My dotfiles for Mac and Ubuntu setup.
- Minimal efforts to install everything, using a Makefile
- Mostly based around Homebrew, Caskroom and Node.js, latest Bash + GNU Utils
- Fast and colored prompt
- Updated macOS defaults (including Caps Lock → Control remap for tmux)
- Well-organized and easy to customize
- The installation and runcom setup is tested weekly on real Ubuntu and macOS machines using a GitHub Action
- Homebrew (packages: Brewfile)
- homebrew-cask (packages: Caskfile)
- Node.js + npm LTS (packages: npmfile)
- Latest Git, Bash 4, Python 3, GNU coreutils, curl, Ruby
- Mackup (sync application settings)
$EDITOR(and Git editor) is GNU nano
On a sparkling fresh installation of macOS:
sudo softwareupdate -i -a
xcode-select --installThe Xcode Command Line Tools includes git and make (not available on stock macOS). Now there are two options:
- Install this repo with
curlavailable:
bash -c "`curl -fsSL https://raw.githubusercontent.com/daniel-trevino/dotfiles/master/remote-install.sh`"This will clone or download, this repo to ~/.dotfiles depending on the availability of git, curl or wget.
- Alternatively, clone manually into the desired location:
git clone https://github.com/daniel-trevino/dotfiles.git ~/.dotfilesUse the Makefile to install everything listed above, and symlink runcom and config (using stow):
cd ~/.dotfiles
makeOn a fresh Ubuntu installation, git and make are needed first:
sudo apt-get update && sudo apt-get install -y git makeThen clone and install:
git clone https://github.com/daniel-trevino/dotfiles.git ~/.dotfiles
cd ~/.dotfiles
makeThis will install system packages via apt, set up Homebrew for Linux, install all Brewfile packages (macOS-only packages are skipped automatically), Node.js, Oh My Zsh, Zinit, Rust/Cargo, Atuin, Vim, and switch the default shell to Zsh.
Note: GUI cask apps are not installed on Linux. A few Brewfile formulae (
dockutil,terminal-notifier,wifi-password) are macOS-only and will be skipped.
Running make will prompt you to choose between two profiles:
| Full (default) | Light | |
|---|---|---|
| Shell config (zsh, oh-my-zsh, zinit, starship) | Yes | Yes |
| Core CLI tools (~23 packages) | Yes | Yes |
| Dev runtimes (Node.js, Python, Go, Rust) | Yes | Yes |
| Claude Code and Codex CLI | Yes | Yes |
| Cloud CLIs, databases, GUI apps, extras | Yes | No |
To skip the prompt, use the shortcut targets:
make light-macos # Light profile on macOS
make light-linux # Light profile on LinuxOr pass the PROFILE variable directly:
make macos PROFILE=light
make linux PROFILE=full # (default)The installation process in the Makefile is tested on every push and every week in this GitHub Action.
After the initial installation, you can quickly install or update individual package lists without running the full setup:
make brewfile # Install/update Homebrew packages from Brewfile
make caskfile # Install/update cask apps from Caskfile
make npmfile # Install/update npm packages from npmfileThis is useful when you've added new packages to the install files and want to apply just those changes.
- Close that terminal that you are using and open a new one. Then you can run the following commands
- Compile zinit via
zinit self-update
dotfiles dock(set Dock items)dotfiles macos(set macOS defaults, including Caps Lock → Control remap for tmux)- Mackup
- Log in to Dropbox (and wait until synced)
ln -s ~/.config/mackup/.mackup.cfg ~(until #632 is fixed)mackup restore
- Remove Spotlight and add setup Alfred command
- Set Aerial screen saver. Open
System Preferences->Desktop & Screen Saver->Screen Saver
$ dotfiles help
Usage: dotfiles <command>
Commands:
clean Clean up caches (brew, npm, gem, rvm)
dock Apply macOS Dock settings
edit Open dotfiles in IDE (code) and Git GUI (stree)
help This help message
macos Apply macOS system defaults
test Run tests
update Update packages and pkg managers (OS, brew, npm, gem)You can put your custom settings, such as Git credentials in the system/.custom file which will be sourced from
.bash_profile automatically. This file is in .gitignore.
Alternatively, you can have an additional, personal dotfiles repo at ~/.extra. The runcom .bash_profile sources all
~/.extra/runcom/*.sh files.
codex/.codex/config.toml is the only Codex configuration source. make link-macos and make link-linux symlink ~/.codex/config.toml to that tracked
file, so changes made by Codex update the dotfiles source directly. Orca keeps
an app-managed runtime mirror under its own $CODEX_HOME; that generated file
is deliberately not symlinked because Orca rewrites it atomically when syncing
settings and managed hooks.
There are two separate brain MCP servers:
work-brainis the personal brain atbrain-dtb.lovable.app/mcp.company-brainis Lovable's Company Brain atbrain.lovable.app/api/public/mcp.
Both use OAuth; no bearer token is loaded from the local agent secret cache.
Codex uses mcp-remote for work-brain OAuth discovery and native HTTP for
company-brain. Claude keeps native, user-scoped HTTP configurations. Each
client keeps its own OAuth sessions.
Authenticate once after linking the dotfiles or adding the servers to Claude:
codex mcp login company-brain
claude mcp login work-brain
claude mcp login company-brainwork-brain opens its browser consent page automatically the first time Codex
connects. To authenticate or test it directly, run:
npx -y -p mcp-remote@0.1.38 mcp-remote-client \
https://brain-dtb.lovable.app/mcp --transport http-onlyThe codex and claude aliases load secrets from the local, Git-ignored
agent-config/secrets/env.cache. Create or update it explicitly:
agent-secrets refreshThe cache is optional. When it is absent, the aliases still start Codex and Claude, but disable their configured MCP servers for that session. This is the default path for light installations and servers without the 1Password CLI. If a cache exists but is invalid, unresolved, or has unsafe permissions, the launch still fails closed instead of silently ignoring it.
When testing from a worktree before it has become the active dotfiles checkout, invoke the utility by path instead:
./bin/agent-secrets refreshIt reads the template from that worktree but stores the ignored cache under the
active $DOTFILES_DIR, so the cache remains available after the worktree is
merged or removed.
The refresh command resolves the references in
agent-config/secrets/env.1password with the 1Password CLI. It is the only
operation that contacts 1Password, so normal agent launches do not require an
approval. Run it again whenever a secret rotates.
The cache is plaintext local state. Its directory is restricted to mode 0700
and the cache to 0600; full-disk encryption and the local user account provide
the remaining at-rest protection. The cache must contain single-line dotenv
values. It is written atomically, and a failed refresh leaves the previous cache
intact.
Useful commands:
agent-secrets status # Show cache metadata without values
agent-secrets clear # Remove the cached secretsTo add a secret, put a NAME={{ op://vault/item/field }} reference in the
tracked template and configure the relevant MCP server to read NAME from its
environment. An invalid, unresolved, or overly permissive cache prevents Codex
and Claude from starting and directs you to refresh it. Refreshing requires
1Password's Developer setting for CLI integration.
-
* existing target is not owned by stow: .bash_profileYou might have done themakecommand without having this repository on~/.dotfileslocation. To fix it you have to move this repository to~/.dotfilesand manually remove the symlinks for those files that have that error usingrm -f symlink_to_dir/. Then runmakeagain. -
warning: setlocale: LC_CTYPE: cannot change locale (UTF-8): No such file or directoryYou might have spelled the locale wrong. Check how the format of the locale is supposed to be written. -
How to add new mac software?Add the name of it on/install/Caskfile. Look at the names at: Homebrew Cask
Many thanks to the dotfiles community. Code structure and inspiration by: webpro