Arguments for/against using vault password files

Hi everyone,

I would appreciate hearing peoples’ various arguments for/against using vault password files versus manually entering passwords.

I’ve been manually entering in vault passwords as I didn’t want to leave keys on my laptop in case stolen / compromised. I’ve seen posts about configuring git to decrypt vault files for diffing purposes using vault password files for ease. After my knee-jerk wtf, I started thinking about it in terms of using SSH identity and authorized key for traversing hosts within your network easily.

Thank you for your thoughts and insights,
Andy

Another option, IMO is to use GPG https://github.com/ansible/ansible/pull/7174