File tree Expand file tree Collapse file tree 1 file changed +16
-1
lines changed Expand file tree Collapse file tree 1 file changed +16
-1
lines changed Original file line number Diff line number Diff line change 19
19
path : " {{ wazuh_secrets_path }}"
20
20
register : waz_exist_result
21
21
22
+ - name : Check if secret is encrypted
23
+ block :
24
+ - name : Try to decrypt secret
25
+ no_log : True
26
+ copy :
27
+ content : " {{ lookup('ansible.builtin.file', wazuh_secrets_path) | ansible.builtin.vault(ansible_vault_password) }}"
28
+ dest : " {{ wazuh_secrets_path }}"
29
+ decrypt : True
30
+ vars :
31
+ ansible_vault_password : " {{ lookup('ansible.builtin.env', 'KAYOBE_VAULT_PASSWORD') }}"
32
+ rescue :
33
+ - name : Secrets already decrypted
34
+ ansible.builtin.debug :
35
+ msg : ' Secret was already decrypted'
36
+ when : waz_exist_result.stat.exists
37
+
22
38
- name : Template new secrets
23
39
no_log : True
24
40
template :
34
50
decrypt : false
35
51
vars :
36
52
ansible_vault_password : " {{ lookup('ansible.builtin.env', 'KAYOBE_VAULT_PASSWORD') }}"
37
- when : not waz_exist_result.stat.exists
You can’t perform that action at this time.
0 commit comments