OnCallReady

Commands

ansible-vault - encryption/decryption utility for Ansible data files

ansible-vault {create,decrypt,edit,view,encrypt,encrypt_string,rekey} [options] [FILE ...]

Options you will use

--vault-password-file FILE
Vault password file.
--vault-id LABEL@SOURCE
The vault identity to use (label@prompt, label@file).
-J, --ask-vault-pass
Ask for the vault password.
--new-vault-password-file FILE
New vault password file for rekey.
--new-vault-id ID
The new vault identity to use for rekey.
--encrypt-vault-id ID
The vault id used to encrypt (required if more than one vault-id is provided).
--output FILE
Output file name for encrypt or decrypt; use - for stdout.
-n, --name NAME
Variable name for encrypt_string.
-p, --prompt
Prompt for the string to encrypt (encrypt_string).
--stdin-name NAME
Specify the variable name for stdin (encrypt_string).

Examples

$ ansible-vault create group_vars/db/vault.yml

a new encrypted vars file

$ ansible-vault encrypt_string --name db_password

one encrypted value

$ ansible-vault view group_vars/db/vault.yml --vault-password-file ~/.vault_pass
$ ansible-vault rekey vault.yml

rotate the vault password

Gotchas

Taught in

Try ansible-vault in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.