It's, uh, a bit ugly. But let's try to make it work for now, improve later. Apparently my wpa_supplicant config file was visible for everyone already, so that's not a regression :D
Because I'm getting tired of too many bash scripts and yet using Ansible seems overkill at the same time.
ansible-galaxy install mnussbaum.base16-builder-ansible