Store Architecture
lazyenv supports multiple secret stores without making the rest of the tool store‑specific.
Two interfaces
Section titled “Two interfaces”lazyenv splits store concerns into two layers:
SecretStore(runtime): read/write secretsSecretStoreAdmin(setup): list orgs/projects/environments, create projects, etc
In practice:
lazyenv sync/pull/run/get/listusesSecretStorelazyenv initand interactive setup usesSecretStoreAdmin
Folder mapping (the hard part)
Section titled “Folder mapping (the hard part)”Different stores represent “folders” differently.
- Infisical supports native secret paths (real folders).
- Doppler/Bitwarden/1Password are effectively flat namespaces, so lazyenv encodes folders as key prefixes.
Infisical
Section titled “Infisical”If secretPath is /apps/web, the key stays the key:
- folder:
/apps/web - key:
DATABASE_URL - stored as:
/apps/web/DATABASE_URL
Doppler / Bitwarden / 1Password
Section titled “Doppler / Bitwarden / 1Password”lazyenv converts the folder path to a prefix derived from the last path segment:
secretPath | Prefix | Stored key |
|---|---|---|
/ | (none) | DATABASE_URL |
/apps/web | WEB__ | WEB__DATABASE_URL |
/apps/api | API__ | API__JWT_SECRET |
/packages/auth | AUTH__ | AUTH__CLIENT_ID |
This keeps the local developer experience consistent even when the store doesn’t have true folders.
Store selection
Section titled “Store selection”The store is selected explicitly:
lazyenv init --store ....lazyenv/config.jsoncontainsstoreand store-specific identifiers likeprojectId
Once configured, the CLI resolves store/project/env/folder using .lazyenv/config.json plus any flags.
See also: