Welcome to the Power Users community on Codidact!
Power Users is a Q&A site for questions about the usage of computer software and hardware. We are still a small site and would like to grow, so please consider joining our community. We are looking forward to your questions and answers; they are the building blocks of a repository of knowledge we are building together.
Using the password_hash filter with an encrypted variable in Ansible
I'm trying to create a user on a number of hosts via Ansible. To do so I created the following task using the user module and the password_hash filter:
- name: Create user
ansible.builtin.user:
name: username
comment: "Some User"
password: "{{ user_password | password_hash('sha512', 'salt') }}"
update_password: always
group: username
state: present
shell: /bin/bash
This works fine as long as I have user_password defined as clear text in the corresponding variable file. But as soon as I store the password encrypted with Ansible vault I get the following error when I try to run the playbook:
fatal: [hostname]: FAILED! => {"msg": "Unexpected templating type error occurred on ({{ user_password | password_hash('sha512', 'salt') }}): secret must be unicode or bytes, not ansible.parsing.yaml.objects.AnsibleVaultEncryptedUnicode. secret must be unicode or bytes, not ansible.parsing.yaml.objects.AnsibleVaultEncryptedUnicode"}
1 answer
I managed to circumvent this problem by explicitly converting the AnsibleVaultEncryptedUnicode object into a string using the string filter:
- name: Create user
ansible.builtin.user:
name: username
comment: "Some User"
password: "{{ user_password | string | password_hash('sha512', 'salt') }}"
update_password: always
group: username
state: present
shell: /bin/bash

0 comment threads