Function: ansible-vault
ansible-vault is a natively compiled function defined in ansible.el.
Signature
(ansible-vault MODE STR PARAMS)
Documentation
Execute `ansible-vault` MODE on STR with the given PARAMS.
MODE is encrypt or decrypt.
STR is the string to be handled.
PARAMS is produced by ansible-vault-get-password and is meant to be an
list of args that can be passed to ansible-vault.
If the first line of STR is indented with whitespace, only those lines
in STR that match that whitespace will be handled by ansible-vault MODE.
The rest will be untouched.
The string that results will be returned.
See the man page ansible-vault(1) for more details.
Source Code
;; Defined in /nix/store/ihs1wd4idvapzygy87ss7ddr2pwcpsxg-emacs-packages-deps/share/emacs/site-lisp/elpa/ansible-20260607.1852/ansible.el
(defun ansible-vault (mode str params)
"Execute `ansible-vault` MODE on STR with the given PARAMS.
MODE is `encrypt' or `decrypt'.
STR is the string to be handled.
PARAMS is produced by `ansible-vault-get-password' and is meant to be an
list of args that can be passed to ansible-vault.
If the first line of STR is indented with whitespace, only those lines
in STR that match that whitespace will be handled by `ansible-vault MODE'.
The rest will be untouched.
The string that results will be returned.
See the man page `ansible-vault(1)' for more details."
(let* ((temp-file (make-temp-file "ansible-vault-ansible"))
(lines (split-string str "\n"))
(first-line (car lines))
(first-line-prefix (if (string-match "^[ \t]*" first-line)
(match-string 0 first-line)
""))
(same-indent-lines (cl-loop for line in lines
while (string-prefix-p first-line-prefix line)
collect line))
(rest-lines (nthcdr (length same-indent-lines) lines))
(cleaned-same-indent-lines
(mapconcat (lambda (line)
(replace-regexp-in-string
(format "^%s" (regexp-quote first-line-prefix))
"" line))
same-indent-lines
"\n")))
(write-region cleaned-same-indent-lines nil temp-file 'append)
(let ((output-buffer (generate-new-buffer " *ansible-vault-output*"))
(status nil))
(unwind-protect
(progn
;; call-process calls the binary directly without spawning /bin/sh
(let ((full-args (append (list mode) params (list temp-file))))
(setq status (apply #'call-process "ansible-vault" nil output-buffer nil full-args)))
(if (/= status 0)
(error "Error in `ansible-vault` execution! Exit code: %s" status)
;; Read the output directly from our isolated buffer
(let ((output (with-current-buffer output-buffer
(string-trim-right (buffer-string)))))
(delete-file temp-file)
(concat (mapconcat
(lambda (line) (concat first-line-prefix line))
(split-string output "\n")
"\n")
(when rest-lines
(concat "\n" (mapconcat 'identity rest-lines "\n")))))))
;; Ensure buffer cleanup happens even if errors occur
(when (buffer-live-p output-buffer)
(kill-buffer output-buffer))))))