we have this problem in system roles with several roles - for example, if you want to set selinux policy, ansible is probably not the entire source of truth e.g. if you just want to allow a port, you don't want to also provide the entire default policy for the system
however, in some cases, you do want to replace everything with your specified policy