Dotfiles and full machine setup managed entirely by mise — packages (Homebrew formulae/casks + Mac App Store), macOS defaults, LaunchAgents, tools, and dotfiles — with secrets injected by fnox from Proton Pass. No chezmoi.
mise.toml— the single config:[vars],[tools],[env],[bootstrap.*],[dotfiles],[tasks].mise.personal.toml— profile overlay (loaded viaMISE_ENV=personal).fnox.toml— Proton Pass secret references (no secret values).home/— dotfile sources (symlinked, or.tmplrendered via Tera).
- Sign in to iCloud and the App Store.
- Run
sh -c "$(curl -fsLs https://raw.githubusercontent.com/h-wb/dotfiles/refs/heads/main/install.sh)"
This installs mise, clones the repo to ~/.dotfiles, symlinks its mise.toml
as the global mise config, and runs mise bootstrap under fnox.
mise run diff # preview what bootstrap would change
mise run apply # apply everything (packages, macOS, dotfiles, tools) with secrets via fnoxBare mise bootstrap works on a machine without secrets (secret-guarded dotfiles
render empty). Per-machine overrides go in an untracked mise.local.toml.
Grant permissions to these apps:
- Full Disk Access: iTerm
- Screen Recording: AltTab
- Accessibility: AltTab, Discord, Plexamp, Raycast, KeyClu, Mos