11# Configuration ownership and maintenance
22
33` home-manager/machine.json ` is the shared source for the username, home directory,
4- architecture, dotfiles and Config Bible paths , backup mount/repository, and KWallet
4+ architecture, dotfiles path , backup mount/repository, and KWallet
55entry names. It contains identifiers, never the Restic password. Edit it before
66building on another host. Home Manager reads it at evaluation time and installs
77it as ` ~/.config/dotfiles/machine.json ` ; operational scripts read the same JSON via
@@ -33,10 +33,10 @@ prerequisites described in [RECOVERY.md](RECOVERY.md). User shell tools, fonts a
3333jq are declared through Home Manager. Python helpers use the system interpreter;
3434the validation environment provides Python separately.
3535
36- The external Config Bible repository contains the full documentation collection.
37- Its location comes from ` configBibleDirectory ` ; its app must be built separately.
38- Personal Restic backups include that directory. The old batch-import instructions
39- have been removed; use the Config Bible repository for its documentation workflow .
36+ The external Config Bible repository owns the handbook and its commands, desktop
37+ launcher, installer, and optional Home Manager module. It installs independently
38+ of dotfiles; see its README. Its installer registers its checkout for personal
39+ backup through the generic ` ~/.config/backup-personal/paths.d/ ` directory .
4040
4141## Validation
4242
@@ -64,7 +64,7 @@ These checks do not run backups, perform restores, or activate a generation.
6464Installed helpers load machine settings explicitly, including when invoked by
6565systemd without interactive shell startup. For a one-off recovery or fixture run,
6666set ` DOTFILES_MACHINE_CONFIG ` to another JSON file. Individual environment values
67- can override defaults: ` DOTFILES_DIR ` , ` CONFIG_BIBLE_HOME ` , ` BACKUP_MOUNT ` ,
67+ can override defaults: ` DOTFILES_DIR ` , ` BACKUP_MOUNT ` ,
6868` RESTIC_REPOSITORY ` , ` HM_PROFILE ` , ` RESTIC_WALLET ` , ` RESTIC_WALLET_FOLDER ` , and
6969` RESTIC_WALLET_ENTRY ` . Mount and repository overrides are independent: override
7070both when relocating the backup repository. Rebuild Home Manager to change the
@@ -110,11 +110,6 @@ historical Git objects or automatically remove local font duplicates.
110110
111111## Runtime checks
112112
113- ` bible-secrets ` returns 0 for a completed scan without matches, 1 when potential
114- secrets are found, and 2 when a directory is missing or a search fails. It reports
115- filenames only. Ripgrep ignore rules still apply; this is a heuristic scan of the
116- searchable tree, not a guarantee that every local file is secret-free.
117-
118113Neovim disables automatic formatting above 1 MiB of buffer contents and restores
119114the previous buffer preference when the buffer shrinks. Manual ` :LazyFormat `
120115remains available. ` ldir ` lists directories and ` lf ` lists files.
@@ -136,7 +131,7 @@ action revisions. It validates and builds without activating Home Manager.
136131## Backup coverage and health
137132
138133Personal Restic captures include ` ~/github ` (including unpushed repository work),
139- ` ~/Projects ` , the configured Config Bible directory , and the existing personal
134+ ` ~/Projects ` , application-registered extra paths , and the existing personal
140135folders. ` backup-secrets ` separately encrypts SSH, GnuPG, and KWallet; GnuPG
141136sockets, lock files, and random-seed state are excluded from its archive.
142137
@@ -174,3 +169,12 @@ and cannot detect secrets pasted into otherwise tracked configuration files.
174169` home-manager/machine.json ` remains tracked because the Git-based Nix flake
175170requires it. It contains machine identifiers and paths, so keep credentials out
176171of it. Use sanitized example files when documenting secret configuration.
172+
173+ ## Application backup registrations
174+
175+ Independent applications can register repositories in
176+ ` ~/.config/backup-personal/paths.d/ ` . Each file contains absolute paths, one per
177+ line; empty lines and lines beginning with ` # ` are ignored. Existing paths are
178+ added to personal backups. Relative paths are rejected before starting Restic.
179+ Applications own their registration files; dotfiles has no dependency on their
180+ source or installation modules.
0 commit comments