Skip to content

Commit 8c6dcce

Browse files
authored
Update wazuh-secrets.yml
1 parent 8fc30a7 commit 8c6dcce

File tree

1 file changed

+1
-25
lines changed

1 file changed

+1
-25
lines changed

etc/kayobe/ansible/wazuh-secrets.yml

Lines changed: 1 addition & 25 deletions
Original file line numberDiff line numberDiff line change
@@ -19,31 +19,6 @@
1919
path: "{{ wazuh_secrets_path }}"
2020
register: waz_exist_result
2121

22-
- name: Decrypt wazuh-secrets to checksum
23-
no_log: True
24-
copy:
25-
content: "{{ lookup('ansible.builtin.file', wazuh_secrets_path) | ansible.builtin.vault(ansible_vault_password) }}"
26-
dest: "{{ wazuh_secrets_path }}"
27-
decrypt: true
28-
vars:
29-
ansible_vault_password: "{{ lookup('ansible.builtin.env', 'KAYOBE_VAULT_PASSWORD') }}"
30-
when: waz_exist_result.stat.exists
31-
32-
- name: Template new secrets
33-
no_log: True
34-
template:
35-
src: wazuh-secrets.yml.j2
36-
dest: "/tmp/wazuh-secrets.yml"
37-
when: waz_exist_result.stat.exists
38-
39-
- name: Copy for checksum
40-
no_log: True
41-
copy:
42-
content: "{{ lookup('ansible.builtin.file', '/tmp/wazuh-secrets.yml') }}"
43-
dest: "{{ wazuh_secrets_path }}"
44-
checksum: yes
45-
when: waz_exist_result.stat.exists
46-
4722
- name: Template new secrets
4823
no_log: True
4924
template:
@@ -59,3 +34,4 @@
5934
decrypt: false
6035
vars:
6136
ansible_vault_password: "{{ lookup('ansible.builtin.env', 'KAYOBE_VAULT_PASSWORD') }}"
37+
when: not waz_exist_result.stat.exists

0 commit comments

Comments
 (0)