Introduction
ansible-vault decrypt converts an encrypted vault file back to plaintext. This is essential for editing secrets, migrating to a new encryption method, or debugging vault-related issues. This guide covers all decryption methods — interactive, password files, vault IDs, and CI/CD automation.
Prerequisites
ansible-vault is included in every Ansible installation — no separate install needed.
# Verify availability
ansible-vault --version
Basic Decryption
Interactive (Prompt for Password)
ansible-vault decrypt secrets.yml
# Vault password: ********
# Decryption successful
Before:
$ANSIBLE_VAULT;1.1;AES256
65333637643363376438633838346563353666636433613032333663666137613839333564393238
3930333031633134346461303636623937353561643464390a...
After:
---
db_password: mysupersecretpassword
api_key: sk-1234567890abcdef
With Password File
# Password stored in a file
echo "mypassword" > ~/.vault_pass
chmod 600 ~/.vault_pass
# Decrypt using password file
ansible-vault decrypt secrets.yml --vault-password-file ~/.vault_pass
With Environment Variable
# Set password in environment
export ANSIBLE_VAULT_PASSWORD_FILE=~/.vault_pass
# Now decrypt without flags
ansible-vault decrypt secrets.yml
Decrypt to stdout (Don't Modify File)
View encrypted content without changing the file:
ansible-vault view secrets.yml
# Vault password: ********
# --- shows decrypted content ---
Or decrypt to a different file:
ansible-vault decrypt secrets.yml --output decrypted-secrets.yml
Vault IDs (Multiple Passwords)
When using different passwords for different environments:
# Encrypt with vault ID
ansible-vault encrypt --vault-id prod@~/.vault_pass_prod secrets-prod.yml
# Decrypt with vault ID
ansible-vault decrypt --vault-id prod@~/.vault_pass_prod secrets-prod.yml
# Multiple vault IDs
ansible-vault decrypt \
--vault-id dev@~/.vault_pass_dev \
--vault-id prod@~/.vault_pass_prod \
secrets.yml
Decrypt Inline Encrypted Variables
When only specific variables are encrypted (not the whole file):
# vars.yml — mixed plain and encrypted values
app_name: myapp
db_password: !vault |
$ANSIBLE_VAULT;1.1;AES256
65333637643363376438633838346563...
View the decrypted value:
# ansible-vault view doesn't work for inline — use ansible debug
ansible localhost -m debug -a "var=db_password" \
-e @vars.yml \
--vault-password-file ~/.vault_pass
Using Decryption in Playbooks
You don't need to manually decrypt files to use them in playbooks:
# Run playbook with vault password
ansible-playbook site.yml --ask-vault-pass
# Or with password file
ansible-playbook site.yml --vault-password-file ~/.vault_pass
ansible.cfg Configuration
[defaults]
vault_password_file = ~/.vault_pass
Now all vault operations work without flags:
ansible-playbook site.yml # Automatically uses vault password
ansible-vault decrypt secrets.yml # Also automatic
Script-Based Password Source
For dynamic password retrieval (e.g., from a password manager):
#!/bin/bash
# ~/.vault_pass_script.sh
# Fetch from 1Password, LastPass, AWS Secrets Manager, etc.
op read "op://DevOps/AnsibleVault/password"
chmod +x ~/.vault_pass_script.sh
ansible-vault decrypt secrets.yml --vault-password-file ~/.vault_pass_script.sh
CI/CD Patterns
GitHub Actions
- name: Decrypt secrets
run: |
echo "${{ secrets.VAULT_PASSWORD }}" > /tmp/.vault_pass
ansible-vault decrypt inventory/group_vars/all/vault.yml \
--vault-password-file /tmp/.vault_pass
rm /tmp/.vault_pass
GitLab CI
deploy:
script:
- echo "$VAULT_PASSWORD" > /tmp/.vault_pass
- ansible-playbook -i inventory site.yml --vault-password-file /tmp/.vault_pass
after_script:
- rm -f /tmp/.vault_pass
Troubleshooting
"Decryption failed"
Wrong password. Verify:
# Try viewing first
ansible-vault view secrets.yml
"input is not vault encrypted data"
The file isn't encrypted or was corrupted:
# Check file header — should start with:
head -1 secrets.yml
# $ANSIBLE_VAULT;1.1;AES256
"Attempting to decrypt but no vault secrets found"
No password provided. Add one of:
--ask-vault-pass
--vault-password-file /path/to/pass
# or set ANSIBLE_VAULT_PASSWORD_FILE
Re-encrypt After Editing
# Decrypt, edit, re-encrypt
ansible-vault decrypt secrets.yml
vim secrets.yml
ansible-vault encrypt secrets.yml
# Or use edit (decrypt→editor→re-encrypt in one step)
ansible-vault edit secrets.yml
Vault Operations Reference
| Command | Description |
|---|---|
ansible-vault encrypt | Encrypt a plaintext file |
ansible-vault decrypt | Decrypt to plaintext |
ansible-vault view | View without modifying |
ansible-vault edit | Decrypt → edit → re-encrypt |
ansible-vault rekey | Change the encryption password |
ansible-vault encrypt_string | Encrypt a single value for inline use |
Related Articles
- Ansible Vault: Encrypt and Decrypt Files
- Ansible Vault Complete Guide
- Ansible no_log: Hide Sensitive Output
- Ansible Best Practices Guide
- Ansible-Core Guide
Conclusion
ansible-vault decrypt is straightforward — provide the file and the password. For production workflows, use password files or scripts instead of interactive prompts, configure vault_password_file in ansible.cfg, and use ansible-vault edit instead of decrypt→edit→encrypt cycles. In CI/CD, inject the password from your secrets manager and clean up immediately after use. Never commit decrypted vault files to version control.