Ansible Vault encrypts sensitive data so you can safely commit it to Git. Passwords, API keys, certificates — all encrypted at rest, decrypted at runtime.
Encrypting Files
# Encrypt a file
ansible-vault encrypt group_vars/production/secrets.yml
# View encrypted file
ansible-vault view group_vars/production/secrets.yml
# Edit encrypted file (opens in $EDITOR)
ansible-vault edit group_vars/production/secrets.yml
# Decrypt a file
ansible-vault decrypt group_vars/production/secrets.yml
# Re-key (change password)
ansible-vault rekey group_vars/production/secrets.ymlEncrypted File Format
$ANSIBLE_VAULT;1.1;AES256
36336262363339613464653036623261
30626465383762343963303637366533
...Create New Encrypted File
ansible-vault create group_vars/production/secrets.ymlWrite your secrets:
---
db_password: "S3cur3P@ss!"
api_key: "sk-prod-abc123def456"
jwt_secret: "my-super-long-jwt-secret-key-here"
smtp_password: "email-password-here"
ssl_private_key: |
-----BEGIN PRIVATE KEY-----
MIIEvQIBADANBgkqhkiG9w0BAQEFAASC...
-----END PRIVATE KEY-----Encrypting Individual Strings
Encrypt just one value instead of an entire file:
ansible-vault encrypt_string 'S3cur3P@ss!' --name 'db_password'Output:
db_password: !vault |
$ANSIBLE_VAULT;1.1;AES256
36336262363339613464653036623261
30626465383762343963303637366533Paste directly into your variables file:
# group_vars/production/vars.yml (committed to Git)
db_host: db.internal
db_port: 5432
db_name: myapp
db_user: appuser
db_password: !vault |
$ANSIBLE_VAULT;1.1;AES256
36336262363339613464653036623261
...Master this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →Running Playbooks with Vault
# Prompt for password
ansible-playbook site.yml --ask-vault-pass
# Password from file
ansible-playbook site.yml --vault-password-file ~/.vault_pass
# Password from environment variable (via script)
ansible-playbook site.yml --vault-password-file ./vault-pass.shvault-pass.sh
#!/bin/bash
echo "$ANSIBLE_VAULT_PASSWORD"ansible.cfg
[defaults]
vault_password_file = ~/.vault_passMultiple Vault Passwords
Different secrets for different environments:
# Encrypt with vault ID
ansible-vault encrypt --vault-id production@prompt group_vars/production/secrets.yml
ansible-vault encrypt --vault-id staging@prompt group_vars/staging/secrets.yml
# Run with multiple vault IDs
ansible-playbook site.yml \
--vault-id production@~/.vault_pass_prod \
--vault-id staging@~/.vault_pass_stagingIn Variables
# Production secrets
db_password: !vault |
$ANSIBLE_VAULT;1.2;AES256;production
36336262363339613464653036623261
...
# Staging secrets
staging_db_password: !vault |
$ANSIBLE_VAULT;1.2;AES256;staging
64623261303632363533396134363438
...Project Structure
inventory/
production/
hosts.yml
group_vars/
all/
vars.yml # Non-sensitive (committed)
vault.yml # Encrypted (committed)
staging/
hosts.yml
group_vars/
all/
vars.yml
vault.ymlvars.yml (plain text)
---
app_name: my-app
app_port: 3000
db_host: db.internal
db_port: 5432
db_name: myappvault.yml (encrypted)
---
vault_db_password: "S3cur3P@ss!"
vault_api_key: "sk-prod-abc123"
vault_jwt_secret: "long-secret-key"Reference Pattern
# vars.yml — reference vault variables with a prefix
db_password: "{{ vault_db_password }}"
api_key: "{{ vault_api_key }}"This makes it clear which values are secrets without opening the vault file.
Get weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →CI/CD Integration
GitHub Actions
- name: Run Ansible
env:
ANSIBLE_VAULT_PASSWORD: ${{ secrets.ANSIBLE_VAULT_PASSWORD }}
run: |
echo "$ANSIBLE_VAULT_PASSWORD" > /tmp/.vault_pass
ansible-playbook site.yml --vault-password-file /tmp/.vault_pass
rm /tmp/.vault_passGitLab CI
deploy:
script:
- echo "$VAULT_PASSWORD" > /tmp/.vault_pass
- ansible-playbook site.yml --vault-password-file /tmp/.vault_pass
- rm /tmp/.vault_pass
variables:
VAULT_PASSWORD: $ANSIBLE_VAULT_PASSWORDBest Practices
| Practice | Why |
|---|---|
Prefix vault variables with vault_ | Clear which values are secrets |
| One vault file per environment | Different passwords per env |
Use vault password file, not --ask-vault-pass | Automation-friendly |
| Never commit vault password files | Add to .gitignore |
| Rotate vault passwords periodically | Security hygiene |
Use encrypt_string for individual values | Smaller encrypted surface |
| Keep non-sensitive vars in plain text | Easier to review in PRs |
What's Next?
Our Ansible Automation in 30 Minutes course covers Vault encryption for production automation. SELinux for System Admins teaches OS-level security. First lessons are free.
---
Ready to go deeper? Check out our hands-on course: Ansible Quickstart — practical exercises you can follow along on your own machine.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
Ansible Vault: Encrypt Secrets Safely
Learn Ansible Vault to encrypt passwords, API keys, and variables. Covers vault create, edit, encrypt_string, and CI/CD usage.
Sealed Secrets Kubernetes Guide
Sealed Secrets encrypts Kubernetes secrets so you can store them safely in Git. Learn how to install Sealed Secrets, encrypt secrets, and manage key rotation.
Vault Secrets Management Guide
Manage secrets with HashiCorp Vault. KV engine, dynamic credentials, auth methods, policies, and Kubernetes integration patterns.
Ansible vs Terraform vs Puppet Guide
Compare Ansible, Terraform, and Puppet for infrastructure automation. Understand when to use each tool and how they complement each other in modern DevOps.
Ansible vs Terraform When to Use
Ansible and Terraform solve different infrastructure problems. Learn when to use each, when to use both together, and how they complement each other.
Arch Linux: Full Control DIY
Arch Linux gives you complete control over every package and configuration. Learn what makes Arch unique and whether it's right for you in 2026.
Explore topics
Browse more articles on the topics covered here.