Skip to main content

python-ansible-vault-rotate

GitHub License pre-commit CircleCI PyPI version codecov Quality Gate Status Maintainability Rating Security Rating

Advanced Python CLI to rotate the secret used for ansible vault inline secrets and files in a project

Features

  • Reencrypt vault files
  • Reencrypt inline vaulted secrets

Installation

It is strongly recommended to use pipx instead of pip if possible:

pipx install ansible-vault-rotate

Otherwise you can also use plain pip, but be warned that this might collide with your ansible installation globally!

pip install ansible-vault-rotate

Usage

Rekey given vault secret with new secret specified on CLI

ansible-vault-rotate --old-vault-secret-source file://my-vault-password \
                     --new-vault-secret-source my-new-secret \
                     --update-source-secret

Rekey only specific files (e.g. when using multiple keys per stage)

ansible-vault-rotate --old-vault-secret-source file://my-vault-password-<stage> \
                     --new-vault-secret-source my-new-secret \
                     --file-glob-pattern group_vars/<stage>/*.yml \
                     --update-source-secret

Getting help about all args

ansible-vault-rotate --help

Development

For development, you will need:

  • Python 3.9 or greater
  • Poetry

Install

poetry install

Run tests

poetry run pytest

Metadata

Release files for ansible-vault-rotate 2.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for ansible-vault-rotate 2.1.0
File Size Uploaded
ansible_vault_rotate-2.1.0.tar.gz 9.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for ansible-vault-rotate 2.1.0
File Interpreter ABI Platform
ansible_vault_rotate-2.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 24.4 kB

Release files / ansible_vault_rotate-2.1.0.tar.gz

Download URL ansible_vault_rotate-2.1.0.tar.gz
Size 9.8 kB
Tags Source
SHA-256 checksum
How to use checksums
f444aabb9b8e8b5561298edd602cd99f2b892b78a582011a341a9ff8596d006a
BLAKE2b-256 checksum
How to use checksums
3e3ed177c2e4e74e51b056039ec572e289b9269b57c0c36f59862470353103b9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/1.8.3 CPython/3.8.20 Linux/6.8.0-1020-aws

Release files / ansible_vault_rotate-2.1.0-py3-none-any.whl

Download URL ansible_vault_rotate-2.1.0-py3-none-any.whl
Size 14.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
6bf19e2d35864ba20bb439f47530996aa9ef81dadb75ecd9508e915d70d04e30
BLAKE2b-256 checksum
How to use checksums
14459a3c9690ce6677d461b851a14c6d8de2330a2ad6e7de83342e55990c6a05
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/1.8.3 CPython/3.8.20 Linux/6.8.0-1020-aws

Release history Release notifications | RSS feed

This release

2.1.0 This release

2 release files

2.0.0

2 release files

1.1.2

2 release files

1.1.1

2 release files

1.1.0

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page