Skip to content

CI/CD Integration

In CI, lazyenv should either run without prompts or fail fast if it would prompt.

FlagPurposeCommands
--yes / -ySkip prompts, use defaultsinit, sync, add
--non-interactiveFail if a command would prompt/guesssync, add
--forceSkip confirmation promptsdelete, migrate
--all-environmentsApply to all environmentssync, add, delete

Notes:

  • --yes is permissive. If lazyenv can’t decide safely, it may skip or prompt depending on the command.
  • --non-interactive is strict. Combine it with --yes for deterministic CI.
  1. Install lazyenv
  2. Export store auth env vars (see your store page)
  3. Run lazyenv sync --yes --non-interactive
name: lazyenv
on:
push:
branches: [main]
jobs:
sync:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 20
- name: Install lazyenv
run: |
corepack enable
pnpm add -g lazyenv
- name: Sync secrets (strict)
env:
# Store auth env vars:
# - Infisical: INFISICAL_API_TOKEN
# - Doppler: DOPPLER_TOKEN
# - Bitwarden: BITWARDEN_ACCESS_TOKEN + BITWARDEN_ORGANIZATION_ID
# - 1Password: OP_SERVICE_ACCOUNT_TOKEN
INFISICAL_API_TOKEN: ${{ secrets.INFISICAL_API_TOKEN }}
run: lazyenv sync --env prod --all-environments --yes --non-interactive
Terminal window
lazyenv sync --env prod --all-environments --yes --non-interactive
Terminal window
lazyenv add API_KEY "$API_VALUE" --all-environments --yes
Terminal window
lazyenv delete OLD_KEY --force

Set the store auth env vars as CI secrets: