# ShokiNNs dotfiles I manage my dotfiles using [dotdrop](https://github.com/deadc0de6/dotdrop). ## How to install ### Script > [!IMPORTANT] > Copy ssh public/private key for age, to encrypt/decrypt files to `~/.age/phg-age-dotfiles` and `~/.age/phg-age-dotfiles.pub` > Otherwise empty files will be created instead. ```shell [[ ! $(command -v brew) ]] && /bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)" \ ; eval "$(/opt/homebrew/bin/brew shellenv)" \ && brew update \ && git clone https://github.com/shokinn/.files ~/.files \ && brew bundle install --file=~/.files/bootstrap/Brewfile \ && sudo sh -c "echo \"/opt/homebrew/bin/zsh\" >> /etc/shells" \ && chsh -s /opt/homebrew/bin/zsh \ && uv tool install --allow-python-downloads --python 3.11 dotdrop \ && echo "Enter profile name (leave empty for default): " \ && read DOTDROP_PROFILE \ && [[ -n ${DOTDROP_PROFILE} ]] && DOTDROP_PROFILE="-p${DOTDROP_PROFILE}" || DOTDROP_PROFILE="" \ && ~/.local/bin/dotdrop ${DOTDROP_PROFILE} --cfg=~/.files/config.yaml install \ && unset DOTDROP_PROFILE \ && export HOMEBREW_CASK_OPTS="--appdir=${HOME}/Applications" \ && brew bundle install --file=~/.files/config/brew/Brewfile \ && mkdir -p ~/workspace/{privat,work} \ && ${SHELL} -c ~/.files/bootstrap/.macos \ && ${SHELL} ``` ### Manual 1. Install [Homebrew](https://brew.sh/) 2. Install `age`, `coreutils`, `fzf`, `libmagic`, `mas`, `uv` and `zsh` via Homebrew. ```shell brew bundle install --file=~/.files/bootstrap/Brewfile ``` 3. Install `drotdrop` via `uv` (`uv tool install --allow-python-downloads --python 3.11 dotdrop`). 4. Copy ssh public/private key for age, to encrypt/decrypt files to `~/.age/phg-age-dotfiles` and `~/.age/phg-age-dotfiles.pub` 5. Clone dotfiles, install dependencies for dotdrop and install dotfiles. ```shell git clone https://github.com/shokinn/.files ~/.files \ && ~/.local/bin/dotdrop --cfg=~/.files/config.yaml install ``` 6. Install my default set of tools: ```shell brew bundle install --file=~/.files/config/brew/Brewfile ``` ## Encrypted files ### Initially import a dot file as encrypted file ```shell dotdrop import --transw=_encrypt --transr=_decrypt ``` Installs/updates will now be automatically decrypted/encrypted. ### Decrypt a dotfile manually ```shell age --decrypt -i ~/.age/phg-age-dotfiles -o ``` ### Encrypt a dotfile manually ```shell cat | age -a -R ~/.age/phg-age-dotfiles.pub > ``` ### Edit an encrypted dotfile 1. Install [age-edit](https://github.com/dbohdan/age-edit) #### Manual command **Default editor:** ```shell age-edit -t /tmp/ -M -a ~/.age/phg-age-dotfiles ``` **VS Code as editor:** ```shell age-edit -e "${HOME}/.local/bin/codew" -t /tmp/ -M -a ~/.age/phg-age-dotfiles ``` #### Aliases for file editing - `ade` uses the default editor - `cade` uses vs code for editing the file Both aliases are configured via my `.zshrc`. ## Deployment secrets `age-docker` manages armored age secrets from a project-local `.age-docker.toml`. It searches upward for the nearest policy file, stopping at the Git root. A policy declares public keys, reusable groups, and the exact recipients for every encrypted file: ```toml version = 1 [keys] phg = "age1..." server = "ssh-ed25519 AAAA..." [groups] users = ["phg"] production = ["server"] [secrets] "secrets/prod.env.age" = ["users", "production"] ``` Recipients are never added implicitly. New ciphertext is verified by decrypting it with `~/.age/phg-age-dotfiles` before the configured file is atomically replaced. Use repeatable `--identity ` options before the subcommand when rotating keys. ```shell age-docker init age-docker check age-docker list age-docker edit secrets/prod.env.age age-docker encrypt prod.env secrets/prod.env.age age-docker decrypt secrets/prod.env.age prod.env age-docker rekey secrets/prod.env.age age-docker rekey --all ``` Manage public keys without changing groups or file policies: ```shell age-docker key add operator 'age1...' age-docker key scan server server.example.com age-docker key remove unused-server ``` `key scan` displays the retrieved SSH key and its SHA256 fingerprint before asking for confirmation. `ssh-keyscan` does not authenticate the result; compare the fingerprint through a trusted channel. Replacing an existing alias requires `--replace`, and non-interactive confirmation requires `--yes`. ## Backup/Restore settings for macOS native user preferences See here for a defaults documentation: ### App list | App | Domain | | ------ | ------------------------------------------- | | Alfred | `com.runningwithcrayons.Alfred-Preferences` | | Ice | `com.jordanbaird.Ice` | | Moom | `com.manytricks.Moom` | ### Backup settings ```shell defaults export ~/.files/config/plist/.plist ``` ### Restore settings ```shell defaults import ~/.files/config/plist/.plist ``` ## Brew ### Install age encrypted Brewfile ```shell gh auth login ssh-keygen -F github.com >/dev/null || ssh-keyscan -t rsa,ed25519 github.com >> ~/.ssh/known_hosts age --decrypt -i ~/.age/phg-age-dotfiles -o - ~/.files/config/brew/vw.Brewfile.age | brew bundle install --file=- ``` ## Documentation ~~Maybe you should [take a look to my documentation](https://docs.pphg.tech/) to understand how I use my dotfiles.~~ My documentation is currently quite outdated and should not be considered for help.