My personal dotfiles for AI-driven, CLI-first development on Linux and macOS. Chezmoi manages the files; mise manages tools and tasks. Read, borrow, or fork to build your own workstation.
Install · Use · Credentials · Adapt
- Terminal: Fish, Starship, Atuin, zoxide, fzf, Ghostty, and Zellij.
- Editor: Neovim with LazyVim, styled with fmind/theme.
- Agents: Antigravity, Claude Code, Codex, Copilot, Grok, and OpenCode share a persona and skills;
dot agent session syncarchives their local sessions for usage reports. - Development: Python with uv, Ruff, ty, and pytest, plus cloud and infrastructure tools.
- Automation: the
dotCLI checks workstation health, manages workspaces, and reports agent usage.
| Platform | Requirements | CI coverage |
|---|---|---|
| Linux x86-64 | glibc 2.39+ (Debian 13 / Ubuntu 24.04+) | Full repository gate and starter tests |
| macOS Apple Silicon | Xcode Command Line Tools | Templates, Python and starter tests |
Other platforms are untested. CI checks templates, code, and builds; it does not run the installer end to end.
Install the host prerequisites first; the rest installs in user space:
# Debian / Ubuntu
sudo apt install -y git curl libatomic1 build-essential gnome-keyring xclip wl-clipboard
# macOS
xcode-select --installThe installer requires mise 2026.10.2 or newer and installs it if absent. Ghostty is the recommended terminal. A container engine is optional.
Warning
These are personal dotfiles: adapt them and back up your files first. Setup overwrites managed files without backups. Agents use broad autonomous permissions, and apply automatically trusts configured workspaces and owner-allowlisted repositories. Review the settings and trust behavior before use.
Read install.sh, then:
git clone https://github.com/fmind/dot.git ~/.local/share/chezmoi
bash ~/.local/share/chezmoi/install.shEnter your own Git name, email, personal-repository email, and GitHub username when prompted; the defaults are mine. Open a new shell and run dot doctor to check the installation.
To resume interrupted setup, rerun the installer. Set SKIP_GIT_PULL=true to use an existing checkout without fetching upstream. From an initialized checkout, mise run full reapplies files and synchronizes locked tools, dot, and completions.
Ghostty and Zellij launch Fish; your login shell stays unchanged. Fish attaches to Zellij once at startup and returns to a shell when Zellij exits or detaches. In another terminal, run fish or set its shell command to ~/.local/share/mise/shims/fish.
dot --help # Discover commands
dot doctor # Check workstation health
dot doctor --headroom # One-line disk and memory check before large work
dot config show # Inspect effective settings
dot agent stats # Review agent usage and prompt statistics
dot orphan # List files no longer managed by chezmoiEdit managed files in ~/.local/share/chezmoi, then preview and apply:
cd ~/.local/share/chezmoi
mise run diff
mise run applyThe Dot CLI guide covers commands, diagnostics, and recovery.
Machine-local settings live in ~/.config/dot.yaml and merge with built-in defaults. Configuration selection is dot --config <path> → DOT_CONFIG_PATH → the default path. A missing default file is fine; a missing explicitly selected file is an error.
Use dot config edit to edit settings; it validates them when the editor exits. Alternate ~/.config/dot.*.yaml profiles are loaded only when selected; these files stay outside Git and chezmoi management.
Usage reports distinguish token counts and estimated API value from actual costs. See the usage guide for reports and subscription settings for renewal dates and charges.
Run these from the checkout; mise tasks lists every task and alias.
| Command | Purpose |
|---|---|
mise run diff |
Preview dotfile changes |
mise run apply |
Apply files and eligible hooks |
mise run full |
Synchronize files, locked tools, CLI, and completions |
mise run upgrade |
Upgrade dependencies, tools, theme, and plugins; apply and reinstall |
mise run all |
Format, check, test, and build the repository |
mise run review:agy |
Ask agy for a structured review of the working-tree diff |
all rewrites formatting but does not deploy. Contributor details: AGENTS.md, verification, and releases.
Shared roles (code, security, and ops reviewers; solution architect; product and course designers; AI evaluator; content editor and presenter; deep researcher; code debugger; project maintainer) are available to Antigravity, Claude Code, Codex, Copilot, Grok, and OpenCode. Edit shared Supagents sources, preview with mise run agents:diff, run mise run agents, then preview and apply the affected chezmoi files. mise run check:agents rejects source warnings and missing, changed, or obsolete generated profiles. See cross-harness agents for invocation, native permission differences, and updating the pinned compiler.
Setup links this repository's skills/ into ~/.agents/skills/, alongside independently installed packages. Restart agent sessions after catalog changes. See skill authoring and catalog maintenance; upgrades from v6.x, or from releases that shipped bf-use, deleguate-tasks, or security-review (now bf, delegate-tasks, and code-security), need the retired-link cleanup.
Use /clipboard to copy the requested deliverable from the preceding exchange, or /clipboard <selection> to choose a result. The clipboard skill verifies the copied text using native macOS or ChromeOS/Linux tools.
Other everyday shortcuts: /full-review reviews a whole project and applies verified fixes, /smoke runs every task and CLI command, /trim <path> shortens without losing meaning, /update-ignores reconciles ignore files with the stack, /auth-status lists expired logins with the exact re-login command, and /handoff saves a continuation prompt before /clear. For writing, /draft-mail creates Gmail drafts only, /social-post writes paste-safe channel copy, and /fact-check verifies claims and links.
dot login all # Everything below that is not ready yet, opening the browser when needed
dot login github # GitHub
dot login workspace # Google Workspace
dot login gcp # Google Cloud and ADC
dot login colab # ADC with Colab scopes, then verify session accessGitHub pushes use SSH, even for HTTPS clones: register an SSH key in GitHub settings. dot login all also reconciles GitHub scopes and, when GWS_PROJECT or auth.workspace.project is set, Workspace APIs and OAuth setup; run dot setup github or dot setup workspace <project-id> for one step alone. Account selection and scope policy live in the authentication guide.
Agent harnesses use their own logins:
| Harness | Command |
|---|---|
| Antigravity | agy |
| Claude Code | claude auth login |
| Codex | codex login |
| Copilot | copilot login |
| Grok | grok login |
| OpenCode | opencode → /connect |
For hooks, notifications, and provider overrides, see agent harnesses and Antigravity. Add optional MCP servers with mcp-setup.
Secrets are not exported at shell startup. Hugging Face, Kaggle, and OpenCode use native credential files, seeded only when absent so later logins survive apply. Use hf auth login, kaggle auth login, or OpenCode's /connect for your own accounts. For customer work, select credentials explicitly using the account override guide.
Supply a personal key to one command with dot secret run; PyPI packages publish through Trusted Publishing, not a personal token. A remove_ marker deletes the retired UV_PUBLISH_TOKEN seed on apply; revoke that token on pypi.org. Personal model integrations default to GCP Agent Platform with ADC; OpenCode uses OpenRouter.
dot secret run STITCH_ACCESS_TOKEN -- <command>The helper preserves existing environment values; an empty value fails instead of loading the personal key. See scoped credentials for supported keys and precedence.
Encrypted sources: only the owner's age key decrypts the committed credentials. Without ~/.config/chezmoi/key.txt, apply skips them; a different key fails decryption. Back up your key. To capture a credential, set its file mode to 0600 and use chezmoi add --encrypt (--create for native login seeds). Never put secret values in command arguments. Rotate native credentials through their tool and refresh the encrypted seed separately.
Migrating from shell exports: apply files and install the updated CLI together (mise run full), remove duplicate key exports from ~/.private.fish, then restart terminals, editors, and agents from a clean login session. Existing processes retain their old credentials; sourcing a file or opening a child shell does not clear them.
Fork and replace these personal defaults:
- Identity: prompts in
.chezmoi.toml.tmpland the clone URL ininstall.sh. Use unmanaged~/.config/git/config.localfor Git overrides andincludeIfprofiles. - Secrets: replace the age recipient and remove or re-encrypt credential sources before applying; see Secret Management.
- Persona: edit
dot_agents/AGENTS.md, which every harness loads. - Workspaces: change
pull.directoriesandtrust.github_ownersin~/.config/dot.yaml, plus Claude's directories indot_claude/modify_settings.jsonand the personal-checkoutincludeIfdirectories indot_gitconfig.tmpl, which commit with the personal-repository email. Mise trust is separate: usemise trust /path/to/mise.tomlor unmanaged~/.config/mise/conf.d/trust.toml. - Theme: change
.chezmoiexternal.toml.tmpl; theme files are pinned to an fmind/theme commit thatmise run upgradeadvances.
There is no complete uninstaller. Record chezmoi managed before removing state: chezmoi purge removes chezmoi's source, configuration, and state but leaves deployed files. mise implode --config removes mise and its tools. Restore your backups and remove remaining deployed files, shell integration blocks, separately installed CLIs, fonts, and agent data as needed.
To roll back, preserve local edits, check out the previous release tag, and run mise run full, then mise run vim to restore locked Neovim plugins. Applying files alone does not reinstall previous tool or CLI versions. Newer files, application data, and migrations are not rolled back.
Report vulnerabilities through SECURITY.md.
MIT © Médéric Hurier (Fmind)