Files
dotfiles-public/dot_local/share/dotup/packages.tsv
T
bcherb2 90bca39396 fix: install bws, isolate the private config, keep credentials out of logs
Three defects the private tier could not survive a fresh machine with.

bws was never installed. The private/bws-secrets row promised seven API
keys and shipped no way to fetch them: dotsecrets shells out to `bws
secret get`, and nothing put that binary on the box. Added as a tarball
channel with checksum verification, musl rather than gnu so it does not
pin a glibc newer than an older LTS carries, plus core/unzip as a real
@needs dependency since the release is a .zip and 24.04 minimal has no
unzip. The releases API needs filtering by tag prefix: sdk-sm is a
monorepo and `latest` usually points at a python SDK, not bws.

Both tiers rendered their config to ~/.config/chezmoi/chezmoi.toml, so
re-running the public installer overwrote the private config and took its
seven promptStringOnce answers with it. Silently -- the templates degrade
politely when data is missing, so the symptom was `git commit` not knowing
who you are, days later. The private tier now renders to private.toml and
the cmp alias carries the matching -c.

`run` echoes its argv to stderr, and the private init argv ends in
https://user:TOKEN@host -- into scrollback, any `dotup 2>log`, and any
agent transcript. Traced through redact_url instead, in both the live and
dry-run branches. The clone is also chmod -R go-rwx afterwards: it lands
at the caller umask, and .git/config stores that same credential URL.

Tests: 90 passing, 9 new covering all three.
2026-08-17 11:15:48 -04:00

122 lines
6.5 KiB
Plaintext

#group pkg flag apt brew note
#
# Five columns, tab separated, greppable by hand. Anything that would have been
# a sixth column is an @ directive instead, so a package with no dependency and
# no install argument -- most of them -- costs nothing to read.
#
# @needs <group/pkg> <dep>... dep is group/pkg or a whole group.
# Closure is transitive in both directions.
# @spec <group/pkg> <arg>... Argument for a channel that cannot be named
# by the package: the npm spec, the flatpak
# app id, the .deb source. Defaults to the
# package name when absent.
# @<group> <note> Group note. Only needed where the members
# fail the safe test for different reasons;
# otherwise the worst child's note is right.
#
# A leading `-` in the apt or brew column means "not from this package manager":
# -tarball -npm -script -snap -deb -flatpak -uv -builtin -xcode.
# A bare `-` means unavailable there. Linux falls back to the brew column before
# giving up -- omp, herdr and lazygit have no apt package at all. The fallback is
# one-directional: there is no apt on a Mac, so a `-` in the brew column is the
# end of the road rather than a reason to read a column of Debian package names.
#
@needs networking/xrdp desktop
@needs networking/xorgxrdp desktop
@needs gpu/container-toolkit docker
@needs agents/codex core/node
@needs agents/pi core/node
@needs agents/pi-plugins core/node
@needs agents/pi-plugins agents/pi
@needs agents/specify-cli core/uv
@needs core/mermaid-cli core/node
@needs core/neovim core/imagemagick core/mermaid-cli
@needs private/bws-secrets core/unzip
#
# npm names carry scopes that the plugin's short name does not. `npm i -g
# rpiv-btw` installs somebody else's package.
@spec agents/codex @openai/codex
@spec agents/pi @earendil-works/pi-coding-agent
@spec agents/pi-plugins @juicesharp/rpiv-ask-user-question @juicesharp/rpiv-btw @juicesharp/rpiv-todo @samfp/pi-memory @tmustier/pi-ralph-wiggum pi-markdown-preview pi-powerline-footer pi-simplify pi-subagents pi-web-access
@spec agents/specify-cli specify-cli
@spec core/mermaid-cli @mermaid-js/mermaid-cli
@spec core/bitwarden-cli bw
@spec apps/obsidian md.obsidian.Obsidian
@spec apps/chrome https://dl.google.com/linux/direct/google-chrome-stable_current_amd64.deb
@spec apps/ghostty gh:mkasberg/ghostty-ubuntu:_amd64.deb
core neovim safe -tarball neovim apt ships 0.9.5 — tarball to /opt/nvim
core ripgrep safe ripgrep ripgrep binary is rg
core fd safe fd-find fd binary is fdfind on ubuntu
core bat safe bat bat binary is batcat on ubuntu
core fzf safe fzf fzf for your shell (ctrl-r); the picker uses its own pinned copy
core eza safe eza eza
core zsh safe zsh -builtin login shell everywhere
core tmux safe tmux tmux
core git-lfs safe git-lfs git-lfs
core lazygit safe - lazygit no apt package
core gh safe gh gh
core chezmoi safe -script chezmoi bootstrap cannot come from the manifest
core go safe -tarball go /usr/local/go on linux
core uv safe -script uv astral installer to ~/.local/bin
core node safe nodejs npm node apt's nodejs ships node WITHOUT npm — both names needed
core imagemagick safe imagemagick imagemagick required by the nvim markdown render path
core mermaid-cli safe -npm -npm mmdc — nvim renders mermaid fences with it
core btop safe btop btop
core htop safe htop htop
core ncdu safe ncdu ncdu
core unzip safe unzip unzip the bws release ships as a .zip, and 24.04 minimal has no unzip
core tree safe tree tree
core cmake safe cmake cmake
core ninja safe ninja-build ninja package name differs from binary
core build-tools safe build-essential -xcode
core magic-wormhole safe magic-wormhole magic-wormhole snap wormhole on dev
core bitwarden-cli safe -snap bitwarden-cli snap bw on ubuntu
core mosh safe mosh mosh
core nmap safe nmap nmap
core binwalk safe binwalk binwalk
core pipx safe pipx pipx
core age safe age age general purpose only now
agents codex safe -npm -npm @openai/codex — unpinned, always latest
agents pi safe -npm -npm @earendil-works/pi-coding-agent
agents pi-plugins safe -npm -npm 10 plugins: rpiv-*, pi-memory, pi-subagents, ...
agents omp safe - can1357/tap/omp oh my pi — tap only, pulls linuxbrew on linux
agents herdr safe - herdr terminal workspace manager for agents
agents specify-cli safe -uv -uv uv tool install
fonts hack-nerd-font safe fonts-powerline font-hack-nerd-font
fonts iosevka-nerd-font safe fonts-powerline font-iosevka-nerd-font
media ffmpeg safe ffmpeg ffmpeg
media sox safe sox sox
media p7zip safe p7zip-full p7zip
apps obsidian gui -flatpak obsidian
apps ghostty gui -deb ghostty
apps chrome gui -deb google-chrome
apps firefox gui firefox firefox
apps vlc gui vlc vlc
@networking daemons, listening ports, and setuid mount helpers
networking openssh-server invasive openssh-server -builtin opens port 22 on every network this box can reach
networking tailscale invasive tailscale tailscale daemon; joins a private network and rewrites DNS
networking avahi-daemon invasive avahi-daemon - daemon; broadcasts this host on the LAN
networking xrdp invasive xrdp - opens port 3389 · useless without the desktop group
networking xorgxrdp invasive xorgxrdp - xrdp's X backend
networking nfs-common invasive nfs-common - setuid mount helper
networking cifs-utils invasive cifs-utils - setuid mount helper
networking davfs2 invasive davfs2 - setuid mount helper
@docker daemon; membership in the docker group is root-equivalent
docker docker-ce invasive docker-ce - daemon; docker group is root-equivalent
docker docker-buildx invasive docker-buildx-plugin -
docker docker-compose invasive docker-compose-plugin -
@desktop changes the display manager — can leave you at a black screen
desktop xfce4 invasive xfce4 - changes the display manager
desktop lightdm invasive lightdm - CAN LEAVE YOU AT A BLACK SCREEN
@gpu kernel modules; a bad driver can break boot
gpu nvidia-driver invasive nvidia-driver-570 - kernel modules; can break boot
gpu cuda-toolkit invasive nvidia-cuda-toolkit -
gpu container-toolkit invasive nvidia-container-toolkit - requires docker
@virt daemon, bridges, and group membership
virt qemu invasive qemu-kvm -
virt libvirt invasive libvirt-daemon-system - daemon + group membership
virt virt-manager invasive virt-manager -
@private one password, typed after the install finishes
private private-repo private - - ~/.local/share/dotfiles-private — agent config, ssh config
private bws-secrets private -tarball -tarball installs bws, then 7 API keys into ~/.config/zsh/secrets.zsh