Personal Fedora Workstation setup with Sway/Wayland, fish-based shell workflows, development tooling, home-office VPN helpers, and Yocto-oriented automation.
Upcoming first release: 0.1.0
- Release notes: CHANGELOG.md
- Contribution workflow: CONTRIBUTING.md
- AI editing and validation rules: .AI-GUIDELINES.md
# Clone dotfiles to home
git clone <repo> ~/dotfiles
# Run base installation
bash ~/dotfiles/install-fedora.sh
# Optionally install dev tools and a pinned or latest VS Code
bash ~/dotfiles/install-fedora-dev.sh
# Reboot and start Sway
reboot
# or:
sway- Fedora-first workstation bootstrap
- Wayland/Sway desktop configuration
- Wayland-native screenshot and screen-recording helpers
- Fish, Bash, and Zsh shell setup
- Developer tooling, editors, and CLI utilities
- Yocto helper scripts and key-profile switching
- VPN, DNS, and remote-access helpers
- Personal documentation built with Sphinx
For the current linux-dps Scarthgap release work, the host-side helpers stay
generic and project-specific validation still lives in the wiki. The main entry
points remain setup-yocto-project, llp-yocto-build, and the Yocto helper
wrappers under shell/yocto, which are used for rc2 validation of the build,
WIC generation, and boot-related workflow.
This repository is intentionally host-focused and automation-focused.
- dotfiles repo owns host setup, helper scripts, wrappers, and local tooling
- project wiki repos own process, architecture, target behavior, and runbooks
- product development repos own implementation (layers, recipes, manifests, CI)
Use this split during updates:
- If a dotfiles helper changes, update the matching wiki usage docs.
- If project workflow docs change, verify helper names and options still match dotfiles.
- If product behavior changes, refresh both wiki process docs and dotfiles examples.
For Yocto topics, keep instructions generic in dotfiles and move project-specific details to the corresponding wiki collection.
Example pattern:
- dotfiles: document generic helper usage (setup, build wrapper, key switching)
- wiki: document a specific project flow (for example LLP, LPO, DPS)
This setup keeps an English keyboard layout and English system settings, while still allowing fast German text input (for example in documentation repos).
Default in this repo:
- Sway keyboard layout stays
uswith variantintl(US-International with dead keys) - Compose key is mapped to Menu key via
compose:menu
Preferred umlaut input with US-International:
"thena-> a-umlaut"theno-> o-umlaut"thenu-> u-umlaut
Compose fallback sequences:
Menu, then", thena-> a-umlautMenu, then", theno-> o-umlautMenu, then", thenu-> u-umlautMenu, thens, thens-> sharp-s- Use uppercase letters for A-umlaut, O-umlaut, U-umlaut
Verification:
swaymsg -t get_inputs | rg -n "xkb_layout|xkb_active_layout_name|xkb_options"Recommended day-to-day usage:
- Use
"+ letter for umlauts ("+a/o/u) - Use
Menu+s+sfor sharp-s
Base system setup for Fedora Workstation 41+. The script is intended to be idempotent and safe to re-run after updates or partial setup.
Phases:
- Package installation for desktop, network, and development tools
- Config symlinks for shell, editor, desktop, and Git setup
- Services and daemon configuration for system integration
- Shared Yocto directory preparation under
/opt/yocto
Usage:
install-fedora.sh [--skip-packages] [--skip-symlinks] [--skip-services] [--skip-docker] \
[--skip-docker-daemon-config] [--skip-dev] \
[--with-ssh-secrets] [--with-netrc-secrets] [--with-1password-ssh-agent]Highlights:
- Sway, Waybar, wofi, foot, and related Wayland tooling
grimshot.shandwf-record.shfor screenshots and browser/player screencasts- Modern CLI tools such as
rg,fd,fzf,zoxide, andhtop - NetworkManager with iwd backend
- Docker using a native Fedora setup path
- Yocto build environment preparation
- Auto-installed VPN DNS repair helper workflow
Optional development tooling bootstrap that can be run independently from the base install.
Includes:
- Neovim, git-delta, meld, and general editor tooling
- Go, Rust toolchain, pre-commit, GitHub CLI, PlantUML, pandoc, and PDF build support for Sphinx
crossfor Windows release builds of the SAT600 field backup tool- MQTT tools such as mosquitto clients and MQTT Explorer
- Yocto host build dependencies
- VS Code installation with version pinning support
- Azure CLI
Example:
VSCODE_VERSION=1.115 bash install-fedora-dev.sh
VSCODE_VERSION="" bash install-fedora-dev.sh
cargo build --release
cross build --release --target x86_64-pc-windows-gnuPDF output for the local documentation workspace is available after the dev script has installed the required LaTeX tooling:
make -C doc-engine latexpdfLegacy Ubuntu and Bash-focused setup paths are kept for reference. The primary target for active maintenance is Fedora with fish and Sway.
The repository includes a local Sphinx documentation workspace in doc-engine.
- Workflow file: .github/workflows/docs-pages.yml
- Published site URL: https://mweitner.github.io/dotfiles/
Activation notes:
- Ensure GitHub Pages is configured to deploy from GitHub Actions.
- Push changes to main, or trigger the workflow manually from the Actions tab.
- Check the deploy job output for the final page URL.
Common validation commands:
make -C doc-engine html
pre-commit run --all-filesUse these before tagging a release or after larger changes to scripts, docs, or shell config.
This repo includes helpers for the case where browser DNS behavior bypasses VPN-provided name resolution.
After connecting to VPN, run:
fix-vpn-dns-browser
test-vpn-dns
test-browser-dnsThe workflow is designed to:
- Configure systemd-resolved domain routing
- Disable conflicting browser DNS behavior where needed
- Clear DNS-related caches
- Re-check browser connectivity
Additional background is documented in INTEGRATION-VPN-DNS-FIX.md.
~/dotfiles/
|- install-fedora.sh
|- install-fedora-dev.sh
|- install.sh
|- shell/
|- fish/
|- sway/
|- waybar/
|- tmux/
|- tmuxp/
|- git/
|- systemd/
|- remmina/
|- doc-engine/
`- .secrets/
Key areas:
shell/: executable helpers, including Yocto and network toolingfish/: shell configuration and interactive helper functionssway/,waybar/,foot/,mako/: desktop environment configurationsystemd/,greetd/,tlp/: system integration and service configurationdoc-engine/: personal documentation source and local HTML build setup.secrets/: private material that must never be committed
sudo dnf upgrade
bash install-fedora.sh --skip-symlinkssetup-yocto-project --project linux-lpo
cd ~/lpo-dev/linux-lpo
lpo-build bitbake -u knotty -v lpo-display-imageswitch-yocto-keys-profile llp prod
switch-yocto-keys-profile lpo dev# Use explicit SWU path
swupdate-ssh-stream --host [email protected] \
--swu ~/ems-dev/linux-dps-scarthgap/build-docker/tmp/deploy/images/imx6s-mcg/dps-image-imx6s-mcg.swu
# Or auto-discover newest SWU from build output
swupdate-ssh-stream --host [email protected] --find-latest --machine imx6s-mcg
# Preflight-only check (no update transfer)
swupdate-ssh-stream --host [email protected] --check-only --find-latest --machine imx6s-mcgThe helper validates target-side prerequisites before streaming:
swupdate-clientmust exist on target/run/swupdate/sockinstctrlmust be present as a socketswupdateservice state is printed when systemd is available
remmina# Authenticate personal GitHub account
gh-account login --host github.com --method web --git-protocol https --user mweitner
# Authenticate enterprise GitHub account
gh-account login --host lis-github.liebherr.com --method web --git-protocol https --user michael-weitner
# If CLI hangs after browser approval (common without desktop keyring), retry with:
gh-account login --host lis-github.liebherr.com --method web --git-protocol https --user michael-weitner --insecure-storage
# If web auth stalls, use token mode instead (token is read from prompt or GH_TOKEN)
gh-account login --host lis-github.liebherr.com --method token --git-protocol https --user michael-weitner
# If you already have enterprise credentials in ~/.netrc, use them directly
gh-account login --host lis-github.liebherr.com --method netrc --git-protocol https --user michael-weitner --insecure-storage
# Show authenticated hosts/accounts
gh-account status
# Show compact host -> users mapping
gh-account list
# Switch active user on a host
gh-account switch --host lis-github.liebherr.com --user michael-weitner
gh-account switch --host github.com --user mweitnerToken notes for enterprise hosts:
- Token page pattern:
https://<host>/settings/tokens - Example enterprise URL:
https://lis-github.liebherr.com/settings/tokens - If token creation is blocked by enterprise policy, use web login mode.
--insecure-storageavoids keyring dependencies and stores auth in~/.config/gh/hosts.yml.--method netrcuses~/.netrc(machine <host> ... password <token>) as a non-interactive fallback.
Private material belongs under .secrets/ and should stay out of Git.
Use the install flags only when you intentionally want to copy local private data into a machine setup:
install-fedora.sh --with-ssh-secrets
install-fedora.sh --with-netrc-secrets
install-fedora.sh --with-1password-ssh-agentDo not document or commit real credentials, tokens, or internal private keys.
pre-commit run --all-files
pre-commit-helper --fix-config
setup-pre-commitRe-run the repair helpers and confirm the expected target resolves through the VPN path.
setup-yocto-project --help
yocto-prefetch-source --help
dps-fetch-release-swu --help
dps-hawkbit-upload --help
dps-tu-reonboard --help
swupdate-ssh-stream --helpThe next intended milestone is 0.1.0, which captures the first documented Fedora-first baseline
for workstation bootstrap, development tooling, documentation, and validation.