put the superseded setup scripts in setup-old, and repair what the move broke
scripts/setup/ is now what the new installer is being built in — machine-setup/ for the box, officer-setup.sh for the platform on top — and everything being replaced moved to scripts/setup-old/. It still works and is still what to run. Three things the move broke, and what each needed: starship.toml is not an old-setup artifact. os-user-shell.ts reads it at RUNTIME to seed a member's ~/.config/starship.toml when their Linux account is provisioned, and line 125 reads it inside a try whose catch returns "could not read the shell templates" — so account provisioning would have failed outright, not degraded. Moved back to scripts/setup/, which is where it belongs anyway (one file, both audiences) and which leaves the code correct with no edit. package.json's `setup` script pointed at a path that no longer exists. It now points at officer-setup.sh, where the installer is going, rather than at setup-old/ which is temporary. officer-setup.sh was created empty. An empty script exits 0, so `bun setup` would have reported success while doing nothing — worse than the broken path it replaced. It now explains that it is not written yet and exits 1, naming the setup-old script to run meanwhile. Also brought .tmux.conf and ufw-docker-rules.conf in beside machine-setup.sh, which reads both from SCRIPT_DIR and had been silently skipping them since the script was vendored. ssh-keys.zip deliberately stays out: it is key material, and *.zip is ignored. Comments in os-user-claude.ts, app-store/preflight.ts and two docs still name the old scripts/setup/setup.sh path. Left alone on purpose — repointing them at setup-old/ only to repoint them again when officer-setup.sh lands is churn. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,100 @@
|
||||
########## TPM AUTO-INSTALL + SESSION PERSISTENCE ##########
|
||||
|
||||
# Auto-install TPM if missing
|
||||
if-shell '[ ! -d ~/.tmux/plugins/tpm ]' \
|
||||
'run-shell "git clone https://github.com/tmux-plugins/tpm ~/.tmux/plugins/tpm"'
|
||||
|
||||
# Plugin list
|
||||
set -g @plugin 'tmux-plugins/tpm'
|
||||
|
||||
# remap prefix from 'C-b' to 'C-a'
|
||||
unbind C-b
|
||||
set-option -g prefix C-a
|
||||
bind-key C-a send-prefix
|
||||
|
||||
set -g base-index 1
|
||||
|
||||
# split panes using | and -
|
||||
unbind '"'
|
||||
unbind %
|
||||
bind | split-window -h
|
||||
bind - split-window -v
|
||||
|
||||
# reload config file (change file location to your the tmux.conf you want to use)
|
||||
unbind r
|
||||
bind r source-file ~/.tmux.conf \; display-message "Config reloaded!" \; refresh-client -S
|
||||
|
||||
# switch panes using Alt-arrow without prefix
|
||||
bind -n M-Left select-pane -L
|
||||
bind -n M-Right select-pane -R
|
||||
bind -n M-Up select-pane -U
|
||||
bind -n M-Down select-pane -D
|
||||
# switch panes using Alt-HJKL without prefix
|
||||
bind -n M-h select-pane -L
|
||||
bind -n M-l select-pane -R
|
||||
bind -n M-k select-pane -U
|
||||
bind -n M-j select-pane -D
|
||||
|
||||
# Enable mouse control (clickable windows, panes, resizable panes)
|
||||
|
||||
# don't rename windows automatically
|
||||
set-option -g allow-rename off
|
||||
|
||||
######################
|
||||
### DESIGN CHANGES ###
|
||||
######################
|
||||
|
||||
# loud or quiet?
|
||||
set -g visual-activity off
|
||||
set -g visual-bell off
|
||||
set -g visual-silence off
|
||||
setw -g monitor-activity off
|
||||
set -g bell-action none
|
||||
|
||||
# modes
|
||||
setw -g clock-mode-colour colour12
|
||||
setw -g mode-style 'fg=colour1 bg=colour18 bold'
|
||||
|
||||
# panes
|
||||
set -g pane-border-style 'fg=colour19 bg=colour0'
|
||||
set -g pane-active-border-style 'bg=colour0 fg=colour9'
|
||||
|
||||
# statusbar
|
||||
set -g status-position bottom
|
||||
set -g status-justify left
|
||||
set -g status-style 'bg=colour2 fg=colour23'
|
||||
# set -g status-left '#[fg=white,bg=black,bold] pastilhas #[default]'
|
||||
set -g status-left '#[fg=#ffffff,bg=#000000,bold] #{USER}@#H #[default]'
|
||||
# set -g status-left-length 20
|
||||
set -g status-right '#[fg=#ffffff,bg=colour1] %d/%m #[fg=#ffffff,bg=colour8] %H:%M:%S '
|
||||
set -g status-right-length 50
|
||||
set -g status-left-length 20
|
||||
|
||||
setw -g window-status-current-style 'fg=colour1 bg=colour19 bold'
|
||||
setw -g window-status-current-format ' #I#[fg=colour249]:#[fg=colour255]#W#[fg=colour249]#F '
|
||||
|
||||
setw -g window-status-style 'fg=colour9 bg=colour18'
|
||||
setw -g window-status-format ' #I#[fg=colour237]:#[fg=colour250]#W#[fg=colour244]#F '
|
||||
|
||||
setw -g window-status-bell-style 'fg=colour255 bg=colour1 bold'
|
||||
# ...existing code...
|
||||
# messages
|
||||
set -g message-style 'fg=#ffffff bg=red bold'
|
||||
# Change the font color for the exit pane confirmation message
|
||||
set -g message-command-style 'fg=#ffffff bg=red bold'
|
||||
|
||||
# ...existing code...
|
||||
|
||||
# messages
|
||||
# set -g message-style 'fg=colour232 bg=colour16 bold'
|
||||
|
||||
##########################
|
||||
### END DESIGN CHANGES ###
|
||||
##########################
|
||||
|
||||
##########################
|
||||
### EASY MOUSE SCROLL ###
|
||||
##########################
|
||||
|
||||
set -g mouse on
|
||||
set -ga terminal-overrides ',*256color*:smcup@:rmcup@'
|
||||
@@ -0,0 +1,33 @@
|
||||
# UFW Docker compatibility rules
|
||||
# Append these to /etc/ufw/after.rules (after the existing COMMIT)
|
||||
# Blocks all external access to Docker-published ports except:
|
||||
# - Trusted IPs (add your own)
|
||||
# - Explicitly allowed public ports (80, 443)
|
||||
# - Docker internal and loopback traffic
|
||||
|
||||
*filter
|
||||
:DOCKER-USER - [0:0]
|
||||
|
||||
# Allow established/related
|
||||
-A DOCKER-USER -m conntrack --ctstate ESTABLISHED,RELATED -j RETURN
|
||||
|
||||
# Allow loopback
|
||||
-A DOCKER-USER -i lo -j RETURN
|
||||
|
||||
# Allow Docker internal networks
|
||||
-A DOCKER-USER -s 172.16.0.0/12 -j RETURN
|
||||
|
||||
# Allow trusted external sources (add more lines as needed)
|
||||
# -A DOCKER-USER -s <TRUSTED_IP> -j RETURN
|
||||
|
||||
# Allow public ports
|
||||
-A DOCKER-USER -i eth0 -p tcp --dport 80 -j RETURN
|
||||
-A DOCKER-USER -i eth0 -p tcp --dport 443 -j RETURN
|
||||
|
||||
# Drop everything else from external
|
||||
-A DOCKER-USER -i eth0 -j DROP
|
||||
|
||||
# Return for non-external traffic
|
||||
-A DOCKER-USER -j RETURN
|
||||
|
||||
COMMIT
|
||||
Reference in New Issue
Block a user