Lesson 19 / 26
Ansible Vault
Encrypt secret variable files and use them safely in playbooks.
Encrypted at rest in Git
Ansible Vault encrypts files (or single values) with AES-256 so secrets such as database passwords can live in version control. Create or encrypt with ansible-vault encrypt, create or encrypt_string; run playbooks with --ask-vault-pass or --vault-password-file. Keep the vault password out of the repository (a password manager, CI secret or secrets service), use separate vaults/passwords for different environments, and consider integrating an external secrets manager for larger teams.
Automation holds the keys
Playbooks touch passwords, keys and production servers, so protect secrets and limit privilege.
Encrypting a file, run
I encrypted a small secret.yml with a throwaway password file. The first line of an encrypted file is the Vault header; the rest is ciphertext. Never commit the password file.
echo "db_password: hunter2" > secret.yml
ansible-vault encrypt secret.yml --vault-password-file vp.txt
head -1 secret.yml
Output:
$ANSIBLE_VAULT;1.1;AES256
Using the encrypted vars
Load the file like any vars file and pass the vault password at run time. (Illustrative.)
# playbook: vars_files: [secret.yml]
ansible-playbook -i inventory.ini site.yml --vault-password-file ~/.vault_passName variables so reviews can find them
A common pattern keeps readable names in plain files that point to vaulted values, for example db_password: "{{ vault_db_password }}". Reviewers can see which secrets exist without decrypting them.
Quick check: Where should the Vault password be stored?
- In a public chat
- In the same Git repo as the playbook
- In the playbook name
- Outside the repository, in a password manager or CI secret
Answer
Outside the repository, in a password manager or CI secret — Keeping the key next to the locked data defeats the purpose of encryption.