python-ansible-vault-rotate
Advanced Python CLI to rotate the secret used for ansible vault inline secrets and files in a project
Features
- Reencrypt vault files
- Reencrypt inline vaulted secrets
Installation
It is strongly recommended to use pipx instead of pip if possible:
pipx install ansible-vault-rotate
Otherwise you can also use plain pip, but be warned that this might collide with your ansible installation globally!
pip install ansible-vault-rotate
Usage
Rekey given vault secret with new secret specified on CLI
ansible-vault-rotate --old-vault-secret-source file://my-vault-password \
--new-vault-secret-source my-new-secret \
--update-source-secret
Rekey only specific files (e.g. when using multiple keys per stage)
ansible-vault-rotate --old-vault-secret-source file://my-vault-password-<stage> \
--new-vault-secret-source my-new-secret \
--file-glob-pattern group_vars/<stage>/*.yml \
--update-source-secret
Getting help about all args
ansible-vault-rotate --help
Development
For development, you will need:
- Python 3.9 or greater
- Poetry
Install
poetry install
Run tests
poetry run pytest
Metadata
Release files for ansible-vault-rotate 2.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| ansible_vault_rotate-2.1.0.tar.gz | 9.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| ansible_vault_rotate-2.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 24.4 kB
Release files / ansible_vault_rotate-2.1.0.tar.gz
| Download URL | ansible_vault_rotate-2.1.0.tar.gz |
|---|---|
| Size | 9.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
f444aabb9b8e8b5561298edd602cd99f2b892b78a582011a341a9ff8596d006a
|
|
BLAKE2b-256 checksum How to use checksums |
3e3ed177c2e4e74e51b056039ec572e289b9269b57c0c36f59862470353103b9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
poetry/1.8.3 CPython/3.8.20 Linux/6.8.0-1020-aws
|
Release files / ansible_vault_rotate-2.1.0-py3-none-any.whl
| Download URL | ansible_vault_rotate-2.1.0-py3-none-any.whl |
|---|---|
| Size | 14.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
6bf19e2d35864ba20bb439f47530996aa9ef81dadb75ecd9508e915d70d04e30
|
|
BLAKE2b-256 checksum How to use checksums |
14459a3c9690ce6677d461b851a14c6d8de2330a2ad6e7de83342e55990c6a05
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
poetry/1.8.3 CPython/3.8.20 Linux/6.8.0-1020-aws
|