This repository contains my personal dotfiles and development environment configuration, managed with Ansible for easy deployment across multiple systems and operating systems.
This repository uses Ansible roles to deploy and manage dotfiles. This approach provides several benefits:
- OS-specific configurations: Automatically generates appropriate configs for different operating systems (Linux, macOS)
- Template-based: Uses Jinja2 templates to create clean configuration files without runtime conditionals
- Idempotent: Can be run multiple times safely
- Modular: Each tool has its own role for easy management
- Secure: Sensitive variables can be encrypted with Ansible Vault
| Role | Description |
|---|---|
system |
System-level configuration and packages (desktop and server) |
neovim |
Neovim text editor configuration |
tmux |
Terminal multiplexer configuration |
zsh |
Zsh shell with modern tools (fzf, zoxide, antidote, oh-my-posh) |
fish |
Fish shell configuration with oh-my-posh |
firewall |
UFW firewall configuration (desktop) |
streamdeck |
Stream Deck scripts for monitor management |
zsa |
ZSA keyboard (ErgoDox/Moonlander) udev rules |
iptables |
Server firewall via iptables-persistent, default-deny inbound |
mariadb |
Locks MariaDB's listening socket to loopback |
bind9 |
Disables DNS recursion (prevents open-resolver abuse) |
fail2ban |
Ban-time/recidive-jail hardening on top of the package defaults |
unattended_upgrades |
Ensures security updates actually auto-apply |
- Ansible installed on your system
- Git (for cloning the repository)
- Supported OS: Linux (Fedora, Arch Linux, Debian-based) or macOS
git clone <repository-url> ~/dotfiles
cd ~/dotfiles# Run all roles
ansible-playbook run.yml --ask-become-pass
# Run specific roles with tags
ansible-playbook run.yml --tags zsh,tmux --ask-become-pass
# Run on localhost
ansible-playbook run.yml -i "localhost," --connection=local --ask-become-passrun.yml- Main playbook that runs all rolesdesktop.yml- Desktop-specific configurationmacos.yml- macOS-specific configurationserver.yml- Server hardening: firewall, MariaDB/BIND lockdown, fail2ban tuning, unattended-upgrades, legacy package purge, SSH hardening
Run it against a remote server (not localhost) by pointing at an inventory with that host, e.g.:
ansible-playbook server.yml -i "your.server.ip," -u your_user --ask-become-passSome roles contain sensitive information (API keys, credentials, project IDs) that should not be stored in plain text. This repository uses Ansible Vault to encrypt sensitive variables.
# Encrypt a vault file (first time)
ansible-vault encrypt roles/<role-name>/vars/vault.yml
# You'll be prompted to create a vault password# Edit encrypted vault file
ansible-vault edit roles/<role-name>/vars/vault.yml
# You'll be prompted for the vault passwordWhen you have encrypted vault files, you need to provide the vault password:
# Prompt for vault password
ansible-playbook run.yml --ask-vault-pass --ask-become-pass
# Use a password file
ansible-playbook run.yml --vault-password-file ~/.vault_pass --ask-become-pass
# Use environment variable
export ANSIBLE_VAULT_PASSWORD_FILE=~/.vault_pass
ansible-playbook run.yml --ask-become-pass# Create password file
echo "your-secure-password" > ~/.vault_pass
chmod 600 ~/.vault_pass
# Add to .gitignore
echo ".vault_pass" >> ~/.gitignoreThe repository includes OS-specific variable files in the vars/ directory:
vars/debian.yml- Debian-based distributionsvars/fedora.yml- Fedoravars/archlinux.yml- Arch Linuxvars/default.yml- Default fallback
These are automatically loaded based on your system's distribution.
Each role can be customized by:
- Overriding variables in the playbook
- Editing role defaults in
roles/<role-name>/defaults/main.yml - Creating host-specific or group-specific variables in inventory
Example:
---
- hosts: all
roles:
- role: zsh
vars:
zsh_bat_theme: "Nord"
zsh_project_home: "$HOME/dev/projects/"Each role has its own README with detailed documentation:
Use tags to run only specific roles:
ansible-playbook run.yml --tags zsh
ansible-playbook run.yml --tags "zsh,tmux,neovim"Test what would change without making actual changes:
ansible-playbook run.yml --check --diffFor debugging:
ansible-playbook run.yml -v # Verbose
ansible-playbook run.yml -vv # More verbose
ansible-playbook run.yml -vvv # Very verboseMIT