Lesson 19 / 26

Ansible Vault

Encrypt secret variable files and use them safely in playbooks.

Encrypted at rest in Git

Ansible Vault encrypts files (or single values) with AES-256 so secrets such as database passwords can live in version control. Create or encrypt with ansible-vault encrypt, create or encrypt_string; run playbooks with --ask-vault-pass or --vault-password-file. Keep the vault password out of the repository (a password manager, CI secret or secrets service), use separate vaults/passwords for different environments, and consider integrating an external secrets manager for larger teams.

Automation holds the keys

Playbooks touch passwords, keys and production servers, so protect secrets and limit privilege.

Three controls: encrypt, limit, hide.
Figure 6.1 — Encrypt, limit and hide.

Encrypting a file, run

I encrypted a small secret.yml with a throwaway password file. The first line of an encrypted file is the Vault header; the rest is ciphertext. Never commit the password file.

echo "db_password: hunter2" > secret.yml
ansible-vault encrypt secret.yml --vault-password-file vp.txt
head -1 secret.yml

Output:

$ANSIBLE_VAULT;1.1;AES256

Using the encrypted vars

Load the file like any vars file and pass the vault password at run time. (Illustrative.)

# playbook: vars_files: [secret.yml]
ansible-playbook -i inventory.ini site.yml --vault-password-file ~/.vault_pass

Name variables so reviews can find them

A common pattern keeps readable names in plain files that point to vaulted values, for example db_password: "{{ vault_db_password }}". Reviewers can see which secrets exist without decrypting them.

Quick check: Where should the Vault password be stored?

  • In a public chat
  • In the same Git repo as the playbook
  • In the playbook name
  • Outside the repository, in a password manager or CI secret
Answer

Outside the repository, in a password manager or CI secret — Keeping the key next to the locked data defeats the purpose of encryption.