Encrypt a Single Variable Inline
Mix plaintext and secret vars.
Encrypt a Single Variable Inline is a free DevOps Bootcamp lesson on CoddyKit. This is lesson 3 of 4. Any 3 lessons of this learning path are free to read in full — after that, CoddyKit PRO unlocks every lesson, plus hands-on practice with a built-in code editor and a 24/7 AI tutor. It is part of the DevOps Bootcamp learning path, and your progress syncs across the web and the CoddyKit app. The DevOps Bootcamp course includes 4 lessons in total.
Not Everything Is Secret
Sometimes one value in a file is sensitive while the rest is harmless. Encrypting the whole file feels heavy-handed. 🤔
Encrypt Just One Variable
Vault can encrypt a single value and leave the rest of the YAML readable. This keeps diffs clean and config browsable.
The encrypt_string Command
Use ansible-vault encrypt_string to turn one plaintext value into an encrypted blob you can paste into any vars file.
ansible-vault encrypt_string 's3cr3t' --name 'db_password'What It Outputs
The command prints a YAML key whose value uses the !vault tag followed by an indented ciphertext block.
db_password: !vault |
$ANSIBLE_VAULT;1.1;AES256
39653764...Paste Into Your Vars
Copy that block straight into group_vars or a play's vars, sitting right beside ordinary plaintext variables.
vars:
app_user: deploy
db_password: !vault |
$ANSIBLE_VAULT;1.1;AES256
39653764...The !vault Tag
The !vault tag is a signal to Ansible: this single value is encrypted and must be decrypted before use.
Used Like Any Variable
At run time the value decrypts transparently. You reference it with normal {{ }} syntax, exactly like a plain var.
- name: Set DB password
debug:
msg: "{{ db_password }}"Avoid Plaintext on the Command Line
Putting a secret in your shell history is risky. Add --stdin-name to type the value interactively instead.
ansible-vault encrypt_string --stdin-name 'db_password'Inline vs Whole File
Inline encryption shines for a few secrets among public config. For files that are all secret, encrypting the whole file is simpler.
Same Password Either Way
Inline values use the same vault password as full-file encryption, so Ansible decrypts both with one passphrase per run.
Diffs Stay Reviewable
A big win: only the secret line is ciphertext, so code review and git diff still show every non-secret change clearly.
Quick Check
You want one value encrypted while the rest of the vars file stays readable.
Recap
With encrypt_string you encrypt one value into a !vault block, mixing secrets and plaintext in the same readable file. ✨
Learn DevOps Bootcamp with an AI tutor — free
Write and run real code in your browser, get instant help from a 24/7 AI tutor, and pick up where you left off on the web or in the app.
- Courses
- 142
- Lessons
- 568
Frequently Asked Questions
Is the “Encrypt a Single Variable Inline” lesson free?
Yes — any 3 lessons of the DevOps Bootcamp learning path, including “Encrypt a Single Variable Inline”, are free to read in full here on the web. After that, CoddyKit PRO unlocks every lesson, plus interactive practice with a built-in code editor and a 24/7 AI tutor. The DevOps Bootcamp course includes 4 lessons in total.
What will I learn in “Encrypt a Single Variable Inline”?
Mix plaintext and secret vars. You practise DevOps Bootcamp with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.
Do I need any experience to start DevOps Bootcamp?
No prior experience is required. DevOps Bootcamp on CoddyKit is structured for beginners through advanced learners, so you can start here or from the beginning and move at your own pace. This is lesson 3 of 4.
How long does the “Encrypt a Single Variable Inline” lesson take?
Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.
Can I write and run code in this DevOps Bootcamp lesson?
Yes. Every DevOps Bootcamp lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.
All lessons in this course
- Encrypt a File with ansible-vault create
- Edit, View & Rekey Vault Files
- Encrypt a Single Variable Inline
- Decrypt at Runtime with --ask-vault-pass