{% macro secret_field(name, label, hint, required, suffix) %}

{{ hint }}

{% endmacro %}
{{ job.plan.playbook|replace('_', ' ')|capitalize }}{{ job.plan.customer }} {{ job.plan.targets|length }} {{ 'host' if job.plan.targets|length == 1 else 'hosts' }} {{ job.mode }}
Awaiting credentialsUntil

Your reviewed scope and options stay unchanged.

One-run credentials {% if has_vault %}{{ secret_field('vault_password', 'Customer Vault password', 'Unlock the Vault for this customer. This is not your AIM Web sign-in password.', true, 'vault') }}{% endif %} {% if has_connection %}{{ secret_field('connection_password', 'Default connection password', 'Requested by Core. Inventory-defined credentials take precedence; this is not a forced override.', true, 'connection') }}{% endif %} {% if has_key %}
SSH key passphrase {% if key_from_vault %} {% endif %}
{{ secret_field('ssh_key_passphrase', 'Separate SSH key passphrase', 'Leave blank to use the customer Vault value.' if key_from_vault else 'Unlock the encrypted customer private key for this run.', not key_from_vault, 'key') }}
{% endif %}
How credentials are used

Used only for this job. AIM Web does not save passwords in plans, history or browser storage. Core performs Vault/key validation after the handoff; submission alone does not verify authentication.

Leaving this form does not cancel the job or extend its reservation. A submitted run continues independently.

Job {{ job.id[:12] }} · {{ job.plan.targets|join(', ') }}

One run only. Not saved by AIM Web.

Not now

Core validates the credentials next. No automatic retry.