An automation engineer stores a sudo password inside a project variable file that is committed to Git. The team requires that the cleartext value never appears in the repository and that playbooks still consume the variable transparently. Which approach meets this requirement?
Encrypting the variable file with ansible-vault encrypt keeps the plaintext password out of the Git repository while the playbook still loads the variables through vars_files at runtime, prompting for or receiving the vault password via --vault-password-file or --ask-vault-pass. This satisfies both the storage requirement and transparent consumption.
Why this answer
Ansible Vault encrypts files and individual values using AES-256 so that secrets can be safely stored in source control. Encrypting the whole variable file with ansible-vault encrypt and loading it through vars_files keeps the plaintext out of Git while playbooks still resolve the variable normally. Decryption happens at runtime using a vault password provided interactively or through a password file.
Exam trap
The trap here is assuming that .gitignore or environment variables provide equivalent protection to Ansible Vault, when only vault encryption keeps the secret usable by Ansible while remaining unreadable in the repository.