Get started

What is one.manifest.json

The workspace's project registry, environment configuration, and local development settings.

6 min readUpdated 3 days agoEdit on GitHub

Every One CLI workspace has a one.manifest.json at its root. It records the workspace identity, projects, environments, and environment-variable source. Commands use it to find projects and select their toolchains.

Example

{
  "version": 1,
  "workspace": {
    "id": "demo-app-2bb61e",
    "name": "demo-app"
  },
  "environments": {
    "names": [
      "dev",
      "preview",
      "prod"
    ],
    "default": "dev"
  },
  "projects": [
    {
      "name": "web",
      "templateId": "react-spa",
      "relativeDir": "apps/web",
      "toolchain": "node",
      "buildVersion": "0.1.0",
      "packageManager": "pnpm",
      "env": {
        "path": "/apps/web",
        "inherits": true,
        "keys": [
          "API_URL"
        ]
      },
      "dev": {
        "command": "pnpm dev"
      }
    },
    {
      "name": "api",
      "templateId": "go-api",
      "relativeDir": "services/api",
      "toolchain": "go",
      "dev": {
        "command": "go run ./cmd/server"
      }
    }
  ],
  "env": {
    "siteUrl": "https://app.infisical.com",
    "projectId": "your-project-id",
    "rootPath": "/"
  }
}

The real file is strict JSON; comments and unknown fields are rejected.

Fields

FieldMeaning
versionManifest schema version, currently 1
workspaceStable id and display name
environmentsEnvironment names and default environment
envOptional Infisical binding: siteUrl, projectId, projectName, rootPath, and keys
projects[]Project names, paths, templates, toolchains, optional packageManager and buildVersion
projects[].envEnvironment overrides: path, inherits, disabled, and declared key names; inherits the workspace backend
projects[].devThe command executed by one dev, plus an optional local Dashboard access url

For Infisical, env can contain projectId, projectName, rootPath, and keys. Key values and local Profile names never belong in the manifest. Keep credentials in the system keyring and values in Infisical.

Who writes it

ActionChange
one createWrites workspace identity, default environments, and an empty project list; leaves env unset
one addRegisters a project and its development command
one env setRecords declared key names; Infisical can initialize its project binding
one serveApplies explicitly reviewed project or environment-source changes with revision checks

one build selects each project's build command from its toolchain. Node projects use package scripts; Go projects use Taskfile.yml. Workspace tasks and the ordinary ci aggregate run through one run.

Manual edits

Keep paths and names consistent when renaming or removing projects. Update projects[].dev.command if the project's development script changes. The workspace layout remains apps/, services/, and packages/.

If the manifest and filesystem disagree, inspect the declared paths and restore the missing project files or fix the registry entry. Do not put business values, dependencies, caches, or build outputs in the manifest.

Removed deployment configuration

The deploy and container domains have been removed. A manifest containing those fields returns MANIFEST_INVALID with a removal hint. Delete the corresponding fields manually; no migration or cleanup of existing Dockerfiles, platform configuration, or CI files is performed.

Invalid JSON or unknown fields also produce MANIFEST_INVALID. See error codes.

Migration from domains

The domains wrapper is no longer accepted. Move an Infisical workspace binding from domains.env.config to top-level env, and move project domains.env / domains.dev to env / dev. Remove kind and config wrappers. For a former dotenv workspace, remove the old binding and any local-file path overrides; bind Infisical when needed.

Old manifests return MANIFEST_INVALID with a migration hint. One CLI does not rewrite manifests or import/delete existing .env files. Move required values to Infisical explicitly. The env pull and switch subcommands and the --env-provider flag have been removed. Legacy preset code d remains reserved and is rejected; use i or omit the environment segment.