Discovering the inventory from the Proxmox API instead of hard-coding it is the best decision in here, and it quietly creates the one failure this design cannot see.
A job never names a host, it selects. So the scope of every job is a function of tags that live in a different repository and change for reasons unrelated to the job. Rename a tag in Terraform, drop one while refactoring a stack, or fat-finger it in a new guest's definition, and the job stops covering that guest. Nothing fails. nr exec fans out to eleven guests instead of twelve, every one of them succeeds, the job exits 0 and the Slack channel stays quiet. Silence is what you built the whole system to mean "everything is fine".