Ansible · question
Q.04 of 27
How do you handle sensitive data like passwords in Ansible?
← All Ansible questions
Re-explain
Ansible Vault is the primary method for encrypting sensitive data like passwords, API keys, and certificates.
Basic Vault operations:
# Encrypt a file
ansible-vault encrypt secrets.yml
# Decrypt a file
ansible-vault decrypt secrets.yml
# Edit encrypted file
ansible-vault edit secrets.yml
# Run playbook with vault password
ansible-playbook site.yml --ask-vault-pass
# Use vault password file
ansible-playbook site.yml --vault-password-file .vault_pass
Encrypting specific variables:
# vars.yml
username: john
password: !vault |
$ANSIBLE_VAULT;1.1;AES256
66386439653762356265343432393730...
Best practices:
- Store vault password in a file with restricted permissions (chmod 600)
- Use separate vault files for different environments
- Encrypt only sensitive variables, not entire playbooks
- Use
no_log: true in tasks handling sensitive data
- Never commit vault passwords to version control
Rewriting in plainer words…
This answer doesn't lend itself to a diagram - it reads best . No credits were charged.
The model's verdict: “”
This answer is explained by a shared concept diagram -
open →
Point the redraw:
How well did you know this?
AI:
Saved in this browser - sign in to keep your review list.
How should your speech become text?
Listening… your words appear above as you speak - tap Stop when you're done.
Recording · cr - tap Stop & transcribe when you're done.
Transcribing with AI…
Voice:
Keep going - a few more words and AI can grade it.
Interview lens
Likely follow-ups, what you can say, and the weak answers to avoid.
Pro · $10/mo
23 of 27 Ansible answers are gated.
Full answers, code samples, AI explanations - simpler, deeper, or as an interactive diagram. Cancel anytime.
-
Full answers + code
-
AI explain - simpler, deeper, or visualized
-
1,000 AI credits / month
-
Cancel anytime