# Environment files in Vault

Store each environment file as one private Vault entry. The file contents, comments and formatting are preserved. These examples use `dreamlake/envs/dev-env` for development and `dreamlake/envs/prod-env` for production.

## Upload

Use a signed-in DreamLake CLI. Run these commands from the directory containing your environment files; replace `.env.dev` and `.env.prod` with your actual filenames.

```bash
# Development
dreamlake vault add --name dreamlake/envs/dev-env --file-name .env --stdin < .env.dev

# Production
dreamlake vault add --name dreamlake/envs/prod-env --file-name .env --stdin < .env.prod
```

`--stdin` reads the complete file without putting its contents in command arguments. `--file-name .env` saves a suggested filename; it does not create a local file. The Vault path and local filename are independent. Dots in Vault selectors identify fields, so the entry names use `dev-env` and `prod-env` rather than `dev.env` and `prod.env`.

Inspect metadata without printing secret values:

```bash
dreamlake vault show --name dreamlake/envs/dev-env
dreamlake vault show --name dreamlake/envs/prod-env
```

## Replace an existing entry

Read its current revision with `show`, then supply that revision explicitly:

```bash
dreamlake vault add --name dreamlake/envs/dev-env --if-match <revision> --file-name .env --stdin < .env.dev
```

Replace `<revision>` with the returned number. A revision mismatch means the entry changed; inspect it before trying again. Use the production path and file to update production.

## Restore

In the destination project directory, run this Python 3 snippet. It fetches the development file without printing its values, creates `.env` with owner-only permissions, and refuses to overwrite an existing file. Retrieval must succeed before the file is created.

```python
import os
import subprocess

data = subprocess.check_output([
    "dreamlake", "vault", "get", "--name", "dreamlake/envs/dev-env"
])
fd = os.open(".env", os.O_WRONLY | os.O_CREAT | os.O_EXCL, 0o600)
with os.fdopen(fd, "wb") as f:
    f.write(data)
print("Restored .env")
```

For production, change the Vault path to `dreamlake/envs/prod-env`. Keep restored files ignored by Git and let your application's usual dotenv loader read them.

Saving a file in Vault does not load it into your shell or deliver it to a remote run. `vault get --to-envs` on a whole-file entry exports one string; it does not parse dotenv lines into separate variables.

CLI syntax checked with DreamLake `0.23.0`. This guide does not upload any files automatically.
