macOS workstation setup for my personal and MLB machines — fish shell, chezmoi management, 1Password secrets through fnox, and Catppuccin theming. XDG spec-compliant where possible.
- Shell — fish, with the tide prompt, fisher
plugins, and custom functions/abbreviations (
up,gh,k8s-*, chezmoi aliases). - Secrets — fnox resolves keys from 1Password on demand, loaded per-directory
via
fnox activate fish; a daemon caches resolved values in memory only. - Env & tools — mise scopes tools and environment variables by directory.
- Themes — Catppuccin for bat, eza, ghostty, and Helix, fetched from upstream archives
(
.chezmoiexternal.toml, 168h refresh). Macterm and Helix follow the system light/dark appearance. - pi — the pi coding agent: homegrown skills (
~/.agents/skills), global extensions, subagent definitions, and npm packages.
If you already have chezmoi:
chezmoi init --apply mgoodnessOtherwise:
sh -c "$(curl -fsLS get.chezmoi.io/lb)" -- init --apply mgoodnesschezmoi init prompts for two independent roles — mlb and personal — which gate
machine-specific Homebrew packages, secrets, git identity, and macOS defaults. A machine can
carry both.
After applying, .chezmoiscripts/ installs Homebrew packages (brew bundle), gh extensions,
pi packages, and agent skills; sets macOS defaults; configures fish as the login shell; and
wires up worktrunk.
Repos live under ~/Code/ by git host — github.com/, emu.github.com/, and
github.mlbam.net/ — each with its own .gitconfig for identity and signing (1Password
op-ssh-sign). gh repo clone places a repo at ~/Code/{host}/{user}/{repo} (run mise install yourself for a plain clone).
Parallel work happens in git worktrees via worktrunk (wt), run inside
Macterm. A fresh chezmoi init --apply installs worktrunk and the macterm cask, and
run_after_31-worktrunk-setup.sh wires up worktrunk's fish integration and pi activity extension.
The pre-start hook in ~/.config/worktrunk/config.toml preps env (mise → direnv) on
wt switch --create <branch>, so each new worktree is ready to go.