What is the recommended project structure for organizing Ansible Vault-encrypted variable files in a role-based project?