David F GliddenandClaude Opus 5 cc9788862c [FIX] Declare wake-digest.py's selftest exemption; correct a stale tracker line
Two unrelated things found while establishing what PENDING-134 actually
needs, which turned out to be nothing.

1. governance-mcp.py --selftest was FAILING. The delegate read-only
   guarantee flagged five undeclared mutating calls in wake-digest.py,
   all inside selftest(), all added by yesterday's REVIEWED-131 (e)/(c)
   build: a job dir with state.json, and two transcripts with and
   without a human turn.

   Declared rather than detector-widened, because failing until someone
   names it is the mechanism's design, not an obstacle to it. Why it is
   safe: every write goes to a tempfile.mkdtemp() tree the same function
   removes, and selftest is reachable from --selftest alone, never from
   a tool call. Its weakness is declared in the same comment: this is a
   FUNCTION-level exemption, so a future non-tempdir write inside
   selftest now passes silently. The narrower rule — "writes confined to
   a tempdir" — is not expressible in this check without data-flow
   analysis, and naming that limit is preferred to a detector that would
   be wrong in a harder-to-see way. Selftest now PASSES, 62 controls.

2. MEMORY.md said "ratio_A_to_B VOID until PENDING-134 lands" and
   "NEXT: rule PENDING-134". Both stale by 18 days: PENDING-134 was
   ruled REVIEWED-121 on 2026-08-14. REVIEWED-121's own closing sets the
   real condition — re-derive ONCE after BOTH it and PENDING-137 land —
   and PENDING-137 is still [PROPOSAL], awaiting a jurist ruling. The
   live blocker on the fr cell is -137, and it needs the jurist, not the
   executor.

   Corrected in place with the superseded text quoted, per the memory
   discipline: a conflict between a memory layer and the substrate is a
   verification trigger, and the substrate wins.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017vKkg2EJF1rGwdFdBogwqx
2026-09-01 10:34:39 +02:00
2025-07-27 13:40:44 +02:00

🖖 David's Dotfiles - "Engage!"

"Make it so!" - A complete macOS setup system inspired by Star Trek's efficiency and elegance.

From zero to fully configured macOS in minutes. This dotfiles repository provides a comprehensive, automated setup for developers, writers, and knowledge workers.

🚀 Quick Start

One command to rule them all:

# From GitHub
git clone https://github.com/davidglidden/dotfiles.git ~/dotfiles && ~/dotfiles/engage

# From Gitea (alternative mirror)
git clone git@git.davidglidden.eu:davidglidden/dotfiles.git ~/dotfiles && ~/dotfiles/engage

That's it! The engage script will guide you through a complete system setup.

✨ What This System Provides

📦 Software Management

  • 120+ CLI tools via Homebrew (development, media, security)
  • 40+ Applications via casks (productivity, creativity, utilities)
  • 20+ Mac App Store apps via mas (native macOS apps)

🔧 Configuration Management

  • Shell setup: Zsh with Antidote, Powerlevel10k, history sync
  • Development tools: Git hooks, SSH templates, NPM config
  • Application configs: LaunchBar, Hazel, Bartender, Karabiner
  • Obsidian vault: Complete knowledge management system

🖥️ macOS System Configuration

  • System preferences: Dock, Finder, keyboard, security
  • Security hardening: Firewall, privacy, authentication
  • Keyboard shortcuts: Mission Control, app shortcuts
  • Developer settings: Safari dev tools, Terminal enhancements

🛡️ Backup & Security Strategy

  • Encrypted backups for sensitive files (SSH keys, credentials)
  • History management with daily snapshots and retention
  • Git hooks for security and code quality
  • Application data backup and restore scripts

📁 Repository Structure

dotfiles/
├── engage                     # 🖖 Master installation script
├── Brewfile                   # Package management (brew/cask/mas)
├── README.md                  # This file
├── .gitconfig                 # Git configuration
├── .npmrc                     # NPM defaults
├── .zshrc                     # Shell configuration
├── .vimrc                     # Vim configuration
├── bin/                       # Custom scripts
│   ├── backup-dotfiles        # Quick dotfiles backup
│   └── check-app-configs      # Configuration status checker
├── git/                       # Git configuration
│   └── hooks/                 # Global git hooks
├── macos/                     # macOS system configuration
│   ├── setup-macos.sh         # Master macOS setup
│   ├── defaults.sh            # System preferences
│   ├── security.sh            # Security hardening
│   └── keyboard-shortcuts.sh  # Custom shortcuts
├── macos-apps/                # macOS app configurations
│   └── backup-app-configs.sh  # App settings backup
├── obsidian/                  # Obsidian knowledge vault
│   ├── setup-obsidian.sh      # Vault configuration
│   └── community-plugins.json # Essential plugins
├── scripts/                   # Installation scripts
│   └── symlinks.sh            # Dotfile linking
├── shell/                     # Shell enhancements
│   └── history-sync.zsh       # History management
└── ssh/                       # SSH configuration
    ├── config.example         # SSH config template
    └── README.md              # SSH setup guide

🎯 Core Philosophy

This system balances automation with choice:

  • Smart defaults that work out of the box
  • Interactive modes for customization
  • Modular design - use what you need
  • Security first - encrypted backups, secure defaults
  • Documentation - clear guides and examples

Inspired by the best dotfiles repositories but designed for real-world complexity.

📱 Essential Applications Included

Development

  • iTerm2 + Kitty - Terminal emulators
  • BBEdit - Text editor with deep macOS integration
  • GitHub Desktop - Git GUI
  • Docker - Containerization

Productivity

  • Obsidian - Knowledge management powerhouse
  • 1Password - Password management
  • LaunchBar - Application launcher
  • Hazel - Automated file organization
  • Drafts - Quick capture and text processing

Utilities

  • Karabiner-Elements - Keyboard customization
  • Bartender - Menu bar organization
  • Keka - Archive utility
  • Oversight - Privacy monitoring
  • Signal - Secure messaging

Creative & Media

  • VLC - Media player
  • HandBrake - Video transcoding
  • Transmit - File transfer
  • Calibre - E-book management

🛠️ Advanced Usage

Manual Installation Steps

If you prefer granular control:

# 1. Install packages only
brew bundle install --file=~/dotfiles/Brewfile

# 2. Set up dotfiles
~/dotfiles/scripts/symlinks.sh

# 3. Configure macOS
~/dotfiles/macos/setup-macos.sh

# 4. Set up applications
~/dotfiles/macos-apps/backup-app-configs.sh

Customization

Modify the Brewfile to add/remove applications:

# Add new CLI tool
brew "your-tool"

# Add new application
cask "your-app"

# Add Mac App Store app
mas "App Name", id: 123456789

Customize macOS defaults in macos/defaults.sh:

# Change dock position
defaults write com.apple.dock orientation -string "left"

# Adjust key repeat speed
defaults write NSGlobalDomain KeyRepeat -int 1

Backup Strategy

Before making changes:

# Backup current dotfiles
~/dotfiles/bin/backup-dotfiles

# Backup macOS settings  
~/dotfiles/macos/backup-defaults.sh

# Backup sensitive files (encrypted)
~/dotfiles/backup-scripts/backup-sensitive.sh

🔐 Security Features

  • SSH keys encrypted with GPG
  • Firewall enabled with stealth mode
  • Privacy settings optimized
  • Git hooks prevent secrets in commits
  • Secure defaults for Safari and system
  • Application permissions documented

🧠 Obsidian Knowledge System

Includes a sophisticated personal knowledge management setup:

  • 13 essential plugins for advanced functionality
  • Template system with Templater integration
  • Daily/weekly/monthly review cycles
  • Christopher Alexander pattern language philosophy
  • Multilingual support (EN/ES/FR/CA)

🤝 Contributing

This is a personal dotfiles repository, but ideas and improvements are welcome:

  1. Fork the repository
  2. Create a feature branch
  3. Test thoroughly on a fresh macOS installation
  4. Submit a pull request with clear description

📜 License

MIT License - Use, modify, and share freely.

🙏 Acknowledgments

Inspired by:


Live long and prosper! 🖖

Made with ❤️ for the macOS community

S
Description
🖖 Complete macOS dotfiles system - 'Engage!'
Readme
14 MiB
Languages
Python 73%
Shell 25.1%
JavaScript 1.2%
Ruby 0.7%