b487b0e855
Fresh history. This is the repo a throwaway VM clones anonymously: it brings a
machine to a working baseline and carries nothing that makes it mine.
56 files. 50 land in $HOME, 3 are chezmoi metadata, 2 are repo documentation,
1 is the manifest, and a 15-file test harness stays behind in .tests/.
What did not travel, and why:
encrypted_private_bws-token.age a real credential; age is dropped entirely
.chezmoidata/bws.toml env-var -> secret-id map; belongs with the
tier that can use it
SECRETS.md documentation of the rules, not config
finish-setup.sh.tmpl superseded by dotup
nvim/init.lua.backup dead file
dot_claude/**, dot_codex/**, 120 files of agent config, private tier
dot_pi/**
De-identified rather than dropped:
.gitconfig [user], the GitHub ssh rewrite and both Gitea host rewrites are
identity, not configuration. They move behind an [include] of
~/.config/git/config.local, which the private tier writes. Git
treats a missing include as a no-op, so a public-only machine
reads the file and stops.
.zshrc the two gitea aliases carried a personal domain and a LAN IP.
They move behind a guarded source of ~/.config/zsh/local.zsh,
the sibling of the secrets.zsh seam phase 2 established.
nvim a commented-out LM Studio endpoint naming a LAN address.
ghostty a stale auto-generated header naming an absolute home directory.
Newly captured, never tracked before: ~/.zshenv, ~/.config/gh/config.yml. The
former sourced ~/.cargo/env unguarded, so every zsh on a machine without rustup
printed an error -- the same shape as the unguarded oh-my-zsh source phase 2
fixed. It is guarded now.
.chezmoiexternal.toml grows from one entry to six. oh-my-zsh, powerlevel10k,
zsh-autosuggestions, zsh-ai and tpm were hand-installed and declared nowhere,
which is why `chezmoi init --apply` on a clean box produced a .zshrc that broke
the shell it configures. The theme and both plugins nest under
.oh-my-zsh/custom/, which is what $ZSH_CUSTOM resolves to.
dotup gains an install engine. It resolves each selected package to a channel
(apt, brew, npm, uv, snap, deb, flatpak, tarball, script, builtin) through one
function every consumer reads, probes apt-cache before batching so a name apt
does not know moves to brew instead of failing all thirty, and retries
individually if a batch still fails -- which earned its keep on the first real
container run, where mermaid-cli's puppeteer dependency failed and the other
twelve npm packages installed anyway. --unattended computes safe defaults fresh
from the manifest rather than inheriting a state file, and refuses private and
invasive rows outright even when a stale state file ticks them.
The manifest gains @spec, a second directive kind alongside @needs, carrying the
argument a channel needs but a package name cannot supply -- the scoped npm
name, the flatpak app id, the .deb source. The TSV stays five columns wide.
Three bugs the container runs found, all fixed here:
* `apt install nodejs` gives you node WITHOUT npm on Ubuntu, so all thirteen
npm packages failed on a fresh box. The manifest asks apt for both names.
* A tool installed a moment ago is not on this process's PATH -- uv lands in
~/.local/bin, npm -g honours the ~/.npmrc prefix, linuxbrew is outside a
non-login PATH. Resolved by looking in the places we just wrote to, never by
exporting a modified PATH.
* `A || { B && C; }` is one || list, so when `command -v sudo` failed the list
failed and `set -e` killed dotup at load. On a non-root machine with no
sudo it died before printing anything. There is a regression test.
.zshenv and .p10k.zsh are marked private_. Both are shell code the login shell
executes and both applied at 664, group-writable. Third occurrence of the class
of bug phase 1 found on .pi/agent/auth.json and phase 2 found on .zshrc; the
first one found on purpose rather than by accident.
Verification: 81 assertions, 81/81 on this box and in ubuntu:24.04, ubuntu:22.04
and debian:12. The installer is driven against a directory of fake package
managers that record what they were asked to do and install nothing, so the
engine is exercised end to end without a package landing on the test machine.
`gitleaks detect` over the full history and the working tree: no leaks found,
with no allowlist and no .gitleaks.toml.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
274 lines
3.7 KiB
Lua
274 lines
3.7 KiB
Lua
-- Colorscheme/theme plugins
|
|
return {
|
|
-- Catppuccin
|
|
{
|
|
"catppuccin/nvim",
|
|
name = "catppuccin",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Tokyo Night
|
|
{
|
|
"folke/tokyonight.nvim",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Kanagawa
|
|
{
|
|
"rebelot/kanagawa.nvim",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Rose Pine
|
|
{
|
|
"rose-pine/neovim",
|
|
name = "rose-pine",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Nightfox family (Nightfox, Nordfox, Dawnfox, Duskfox, Carbonfox, Terafox)
|
|
{
|
|
"EdenEast/nightfox.nvim",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Gruvbox
|
|
{
|
|
"ellisonleao/gruvbox.nvim",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Gruvbox Material
|
|
{
|
|
"sainnhe/gruvbox-material",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Nord
|
|
{
|
|
"shaunsingh/nord.nvim",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Nordic
|
|
{
|
|
"AlexvZyl/nordic.nvim",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Everforest
|
|
{
|
|
"neanias/everforest-nvim",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Dracula
|
|
{
|
|
"Mofiqul/dracula.nvim",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- OneDark
|
|
{
|
|
"navarasu/onedark.nvim",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- One Dark Pro
|
|
{
|
|
"olimorris/onedarkpro.nvim",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Solarized
|
|
{
|
|
"maxmx03/solarized.nvim",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Monokai Pro
|
|
{
|
|
"loctvl842/monokai-pro.nvim",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Cyberdream
|
|
{
|
|
"scottmckendry/cyberdream.nvim",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Oxocarbon
|
|
{
|
|
"nyoom-engineering/oxocarbon.nvim",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Melange
|
|
{
|
|
"savq/melange-nvim",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Nightfly
|
|
{
|
|
"bluz71/vim-nightfly-colors",
|
|
name = "nightfly",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Moonfly
|
|
{
|
|
"bluz71/vim-moonfly-colors",
|
|
name = "moonfly",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Sonokai
|
|
{
|
|
"sainnhe/sonokai",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Edge
|
|
{
|
|
"sainnhe/edge",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Ayu
|
|
{
|
|
"Shatur/neovim-ayu",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Material
|
|
{
|
|
"marko-cerovac/material.nvim",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Palenight
|
|
{
|
|
"drewtempelmeyer/palenight.vim",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- GitHub theme
|
|
{
|
|
"projekt0n/github-nvim-theme",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Tokyodark
|
|
{
|
|
"tiagovla/tokyodark.nvim",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Darkplus (VS Code dark theme)
|
|
{
|
|
"lunarvim/darkplus.nvim",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Poimandres
|
|
{
|
|
"olivercederborg/poimandres.nvim",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Flow
|
|
{
|
|
"0xstepit/flow.nvim",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Modus themes
|
|
{
|
|
"miikanissi/modus-themes.nvim",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Zenbones
|
|
{
|
|
"mcchrish/zenbones.nvim",
|
|
dependencies = "rktjmp/lush.nvim",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Apprentice
|
|
{
|
|
"romainl/Apprentice",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Jellybeans
|
|
{
|
|
"nanotech/jellybeans.vim",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Tender
|
|
{
|
|
"jacoborus/tender.vim",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Horizon
|
|
{
|
|
"ntk148v/vim-horizon",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Moonlight
|
|
{
|
|
"shaunsingh/moonlight.nvim",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
|
|
-- Lackluster
|
|
{
|
|
"slugbyte/lackluster.nvim",
|
|
lazy = false,
|
|
priority = 1000,
|
|
},
|
|
}
|