Why Ansible Vault?
Hardcoding passwords in playbooks is a security risk. Ansible Vault encrypts sensitive data so you can safely commit it to version control.
Create an Encrypted File
ansible-vault create secrets.ymlEnter a vault password when prompted. The file opens in your editor — add your secrets:
db_password: "SuperSecret123"
api_key: "sk-abc123def456"Save and close. The file is now AES-256 encrypted.
View and Edit
# View without editing
ansible-vault view secrets.yml
# Edit in place
ansible-vault edit secrets.ymlMaster this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →Encrypt an Existing File
ansible-vault encrypt vars/production.ymlDecrypt it back:
ansible-vault decrypt vars/production.ymlEncrypt a Single Variable
For inline encryption without encrypting the whole file:
ansible-vault encrypt_string 'SuperSecret123' --name 'db_password'Output:
db_password: !vault |
$ANSIBLE_VAULT;1.1;AES256
6231326536613163...Paste this directly into your vars file. The rest of the file stays readable.
Use in Playbooks
Reference vault variables like any other variable:
- name: Configure database
hosts: db_servers
vars_files:
- secrets.yml
tasks:
- name: Set database password
ansible.builtin.lineinfile:
path: /etc/myapp/db.conf
regexp: '^password='
line: "password={{ db_password }}"Run with the vault password:
ansible-playbook site.yml --ask-vault-pass
# Or use a password file
ansible-playbook site.yml --vault-password-file ~/.vault_passGet weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →Multiple Vault Passwords
Use vault IDs for different environments:
# Create with an ID
ansible-vault create --vault-id prod@prompt secrets-prod.yml
ansible-vault create --vault-id dev@prompt secrets-dev.yml
# Run with multiple vault IDs
ansible-playbook site.yml \
--vault-id prod@~/.vault_pass_prod \
--vault-id dev@~/.vault_pass_devCI/CD Integration
Store the vault password as a CI secret and write it to a temp file:
# GitHub Actions example
- name: Run playbook
env:
VAULT_PASS: ${{ secrets.ANSIBLE_VAULT_PASSWORD }}
run: |
echo "$VAULT_PASS" > /tmp/.vault_pass
ansible-playbook site.yml --vault-password-file /tmp/.vault_pass
rm /tmp/.vault_passBest Practices
- Never commit vault passwords to Git — use CI/CD secrets or a password manager
- Use
encrypt_stringfor individual values so the file structure stays readable - Rotate vault passwords periodically — re-encrypt with
ansible-vault rekey - Use vault IDs to separate production and development secrets
- Add
.vault_passto.gitignoreas a safety net
Related Posts
- Ansible Automation in Minutes for getting started
- Terraform Security Practices for IaC secrets management
- Securing Your OpenClaw Agent for agent security
---
Ready to go deeper? Check out our hands-on course: Ansible Quickstart — practical exercises you can follow along on your own machine.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
Ansible Vault Secrets Encryption
Encrypt secrets with Ansible Vault for secure automation. Cover file encryption, string-level vaulting, multi-password setups, and CI/CD pipeline integration.
Vault Secrets Management Guide
Manage secrets with HashiCorp Vault. KV engine, dynamic credentials, auth methods, policies, and Kubernetes integration patterns.
Sops Encrypted Secrets in Git
SOPS encrypts secret values in YAML, JSON, and dotenv files while keeping keys readable. Learn how to use SOPS with age, AWS KMS, or GCP KMS.
Ansible vs Terraform vs Puppet Guide
Compare Ansible, Terraform, and Puppet for infrastructure automation. Understand when to use each tool and how they complement each other in modern DevOps.
Ansible vs Terraform When to Use
Ansible and Terraform solve different infrastructure problems. Learn when to use each, when to use both together, and how they complement each other.
Arch Linux: Full Control DIY
Arch Linux gives you complete control over every package and configuration. Learn what makes Arch unique and whether it's right for you in 2026.
Explore topics
Browse more articles on the topics covered here.