Files
bcherb2 a001406a33 test: container lab for the two-tier apply
A disposable ubuntu container, a fake private tier and a fake bootstrap
endpoint, so the whole documented path — chezmoi init --apply, dotup pick,
dotup private, cmp apply, dotsecrets — can run end to end without touching a
real machine or a real credential. The fake tier mirrors the real one's
structure (seven secrets and one alias) because dotsecrets is copied verbatim
and the "8 exports, not 7" assertion depends on that cardinality; its ids are
sequential and obviously synthetic.

check-verbatim.sh keeps the fake tier's copies of shipped files honest, and
snapshot.sh records file modes so a 644 where a 600 belongs is a diff.
2026-08-21 22:34:53 -04:00

92 lines
3.8 KiB
Plaintext

# .chezmoiignore -- PRIVATE tier.
#
# This is gitignore syntax. A `#` in the middle of a line becomes part of the
# pattern, silently producing an entry that matches nothing, so every comment
# in this file is on its own line. Learned in phase 1; it does not announce
# itself.
#
# Ignoring changes what chezmoi manages. It never removes or modifies a file
# on any machine.
# Repo documentation and the endpoint artifact, not dotfiles. Without these
# they land as ~/README.md and ~/bootstrap.env.example.
README.md
bootstrap.env.example
# Runbook scripts for the bootstrap endpoint. Operator tooling that is run by
# hand a few times a year, not configuration that belongs in a home directory.
# They live here rather than in the public tier because they name the endpoint
# host and route, and the public repo is cloneable by strangers.
ops
ops/**
# chezmoi's own config directory. Never manage the thing that configures the
# manager.
.config/chezmoi
.config/chezmoi/**
# Nested git checkouts.
**/.git
**/.git/**
# Generated at apply time by run_after_50-secrets.sh, never tracked anywhere.
# If this line is ever removed, `chezmoi add` on a finished machine sweeps the
# seven API keys straight into the repo.
.config/zsh/secrets.zsh
# The per-machine delta that Q5 puts opposite the base settings.json below.
# Claude Code writes this one; chezmoi must never fight it.
.claude/settings.local.json
.claude.json
# `bws` writes a 600-mode state cache here on its first successful call --
# ~/.config/bws/state/<uuid>, about 2 KB. It is derived from the access token
# and belongs in no repository. Found by watching what appeared in a throwaway
# home directory after the first apply, not by reading the documentation.
.config/bws
.config/bws/**
# The bws access token itself. `dotup` writes this from the bootstrap endpoint
# before this repo is even cloned, so chezmoi has no business managing it: a
# managed copy would overwrite a freshly-rotated token with a stale committed
# one on the next apply. It was committed exactly once, in phase 4, by a
# `chezmoi add` of the live file. Listing it here makes chezmoi decline the
# same `add` rather than accept it silently.
.config/bitwarden
.config/bitwarden/**
# ---------------------------------------------------------------- ssh ---
# Deny-by-default, then name the three things that travel. Q3 is answered as
# "sync public keys, not private": public keys are not secret, private keys
# never cross a network and are generated per machine.
#
# The wildcard is the point. An id_ed25519 generated on this machine tomorrow
# matches `.ssh/*` and is matched by no negation below, so `chezmoi add ~/.ssh`
# cannot sweep it up. New key files are excluded by default rather than
# remembered about.
#
# ~/.ssh/known_hosts is excluded by the same rule, deliberately: it is a log of
# where this machine has been, it rewrites itself constantly, and syncing it
# would make `chezmoi status` permanently dirty.
#
# NOTE THE ABSENCE of `!.ssh/*.pub`. Public keys do travel -- that is what
# ~/.ssh/pubkeys/ is for -- but NOT at ~/.ssh/id_ed25519.pub, and the
# distinction is not pedantry:
#
# Every machine generates its own keypair. If this tier also wrote
# id_ed25519.pub, that machine would end up with ITS private key sitting
# next to SOMEONE ELSE'S public key under the matching name. `ssh-copy-id`
# and every agent-only auth path read the .pub, so you would authorise the
# wrong machine and watch it appear to work.
#
# The practical value of syncing public keys is authorized_keys -- a new box
# accepting the keys you already have, with nothing to paste. That is carried
# in full. ~/.ssh/pubkeys/*.pub is the archive of the keys you own, for pasting
# into GitHub and Gitea, parked where ssh will never mistake one for the local
# identity.
.ssh/*
!.ssh/config
!.ssh/authorized_keys
!.ssh/pubkeys
!.ssh/pubkeys/*.pub