feat: public dotfiles tier — no credential, no identity, one installer
Fresh history. This is the repo a throwaway VM clones anonymously: it brings a
machine to a working baseline and carries nothing that makes it mine.
56 files. 50 land in $HOME, 3 are chezmoi metadata, 2 are repo documentation,
1 is the manifest, and a 15-file test harness stays behind in .tests/.
What did not travel, and why:
encrypted_private_bws-token.age a real credential; age is dropped entirely
.chezmoidata/bws.toml env-var -> secret-id map; belongs with the
tier that can use it
SECRETS.md documentation of the rules, not config
finish-setup.sh.tmpl superseded by dotup
nvim/init.lua.backup dead file
dot_claude/**, dot_codex/**, 120 files of agent config, private tier
dot_pi/**
De-identified rather than dropped:
.gitconfig [user], the GitHub ssh rewrite and both Gitea host rewrites are
identity, not configuration. They move behind an [include] of
~/.config/git/config.local, which the private tier writes. Git
treats a missing include as a no-op, so a public-only machine
reads the file and stops.
.zshrc the two gitea aliases carried a personal domain and a LAN IP.
They move behind a guarded source of ~/.config/zsh/local.zsh,
the sibling of the secrets.zsh seam phase 2 established.
nvim a commented-out LM Studio endpoint naming a LAN address.
ghostty a stale auto-generated header naming an absolute home directory.
Newly captured, never tracked before: ~/.zshenv, ~/.config/gh/config.yml. The
former sourced ~/.cargo/env unguarded, so every zsh on a machine without rustup
printed an error -- the same shape as the unguarded oh-my-zsh source phase 2
fixed. It is guarded now.
.chezmoiexternal.toml grows from one entry to six. oh-my-zsh, powerlevel10k,
zsh-autosuggestions, zsh-ai and tpm were hand-installed and declared nowhere,
which is why `chezmoi init --apply` on a clean box produced a .zshrc that broke
the shell it configures. The theme and both plugins nest under
.oh-my-zsh/custom/, which is what $ZSH_CUSTOM resolves to.
dotup gains an install engine. It resolves each selected package to a channel
(apt, brew, npm, uv, snap, deb, flatpak, tarball, script, builtin) through one
function every consumer reads, probes apt-cache before batching so a name apt
does not know moves to brew instead of failing all thirty, and retries
individually if a batch still fails -- which earned its keep on the first real
container run, where mermaid-cli's puppeteer dependency failed and the other
twelve npm packages installed anyway. --unattended computes safe defaults fresh
from the manifest rather than inheriting a state file, and refuses private and
invasive rows outright even when a stale state file ticks them.
The manifest gains @spec, a second directive kind alongside @needs, carrying the
argument a channel needs but a package name cannot supply -- the scoped npm
name, the flatpak app id, the .deb source. The TSV stays five columns wide.
Three bugs the container runs found, all fixed here:
* `apt install nodejs` gives you node WITHOUT npm on Ubuntu, so all thirteen
npm packages failed on a fresh box. The manifest asks apt for both names.
* A tool installed a moment ago is not on this process's PATH -- uv lands in
~/.local/bin, npm -g honours the ~/.npmrc prefix, linuxbrew is outside a
non-login PATH. Resolved by looking in the places we just wrote to, never by
exporting a modified PATH.
* `A || { B && C; }` is one || list, so when `command -v sudo` failed the list
failed and `set -e` killed dotup at load. On a non-root machine with no
sudo it died before printing anything. There is a regression test.
.zshenv and .p10k.zsh are marked private_. Both are shell code the login shell
executes and both applied at 664, group-writable. Third occurrence of the class
of bug phase 1 found on .pi/agent/auth.json and phase 2 found on .zshrc; the
first one found on purpose rather than by accident.
Verification: 81 assertions, 81/81 on this box and in ubuntu:24.04, ubuntu:22.04
and debian:12. The installer is driven against a directory of fake package
managers that record what they were asked to do and install nothing, so the
engine is exercised end to end without a package landing on the test machine.
`gitleaks detect` over the full history and the working tree: no leaks found,
with no allowlist and no .gitleaks.toml.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,210 @@
|
||||
# LazyVim Plugin Cheatsheet
|
||||
|
||||
Quick reference for the custom plugins in your configuration.
|
||||
|
||||
---
|
||||
|
||||
## Git Tools (`lua/plugins/git.lua`)
|
||||
|
||||
### git-blame.nvim
|
||||
Shows git blame information at the end of each line.
|
||||
|
||||
**Commands:**
|
||||
- `:GitBlameToggle` - Toggle git blame on/off
|
||||
- `:GitBlameEnable` - Enable git blame
|
||||
- `:GitBlameDisable` - Disable git blame
|
||||
- `:GitBlameOpenCommitURL` - Open commit in browser
|
||||
- `:GitBlameCopySHA` - Copy commit SHA to clipboard
|
||||
|
||||
**Default:** Enabled on startup
|
||||
|
||||
---
|
||||
|
||||
### diffview.nvim
|
||||
Advanced git diff and history viewer.
|
||||
|
||||
**Key Bindings:**
|
||||
- `<leader>gd` - Open diff view of current changes
|
||||
- `<leader>gh` - View current file's git history
|
||||
- `<leader>gH` - View entire repo's git history
|
||||
|
||||
**Commands:**
|
||||
- `:DiffviewOpen` - Open diff view
|
||||
- `:DiffviewClose` - Close diff view
|
||||
- `:DiffviewFileHistory` - View repo history
|
||||
- `:DiffviewFileHistory %` - View current file history
|
||||
- `:DiffviewRefresh` - Refresh the diff view
|
||||
|
||||
**In Diffview:**
|
||||
- `]c` / `[c` - Jump to next/previous change
|
||||
- `<tab>` / `<S-tab>` - Select next/previous file
|
||||
- `gf` - Open file in new tab
|
||||
- `q` - Close diffview
|
||||
|
||||
---
|
||||
|
||||
## UI Enhancements (`lua/plugins/ui-enhancements.lua`)
|
||||
|
||||
### render-markdown.nvim
|
||||
Renders markdown with better formatting while editing.
|
||||
|
||||
**Features:**
|
||||
- Automatically styles headers, lists, code blocks
|
||||
- Works only in markdown files
|
||||
- No commands needed - always active in `.md` files
|
||||
|
||||
**Toggle:** Disable by setting `enabled = false` in config
|
||||
|
||||
---
|
||||
|
||||
### hlargs.nvim
|
||||
Highlights function arguments with different colors.
|
||||
|
||||
**Features:**
|
||||
- Automatically highlights function parameters
|
||||
- Helps distinguish arguments visually
|
||||
- Works across all supported languages
|
||||
|
||||
**No commands needed** - always active
|
||||
|
||||
---
|
||||
|
||||
### twilight.nvim
|
||||
Dims inactive code to focus on current block.
|
||||
|
||||
**Key Bindings:**
|
||||
- `<leader>ut` - Toggle Twilight mode
|
||||
|
||||
**Commands:**
|
||||
- `:Twilight` - Toggle twilight
|
||||
- `:TwilightEnable` - Enable twilight
|
||||
- `:TwilightDisable` - Disable twilight
|
||||
|
||||
**Best for:** Focusing on specific functions or code blocks
|
||||
|
||||
---
|
||||
|
||||
### theme-hub.nvim
|
||||
Browse and switch colorschemes with live preview.
|
||||
|
||||
**Key Bindings:**
|
||||
- `<leader>uT` - Open Theme Hub
|
||||
|
||||
**Commands:**
|
||||
- `:ThemeHub` - Open theme browser
|
||||
|
||||
**In Theme Hub:**
|
||||
- `j` / `k` - Navigate themes
|
||||
- `<CR>` - Apply selected theme
|
||||
- `<Esc>` / `q` - Close without applying
|
||||
|
||||
---
|
||||
|
||||
## Search Tools (`lua/plugins/search.lua`)
|
||||
|
||||
### nvim-hlslens
|
||||
Enhanced search highlighting with match counts.
|
||||
|
||||
**Key Bindings:**
|
||||
- `n` - Next search result (enhanced)
|
||||
- `N` - Previous search result (enhanced)
|
||||
- `*` - Search word under cursor (enhanced)
|
||||
- `#` - Search word backward (enhanced)
|
||||
- `g*` / `g#` - Search without word boundaries
|
||||
|
||||
**Features:**
|
||||
- Shows match count (e.g., "3/15")
|
||||
- Floating window near cursor
|
||||
- Automatically clears after cursor movement
|
||||
|
||||
---
|
||||
|
||||
### search-replace.nvim
|
||||
Advanced multi-buffer search and replace.
|
||||
|
||||
**Single Buffer Operations:**
|
||||
- `<leader>rs` - Search/replace in visual selection
|
||||
- `<leader>ro` - Search/replace (open prompt)
|
||||
- `<leader>rw` - Search/replace word under cursor
|
||||
- `<leader>rW` - Search/replace WORD under cursor
|
||||
- `<leader>re` - Search/replace expression
|
||||
- `<leader>rf` - Search/replace filename
|
||||
|
||||
**Multi-Buffer Operations:**
|
||||
- `<leader>rbs` - Search/replace selections (all buffers)
|
||||
- `<leader>rbo` - Search/replace open (all buffers)
|
||||
- `<leader>rbw` - Search/replace word (all buffers)
|
||||
- `<leader>rbW` - Search/replace WORD (all buffers)
|
||||
- `<leader>rbe` - Search/replace expression (all buffers)
|
||||
- `<leader>rbf` - Search/replace filename (all buffers)
|
||||
|
||||
**Commands:**
|
||||
- `:SearchReplaceSingleBuffer` - Single buffer mode
|
||||
- `:SearchReplaceMultiBuffer` - Multi-buffer mode
|
||||
- `:SearchReplaceWithinVisualSelection` - Within selection
|
||||
|
||||
---
|
||||
|
||||
## File Type Tools (`lua/plugins/filetypes.lua`)
|
||||
|
||||
### csvview.nvim
|
||||
Formats and aligns CSV/TSV files for better readability.
|
||||
|
||||
**Key Bindings:**
|
||||
- `<leader>cv` - Toggle CSV view (only in CSV/TSV files)
|
||||
|
||||
**Commands:**
|
||||
- `:CsvViewEnable` - Enable CSV formatting
|
||||
- `:CsvViewDisable` - Disable CSV formatting
|
||||
- `:CsvViewToggle` - Toggle CSV view
|
||||
|
||||
**File Types:** Automatically works with `.csv` and `.tsv` files
|
||||
|
||||
---
|
||||
|
||||
## Built-in LazyVim Extras
|
||||
|
||||
These are enabled via `lazyvim.json` and have their own keybindings:
|
||||
|
||||
### Telescope
|
||||
- `<leader>ff` - Find files
|
||||
- `<leader>fg` - Live grep
|
||||
- `<leader>fb` - Browse buffers
|
||||
- `<leader>fh` - Help tags
|
||||
|
||||
### Neo-tree
|
||||
- `<leader>e` - Toggle file explorer
|
||||
- `<leader>E` - Toggle file explorer (current file)
|
||||
|
||||
### Harpoon2
|
||||
- `<leader>h` - Harpoon menu
|
||||
- `<leader>a` - Add file to harpoon
|
||||
|
||||
### Aerial (Code Outline)
|
||||
- `<leader>cs` - Open symbols outline
|
||||
|
||||
### Project Management
|
||||
- `<leader>fp` - Find project
|
||||
|
||||
---
|
||||
|
||||
## Tips
|
||||
|
||||
1. **Enable/Disable Plugins:** Edit the respective file in `lua/plugins/` and set `enabled = false`
|
||||
2. **View All Keymaps:** Press `<leader>sk` (search keymaps) in Telescope
|
||||
3. **Check Plugin Status:** Run `:Lazy` to see installed plugins
|
||||
4. **Update Plugins:** Run `:Lazy update`
|
||||
5. **View Help:** Most plugins have `:help <plugin-name>` documentation
|
||||
|
||||
---
|
||||
|
||||
## Plugin Files Location
|
||||
|
||||
```
|
||||
~/.config/nvim/lua/plugins/
|
||||
├── git.lua # Git blame & diffview
|
||||
├── ui-enhancements.lua # Render-markdown, hlargs, twilight, theme-hub
|
||||
├── search.lua # Hlslens, search-replace
|
||||
├── filetypes.lua # CSV viewer
|
||||
└── markdown.lua # Markdown-specific config
|
||||
```
|
||||
Reference in New Issue
Block a user