For example:
$ mkdir -p ./inventories/group_vars/all/{vars,vault}
$ ansible-vault create ./inventories/group_vars/all/vault/all.yml
$ ansible-vault edit ./inventories/group_vars/all/vault/all.yml
vaulted_vcenter_username: <username>
vaulted_vcenter_password: <password>
$ vim ./inventories/group_vars/all/vars/all.yml
vcenter_username: "{{ vaulted_vcenter_username }}"
vcenter_password: "{{ vaulted_vcenter_password }}"
Then use vcenter_username & vcenter_password in your roles or plays (with a .vault_pass or --ask-vault-pass as required).