This repository has no description
README.md

Debian setup #

Ansible playbooks for a fresh Debian trixie (GNOME) machine. Targets the current user on localhost; sudo is prompted via --ask-become-pass.

First run (new machine) #

sudo apt-get install -y git
git clone https://tangled.sh/seth.computer/dotfiles ~/dotfiles
~/dotfiles/debian/bootstrap.sh

Later runs #

setup.yml is idempotent; re-run it anytime (also picks up new ghostty and obsidian releases, which have no apt repo).

ansible-playbook ~/dotfiles/debian/ansible/setup.yml --ask-become-pass

Update all apt packages:

ansible-playbook ~/dotfiles/debian/ansible/update.yml --ask-become-pass

What setup.yml does #

  • apt packages: thunderbird, zsh, git, curl, gnupg, jq, wl-clipboard, xdg-utils
  • apt repos + install: Helium (helium-bin), 1Password (+ op CLI), Tailscale, Signal (amd64 only — no arm64 build)
  • Docker Engine (rootless): installs the engine from Docker's apt repo, disables the rootful system daemon, and runs the daemon as the login user via dockerd-rootless-setuptool.sh + a user systemd service with lingering enabled
  • ghostty and obsidian: latest GitHub-release .debs (mkasberg/ghostty-ubuntu, obsidianmd/obsidian-releases)
  • Helium extensions (1Password, Vimium, Margin, Dark Reader) via Chromium force-install policy
  • clones dotfiles to ~/dotfiles and runs sync.sh
  • homebrew at /home/linuxbrew/.linuxbrew, then brewsync (brew bundle --zap --force-cleanup; app casks and mas entries are skipped on Linux — font casks are not, they install to ~/.local/share/fonts, which is how ghostty's Iosevka nerd font gets there; mac-only formulae need an if OS.mac? guard in the Brewfile)
  • mise install for all tools in the mise config
  • caps lock → ctrl (kernel-level udev hwdb remap, applies in every session)
  • login shell → zsh; default browser → Helium
  • unattended security upgrades (daily, Debian's stock config)
  • pi Umans login: API key pulled from 1Password (umans-api-key item, password field) into ~/.pi/agent/auth.json

Manual steps #

  • Sign in to the 1Password desktop app, then enable Integrate with 1Password CLI in its developer settings. Until then, setup skips the pi Umans login (it prints a note); re-run setup afterwards.
  • The op key fetch triggers a 1Password approval prompt — approve it while setup runs.
  • Authenticate tailscale: sudo tailscale up (opens a browser login). The service itself is enabled by the package.
  • If the Helium extensions don't auto-install, that's the upstream force-install bug — install them manually from the Chrome Web Store.

Caveats #

  • Helium extension force-installs are currently broken upstream (helium#1737). The policy file is in place and correct; until the bug is fixed, install the extensions manually from the Chrome Web Store.
  • Ghostty and Obsidian ship no apt repo on Debian, so apt upgrade will not update them. Re-run setup.yml to pick up new releases.
  • 1Password sign-in and developer settings (CLI, SSH agent) are manual.
  • Homebrew's docker/docker-buildx/lima/colima are macOS-only in the Brewfile; on Linux the Docker Engine from apt provides the CLI and daemon.