Memory hook: Render the right file, enforce the right access, protect the secret.
Must remember
copy transfers static content; template renders Jinja using variables and facts. Quote and validate input data, set ownership/mode deliberately and use supported validation before replacing a critical configuration file. A configuration template should produce stable output when inputs have not changed.
Use user/group modules to manage identity state. Distinguish a user's primary group from supplementary groups; replacing the full supplementary group list can remove required access if append behavior was intended. Password values must use the form expected by the target module/system. SSH authorized keys need correct identity, path and file permissions.
Unix ownership/modes and SELinux policy are separate controls. Restore the appropriate labels and define persistent file-context mappings where needed; a one-time label change may not survive relabeling. Use supported SELinux booleans or policy configuration for the actual service need instead of disabling enforcement to hide a denial.
Ansible Vault encrypts sensitive variable files or values at rest. Supply the correct vault identity/password through an approved mechanism and keep that password separate from the encrypted content. Vault does not automatically protect decrypted values in logs, templates, temporary files or destination systems. Use no_log where needed while retaining enough nonsecret evidence to diagnose failures. Ansible debugging can still expose sensitive data; do not assume no_log protects every debug path.
Review rendered files and diffs for accidental secret exposure. File mode should fit the consuming process and least privilege. Backups of old configurations can contain secrets too. Re-keying Vault changes its encryption credential; rotating a real application password is a separate operation that also requires updating consumers safely.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Host-specific configuration file | Template with validated variables and controlled permissions. |
| Encrypted variables in source control | Vault plus separately protected decryption credentials. |
| Service denied despite correct Unix permissions | Inspect SELinux contexts/booleans and audit evidence. |
Traps
- Vault encryption does not redact every runtime use of a value.
- Disabling SELinux does not fix the intended policy configuration.
Active recall
1. copy versus template?
Static content transfer versus variable-driven rendering.
2. Why be careful with supplementary groups?
A replacement can remove existing access that should remain.
3. Why make SELinux mappings persistent?
Relabeling or reboot-related processes can undo temporary label changes.
4. What does no_log help protect?
Task output that might expose sensitive values; it is not a full system-wide secret solution.
5. Vault rekey versus application secret rotation?
Change encryption protection of stored content versus change the credential used by the application.