Files
dotfiles/BACKUP_STRATEGY.md
T
David F GliddenandClaude 0838f1cf8c Initial commit: Complete macOS dotfiles system
🖖 Features:
- Master 'engage' script for one-command setup
- 120+ CLI tools via Homebrew
- 40+ Applications (casks + MAS apps)
- Complete macOS system configuration
- Security hardening and privacy settings
- Obsidian knowledge vault setup
- Comprehensive backup strategies
- Automated symlink management

Live long and prosper\! 🚀

🤖 Generated with Claude Code (https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-07-27 13:17:01 +02:00

2.1 KiB

Dotfiles Backup Strategy

Overview

This dotfiles repository uses a multi-layered backup approach:

  1. Version Control (Git) - For non-sensitive configuration files
  2. Encrypted Backups - For sensitive files (SSH keys, credentials)
  3. Historical Backups - For shell history and evolving configs
  4. Symlinks - To maintain live connections to config files

What Gets Backed Up Where

In Git (Public)

  • Shell configurations (.zshrc, .bashrc)
  • Git config (sanitized)
  • Vim configuration
  • Shell scripts and utilities
  • Application configs (non-sensitive)

Encrypted Backups (Private)

  • SSH private keys
  • AWS/Cloud credentials
  • API tokens
  • Password databases

Historical Backups

  • Shell history (daily snapshots, 7-day retention)
  • Checkpoint versions of frequently edited configs

Backup Commands

1. Quick Backup (non-sensitive files)

~/dotfiles/bin/backup-dotfiles

2. Sensitive Files Backup (encrypted)

~/dotfiles/backup-scripts/backup-sensitive.sh

3. Manual History Checkpoint

# In your shell
history_checkpoint

Restore Process

On a New Machine

  1. Clone dotfiles:

    git clone https://github.com/yourusername/dotfiles.git ~/dotfiles
    
  2. Run installation script (once created):

    ~/dotfiles/install.sh
    
  3. Restore sensitive files (if you have backups):

    # Decrypt SSH keys
    gpg -d ~/dotfiles/backups/ssh_[timestamp].tar.gz.gpg | tar -xzf -
    
  4. Set up application-specific configs:

    • Run mackup restore for application preferences
    • Import browser bookmarks/passwords
    • Configure cloud service credentials

Security Best Practices

  1. Never commit:

    • Private keys
    • Passwords or tokens
    • Personal information
  2. Use .gitignore properly:

    backups/
    *.key
    *.pem
    secrets/
    
  3. Encrypt sensitive backups with GPG

  4. Store encrypted backups in a secure location (not in git)

  5. Rotate keys regularly

Maintenance

  • Run backup scripts weekly
  • Review and clean old backups monthly
  • Update scripts as your setup evolves
  • Test restore process periodically