⚠ THIS COMMIT'S CONTENTS ARE MIXED, BY EXECUTOR ERROR, AND THE MESSAGE NOW SAYS SO RATHER THAN DESCRIBING ONLY ONE PART. The original message named only the governance-mcp.py change; `git add -A` had swept four other files. Amended before push, so no shared history is rewritten. What is actually here: 1. REVIEWED-119 and REVIEWED-120 (REVIEWED.md, +38) — STEWARD acts, placed during this session. 119 authorizes PENDING-135 option (c), instance 8 reclassified as a negative-candidate with the sub-type name held open, and corrects the item's own claim that option (d) was blocked cross-repo (the constraint is studium/v2-gold@1 §14.2, engine-side and D-1, not the chamber-locked studium/meta@1). 120 authorizes PENDING-136 option (c), retiring bare `distinct_spans`. 2. PENDING-135, PENDING-136 and the PENDING-131 Addendum 4 defect-count fix (PENDING.md, +212) — executor filings, and the ones that legitimately belong to a session wrap. 3. The session ledger (claude/memory/session-ledger-2026-08-13.md) — likewise. 4. governance-mcp.py (+24) — the [FIX] the original message described: two V0-lane key descriptions had gone stale the same day the dispositions landed. PENDING-134's H1 holds the doctrine ruling until those keys are actually SERVED (the running client keeps the old eight-key map until restart, which is steward action and still pending). The descriptions are what the jurist reads to decide which key to OPEN, so a stale index served at first contact would mislead on first contact — the class this whole arc is about. Selftest 54 checks, 0 failures. 5. Brewfile (+1, `mas "NordVPN"`) — NOT this session's work. It belongs to sysupdate's sweep and was swept in by the same error. Left in place rather than surgically removed: extracting it would rewrite more than it repairs, and the line is already accurate. Recorded so the next reader is not misled about which process authored it. The wrap protocol's §6.5 requires a scoped add for exactly this reason — the steward's in-progress changes belong to the steward's sweep, and a governance act placed by the steward must not be recorded under an executor's message. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01G38S6gU6G7akko9syvB7nu
🖖 David's Dotfiles - "Engage!"
"Make it so!" - A complete macOS setup system inspired by Star Trek's efficiency and elegance.
From zero to fully configured macOS in minutes. This dotfiles repository provides a comprehensive, automated setup for developers, writers, and knowledge workers.
🚀 Quick Start
One command to rule them all:
# From GitHub
git clone https://github.com/davidglidden/dotfiles.git ~/dotfiles && ~/dotfiles/engage
# From Gitea (alternative mirror)
git clone git@git.davidglidden.eu:davidglidden/dotfiles.git ~/dotfiles && ~/dotfiles/engage
That's it! The engage script will guide you through a complete system setup.
✨ What This System Provides
📦 Software Management
- 120+ CLI tools via Homebrew (development, media, security)
- 40+ Applications via casks (productivity, creativity, utilities)
- 20+ Mac App Store apps via
mas(native macOS apps)
🔧 Configuration Management
- Shell setup: Zsh with Antidote, Powerlevel10k, history sync
- Development tools: Git hooks, SSH templates, NPM config
- Application configs: LaunchBar, Hazel, Bartender, Karabiner
- Obsidian vault: Complete knowledge management system
🖥️ macOS System Configuration
- System preferences: Dock, Finder, keyboard, security
- Security hardening: Firewall, privacy, authentication
- Keyboard shortcuts: Mission Control, app shortcuts
- Developer settings: Safari dev tools, Terminal enhancements
🛡️ Backup & Security Strategy
- Encrypted backups for sensitive files (SSH keys, credentials)
- History management with daily snapshots and retention
- Git hooks for security and code quality
- Application data backup and restore scripts
📁 Repository Structure
dotfiles/
├── engage # 🖖 Master installation script
├── Brewfile # Package management (brew/cask/mas)
├── README.md # This file
├── .gitconfig # Git configuration
├── .npmrc # NPM defaults
├── .zshrc # Shell configuration
├── .vimrc # Vim configuration
├── bin/ # Custom scripts
│ ├── backup-dotfiles # Quick dotfiles backup
│ └── check-app-configs # Configuration status checker
├── git/ # Git configuration
│ └── hooks/ # Global git hooks
├── macos/ # macOS system configuration
│ ├── setup-macos.sh # Master macOS setup
│ ├── defaults.sh # System preferences
│ ├── security.sh # Security hardening
│ └── keyboard-shortcuts.sh # Custom shortcuts
├── macos-apps/ # macOS app configurations
│ └── backup-app-configs.sh # App settings backup
├── obsidian/ # Obsidian knowledge vault
│ ├── setup-obsidian.sh # Vault configuration
│ └── community-plugins.json # Essential plugins
├── scripts/ # Installation scripts
│ └── symlinks.sh # Dotfile linking
├── shell/ # Shell enhancements
│ └── history-sync.zsh # History management
└── ssh/ # SSH configuration
├── config.example # SSH config template
└── README.md # SSH setup guide
🎯 Core Philosophy
This system balances automation with choice:
- Smart defaults that work out of the box
- Interactive modes for customization
- Modular design - use what you need
- Security first - encrypted backups, secure defaults
- Documentation - clear guides and examples
Inspired by the best dotfiles repositories but designed for real-world complexity.
📱 Essential Applications Included
Development
- iTerm2 + Kitty - Terminal emulators
- BBEdit - Text editor with deep macOS integration
- GitHub Desktop - Git GUI
- Docker - Containerization
Productivity
- Obsidian - Knowledge management powerhouse
- 1Password - Password management
- LaunchBar - Application launcher
- Hazel - Automated file organization
- Drafts - Quick capture and text processing
Utilities
- Karabiner-Elements - Keyboard customization
- Bartender - Menu bar organization
- Keka - Archive utility
- Oversight - Privacy monitoring
- Signal - Secure messaging
Creative & Media
- VLC - Media player
- HandBrake - Video transcoding
- Transmit - File transfer
- Calibre - E-book management
🛠️ Advanced Usage
Manual Installation Steps
If you prefer granular control:
# 1. Install packages only
brew bundle install --file=~/dotfiles/Brewfile
# 2. Set up dotfiles
~/dotfiles/scripts/symlinks.sh
# 3. Configure macOS
~/dotfiles/macos/setup-macos.sh
# 4. Set up applications
~/dotfiles/macos-apps/backup-app-configs.sh
Customization
Modify the Brewfile to add/remove applications:
# Add new CLI tool
brew "your-tool"
# Add new application
cask "your-app"
# Add Mac App Store app
mas "App Name", id: 123456789
Customize macOS defaults in macos/defaults.sh:
# Change dock position
defaults write com.apple.dock orientation -string "left"
# Adjust key repeat speed
defaults write NSGlobalDomain KeyRepeat -int 1
Backup Strategy
Before making changes:
# Backup current dotfiles
~/dotfiles/bin/backup-dotfiles
# Backup macOS settings
~/dotfiles/macos/backup-defaults.sh
# Backup sensitive files (encrypted)
~/dotfiles/backup-scripts/backup-sensitive.sh
🔐 Security Features
- SSH keys encrypted with GPG
- Firewall enabled with stealth mode
- Privacy settings optimized
- Git hooks prevent secrets in commits
- Secure defaults for Safari and system
- Application permissions documented
🧠 Obsidian Knowledge System
Includes a sophisticated personal knowledge management setup:
- 13 essential plugins for advanced functionality
- Template system with Templater integration
- Daily/weekly/monthly review cycles
- Christopher Alexander pattern language philosophy
- Multilingual support (EN/ES/FR/CA)
🤝 Contributing
This is a personal dotfiles repository, but ideas and improvements are welcome:
- Fork the repository
- Create a feature branch
- Test thoroughly on a fresh macOS installation
- Submit a pull request with clear description
📜 License
MIT License - Use, modify, and share freely.
🙏 Acknowledgments
Inspired by:
- Mathias Bynens' dotfiles
- ptb/mac-setup
- Homebrew Bundle
- The Star Trek universe for the best command ever: "Engage!"
Live long and prosper! 🖖
Made with ❤️ for the macOS community