First, create a key file, e.g., vault_pass_file, which ideally contains a long sequence of random characters.
In linux systems you could use pwgen to create a random password file:
pwgen 256 1 > vault_pass_file
Then, use this file to encrypt sensitive data, e.g., groups_vars/group.yml:
ANSI...