Automating the search for secrets in git and ansible

Do you know what is stored in your git repository? Among the hundreds of commits, are there passwords from product servers that got there by mistake?

But what if the ansible script crashes when publishing and highlights the passwords in the log?

I will tell you about how we tried to automate such checks and what came of it.

Hello, Habr!

My name is Oleg, I work in a rather large bank for the Russian Federation, in the IT for IT division.

