Skip to content

Provisioners

Provisioners are optional helpers that can produce secret values during lazyenv sync instead of always prompting.

Configure them in .lazyenv/config.json:

  • provisioners: the definitions (what to run / what outputs exist)
  • provisionerRules: binds keys (via match patterns) to a provisioner type and behavior
  • browser: guided/automated browser flows (OAuth setup, etc.), with stagehand or playwright engines
  • generator: local generators (random bytes, UUIDs)
  • program: run a local program/script to produce outputs

During lazyenv sync, if a key matches a provisionerRules[].match, lazyenv can provision it based on the rule:

  • onMissing: what to do when the key is missing
  • onExists: what to do when the key already exists (rotation)
  • allowNonInteractive: opt-in for CI use with --yes --non-interactive

See also: CLI Commands.