Function: ansible-vault

ansible-vault is a natively compiled function defined in ansible.el.

Signature

(ansible-vault MODE STR PARAMS)

Documentation

Execute `ansible-vault` MODE on STR with the given PARAMS.

MODE is encrypt or decrypt.

STR is the string to be handled.

PARAMS is produced by ansible-vault-get-password and is meant to be an list of args that can be passed to ansible-vault.

If the first line of STR is indented with whitespace, only those lines in STR that match that whitespace will be handled by ansible-vault MODE. The rest will be untouched.

The string that results will be returned.

See the man page ansible-vault(1) for more details.

Source Code

;; Defined in /nix/store/ihs1wd4idvapzygy87ss7ddr2pwcpsxg-emacs-packages-deps/share/emacs/site-lisp/elpa/ansible-20260607.1852/ansible.el
(defun ansible-vault (mode str params)
  "Execute `ansible-vault` MODE on STR with the given PARAMS.

MODE is `encrypt' or `decrypt'.

STR is the string to be handled.

PARAMS is produced by `ansible-vault-get-password' and is meant to be an
list of args that can be passed to ansible-vault.

If the first line of STR is indented with whitespace, only those lines
in STR that match that whitespace will be handled by `ansible-vault MODE'.
The rest will be untouched.

The string that results will be returned.

See the man page `ansible-vault(1)' for more details."
  (let* ((temp-file (make-temp-file "ansible-vault-ansible"))
         (lines (split-string str "\n"))
         (first-line (car lines))
         (first-line-prefix (if (string-match "^[ \t]*" first-line)
                                (match-string 0 first-line)
                              ""))
         (same-indent-lines (cl-loop for line in lines
                                     while (string-prefix-p first-line-prefix line)
                                     collect line))
         (rest-lines (nthcdr (length same-indent-lines) lines))
         (cleaned-same-indent-lines
          (mapconcat (lambda (line)
                       (replace-regexp-in-string
                        (format "^%s" (regexp-quote first-line-prefix))
                        "" line))
                     same-indent-lines
                     "\n")))
    (write-region cleaned-same-indent-lines nil temp-file 'append)

    (let ((output-buffer (generate-new-buffer " *ansible-vault-output*"))
          (status nil))
      (unwind-protect
          (progn
            ;; call-process calls the binary directly without spawning /bin/sh
            (let ((full-args (append (list mode) params (list temp-file))))
              (setq status (apply #'call-process "ansible-vault" nil output-buffer nil full-args)))

            (if (/= status 0)
                (error "Error in `ansible-vault` execution! Exit code: %s" status)
              ;; Read the output directly from our isolated buffer
              (let ((output (with-current-buffer output-buffer
                              (string-trim-right (buffer-string)))))
                (delete-file temp-file)
                (concat (mapconcat
                         (lambda (line) (concat first-line-prefix line))
                         (split-string output "\n")
                         "\n")
                        (when rest-lines
                          (concat "\n" (mapconcat 'identity rest-lines "\n")))))))
        ;; Ensure buffer cleanup happens even if errors occur
        (when (buffer-live-p output-buffer)
          (kill-buffer output-buffer))))))