Personal cross-platform dotfiles managed with chezmoi.
On a fresh machine, NREDF automatically provisions a complete modern terminal environment with unified shell configurations across Linux, macOS, and Windows.
The core stack powering this setup includes:
- Dotfiles & Packages: chezmoi (declarative state management), aqua (declarative CLI tool manager), and sheldon (fast shell plugin manager)
- Shell & Navigation: Oh My Posh (cross-shell prompt theme), Carapace (multi-shell completion), Atuin (encrypted history sync & search), zoxide (smart
cd), and fzf (fuzzy finding) - Modern CLI Replacements: lsd (enhanced
ls), bat (catclone with syntax highlighting), ripgrep (rgfast search), fd (fastfindalternative), and tealdeer (tldrcheatsheets) - Terminal Workspace & Editor: Zellij (terminal multiplexer & workspace manager), Yazi (async terminal file manager), and AstroNvim (aesthetic, extensible Neovim IDE)
Using chezmoi's installer directly:
sh -c "$(curl -fsLS get.chezmoi.io)" -- -b ~/.local/bin init --apply NemesisRE/dotfilesOr run the bootstrap script:
bash <(curl -fsSL https://raw.githubusercontent.com/NemesisRE/dotfiles/main/bootstrap.sh)Prerequisites:
curl,git(auto-installed on Debian/Ubuntu). On macOS, Homebrew is used when available.
Open PowerShell and run the bootstrap script:
irm https://raw.githubusercontent.com/NemesisRE/dotfiles/main/bootstrap.ps1 | iexOr using chezmoi directly via winget:
winget install twpayne.chezmoi
chezmoi init --apply NemesisRE/dotfiles
aqua install -a -lTip
For in-depth platform configurations, check the dedicated Linux Guide, macOS Guide, and Windows Guide. Explore all tools, shells, and Neovim in the Documentation Hub.
- chezmoi is installed (
~/.local/bin/chezmoion Unix,%USERPROFILE%\.local\bin\chezmoi.exeor winget on Windows) - The dotfiles repository is cloned to
~/.local/share/chezmoi - aqua is installed and declarative CLI tools are linked
- All dotfiles and profiles are applied to
~/ - Shell libraries for all shells (Bash, Zsh, Fish, Nu, and PowerShell) are deployed to
~/.local/share/nredf/shell/; PowerShell entry-point profiles are maintained inDocuments/PowerShell(with~/.config/powershellsymlinked on Linux/macOS)
The initial chezmoi init prompts for machine-local values (such as Git name/email, secrets profile preset, SSH agent provider, and remote multiplexer). Answers are stored in ~/.config/chezmoi/chezmoi.toml and override defaults without dirtying tracked repository files. To re-prompt or reconfigure anytime, run chezmoi init --prompt && chezmoi apply.
If you use Bitwarden, KeePassXC, or 1Password, your AQUA_GITHUB_TOKEN and Git SSH commit signing key are automatically resolved from your secret store without manual token entry. For full details on setting up personal or work secret profiles, see the Secrets Guide.
Alternatively, if no secret store is configured and neither GITHUB_TOKEN nor AQUA_GITHUB_TOKEN is set, the first interactive session also offers to run aqua token set and store a token in your system keyring to prevent GitHub API rate limits.
# Reconfigure machine settings (name, email, secret store, signing key, SSH agent)
chezmoi init --prompt && chezmoi apply
# Configure aqua's GitHub token manually later (keyring fallback)
nredf_aqua_token_setup
# Restart your shell
exec $SHELLOn Windows:
# Reconfigure machine settings
chezmoi init --prompt; chezmoi apply
# Reload PowerShell session
reloadComprehensive, platform-specific and tool-specific guides:
| Guide | Description |
|---|---|
| Linux Guide | Distro packages (apt, pacman, dnf), Linuxbrew, WSL with npiperelay, Kitty, shortcuts, tips, and troubleshooting |
| macOS Guide | Apple Silicon & Intel Homebrew, modern Bash 5.x migration, Option-as-Alt fixes, Bitwarden SSH, Kitty, shortcuts, and troubleshooting |
| Windows Guide | Windows Terminal, PowerShell 7+ & 5.1, Developer Mode, Win32 Long Paths, UTC RTC dual-boot fix, OneDrive junctions, Defender exclusions |
| Unified Shells Guide | Feature parity matrix across Zsh, Bash, Fish, Nushell, and PowerShell (pwsh), keybindings, PSReadLine, ble.sh, unified aliases, and reload |
| Core Tools Reference | Declarative CLI tools (aqua, chezmoi), history sync (atuin), fuzzy find (fzf), smart jump (zoxide), lsd, bat, lazygit (lzg), lazydocker (lzd), lazyjournal (lzj), lnav, yazi (yy), bottom (btm), k9s, and builtin multiplexer zellij |
| Secrets & Multi-Store Guide | Pluggable secret store management (Bitwarden, KeePassXC, 1Password), URI routing, zero-duplication SSH keys, and automated aqua token sync |
| Neovim Guide | Dedicated AstroNvim v6 documentation: OneDark-Pro theme, full keyboard shortcuts cheat sheet, LSP, Mason, Lazy, plugins, tips, and troubleshooting |
chezmoi update # Pull latest dotfiles and re-apply
chezmoi edit ~/.zshrc # Edit a managed file
aqua install -a # Install/update all managed CLI tools
sheldon lock --update # Refresh zsh plugin lockfile against upstreamOn Windows (PowerShell):
chezmoi update # Pull latest dotfiles and re-apply
aqua install -a # Update/install managed CLI tools
reload # Reload current PowerShell environmentA native background scheduler (launchd on macOS, systemd --user on Linux, Task Scheduler on Windows) runs once a day with low CPU/I/O priority: it fast-forwards this repo, re-applies dotfiles, upgrades chezmoi/aqua/Homebrew, and refreshes the Sheldon plugin lock — all without adding a single millisecond to interactive shell startup. See the "Automated Daily Maintenance & Hot-Reloading" section of the Unified Shells Guide for exactly what it runs, how it skips itself when a secret store is locked, and how an already-open shell picks up the result (reload / reload -f).
Every .chezmoiscripts/ hook and get-*.tmpl vault lookup checks $CI (in addition to $NREDF_NO_BOOTSTRAP, see below) before it installs anything, calls a package manager, or reads a secret store, and exits cleanly instead. This is what lets .github/scripts/check.sh dry-run the entire tree — including the Windows and vault-gated paths — in GitHub Actions with CI=1, with no network access and no bw/op/keepassxc-cli in sight.
home/.chezmoiremove.tmpl lists target paths chezmoi deletes on chezmoi apply once they're no longer part of the tracked source — how this repo retires an old config layout (completions replaced by Carapace, deprecated dotfiles, a legacy shell-override directory) without leaving orphaned files behind on every machine.
Renovate opens PRs for everything version-pinned in this repo, not just package.json-style manifests:
- GitHub Actions: grouped, with a 3-day release wait (they run third-party code in CI).
- mise tool versions: parsed out of
home/dot_config/mise/config.toml.tmpl. - aqua packages: both the registry
ref:and each package'sversion:inhome/dot_config/aquaproj-aqua/aqua.yaml, via custom regex managers (grouped as "aqua packages"). ble.sh(home/.chezmoidata/ble.yaml) and Kitty (home/.chezmoidata/kitty.yaml): release-tag/version bumps.- The Windows aqua bootstrap (
home/.chezmoidata/aqua-bootstrap.yaml).
Kitty and the aqua bootstrap are also pinned by SHA-256. A Renovate PR that bumps either version alone would fail the checksum-verification CI job, so .github/workflows/refresh-pins.yml recomputes and commits the matching hashes on the PR branch and re-runs CI, letting Renovate automerge once it's green. Minor/patch/digest bumps elsewhere automerge the same way, on green CI only.
Recommended workflow:
- Let Renovate open PRs (most automerge on green CI without any action).
- For anything that doesn't automerge, review and merge in this repository.
- Apply everywhere via
chezmoi update.
| Variable | Default | Purpose |
|---|---|---|
NREDF_DOT_PATH |
~/.local/share/nredf |
Shell library root |
NREDF_COMMON_RC_PROFILE |
full |
RC profile level (full / login-minimal / interactive-minimal) |
NREDF_NO_BOOTSTRAP |
unset | Set to 1 to skip every install/link/bootstrap hook and every vault secret lookup (GitHub token, git signing key, MCP servers) during chezmoi apply — the same switch CI flips on for its dry-runs |
This project is licensed under the GNU General Public License v3.0.