Introduction

ansible-vault decrypt converts an encrypted vault file back to plaintext. This is essential for editing secrets, migrating to a new encryption method, or debugging vault-related issues. This guide covers all decryption methods — interactive, password files, vault IDs, and CI/CD automation.

Prerequisites

ansible-vault is included in every Ansible installation — no separate install needed.

# Verify availability
ansible-vault --version

Basic Decryption

Interactive (Prompt for Password)

ansible-vault decrypt secrets.yml
# Vault password: ********
# Decryption successful

Before:

$ANSIBLE_VAULT;1.1;AES256
65333637643363376438633838346563353666636433613032333663666137613839333564393238
3930333031633134346461303636623937353561643464390a...

After:

---
db_password: mysupersecretpassword
api_key: sk-1234567890abcdef

With Password File

# Password stored in a file
echo "mypassword" > ~/.vault_pass
chmod 600 ~/.vault_pass

# Decrypt using password file
ansible-vault decrypt secrets.yml --vault-password-file ~/.vault_pass

With Environment Variable

# Set password in environment
export ANSIBLE_VAULT_PASSWORD_FILE=~/.vault_pass

# Now decrypt without flags
ansible-vault decrypt secrets.yml

Decrypt to stdout (Don't Modify File)

View encrypted content without changing the file:

ansible-vault view secrets.yml
# Vault password: ********
# --- shows decrypted content ---

Or decrypt to a different file:

ansible-vault decrypt secrets.yml --output decrypted-secrets.yml

Vault IDs (Multiple Passwords)

When using different passwords for different environments:

# Encrypt with vault ID
ansible-vault encrypt --vault-id prod@~/.vault_pass_prod secrets-prod.yml

# Decrypt with vault ID
ansible-vault decrypt --vault-id prod@~/.vault_pass_prod secrets-prod.yml

# Multiple vault IDs
ansible-vault decrypt \
  --vault-id dev@~/.vault_pass_dev \
  --vault-id prod@~/.vault_pass_prod \
  secrets.yml

Decrypt Inline Encrypted Variables

When only specific variables are encrypted (not the whole file):

# vars.yml — mixed plain and encrypted values
app_name: myapp
db_password: !vault |
  $ANSIBLE_VAULT;1.1;AES256
  65333637643363376438633838346563...

View the decrypted value:

# ansible-vault view doesn't work for inline — use ansible debug
ansible localhost -m debug -a "var=db_password" \
  -e @vars.yml \
  --vault-password-file ~/.vault_pass

Using Decryption in Playbooks

You don't need to manually decrypt files to use them in playbooks:

# Run playbook with vault password
ansible-playbook site.yml --ask-vault-pass

# Or with password file
ansible-playbook site.yml --vault-password-file ~/.vault_pass

ansible.cfg Configuration

[defaults]
vault_password_file = ~/.vault_pass

Now all vault operations work without flags:

ansible-playbook site.yml  # Automatically uses vault password
ansible-vault decrypt secrets.yml  # Also automatic

Script-Based Password Source

For dynamic password retrieval (e.g., from a password manager):

#!/bin/bash
# ~/.vault_pass_script.sh
# Fetch from 1Password, LastPass, AWS Secrets Manager, etc.
op read "op://DevOps/AnsibleVault/password"
chmod +x ~/.vault_pass_script.sh
ansible-vault decrypt secrets.yml --vault-password-file ~/.vault_pass_script.sh

CI/CD Patterns

GitHub Actions

- name: Decrypt secrets
  run: |
    echo "${{ secrets.VAULT_PASSWORD }}" > /tmp/.vault_pass
    ansible-vault decrypt inventory/group_vars/all/vault.yml \
      --vault-password-file /tmp/.vault_pass
    rm /tmp/.vault_pass

GitLab CI

deploy:
  script:
    - echo "$VAULT_PASSWORD" > /tmp/.vault_pass
    - ansible-playbook -i inventory site.yml --vault-password-file /tmp/.vault_pass
  after_script:
    - rm -f /tmp/.vault_pass

Troubleshooting

"Decryption failed"

Wrong password. Verify:

# Try viewing first
ansible-vault view secrets.yml

"input is not vault encrypted data"

The file isn't encrypted or was corrupted:

# Check file header — should start with:
head -1 secrets.yml
# $ANSIBLE_VAULT;1.1;AES256

"Attempting to decrypt but no vault secrets found"

No password provided. Add one of:

--ask-vault-pass
--vault-password-file /path/to/pass
# or set ANSIBLE_VAULT_PASSWORD_FILE

Re-encrypt After Editing

# Decrypt, edit, re-encrypt
ansible-vault decrypt secrets.yml
vim secrets.yml
ansible-vault encrypt secrets.yml

# Or use edit (decrypt→editor→re-encrypt in one step)
ansible-vault edit secrets.yml

Vault Operations Reference

CommandDescription
ansible-vault encryptEncrypt a plaintext file
ansible-vault decryptDecrypt to plaintext
ansible-vault viewView without modifying
ansible-vault editDecrypt → edit → re-encrypt
ansible-vault rekeyChange the encryption password
ansible-vault encrypt_stringEncrypt a single value for inline use

Conclusion

ansible-vault decrypt is straightforward — provide the file and the password. For production workflows, use password files or scripts instead of interactive prompts, configure vault_password_file in ansible.cfg, and use ansible-vault edit instead of decrypt→edit→encrypt cycles. In CI/CD, inject the password from your secrets manager and clean up immediately after use. Never commit decrypted vault files to version control.