See the comment for more details
This replaces the default recipe and will make it much easier to create other types of instances, for example for replication
It sets up 389 Directory Server, including a TLS cert acquired using Let's Encrypt in production (that requires ldap.kosmos.org pointing to the server's IP)