Very specific to Ansible, but works fine. It's a shame only files containing variables (we're using group_vars) can be encrypted, and not arbitrary files or templates.
Very specific to Ansible, but works fine. It's a shame only files containing variables (we're using group_vars) can be encrypted, and not arbitrary files or templates.
There are two things currently that bother me about ansible-vault. The first is that the 'edit' command write a completely new file even if I didn't change anything. And the second is that the diffs in git become useless. I'd love to have a special diff driver for ansible-vault encrypted files that decrypts before diffing when the secret is available.
Agreed on the useless diffs however, it makes reviewing pull requests or changes much harder.
I wouldn't encrypt a whole playbook for example.
- no file encryption, only YML
- no separate values, only entire file
- OMG it's s...l...o...w...
- password based instead of certs
- only one password
- password cannot even stored in an env var
More: http://jpmens.net/2014/02/22/my-thoughts-on-ansible-s-vault/
But yeah, the "only one password" is the biggest pain for me...
echo "$ANSIBLE_VAULT_PASSWORD"