0Pricing
Ansible Academy · Lesson

Edit, View & Rekey Vault Files

Manage encrypted content safely.

Edit, View & Rekey Vault Files is a free Ansible Academy lesson on CoddyKit — lesson 2 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Ansible Academy learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.

Living With Encrypted Files

Once a file is vaulted you still need to read it, change it and rotate its password. Vault has a subcommand for each job. 🔧

Never Edit by Hand

Opening the ciphertext in a normal editor only corrupts it. Always go through ansible-vault so it decrypts and re-encrypts for you.

Edit a Vaulted File

The ansible-vault edit command decrypts to a temp file, opens your editor, then re-encrypts on save. The plaintext never touches disk.

ansible-vault edit secrets.yml

View Without Changing

To peek at contents without risking edits, use ansible-vault view. It prints the decrypted text to your terminal.

ansible-vault view secrets.yml

Decrypt to Plaintext

ansible-vault decrypt permanently turns the file back into plaintext on disk. Use it with care, never on a tracked secrets file.

ansible-vault decrypt secrets.yml

Rekey: Rotate the Password

When a password leaks or a teammate leaves, ansible-vault rekey swaps the old password for a new one in one step.

ansible-vault rekey secrets.yml

Rekey Prompts

Rekey first asks for the current password, then for the new one twice. It re-encrypts the same secrets under the fresh key.

Vault password:
New Vault password:
Confirm New Vault password:

Operate on Many Files

Most subcommands accept several files at once, so you can rekey a whole folder of secrets in a single run.

ansible-vault rekey group_vars/all/vault.yml host_vars/db/vault.yml

Skip the Prompt with a File

Tired of typing? Point Vault at a password file so commands run without an interactive prompt.

ansible-vault view secrets.yml --vault-password-file .vault_pass

Confirm It Is Encrypted

Not sure of a file's state? Just look at the first line. If it shows the $ANSIBLE_VAULT header, it is still encrypted.

head -1 secrets.yml
$ANSIBLE_VAULT;1.1;AES256

Re-encrypt After Editing

You never call encrypt again after edit. The edit command always re-encrypts on save, so the file stays locked automatically.

Quick Check

A teammate left the company and knew the vault password.

Recap

You can now edit, view, decrypt and rekey vault files, all without ever leaving plaintext on disk. ✨

Frequently asked questions

Is the “Edit, View & Rekey Vault Files” lesson free?

Yes — the full text of “Edit, View & Rekey Vault Files” is free to read here on the web, and the Ansible Academy course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Ansible Academy course, upgrade to CoddyKit PRO.

What will I learn in “Edit, View & Rekey Vault Files”?

Manage encrypted content safely. You practise Ansible Academy with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.

Do I need any experience to start Ansible Academy?

No prior experience is required. Ansible Academy on CoddyKit is structured for beginners through advanced learners; this is — lesson 2 of 4, so you can start here or from the beginning and move at your own pace.

How long does the “Edit, View & Rekey Vault Files” lesson take?

Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.

Can I write and run code in this Ansible Academy lesson?

Yes. Every Ansible Academy lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.

All lessons in this course

  1. Encrypt a File with ansible-vault create
  2. Edit, View & Rekey Vault Files
  3. Encrypt a Single Variable Inline
  4. Decrypt at Runtime with --ask-vault-pass
← Back to Ansible Academy