apt dist-upgrade reboot enabled, lint fixes
second round, for testing
lint clean, testing needed
prereqs assert w/dig doesn't loop properly
use head not all for target hosts in single

@@ -67,6 +67,8 @@
       command: "iptables -t nat -C POSTROUTING -s ! -d -j MASQUERADE"
       register: iptables_check
       failed_when: "iptables_check|failed and 'No chain/target/match by that name' not in iptables_check.stderr"
+      tags:
+        - skip_ansible_lint # FIXME: should use iptables module when it supports inversion of ranges
     - name: Create iptables rule
       when: "iptables_check.rc != 0"