# Ansible Vault — Ansible: Automate Servers with Playbooks

Source: https://www.geekswithgeeks.com/en/ansible/sec-vault

> Encrypt secret variable files and use them safely in playbooks.

## Encrypted at rest in Git

**Ansible Vault** encrypts files (or single values) with AES-256 so secrets such as database passwords can live in version control. Create or encrypt with `ansible-vault encrypt`, `create` or `encrypt_string`; run playbooks with `--ask-vault-pass` or `--vault-password-file`. Keep the vault password **out of the repository** (a password manager, CI secret or secrets service), use separate vaults/passwords for different environments, and consider integrating an external secrets manager for larger teams.

## Automation holds the keys

Playbooks touch passwords, keys and production servers, so protect secrets and limit privilege.

![Three controls: encrypt, limit, hide.](assets/figures/ansible/section-6-map.svg) — Figure 6.1 — Encrypt, limit and hide.

## Encrypting a file, run

I encrypted a small `secret.yml` with a throwaway password file. The first line of an encrypted file is the Vault header; the rest is ciphertext. Never commit the password file.

```bash
echo "db_password: hunter2" > secret.yml
ansible-vault encrypt secret.yml --vault-password-file vp.txt
head -1 secret.yml
```

Output:

```
$ANSIBLE_VAULT;1.1;AES256
```

## Using the encrypted vars

Load the file like any vars file and pass the vault password at run time. (Illustrative.)

```bash
# playbook: vars_files: [secret.yml]
ansible-playbook -i inventory.ini site.yml --vault-password-file ~/.vault_pass
```

## Name variables so reviews can find them

A common pattern keeps readable names in plain files that point to vaulted values, for example `db_password: "{{ vault_db_password }}"`. Reviewers can see which secrets exist without decrypting them.

**Quiz:** Where should the Vault password be stored?

- [ ] In a public chat
- [ ] In the same Git repo as the playbook
- [ ] In the playbook name
- [x] Outside the repository, in a password manager or CI secret

*Answer:* Outside the repository, in a password manager or CI secret. Keeping the key next to the locked data defeats the purpose of encryption.
