My personal configuration, deployed with mise.
mise.toml is the shared config. It pins the tools mise installs, age and
fnox, and defines the task shortcuts.
Machine-specific settings live in mise.<env>.toml. Mise reads that file only
when you pass -E <env> on the command line. Each environment file has three
sections:
[vars]holds the values templates read. Secret values are age-encrypted and get decrypted during deploy.[dotfiles]maps paths in this repo to paths under$HOME, either copied as files or rendered as templates.[bootstrap.hooks.post-dotfiles]runs after the files are in place. Today it reloads systemd user units, creates the tmpfiles, and enables the vdirsyncer timer and the rclone mount unit.
The age key is not in the repo. fnox reads it from the OS keychain and passes
it to mise, so every deploy goes through fnox exec.
mise install # installs age and fnox
mise run knopki@rog ls # shows the status, writes nothing
mise run knopki@rog diff # shows what apply would change
mise run knopki@rog apply # applies the dotfiles, then runs the hook
mise run knopki@rog unapply # removes them againThe knopki@rog task wraps fnox exec -- mise -E knopki@rog bootstrap dotfiles. Extra arguments go to bootstrap dotfiles, so ls, diff, apply
and the rest all work.
prek runs a set of checks before each commit. The hooks are in prek.toml.
scripts/check.py covers what a stock linter can't: a leaked age secret key, a
plaintext value in [vars], and a source in the dotfile map that points at
nothing.
prek run --all-files # run every hook over the whole repoA fresh clone needs prek install once. Third-party skills under
agents/skills/ and the generated fish completions are left out. New hooks go
in prek.toml, new helper scripts go in scripts/.
There is one right now, knopki@rog, in mise.knopki@rog.toml. A second
machine means a second mise.<env>.toml with its own vars, dotfile map and
hook, plus a task if you want the short form.
mise brings only age and fnox. The rest is expected on the machine:
- Shell and prompt:
fish,bash,starship,fzf,fd,bat,eza,tree - Everyday CLI:
git(git-lfsis picked up if present),gnupgwith a workinggpg-agentand pinentry,curl,wget,rsync,grep,hexdump,sudo, systemd user units andsystemd-tmpfiles - Editors and viewers:
helixwithbiome,dprint,shfmt,stylua,nixfmt,ruff,tombi,fish-lsp,just-lspandsystemd-lspon PATH,zed(it installs its own extensions),htop,lazygit,mpv - Personal data:
taskandtimewwithpython3for the task hooks,khal,khard,vdirsyncer - Backups and remotes:
restic,rcloneandfuse3for the mount unit - Toolchains:
uv,npm,terraform,podman, plus shell completions forgcloud,terramate,terraform-docs,checkov,arduino-cliandprek - Desktop:
xdg-utils, a session with dbus and pipewire, and the apps behind the autostart entries (Nextcloud,KeePassXC,Telegram,Remmina, ROG Control Center) - Agents:
opencode,nono,pi,herdr,worktrunk
mise.local.toml, mise.*.local.toml and *.age.key are gitignored, so local
overrides and keys stay out of the repo.