7 ms·
Using GNU Stow to manage your dotfiles (2012)
- politelemon 4y agoIt feels unsafe to store dot files in source control as the article mentions. Is this a common practice? They could contain sensitive information and I fear people might be tempted to push to GitHub. What about storing such files in a password manager/database?
- lvass 4y ago>contain sensitive information and I fear people might be tempted to push to GitHub Nothing can really protect someone from this level of insanity.
- politelemon 4y agoAnecdotal, I encounter it quite often at work among 'newer' developers, who have been doing this ever since Github private repos went free! That's why my question. Thanks for the answers everyone, it does come down to diligence and knowing what you're doing.
- yoyohello13 4y agoMany people have their dotfiles up on GitHub. As long as you're aware of what is in your dotfiles it pretty benign. Just put your passwords elsewhere.
- marcinreal 4y agoJust don't push to GitHub. :) You can also pick and choose what you want in the repos with this method. It's a very useful technique for tracking and rolling back changes to dotfiles that you care about. You can even make backups of the directory which can help you bootstrap new machines really quick. In a similar vein, I also have a git repo containing my todo list, journal, etc. and review and commit the changes once a week. Very helpful for catching accidental deletions/modifications. I have never been tempted to push these repos.
- aidenn0 4y agoThere are plenty of tools to manage secrets in VCS, so that's always an option. As an aside, most programs now have a method to move sensitive information outside of the configuration file, so you can minimize what ends up in there.
- layer8 4y agoThere are a number of possible solutions: git-remote-gcrypt: https://github.com/spwhitton/git-remote-gcrypt https://github.com/spwhitton/git-remote-gcrypt git-crypt: https://github.com/AGWA/git-crypt https://github.com/AGWA/git-crypt git-secret: https://github.com/sobolevn/git-secret https://github.com/sobolevn/git-secret However, most people who self-host their Git repository are fine with just transport-level encryption (TLS).
- BrotherBisquick 4y agoYou simply don't push anything that has sensitive information in it. You pick and choose. Stow makes this easy, because the only things being pushed are files you explicitly move to a specific directory. Real world example: - Let's say I want to version control ~/.ssh/config and ~/.ssh/authorized_keys - I move these two files to ~/.dotfiles/ssh - ~/.dotfiles is version controlled, so I push the new files to gitlab. I'm only pushing two harmless files: my ssh configs, and authorized keys. Git, stow, and ~/.dotfiles don't see anything else. - After pushing, I run "stow ssh" inside ~/.dotfiles. This symlinks these two files to ~/.ssh I don't worry about pushing anything sensitive, because it's basically impossible for me to accidentally move something to ~/.dotfiles and then run 'git push.'
- smm11 4y agorsync dot files to wherever.
- 5e92cb50239222b 4y ago… and lose change history, handle merge conflicts by yourself (or lose edits made on other systems if you ever forget to re-sync), and all the other features of a proper VCS.
- heyoni 4y agoThese comments are like that famous one where dropbox was announced on HN and someone replied to it with an rsync script “that is essentially the same”. What’s it called when people do that?
- politelemon 4y agoPooh-poohing? Dismissiveness? Being an HNer?
- marcinreal 4y agoHah, I recently had to setup a cronjob that rsync's my org-mode files to iCloud. (iCloud didn't work with symlinks, but I needed to somehow sync my org-mode files to my phone.) Anyway, my org directory happens to be a git repo, and I rsync the whole repo including .git, so that's technically something you can do. :)
- 5e92cb50239222b 4y agoI very much prefer this simple method: https://www.atlassian.com/git/tutorials/dotfiles https://www.atlassian.com/git/tutorials/dotfiles tl;dr: it puts the .git directory aside and lets you use it to store any files on your filesystem. All the usual commands work, except you use something like `config` or `dofiles` instead of `git`: $ config add ~/.config $ config commit -m initial\ commit It's pretty much the same as creating a git repository in /, but doesn't mess with your normal git usage (so if you run `git status` in `/home/foo/src/my-awesome-project` and git repository has not been created there yet, git will fail with "not a git repository" and won't show you the contents of your whole filesystem tree).
- politelemon 4y agoThanks for sharing that. Question, where do you normally push the "repo" to?
- bryankaplan 4y agoI'm not the person you asked, but it's trivial to host your own git repos on a server.
- 5e92cb50239222b 4y agoDoesn't matter in my case, there are no secrets there (so I use a public git forge). If this doesn't work for you, you can just push to any old server via ssh: $ git remote add foobar address:path/relative/to/home/dir $ git push foobar , or self-host Gitea with registration closed if you want a proper forge.
- lvass 4y ago>if you run `git status` Is this a problem if you gitignore * (whitelisting)?
- 5e92cb50239222b 4y agoI used this initially (before running into the link above), but it still requires using a 'global' git repository which had its share of issues (some build scripts didn't like it, for example).
- AndrewVos 4y agoI use my own tool for this: https://github.com/AndrewVos/pj https://github.com/AndrewVos/pj
- simjue 4y agoShameless self-plug: I could never get along with storing the whole content of the dotfiles when I casually just added a few lines I cared about, so I developed my own tool called confible. You can specify to just append a few lines or add the whole config and it can run commands (e.g. installing the specific tool together with its config). You can find it at https://github.com/sj14/confible https://github.com/sj14/confible
- heyoni 4y agoThat’s pretty cool. The dumbed down version of that for me is sourcing different zshrc files depending on the machine I’m using…which obviously wouldn’t work for anything else.
- romeoblade 4y agoI started using fossil for this very thing. I was using git, however I like that fossil allows you to put the repository where ever you want on the file system. I don't have to worry about alias's, using .gitignore, or setting it it up where it doesn't show untracked files. As far as fossil is concerned, once you close the repo, it's out of site of mind. I still use git for most everything else. Only my dot files and my personal obsidian vaults are backed up to fossil.
- cssanchez 4y agoDo you use a cloud host like Github for Fossil?
- thunderbong 4y agoIf you have fossil installed on a server which is always on, you already have it! Otherwise, you can always use chisel [0] [0]: https://chiselapp.com https://chiselapp.com
- romeoblade 4y agoI have a small digital ocean droplet, lowest tier serving mine. I need to probably do a write up of the steps soon before I forget. I'ts its own web server so you have a lot of options. SCGI, HTTPS, SSH, Socket Listener. I have mine behind reverse proxy sand boxed with systemd's DynamicUsers feature.
- masklinn 4y agoCould you explain further? Because > I was using git, however I like that fossil allows you to put the repository where ever you want on the file system. I don't have to worry about alias's, using .gitignore, or setting it it up where it doesn't show untracked files. Git also lets you put the repository wherever you want on the filesystem, via worktrees or via the `--separate` link. And I fail to see the relationship with aliases or ignore files (the last item I guess you're talking about fossil not showing untracked files by default?)
- 4y ago
- j1elo 4y agoIt's 2022 and I still use this program since I read that article so many years ago. It's handy but sometimes a bit of manual preparation must be done on a new clean machine. For example if you want to stow only some files under ~/.config/program/ and not the whole program/ directory, you must first run an mkdir and then run stow to put the appropriate symlinks in place.
- heyoni 4y agoI use this too but every other time I come back to it I have to really read through the docs to figure stuff out. That’s just me not writing very useful notes though -_-
- marcinreal 4y agoWhen I did the setup I kept the commands I used in a Makefile. In theory, running `make` should do all the setup for me on a new machine.
- lasftew 4y agoUse the --no-folding flag to prevent stow from linking directories.
- BrotherBisquick 4y agoTo reiterate, the --no-folding flag prevents creation of symlinked directories, and it really should be the default behavior. I don't blame you for not knowing about this flag. Here's its description in the manpage: > Disable folding of newly stowed directories when stowing, and refolding of newly foldable directories when unstowing. This is confusing because it's a circular definition. It doesn't explain what "folding" means. It should just read, "prevents creation of symlinked directories" or something.
- j1elo 4y agoProblem is, this still makes sense in some cases but doesn't in others, and stow, as it is, doesn't care about the distinction. For example, on a machine where ~/.config/autostart/ doesn't still exist, I do not want that either ~/.config or ~/.config/autostart are created as symlinks to my stowed package; otherwise any newly installed file, from unrelated apps, would end up in my package! I just want this path to exist as a proper dir, and only contain whatever symlinks are needed from stow. Thus an `mkdir -p` is still needed before running stow. On the other hand, I do want that ~/.config/wireshark/ is a symlink to the stow repository. So no mkdir in this case. Regardless, having a script that adds extra per-package pre-process/post-process logic before/after running stow is still needed, anyway.
- neeasade 4y agoBeen doing this for about a decade, it works nicely. Def recommend stows `--no-folding` flag (which prevents it from symlinking directories, just files) obligatory vanity link: http://noriceno.life http://noriceno.life
- vinceguidry 4y agoI wound up writing my own stow replacement in Ruby, that moved the files rather than symlinked them. It does pattern-match the filenames with a list, anything on the list gets symlinked. It can also copy home-rolled binaries into /usr/local/bin. I suppose I could use both stow and etckeeper but a simple script can keep everything synced to my precise liking.
- canistel 4y agoI have to admit, sheepishly, that I use RCS for version controlling dot files and even files such as fstab and grub. I use it in Windows too. Infrequently, even on binary files (smirk). There, I have said it, and taken the load off my conscience...
- mek6800d2 4y agoA load off my mind too -- I now know there at least two of us in the world! :)
- dang 4y agoRelated: Using GNU Stow to manage your dotfiles (2012) - https://news.ycombinator.com/item?id=25549462 https://news.ycombinator.com/item?id=25549462 - Dec 2020 (113 comments) Using GNU Stow to manage dotfiles (2013) - https://news.ycombinator.com/item?id=15196141 https://news.ycombinator.com/item?id=15196141 - Sept 2017 (24 comments) Using GNU Stow to manage your dotfiles - https://news.ycombinator.com/item?id=8487840 https://news.ycombinator.com/item?id=8487840 - Oct 2014 (68 comments) Using GNU Stow to manage your dotfiles - https://news.ycombinator.com/item?id=6331485 https://news.ycombinator.com/item?id=6331485 - Sept 2013 (69 comments)
- tpoacher 4y agoSo, if I understand correctly, you can use GNU Stow to manage dotfiles?
- milicat 4y agoInteresting. I'd consider it, if I wasn't already on NixOS with home-manager.
- surrTurr 4y agoAre you using NixOS as your main desktop?
- jphsnsir 4y agoYes
- JamesSwift 4y agoStow was a good stepping stone before I adopted nix + home-manager. Its more effort to learn overall but also a much cleaner/stronger approach IMO.
- pilcha 4y agoAfter trying a bunch of tools I settled on git-tracking $HOME with '*' on my .gitignore (ignores everything, you have to add new files by --force). Is this better? symlinks seem like a smell.
- marcinreal 4y agoI didn't know about the --force flag. You can also whitelist files in .gitignore with !filename.[0] Is there a reason to avoid symlinks? I've been using this setup for a few years now, (using an artisanal, home-rolled script before I discovered stow) and it's worked superbly. [0]: https://monkeyfacts.io/git-whitelist-directory-subfiles/ https://monkeyfacts.io/git-whitelist-directory-subfiles/
- lambdaba 4y agoSymlinks can be broken, so if you can avoid them altogether why not? It's just an extra if tiny bit of complexity
- pjz 4y agohint: instead of using .gitignore, use .git/info/exclude - then there's no extraneous files in $HOME. And I agree, symlinks seem like a smell.
- hoosieree 4y agoHuh, I guess I implemented something like stow for myself without realizing it. I keep my dotfiles in a private git repo, and in that repo is a shell script that creates symlinks (or creates folders with symlinks inside). Paths are hard-coded in the shell script, but that actually reduces my cognitive load.
- clktmr 4y agoI'm doing the same: https://gist.github.com/clktmr/7343895cc0dcc5a80a6c3d39d22ca0d9 https://gist.github.com/clktmr/7343895cc0dcc5a80a6c3d39d22ca... This will also backup and restore any files it might override.
- blueflow 4y agoTrack you ~/.config (or whatever your XDG_CONFIG_HOME is) directory in git, and create symlinks for those programs that don't look there, optionally by script. Many programs already use that directory to store their configs. The Arch Linux folks are nagging every upstream into supporting it[1]. Also it requires no extra dependency aside git. I think i say this everytime a dotfiles manager comes up. [1] https://wiki.archlinux.org/title/XDG_Base_Directory https://wiki.archlinux.org/title/XDG_Base_Directory
- hiq 4y agoThis sounds like a good idea, I'd save all the `ln` commands the install.sh of my dotfiles repo. But do you just .gitignore all stuff in your .config you're not interested in?
- blueflow 4y agoI used to have some ignored, but nowadays i live with the files showing up as untracked.
- lambdaba 4y agoI take the opposite approach in that I keep the default config file locations and have .gitignore set to "*", and just force-add files as needed. Also have GIT_DIR and GIT_WORK_TREE=$HOME
- jasonpeacock 4y agoThere's also `homesick`[1], which is a Ruby dotfile manager. If you don't feel like managing a Ruby distro and want something more portable (and `homesick` looks to be a stale project anyway), you can use `homeshick`[2] which is a Bash port that's still being maintained. (I use `homeshick`) The last time I dug into this, `homeshick` was had more features and fit my needs better than `stow`. Alternatively, check out YADM[3], "Yet Another Dotfile Manager", which I'm probably switching to once I get some time. [1] https://github.com/technicalpickles/homesick https://github.com/technicalpickles/homesick [2] https://github.com/andsens/homeshick https://github.com/andsens/homeshick [3] https://yadm.io/ https://yadm.io/
- Despacito2019 4y agoI like to use yadm too! it's basically just git a few niceties like encryption
- pheasantquiff 4y ago(since no one has mentioned it yet). This project's name sounds a lot like GNUSTO, a magic word used in the Infocom/Sorcerer games to record an incantation in your spell book. https://en.wikipedia.org/wiki/Sorcerer_(video_game) https://en.wikipedia.org/wiki/Sorcerer_(video_game)
- tpoacher 4y agoI've seen this post on hackernews a few times now (as dang diligently pointed out). However, typically they don't mention that more recent versions of Stow actually have specific functionality for dotfiles, which is support for the `dot-` prefix. Check the man page for your version of stow. If the string "dot-" doesn't appear anywhere, you have an old version of stow. Also interesting to me was the fact that the `make` manual has information on how `stow` is actually one of the recommended workflows in makefiles (in the context of setting a DESTDIR); but I've never seen anyone actually do that in practice.