Commit Graph
84 Commits
Author SHA1 Message Date
bchanot ef418fea04 chore(memory): journal — tmux selection, keep tmux 2026-10-06 15:05:00 +02:00
bchanot b73ee086fd Merge bugfix/tmux-selection into develop 2026-10-06 15:04:48 +02:00
bchanot b900c6d3a3 fix(tmux): visible selection colour, mouse drag copies on release
- mode-style bg=yellow,fg=black (black on a dark terminal was invisible)
- MouseDragEnd1Pane copies (pbcopy on macOS, tmux buffer elsewhere) without leaving copy-mode
2026-10-06 15:02:42 +02:00
bchanot ec9187c70f chore(memory): BDR-017 tmux ctrl+uhjk, BDR-018 Linux clipboard OSC 52 2026-10-06 14:28:35 +02:00
bchanot 7abef66f50 chore(memory): journal — tmux keys + Linux deploy 2026-10-06 14:26:39 +02:00
bchanot e3be25f94c Merge bugfix/tmux-macos-keys into develop 2026-10-06 14:26:29 +02:00
bchanot d2821fa462 feat(tmux): deploy the config on Linux too; prefix i / - splits
- install.sh: deploy_tmux_config runs on both OSes after the bashrc (gated on tmux)
- tmux.conf: clipboard via if-shell (pbcopy on macOS, tmux buffer + OSC 52 elsewhere)
- bashrc-linux exports XDG_CACHE_HOME like the macOS rc files
- prefix i = side-by-side split, prefix - = stacked split (h/j/k/l kept)
- verified in an Ubuntu 24.04 container (tmux 3.4): deploy, bindings, split, plugins, libtmux
2026-10-06 13:09:34 +02:00
bchanot ca8b1c19c9 feat(tmux): pane moves on ctrl+u/h/j/k (arrow layout, AZERTY/QWERTY invariant)
Replaces ctrl+h/j/k/l and the option+arrow bindings. Resize mirrors it with prefix.
C-l is free again, so it clears the shell screen.
2026-10-06 13:05:25 +02:00
bchanot b2244fc7ba feat(tmux): option+arrow moves between panes without prefix 2026-10-06 13:02:37 +02:00
bchanot d639f22e08 fix(tmux): macOS clipboard, C-a passthrough, vim detection
- y/p use pbcopy/pbpaste (xsel is X11, absent on macOS); xsel kept as the Linux variant in a comment
- bind C-a send-prefix: C-a C-a sends a literal C-a to the shell
- is_vim reads #{pane_current_command}; the @tmux_vim_<pane> variable was never set, so C-h/j/k/l never reached vim
2026-10-06 12:41:18 +02:00
bchanot 7adcef4f94 Merge feature/tmux-config into develop 2026-10-06 12:27:34 +02:00
bchanot 825abe842a feat(macos): deploy tmux.conf + tpm plugins; cloudpex becomes an install-time offer
- tmux.conf (vi keys, C-a prefix, resurrect/continuum, window-name) → ~/.config/tmux/tmux.conf
  on macOS; tpm cloned, plugins fetched headlessly, libtmux installed non-fatally
- bashrc-osx / zshrc-osx export XDG_CACHE_HOME (session save dir of the config)
- Linux: install_cloudpex → offer_cloudpex ([y/N] with the /tmp and SSH offers)
- README + CLAUDE.md updated
2026-10-06 12:27:22 +02:00
bchanot 1fbbffcedc chore(memory): journal — v1.0.0 release 2026-10-06 11:53:26 +02:00
bchanot dda3fabcf7 Merge release/1.0.0 into develop 2026-10-06 11:41:37 +02:00
bchanot caf388ce0b chore(release): 1.0.0 — version.txt + CHANGELOG 2026-10-06 11:39:40 +02:00
bchanot dd36bc6f18 chore(githooks): refresh post-commit/post-merge from the lib (hook label) 2026-10-06 11:38:56 +02:00
Bastien CHANOT 7acdcd4128 Merge feature/gitconfig-user-scope into develop 2026-10-06 11:25:48 +02:00
Bastien CHANOT d293943106 feat(install): add git-delta to the apt and brew packages
gitconfig sets core.pager = delta; without the binary git cannot page.
2026-10-06 10:55:24 +02:00
Bastien CHANOT 51521e7ca4 feat(git): deploy user-scope ~/.gitconfig from the repo template
Git never expands $VARS in its config, so gitconfig carries @USER@ and
@EMAIL@ placeholders that install.sh fills from the deployed bashrc's
USER/EMAIL exports. A differing ~/.gitconfig is kept as
~/.gitconfig.backup-<date>; an identical one is left alone. A repo's
.git/config still overrides it. excludesfile uses ~ (git expands it,
not $HOME).

The rc files now override $USER, so the installer takes the login name
from id -un for dscl and the code-server unit.
2026-10-06 10:55:24 +02:00
Bastien CHANOT 3b53213af4 feat(shell): export identity as USER/EMAIL instead of VIUSER/VIMAIL
Same names in bashrc-linux, bashrc-osx and zshrc-osx, so the vim header
and the rendered ~/.gitconfig share one identity.
2026-10-06 10:55:14 +02:00
Bastien CHANOT f053164cf7 chore(memory): BDR-015/016 macOS + zshrc backup, LRN-014 BSD traps, BLK-007 master URL, journal 2026-10-05 17:32:33 +02:00
Bastien CHANOT 7d5dabda36 Merge feature/macos-support into develop 2026-10-05 17:28:53 +02:00
Bastien CHANOT 7edde9d0f3 chore(todo): macOS support + zsh choice plans 2026-10-05 17:28:47 +02:00
Bastien CHANOT cebc1f055a docs: macOS install, shell choice and zsh files 2026-10-05 17:28:47 +02:00
Bastien CHANOT 093d21f8a1 feat(install): macOS via Homebrew, colima, brew services, bash/zsh login shell choice, gaps report; cp -Rpv for BSD cp 2026-10-05 17:28:47 +02:00
Bastien CHANOT 6b60b64c8f feat(zsh): macOS zshrc (oh-my-zsh) + bchanot theme porting the bash prompt 2026-10-05 17:28:47 +02:00
Bastien CHANOT f09151d1f3 feat(bashrc-osx): mirror bashrc-linux with macOS deltas (brew env, ls -G, EPOCHREALTIME timer, cc without systemd-run) 2026-10-05 17:28:46 +02:00
Bastien CHANOT 72648597ee fix(dt): macOS portability (lsof cwd, BSD date start time, bash 3.2 tilde, sed -E help) 2026-10-05 17:28:39 +02:00
bastien 1a4f8d4715 Merge feature/apt-packages into develop 2026-09-28 21:57:04 +02:00
bastien ba1817a4e9 chore(memory): BDR-014 apt mirror choices, LRN-013 gitleaks version probe 2026-09-28 21:57:03 +02:00
bastien 3c5b1ece6e chore(memory): journal — apt packages feature, gitleaks hook fix 2026-09-28 21:41:27 +02:00
bastien 9e49b9d92c chore(githooks): refresh pre-commit (gitleaks protect fallback) + track reference-transaction 2026-09-28 21:41:06 +02:00
bastien 0bc9e3f467 feat(install): mirror this machine's apt packages
gitleaks, web stack (mariadb-server, imagemagick, unversioned php-* modules),
ubuntu-desktop-minimal before the RDP setup, and a lspci-gated
install_nvidia_driver() that runs ubuntu-drivers install. README + TODO updated.
2026-09-28 21:41:05 +02:00
bastien 58adb28ec2 chore(memory): journal, branch cleanup + gitea-deploy split out 2026-09-22 18:03:46 +02:00
bastien a42e8f6024 chore(githooks): refresh pre-commit/post-commit/post-merge from the lib (gitleaks backstop, autopush) 2026-09-22 17:55:41 +02:00
bastien cfd144d158 chore(memory): journal, security baseline merged 2026-09-22 17:53:53 +02:00
bastien a6c416e1cf Merge feature/security-baseline into develop 2026-09-22 17:53:46 +02:00
bastien 26c8e345c5 chore(memory): BDR-013 security baseline, LRN-012 fail2ban port vs allports, journal 2026-09-22 17:47:35 +02:00
bastien 55ede6f08c feat(install): security baseline: fail2ban, unattended-upgrades, sshd hardening
Always applied in the Linux block, no prompt, idempotent:
- install_fail2ban: fail2ban + nftables, etc/fail2ban/jail.d/local.conf.
  sshd jail reads the journal (backend systemd, works with or without
  auth.log) and bans the offender on every port, so the SSH port is
  irrelevant: the previous server's jail banned 22 while sshd listened
  on 337. 5 failures / 10 min / 1 h. Loopback + RFC1918 never banned.
- install_unattended_upgrades: package + 20auto-upgrades (the file
  dpkg-reconfigure writes, without the prompt).
- harden_sshd: sshd_config.d/20-hardening.conf (PermitRootLogin no,
  MaxAuthTries 3, LoginGraceTime 20), sshd -t gated: a rejected file is
  removed and the install continues with a warning. Auth methods, port
  and user lists untouched.
Docs: README table + step 13 + packages, CLAUDE.md layout.
2026-09-22 17:47:34 +02:00
bastien 0d2e96819a chore(memory): journal 2026-09-22, round-2 TODO closed 2026-09-22 17:35:05 +02:00
bastien 836bb675bf Merge feature/tmp-disk-ssh-oom-cloudpex into develop 2026-09-22 17:34:31 +02:00
bastien 6e38c3b6cf Merge main into develop 2026-09-22 17:34:30 +02:00
bastien a9f7b6437f chore(memory): capitalize /tmp on disk, SSH guard, cloudpex conf (BDR-010..012, LRN-009..011, BLK-005/006, EVAL-002) 2026-09-22 17:34:18 +02:00
bastien 4f8bb61458 feat(cloudpex): site values out of the script, prompted at install into /etc/cloudpex.conf
cloudpex/cloudpex no longer carries the NAS host, share name, SMB user,
mount point or SMB version. It reads /etc/cloudpex.conf (root:root 0600,
KEY=value) line by line, never sources it, and dies with a hint when the
file is missing, incomplete or has a relative mount point.

cloudpex/install.sh prompts for the five values (regex-validated, re-asked
on bad input so the main installer never aborts), shows and keeps an
existing config unless answered n, and skips the config when no terminal
is attached. README (FR) + root README + CLAUDE.md updated.
2026-09-22 17:34:18 +02:00
bastien 872079bafb feat(install): offer /tmp on disk + SSH memory guard, deploy cloudpex helper
/tmp is a RAM-backed tmpfs on Ubuntu (50% of RAM). Agent runs fill it: half
the RAM goes, then every temp-file creation fails with ENOSPC and shells
break. Swap does not lift the cap, so the fix is /tmp on disk.

End-of-install offers (Linux, [y/N], skipped without a terminal, idempotent):
- offer_tmp_on_disk: mask tmp.mount + etc/tmpfiles.d/tmp.conf (wipe at
  boot, 10-day purge, /var/tmp rule kept). Effective at next reboot.
- offer_ssh_memory_guard: the previous server's rules. ssh.service drop-in
  (OOMScoreAdjust=-1000, MemoryMin=256M) + earlyoom with --avoid sshd and
  --prefer node/java. MemoryMin covers sshd only; earlyoom is the real guard.

install_cloudpex deploys the NAS mount helper in the Linux block.
Docs: README steps 12-14 + table, CLAUDE.md layout + lint command.
2026-09-22 16:57:08 +02:00
bastien 9dacef3823 feat(cloudpex): track the on-demand SMB mount helper, add installer + README
cloudpex/cloudpex mounts //192.168.1.111/CloudPex on /mnt/cloudpex on demand
(password prompted, nothing stored, noexec/nosuid/nodev, dir_mode 0750).
cloudpex/install.sh reproduces the live deployment: /usr/local/bin/cloudpex
root:root 0755, /mnt/cloudpex, cifs-utils if mount.cifs is missing.
README (FR) explains why on-demand and not fstab (RECOVERY doc 04).
2026-09-22 16:57:08 +02:00
bastien a210d0173b added correct dtach 2026-09-22 02:07:49 +00:00
Bastien Chanot 5a8b575f1a added the gh package instalation in install script 2026-07-01 21:25:14 +02:00
Bastien Chanot bd593e007d Merge feature/doc-sync into develop 2026-07-01 14:31:36 +02:00
Bastien ChanotandClaude Opus 4.8 bfd9f31ff0 docs: install.sh OS auto-detect
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RNaYKPEkjH1jbgoX1TwKMX
2026-07-01 14:31:36 +02:00