github ansible-collections/community.sops 2.5.0

3 hours ago

Release Summary

Feature release.

Minor Changes

  • decrypt filter plugin - the result of the filter is marked as a secret on ansible-core 2.22+ unless the new option register_result_as_secret is set to false. Note that the filter does not parse structured output, so invidiual values appearing in it are not registered (#304).
  • load_vars - a new option register_values_as_secrets allows to register all loaded values as secrets on ansible-core 2.22+. Note that this is not enabled by default since it can easily happen that non-sensitive, common words or phrases appear as values in encrypted files (#304).
  • sops lookup and sops vars plugin - the values for the age_key, aws_secret_access_key, aws_session_token, and gcp_oauth_access_token options are marked as secret on ansible-core 2.22+ (#304).
  • sops lookup plugin - the result of the lookup is marked as a secret on ansible-core 2.22+ unless the new option register_result_as_secret is set to false. Note that the lookup does not parse structured output, so invidiual values appearing in it are not registered (#304).
  • sops vars plugin - a new option register_values_as_secrets allows to register all loaded values as secrets on ansible-core 2.22+. Note that this is not enabled by default since it can easily happen that non-sensitive, common words or phrases appear as values in encrypted files (#304).

Bugfixes

  • load_vars - on ansible-core 2.22+, avoid deprecated function (#307).

Don't miss a new community.sops release

NewReleases is sending notifications on new releases.