Switching Stores
lazyenv supports multiple secret stores (infisical, doppler, bitwarden, onepassword). Use lazyenv migrate to copy secrets and optionally update .lazyenv/config.json.
Store selection
Section titled “Store selection”- Default store is set in
.lazyenv/config.jsonasstore. - Most commands accept
--store <store>to override per command.
Recommended workflow: lazyenv migrate
Section titled “Recommended workflow: lazyenv migrate”Infisical -> Doppler
Section titled “Infisical -> Doppler”export INFISICAL_API_TOKEN="st.xxx"export DOPPLER_TOKEN="dp.st.xxx"
# Uses .lazyenv/config.json store + projectId as the source by default.lazyenv migrate --to doppler --project-to my-doppler-project --auto-map --forceDoppler -> Infisical
Section titled “Doppler -> Infisical”export DOPPLER_TOKEN="dp.st.xxx"export INFISICAL_API_TOKEN="st.xxx"
lazyenv migrate --from doppler --to infisical \ --project-from my-doppler-project \ --project-to xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx \ --organization-id xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx \ --auto-map --forceNotes:
- If you omit
--from, it defaults to.lazyenv/config.jsonstore. - If you omit
--project-from, it defaults to.lazyenv/config.jsonprojectId. - When switching to Infisical and updating config, you must provide
--organization-id(or have it set already).
See lazyenv migrate for all options.
Verification
Section titled “Verification”After migration, spot-check a few secrets and folders:
lazyenv list --env devlazyenv get DATABASE_URL --folder apps/webFolder mapping
Section titled “Folder mapping”lazyenv keeps your workspaceFolders[*].secretPath as the source of truth for folder layout:
- Infisical uses native folder paths like
/apps/web. - Doppler uses prefixes derived from the last path segment (e.g.
/apps/web->WEB__).
Examples:
| Folder Path | Doppler Prefix | Example Secret |
|---|---|---|
/ | (none) | DATABASE_URL |
/apps/web | WEB__ | WEB__DATABASE_URL |
/apps/api | API__ | API__JWT_SECRET |