- hosts: localhost gather_facts: no vars: # ansible-vault encrypt_string root # vault_password_file = test_vault_pass vaulted_root_string: !vault | $ANSIBLE_VAULT;1.1;AES256 39333565666430306232343266346635373235626564396332323838613063646132653436303239 3133363232306334393863343563366131373565616338380a666339383162333838653631663131 36633637303862353435643930393664386365323164643831363332666435303436373365393162 6535383134323539380a613663366631626534313837313565666665336164353362373431666366 3464 tasks: - name: make sure group root exists group: name: "{{ vaulted_root_string }}"