diff --git a/Brewfile b/Brewfile index 21531fd..5549842 100644 --- a/Brewfile +++ b/Brewfile @@ -56,7 +56,7 @@ brew "restic" cask "hammerspoon" brew "goat" brew "nmap" -brew "iproute2mac" +brew "iproute2mac" if OS.mac? brew "mtr" brew "wireshark" brew "nikto" @@ -75,7 +75,7 @@ cask "ngrok" brew "pandoc" brew "imagemagick" brew "ffmpeg" -brew "terminal-notifier" +brew "terminal-notifier" if OS.mac? brew "oath-toolkit" brew "openconnect" brew "openvpn" @@ -102,7 +102,7 @@ brew "glab" tap "atlassian/homebrew-acli", trusted: true brew "acli" brew "ghorg" -brew "mas" +brew "mas" if OS.mac? # Libs brew "yubikey-personalization" diff --git a/debian/README.md b/debian/README.md index c716324..05f9bd8 100644 --- a/debian/README.md +++ b/debian/README.md @@ -37,7 +37,8 @@ ansible-playbook ~/dotfiles/debian/ansible/update.yml --ask-become-pass force-install policy - clones dotfiles to `~/dotfiles` and runs `sync.sh` - homebrew at `/home/linuxbrew/.linuxbrew`, then brewsync - (`brew bundle --zap --force-cleanup`; casks are skipped on Linux) + (`brew bundle --zap --force-cleanup`; casks and `mas` entries are skipped + on Linux; mac-only formulae need an `if OS.mac?` guard in the Brewfile) - `mise install` for all tools in the mise config - caps lock mapped to ctrl; login shell → zsh; default browser → Helium - unattended security upgrades (daily, Debian's stock config) diff --git a/debian/ansible/setup.yml b/debian/ansible/setup.yml index 36cd1f2..432840c 100644 --- a/debian/ansible/setup.yml +++ b/debian/ansible/setup.yml @@ -232,6 +232,31 @@ shell: /usr/bin/zsh become: true + - name: Read keyboard input sources + ansible.builtin.command: + argv: + - gsettings + - get + - org.gnome.desktop.input-sources + - sources + register: kb_sources + changed_when: false + become: false + + # An empty sources list leaves GNOME without a managed keyboard layout, + # and xkb-options (caps lock) are then ignored. Only fills it in when + # empty, so custom layouts are never clobbered. + - name: Set default keyboard layout when none configured + ansible.builtin.command: + argv: + - gsettings + - set + - org.gnome.desktop.input-sources + - sources + - "[('xkb', 'us')]" + when: kb_sources.stdout | trim in ['@as []', '[]'] + become: false + - name: Read keyboard xkb options ansible.builtin.command: argv: