Encrypt secrets with Ansible Vault, keep them out of task output with no_log, and keep the vault password out of the repository. Vault encrypts a whole file or a single variable, so the encrypted content can sit in source control beside the playbooks. When a playbook runs, you supply the vault password and Ansible decrypts what it needs.
# Encrypt a file
ansible-vault encrypt secrets.yml
# Decrypt a file
ansible-vault decrypt secrets.yml
# Edit encrypted file
ansible-vault edit secrets.yml
# Run playbook with vault password
ansible-playbook site.yml --ask-vault-pass
# Use vault password file
ansible-playbook site.yml --vault-password-file .vault_pass
Encrypting only the sensitive values keeps the rest of a vars file readable in code review.
# vars.yml
username: john
password: !vault |
$ANSIBLE_VAULT;1.1;AES256
66386439653762356265343432393730...
Four habits keep it safe:
- Keep the vault password in a file only its owner can read, set with
chmod 600, and never commit it. - Use a separate vault file for each environment, each with its own password.
- Encrypt only the sensitive variables, not entire playbooks.
- Add
no_log: trueto tasks that handle secrets. Vault protects data only at rest, so a decrypted value would otherwise show up in output and logs.
When many teams share secrets or rotate them often, fetch them at run time from an external manager such as HashiCorp Vault instead.
This answer doesn't lend itself to a diagram - it reads best . No credits were charged.
Why there's no diagram: “”
The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓
The diagram below the answer is the concept . Jump to it ↓