Skip to content

Store Architecture

lazyenv supports multiple secret stores without making the rest of the tool store‑specific.

lazyenv splits store concerns into two layers:

  • SecretStore (runtime): read/write secrets
  • SecretStoreAdmin (setup): list orgs/projects/environments, create projects, etc

In practice:

  • lazyenv sync/pull/run/get/list uses SecretStore
  • lazyenv init and interactive setup uses SecretStoreAdmin

Different stores represent “folders” differently.

  • Infisical supports native secret paths (real folders).
  • Doppler/Bitwarden/1Password are effectively flat namespaces, so lazyenv encodes folders as key prefixes.

If secretPath is /apps/web, the key stays the key:

  • folder: /apps/web
  • key: DATABASE_URL
  • stored as: /apps/web/DATABASE_URL

lazyenv converts the folder path to a prefix derived from the last path segment:

secretPathPrefixStored key
/(none)DATABASE_URL
/apps/webWEB__WEB__DATABASE_URL
/apps/apiAPI__API__JWT_SECRET
/packages/authAUTH__AUTH__CLIENT_ID

This keeps the local developer experience consistent even when the store doesn’t have true folders.

The store is selected explicitly:

  • lazyenv init --store ...
  • .lazyenv/config.json contains store and store-specific identifiers like projectId

Once configured, the CLI resolves store/project/env/folder using .lazyenv/config.json plus any flags.

See also: