on-demand instance running Firefox + VNC so a GWR Delay Repay claim (or similar interactive web task) can be driven from it. The new host needs stunnel (mTLS) plus SSH certs/keys set up during provisioning.
Related: ansible/todo (skeleton play, netrc, no-unattended-upgrades, SSH-key policy), john/travel/delay-repay-vnc-howto (driving Firefox via VNC), and john/system-config.
Session outcome, the webdrive toolkit, and everything learned (OCR speed on 2 vCPU, the tiered patch locator, dynamic-content handling, dual-uid/known_hosts gotchas, teardown): see delayrepay.