Skip to main content
Infisical supports migrating existing resources from Vault and Doppler. A migration can be performed either through an ongoing in-platform connection to the source, or through a one-time bulk import.

Per-platform guides

The guides below cover the migration process for each supported platform. Each guide includes the steps to configure the connection, a description of which resources can be migrated, and any translation that Infisical performs during the import.

Vault

Migrate KV secrets, Kubernetes authentication configuration, dynamic secret configurations, and policies from HashiCorp Vault.

Doppler

Migrate secrets from Doppler projects and configs, including both root and branch environments.
If a platform isn’t listed, open an issue on the Infisical repository to request support for it.

Migration approaches

The guides above use one of the following two migration approaches.
  • In-platform migration. Infisical connects to the source platform using an App Connection that is scoped either to a single project or to the entire organization. Resources can be imported on demand from any location where the connection is available. This approach is supported for Vault and Doppler.
  • Bulk one-time import. Infisical performs a one-time, organization-wide import using credentials provided at the time of the import. This approach is suitable for an initial cutover when moving entirely from another platform to Infisical. It’s supported for HashiCorp Vault. See the bulk import section of the Vault guide for details.