Skip to content

Commit d3e36dc

Browse files
authored
Merge pull request #1171 from stackhpc/Hide-Wazuh-Secrets
Encrypt wazuh-secrets.yml once templated
2 parents 76b384d + 4b84af2 commit d3e36dc

File tree

1 file changed

+8
-6
lines changed

1 file changed

+8
-6
lines changed

etc/kayobe/ansible/wazuh-secrets.yml

Lines changed: 8 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -15,13 +15,15 @@
1515
state: directory
1616

1717
- name: Template new secrets
18+
no_log: True
1819
template:
1920
src: wazuh-secrets.yml.j2
2021
dest: "{{ wazuh_secrets_path }}"
21-
notify: Please encrypt keys
2222

23-
handlers:
24-
- name: Please encrypt keys
25-
debug:
26-
msg: >-
27-
Please encrypt the keys using Ansible Vault.
23+
- name: In-place encrypt wazuh-secrets
24+
copy:
25+
content: "{{ lookup('ansible.builtin.file', wazuh_secrets_path) | ansible.builtin.vault(ansible_vault_password) }}"
26+
dest: "{{ wazuh_secrets_path }}"
27+
decrypt: false
28+
vars:
29+
ansible_vault_password: "{{ lookup('ansible.builtin.env', 'KAYOBE_VAULT_PASSWORD') }}"

0 commit comments

Comments
 (0)