Release Summary
Feature release.
Minor Changes
- decrypt filter plugin - the result of the filter is marked as a secret on ansible-core 2.22+ unless the new option
register_result_as_secretis set tofalse. Note that the filter does not parse structured output, so invidiual values appearing in it are not registered (#304). - load_vars - a new option
register_values_as_secretsallows to register all loaded values as secrets on ansible-core 2.22+. Note that this is not enabled by default since it can easily happen that non-sensitive, common words or phrases appear as values in encrypted files (#304). - sops lookup and sops vars plugin - the values for the
age_key,aws_secret_access_key,aws_session_token, andgcp_oauth_access_tokenoptions are marked as secret on ansible-core 2.22+ (#304). - sops lookup plugin - the result of the lookup is marked as a secret on ansible-core 2.22+ unless the new option
register_result_as_secretis set tofalse. Note that the lookup does not parse structured output, so invidiual values appearing in it are not registered (#304). - sops vars plugin - a new option
register_values_as_secretsallows to register all loaded values as secrets on ansible-core 2.22+. Note that this is not enabled by default since it can easily happen that non-sensitive, common words or phrases appear as values in encrypted files (#304).
Bugfixes
- load_vars - on ansible-core 2.22+, avoid deprecated function (#307).