A twilight garden where bright green paths connect young shoots.

A quieter way to tend your home directory

One garden.
Every setup.

Keep your dotfiles in profiles, link them into ~, and keep secrets in their vault.

Open source · Unlicense

Scroll to explore

A profile is a plot of its own

Your setup, kept together.

dot installs and maintains one or more dotfiles profiles. Each profile is a data repository with a dot.json manifest, cloned into ~/.dot/<key>.

The files stay in their repository. Symbolic links bring them into your home directory, while the guard and vault integrations help keep the sensitive parts in the right place.

Explore the documentation

one profile

~/.dot/personal/home/.zshrc~/.zshrc
~/.dot/personal/bin/~/.local/bin/

The path in ~ leads back to the profile.

Plant files where programs expect them

From repository to home.

Keep deployable files under home/ and executables under bin/. dot install links them into the places your system already uses.

01

Files become links

home/.zshrc → ~/.zshrc
bin/backup → ~/.local/bin/backup
02

Keep editing in place

~/.zshrc → profile/home/.zshrc
03

Safe to repeat

Existing files move to a backup. Running dot install again changes nothing.

dot install -n prints steps without running them. Existing files are not overwritten.

A lock on the garden gate

Catch a leak before it leaves.

dot guard checks files and git metadata for forbidden terms and secrets, from one-line hooks on commit and push.

The guard fails closed if its terms list is missing or its scanner is unavailable. It reports file names, branches and commits, never the text it found.

Checks happen before dot push writes and pushes profile changes.

The key stays with the vault

Use a secret.
Keep it out of config.

Store a reference in your profile. dot secrets run reads the value from Bitwarden (bw) or Proton Pass (pass-cli) only when the wrapped command needs it.

Names stay in a local secrets.local file with mode 600. A value is not passed as a process argument or left in your shell.

vault → command
dot secrets add GITHUB_TOKEN bw:github-token
dot secrets run GITHUB_TOKEN -- gh api user

Personal and work can share a machine

More than one patch.

Keep profiles side by side. Each can bring a different git identity, and dot treats them all the same way.

personal

personal

dot install https://github.com/you/dotfiles-perso.git

One repository, one profile.

work

work

dot install https://github.com/you/dotfiles-work.git -p work

Choose a profile for repositories under a folder.

Both profiles update with dot pull. If they claim the same link, install refuses before writing.

Tend shared tools from one profile

One place for agent config.

dot settings and dot mcp merge a profile's settings and MCP servers into Claude Code, Codex and OpenCode.

Preview the plan before applying it, or preview the settings diff.

profilehome/.claude/settings.base.jsonhome/.config/mcp/servers.json
  • Claude Code
  • Codex
  • OpenCode

Start with a profile

Put down roots.

Install the static binary and, if you want, give the installer a profile URL. The installer checks the download, then runs dot self-update.

All documentation
quick startLinux · macOS
curl -fsSL https://raw.githubusercontent.com/fmatsos/dot/main/install.sh | sh -s -- https://github.com/you/dotfiles.git
dot install https://github.com/you/dotfiles.git -n
dot doctor
View dot on GitHub

A small set of clear commands

The tools in your kit.

From installing links to checking a profile, the command reference is in the README.

dot install

Clone, register and link a profile.

dot pull · dot push

Update profiles, or commit and push tracked changes.

dot status · dot doctor

See profile changes or get a read-only health report.

dot adopt · dot backups

Bring a home file into a profile, or restore a backup.

dot guard · dot secrets

Check for leaks and resolve secrets from your vault.

dot settings · dot mcp

Merge agent settings and MCP servers.

See all commands and options

Grow the project

Built in the open.

dot is written in Go with Cobra. The project documents its design, development workflow and private vulnerability reporting.

Public domain

Unlicense

Read the license