# Ansible shell/command modules with Doppler

**URL:** <https://community.doppler.com/t/ansible-shell-command-modules-with-doppler/267>\
**Category:** Need Help\
**Created:** [July 27, 2021, 8:24pm UTC](https://community.doppler.com/t/ansible-shell-command-modules-with-doppler/267 "2021-07-27T20:24:00Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lily](https://avatars.discourse-cdn.com/v4/letter/l/97f17d/32.png) [@Lily](https://community.doppler.com/u/Lily)\
**Post date:** [July 27, 2021, 8:24pm UTC](https://community.doppler.com/t/ansible-shell-command-modules-with-doppler/267/1 "2021-07-27T20:24:00Z")

</div>

I was wondering if I could use Doppler with Ansible. I don’t see any native integrations with Ansible. I know that Ansible has a Hashicorp Vault plugin that uses secrets in Ansible playbooks…

[https://docs.ansible.com/ansible/latest/collections/community/hashi\_vault/hashi\_vault\_lookup.html#ansible-collections-community-hashi-vault-hashi-vault-lookup](https://docs.ansible.com/ansible/latest/collections/community/hashi_vault/hashi_vault_lookup.html#ansible-collections-community-hashi-vault-hashi-vault-lookup)

Since there seems to be no native support for Ansible and Doppler I was thinking I could just use the Doppler Cli with the Ansible Shell or command module? Or maybe the raw module? The reason I ask is that I don’t want Ansible to accidentally leak any of my Doppler secrets.

Is their any planned integrations with Ansible in the future?

Thank You

---

<div class="post-metadata">

**Author:** ![ryan-blunden](https://sea2.discourse-cdn.com/flex016/user_avatar/community.doppler.com/ryan-blunden/32/9_2.png) [@ryan-blunden](https://community.doppler.com/u/ryan-blunden)\
**Post date:** [July 27, 2021, 9:58pm UTC](https://community.doppler.com/t/ansible-shell-command-modules-with-doppler/267/2 "2021-07-27T21:58:08Z")

</div>

Hi @Lily and welcome to the Doppler community!

From taking a quick look at the Ansible docs, you should be able to use Ansible’s built-in support for environment variables with the Doppler CLI by running:

```auto
# `DOPPLER_TOKEN` environment variable must be set 
doppler run -- ansible-playbook playbook.yml

```

If triggering the playbook using a GitHub Action, the step could look like:

```auto
- name: Ansible Playbook
    run: doppler run -- ansible-playbook playbook.yml
    env:
        DOPPLER_TOKEN: ${{ secrets.DOPPLER_TOKEN }}

```

Then I believe inside your playbook, you can reference a Doppler injected environment variable using:

```auto
{{ lookup('env', 'SECRET_FROM_DOPPLER') }}

```

Let me know if that works as I’m not an Ansible user and need to get across it more.

We don’t yet have an Ansible integration, but I’ve added it to our engineering backlog and will let you know once it’s available (although I can’t offer an ETA at this stage).

---

<div class="post-metadata">

**Author:** ![rit001](https://sea2.discourse-cdn.com/flex016/user_avatar/community.doppler.com/rit001/32/382_2.png) [@rit001](https://community.doppler.com/u/rit001)\
**Post date:** [September 14, 2022, 9:53am UTC](https://community.doppler.com/t/ansible-shell-command-modules-with-doppler/267/4 "2022-09-14T09:53:12Z")

</div>

Ryan’s answer above currently seems to be the main documentation available for using Doppler with Ansible, so I’m posting this just to update it a little

To read a shell environment variable from within an Ansible script you would use

```auto
"{{ lookup('env', 'SECRET_FROM_DOPPLER') }}"

```

with a working example looking like

```auto
   var:
      stored_value: "{{ lookup('env', 'SECRET_FROM_DOPPLER') }}"

```

---

<div class="post-metadata">

**Author:** ![swasher](https://sea2.discourse-cdn.com/flex016/user_avatar/community.doppler.com/swasher/32/832_2.png) [@swasher](https://community.doppler.com/u/swasher)\
**Post date:** [August 4, 2023, 8:07am UTC](https://community.doppler.com/t/ansible-shell-command-modules-with-doppler/267/5 "2023-08-04T08:07:45Z")

</div>

But how select doppler’s config depent on ansible target? I have `prod` and `stage` servers with different secrets. I’m using Makefile, so command look as

`$ make deploy server=stage`

And makefile content is

```auto
deploy:
    wsl ansible-playbook --limit $(server) ansible/provision.yml

```

How I can swith between prod and stage doppler’s config in this case?

---

<div class="post-metadata">

**Author:** ![watsonian](https://sea2.discourse-cdn.com/flex016/user_avatar/community.doppler.com/watsonian/32/267_2.png) [@watsonian](https://community.doppler.com/u/watsonian)\
**Post date:** [August 4, 2023, 6:16pm UTC](https://community.doppler.com/t/ansible-shell-command-modules-with-doppler/267/6 "2023-08-04T18:16:06Z")

</div>

@swasher You’d probably need to adjust your deploy command to something like this:

```auto
wsl doppler run -p YOUR_DOPPLER_PROJECT -c $(server) -- ansible-playbook --limit $(server) ansible/provision.yml

```

This would assume that your Doppler configs share the same name as what you’re passing in via your `server`. Note that I’m not super familiar with usage for that `wsl` command you’re using, so you may need to tweak the command slightly. The main point is passing in the `-c` flag to designate which config you want used.

Let me know if that works for you. If not, I’ll see what else I can come up with for you!

Regards,  
-Joel
