Credentials

Read a stored credential in an expression


Read a stored credential by name or by regular expression, with a fallback:

fn.fnCredentials('credentialname_or_regex','fallback_credentialname_or_regex')

// Try to use `fnRestBasic` and `fnRestJwtSecure` if possible, this avoids passwords and tokens going over the network.

// output : a credential object with all properties (user, password, host, port)

The exact name is tried first. When no credential has that name, the name is used as a regular expression, and then the fallback is tried.

Credentials from a secret store

A credential that names a secret store gets its user and password from that store at runtime. fn.fnCredentials('myapp') keeps working unchanged.

A secret can also be read without a credential row, wherever a credential name is accepted (including fnRestBasic, fnRestJwtSecure and the header substitutions of fnRestAdvanced):

fn.fnCredentials('secret:vault:secret/ontap')   // secret:<store>:<reference>
fn.fnCredentials('vault:secret/ontap')          // the store named `vault`

The keys of the secret are mapped as described under Key names. A secret with another shape is reshaped with a jq expression as the third argument:

// secret: { "creds": { "u": "admin", "p": "Netapp12" } }
fn.fnCredentials('vault:secret/weird','','.creds | { user: .u, password: .p }')

Copyright © 2023-2026 AnsibleForms. All rights reserved.

This site uses Just the Docs, a documentation theme for Jekyll.