Veyepar in /srv code owned by root.
This puts everything in the right place and owned by the right user.
veyepar.cfg is in /etc/veyepar it sets media_dir=/srv/$nfs/video which defaulted to ~/Videos/veyepar
auth tokens are still in the code dir, but they get constructed on the machine I read email on (my laptop) and ansible moves them to the production box, where they are owned by root and that's fine.
The test suite runs, all the artifacts get created under /srv/$nfs/video which is owned by $user.