Skip to content

Latest commit

 

History

History
121 lines (87 loc) · 6.43 KB

File metadata and controls

121 lines (87 loc) · 6.43 KB

dothaven

Discover, back up, and migrate your machine's dev config — feeding chezmoi with age-encrypted secrets.

dothaven inventories what's on your machine (shell, git, editors, SSH, cloud CLIs, Homebrew, global packages, runtimes, fonts, AI tooling), scans it for secrets, and prepares an encrypted hand-off to chezmoi so a clean-install machine comes back without losing a thing.

Binary Single static Go binary — no runtime to install
Platforms macOS & Linux · amd64 & arm64
Backbone chezmoi + age for storage, encryption, and apply
Docs https://doguyilmaz.github.io/dothaven

Install

# Homebrew (signed and notarized)
brew install --cask doguyilmaz/tap/dothaven

# Go
go install github.com/doguyilmaz/dothaven/cmd/dothaven@latest

# From source
git clone https://github.com/doguyilmaz/dothaven && cd dothaven && go build ./cmd/dothaven

Running dothaven needs nothing else. The chezmoi-export and init commands additionally use chezmoi and a configured age key — see Encryption & chezmoi.

Quick start

dothaven                         # menu — start here if you're not sure
dothaven guide                   # a few questions → the exact commands for your case
dothaven ready                   # before wiping: is anything only on this Mac?
dothaven scan ~                  # scan for secrets (exits 2 if any are HIGH)
dothaven backup                  # timestamped copy of your config, on this Mac
dothaven chezmoi-export          # plan what would go to chezmoi, plain vs encrypted
dothaven chezmoi-export --apply  # execute (needs chezmoi + age)
dothaven check                   # do my config files still parse?
dothaven backup --archive --encrypt   # one age-encrypted file you can carry
dothaven status                  # latest backup vs this machine
dothaven migrate --dry-run       # on a new Mac: what chezmoi would apply

Anything that changes files you already have asks first and takes --dry-run; backup and the exports only ever add. Off a terminal there is nobody to ask, so those commands refuse unless you pass --yes.

The hybrid model

dothaven is the discovery + audit + export layer; chezmoi is the storage + encryption + apply backbone.

Stage Owner
Discover the machine, snapshot installed config dothaven
Scan for secrets, redact by default dothaven
Build a chezmoi add plan + a run_onchange install script dothaven
Track files in a private source repo chezmoi
Encrypt the files marked secret chezmoi + age
Write files back into $HOME on a new machine chezmoi

dothaven decides what to encrypt; chezmoi performs it. It is not itself an encryption or sync engine.

Commands

collect Inventory the machine into a JSON snapshot
doctor Diff a snapshot against this machine (non-zero exit on drift)
guide Answer a few questions, get the commands that fit
check Parse every tracked config; report the broken ones
ready Before a wipe: uncommitted, unpushed and stashed work
scan / security Find secrets (console / Markdown report)
backup / restore Copy tracked config files out and back, with a redaction gate
status / diff Compare a backup against the live machine
compare / list Diff two snapshots / print a snapshot section
chezmoi-export Plan (or --apply) adding configs to chezmoi, encrypting secrets, templating host paths
init / migrate Check chezmoi + age prerequisites / apply your source on a clean machine
defaults / services Capture & restore macOS app prefs / Homebrew service config (export + import)

Full reference, with every flag: Commands.

Missing a tool?

dothaven aims to be a superset of what chezmoi covers — every cloud CLI, version manager, editor, terminal, and credential store a developer uses. If something you rely on isn't tracked yet, it's a one-line registry add:

Request a config / tool (just the tool name + its config path).

What's out of scope

dothaven captures configuration, not data or system state. By design it does not carry:

  • Data — databases (Postgres/MySQL data dirs, ~/.docker images & volumes), anything you'd dump/restore. Reinstall the engine; re-import the data.
  • System & service-daemon config in /etc (e.g. /etc/nginx) — needs root and is machine-specific. (Homebrew-prefix service config under $(brew --prefix)/etc is in scope — it's user-editable dev config.)
  • App-bundle internals — XAMPP/MAMP and similar live in /Applications; the app comes back via its Homebrew cask, its bundled config/data does not.
  • Toolchain binaries & caches — language runtimes, SDKs, build caches (~/.gradle/caches, Xcode DerivedData, ~/.pub-cache), node_modules. Versions are inventoried and reinstalled via your version manager / package manager, not copied byte-for-byte.
  • Secrets dothaven can't reach — the macOS Keychain / Secret Service.

The rule of thumb: if it's a file you'd edit, it's in scope; if it's data, a binary, or owned by root, it isn't.

Security

A pattern scanner classifies findings as HIGH/MEDIUM/LOW with an action of skip/redact/include. Secrets are redacted by default before anything is written, and a file containing a private key (a skip-action secret) is never written into a plaintext backup or snapshot. On export, high-sensitivity files are added with chezmoi add --encrypt. See Security & redaction.

The age key is the only thing protecting your encrypted files. Lose it and they are unrecoverable — back it up offline and never commit it.

Development

go build ./...      # build
go test ./...       # unit + testscript e2e
gofmt -l ./cmd ./internal   # formatting (CI gate)

Layout: cmd/dothaven (entry point) + internal/{snapshot,scan,sys,collect,registry,backup,restore,chezmoi,cli}. See Architecture.

The docs site is Hugo + Hextra: cd docs && hugo server.

License

MIT.