SELinux hosts
Nothing to configure. With SELinux enforcing (Fedora, RHEL, CentOS and derivatives), the
container must be allowed to read its bind-mounted files. So the mounts in
docker-compose.prod.yml and the Ansible template (nginx.conf,
nginx/certs, /etc/letsencrypt) carry the :z relabel
option, a no-op elsewhere.