ansible-vault - encryption/decryption utility for Ansible data files
ansible-vault {create,decrypt,edit,view,encrypt,encrypt_string,rekey} [options] [FILE ...]
Options you will use
--vault-password-file FILE- Vault password file.
--vault-id LABEL@SOURCE- The vault identity to use (label@prompt, label@file).
-J, --ask-vault-pass- Ask for the vault password.
--new-vault-password-file FILE- New vault password file for rekey.
--new-vault-id ID- The new vault identity to use for rekey.
--encrypt-vault-id ID- The vault id used to encrypt (required if more than one vault-id is provided).
--output FILE- Output file name for encrypt or decrypt; use - for stdout.
-n, --name NAME- Variable name for encrypt_string.
-p, --prompt- Prompt for the string to encrypt (encrypt_string).
--stdin-name NAME- Specify the variable name for stdin (encrypt_string).
Examples
$ ansible-vault create group_vars/db/vault.ymla new encrypted vars file
$ ansible-vault encrypt_string --name db_passwordone encrypted value
$ ansible-vault view group_vars/db/vault.yml --vault-password-file ~/.vault_pass$ ansible-vault rekey vault.ymlrotate the vault password
Gotchas
- The file starts with $ANSIBLE_VAULT;1.1;AES256 (1.2;AES256;LABEL with a vault id), then the hex payload.
- A vault protects the file at rest. It does not stop -vvv, debug or a failing task from printing the value: use no_log: true.
- Never commit the password file. Keep it mode 600, or use an executable script that reads a secrets manager.
Taught in
Try ansible-vault in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.