Files
dotfiles-public/dot_local/share/dotup/packages.tsv
T
bcherb2 90bca39396 fix: install bws, isolate the private config, keep credentials out of logs
Three defects the private tier could not survive a fresh machine with.

bws was never installed. The private/bws-secrets row promised seven API
keys and shipped no way to fetch them: dotsecrets shells out to `bws
secret get`, and nothing put that binary on the box. Added as a tarball
channel with checksum verification, musl rather than gnu so it does not
pin a glibc newer than an older LTS carries, plus core/unzip as a real
@needs dependency since the release is a .zip and 24.04 minimal has no
unzip. The releases API needs filtering by tag prefix: sdk-sm is a
monorepo and `latest` usually points at a python SDK, not bws.

Both tiers rendered their config to ~/.config/chezmoi/chezmoi.toml, so
re-running the public installer overwrote the private config and took its
seven promptStringOnce answers with it. Silently -- the templates degrade
politely when data is missing, so the symptom was `git commit` not knowing
who you are, days later. The private tier now renders to private.toml and
the cmp alias carries the matching -c.

`run` echoes its argv to stderr, and the private init argv ends in
https://user:TOKEN@host -- into scrollback, any `dotup 2>log`, and any
agent transcript. Traced through redact_url instead, in both the live and
dry-run branches. The clone is also chmod -R go-rwx afterwards: it lands
at the caller umask, and .git/config stores that same credential URL.

Tests: 90 passing, 9 new covering all three.
2026-08-17 11:15:48 -04:00

6.5 KiB

1#grouppkgflagaptbrewnote
2#
3# Five columns, tab separated, greppable by hand. Anything that would have been
4# a sixth column is an @ directive instead, so a package with no dependency and
5# no install argument -- most of them -- costs nothing to read.
6#
7# @needs <group/pkg> <dep>... dep is group/pkg or a whole group.
8# Closure is transitive in both directions.
9# @spec <group/pkg> <arg>... Argument for a channel that cannot be named
10# by the package: the npm spec, the flatpak
11# app id, the .deb source. Defaults to the
12# package name when absent.
13# @<group> <note> Group note. Only needed where the members
14# fail the safe test for different reasons;
15# otherwise the worst child's note is right.
16#
17# -tarball -npm -script -snap -deb -flatpak -uv -builtin -xcode.
18# A bare `-` means unavailable there. Linux falls back to the brew column before
19# giving up -- omp, herdr and lazygit have no apt package at all. The fallback is
20# one-directional: there is no apt on a Mac, so a `-` in the brew column is the
21# end of the road rather than a reason to read a column of Debian package names.
22#
23@needsnetworking/xrdpdesktop
24@needsnetworking/xorgxrdpdesktop
25@needsgpu/container-toolkitdocker
26@needsagents/codexcore/node
27@needsagents/picore/node
28@needsagents/pi-pluginscore/node
29@needsagents/pi-pluginsagents/pi
30@needsagents/specify-clicore/uv
31@needscore/mermaid-clicore/node
32@needscore/neovimcore/imagemagick core/mermaid-cli
33@needsprivate/bws-secretscore/unzip
34#
35# npm names carry scopes that the plugin's short name does not. `npm i -g
36# rpiv-btw` installs somebody else's package.
37@specagents/codex@openai/codex
38@specagents/pi@earendil-works/pi-coding-agent
39@specagents/pi-plugins@juicesharp/rpiv-ask-user-question @juicesharp/rpiv-btw @juicesharp/rpiv-todo @samfp/pi-memory @tmustier/pi-ralph-wiggum pi-markdown-preview pi-powerline-footer pi-simplify pi-subagents pi-web-access
40@specagents/specify-clispecify-cli
41@speccore/mermaid-cli@mermaid-js/mermaid-cli
42@speccore/bitwarden-clibw
43@specapps/obsidianmd.obsidian.Obsidian
44@specapps/chromehttps://dl.google.com/linux/direct/google-chrome-stable_current_amd64.deb
45@specapps/ghosttygh:mkasberg/ghostty-ubuntu:_amd64.deb
46coreneovimsafe-tarballneovimapt ships 0.9.5 — tarball to /opt/nvim
47coreripgrepsaferipgrepripgrepbinary is rg
48corefdsafefd-findfdbinary is fdfind on ubuntu
49corebatsafebatbatbinary is batcat on ubuntu
50corefzfsafefzffzffor your shell (ctrl-r); the picker uses its own pinned copy
51coreezasafeezaeza
52corezshsafezsh-builtinlogin shell everywhere
53coretmuxsafetmuxtmux
54coregit-lfssafegit-lfsgit-lfs
55corelazygitsafe-lazygitno apt package
56coreghsafeghgh
57corechezmoisafe-scriptchezmoibootstrap cannot come from the manifest
58coregosafe-tarballgo/usr/local/go on linux
59coreuvsafe-scriptuvastral installer to ~/.local/bin
60corenodesafenodejs npmnodeapt's nodejs ships node WITHOUT npm — both names needed
61coreimagemagicksafeimagemagickimagemagickrequired by the nvim markdown render path
62coremermaid-clisafe-npm-npmmmdc — nvim renders mermaid fences with it
63corebtopsafebtopbtop
64corehtopsafehtophtop
65corencdusafencduncdu
66coreunzipsafeunzipunzipthe bws release ships as a .zip, and 24.04 minimal has no unzip
67coretreesafetreetree
68corecmakesafecmakecmake
69coreninjasafeninja-buildninjapackage name differs from binary
70corebuild-toolssafebuild-essential-xcode
71coremagic-wormholesafemagic-wormholemagic-wormholesnap wormhole on dev
72corebitwarden-clisafe-snapbitwarden-clisnap bw on ubuntu
73coremoshsafemoshmosh
74corenmapsafenmapnmap
75corebinwalksafebinwalkbinwalk
76corepipxsafepipxpipx
77coreagesafeageagegeneral purpose only now
78agentscodexsafe-npm-npm@openai/codex — unpinned, always latest
79agentspisafe-npm-npm@earendil-works/pi-coding-agent
80agentspi-pluginssafe-npm-npm10 plugins: rpiv-*, pi-memory, pi-subagents, ...
81agentsompsafe-can1357/tap/ompoh my pi — tap only, pulls linuxbrew on linux
82agentsherdrsafe-herdrterminal workspace manager for agents
83agentsspecify-clisafe-uv-uvuv tool install
84fontshack-nerd-fontsafefonts-powerlinefont-hack-nerd-font
85fontsiosevka-nerd-fontsafefonts-powerlinefont-iosevka-nerd-font
86mediaffmpegsafeffmpegffmpeg
87mediasoxsafesoxsox
88mediap7zipsafep7zip-fullp7zip
89appsobsidiangui-flatpakobsidian
90appsghosttygui-debghostty
91appschromegui-debgoogle-chrome
92appsfirefoxguifirefoxfirefox
93appsvlcguivlcvlc
94@networkingdaemons, listening ports, and setuid mount helpers
95networkingopenssh-serverinvasiveopenssh-server-builtinopens port 22 on every network this box can reach
96networkingtailscaleinvasivetailscaletailscaledaemon; joins a private network and rewrites DNS
97networkingavahi-daemoninvasiveavahi-daemon-daemon; broadcasts this host on the LAN
98networkingxrdpinvasivexrdp-opens port 3389 · useless without the desktop group
99networkingxorgxrdpinvasivexorgxrdp-xrdp's X backend
100networkingnfs-commoninvasivenfs-common-setuid mount helper
101networkingcifs-utilsinvasivecifs-utils-setuid mount helper
102networkingdavfs2invasivedavfs2-setuid mount helper
103@dockerdaemon; membership in the docker group is root-equivalent
104dockerdocker-ceinvasivedocker-ce-daemon; docker group is root-equivalent
105dockerdocker-buildxinvasivedocker-buildx-plugin-
106dockerdocker-composeinvasivedocker-compose-plugin-
107@desktopchanges the display manager — can leave you at a black screen
108desktopxfce4invasivexfce4-changes the display manager
109desktoplightdminvasivelightdm-CAN LEAVE YOU AT A BLACK SCREEN
110@gpukernel modules; a bad driver can break boot
111gpunvidia-driverinvasivenvidia-driver-570-kernel modules; can break boot
112gpucuda-toolkitinvasivenvidia-cuda-toolkit-
113gpucontainer-toolkitinvasivenvidia-container-toolkit-requires docker
114@virtdaemon, bridges, and group membership
115virtqemuinvasiveqemu-kvm-
116virtlibvirtinvasivelibvirt-daemon-system-daemon + group membership
117virtvirt-managerinvasivevirt-manager-
118@privateone password, typed after the install finishes
119privateprivate-repoprivate--~/.local/share/dotfiles-private — agent config, ssh config
120privatebws-secretsprivate-tarball-tarballinstalls bws, then 7 API keys into ~/.config/zsh/secrets.zsh