DreamLake

Environment files in Vault

Store each environment file as one private Vault entry. The file contents, comments and formatting are preserved. These examples use dreamlake/envs/dev-env for development and dreamlake/envs/prod-env for production.

Upload

Use a signed-in DreamLake CLI. Run these commands from the directory containing your environment files; replace .env.dev and .env.prod with your actual filenames.

bash
# Development
dreamlake vault add --name dreamlake/envs/dev-env --file-name .env --stdin < .env.dev

# Production
dreamlake vault add --name dreamlake/envs/prod-env --file-name .env --stdin < .env.prod

--stdin reads the complete file without putting its contents in command arguments. --file-name .env saves a suggested filename; it does not create a local file. The Vault path and local filename are independent. Dots in Vault selectors identify fields, so the entry names use dev-env and prod-env rather than dev.env and prod.env.

Inspect metadata without printing secret values:

bash
dreamlake vault show --name dreamlake/envs/dev-env
dreamlake vault show --name dreamlake/envs/prod-env

Replace an existing entry

Read its current revision with show, then supply that revision explicitly:

bash
dreamlake vault add --name dreamlake/envs/dev-env --if-match <revision> --file-name .env --stdin < .env.dev

Replace <revision> with the returned number. A revision mismatch means the entry changed; inspect it before trying again. Use the production path and file to update production.

Restore

In the destination project directory, run this Python 3 snippet. It fetches the development file without printing its values, creates .env with owner-only permissions, and refuses to overwrite an existing file. Retrieval must succeed before the file is created.

python
import os
import subprocess

data = subprocess.check_output([
    "dreamlake", "vault", "get", "--name", "dreamlake/envs/dev-env"
])
fd = os.open(".env", os.O_WRONLY | os.O_CREAT | os.O_EXCL, 0o600)
with os.fdopen(fd, "wb") as f:
    f.write(data)
print("Restored .env")

For production, change the Vault path to dreamlake/envs/prod-env. Keep restored files ignored by Git and let your application's usual dotenv loader read them.

Saving a file in Vault does not load it into your shell or deliver it to a remote run. vault get --to-envs on a whole-file entry exports one string; it does not parse dotenv lines into separate variables.

CLI syntax checked with DreamLake 0.23.0. This guide does not upload any files automatically.