DevOps / Ansible Interview questions
Why should you avoid hardcoding secrets in playbooks?
A hardcoded password or API key in a playbook or variable file gets committed to version control history permanently - even deleting it in a later commit doesn't remove it from earlier history that anyone with repo access (or a leaked clone) can still read. Secrets in plain YAML also tend to leak into console output, CI logs, and backups far more easily than a value that's deliberately protected.
- name: Bad - visible in logs and version control ansible.builtin.debug: msg: "Password is hunter2" - name: Better - vault-encrypted and hidden from output ansible.builtin.mysql_user: password: "{{ vault_db_password }}" no_log: true
Ansible Vault exists specifically to solve this: it lets secrets live encrypted in the same repository as everything else, decrypted only in memory at runtime with a password the playbook itself never contains. Pairing vault-encrypted variables with no_log: true on tasks that touch sensitive values also prevents those values from appearing in Ansible's own console or log output during a run.
More Related questions...