A /mission-control pane showing live agents, recent tool calls and files touched this session.

A macOS-focused developer workstation built around Zsh, Powerlevel10k, modern CLI tools, and battle-tested automation. Everything is wired together with bestow (a Go-based GNU Stow successor), encrypted secrets, and a centralized package manifest so each new machine behaves exactly like the last one.
z command), Atuin history (Ctrl+R and up-arrow), and Ghostty compatible key bindingsgw), and curated helper aliases/functions (take, kill_by_port, show_tools, etc.)<leader>d… plus F5/F10/F11) shared by every language. Go (delve) supports debugging the test under the cursor, launching the program with arguments, and attaching to a remote dlv --headless; Python, Java, and Ballerina are wired in too. Adding another debugger is a single drop-in file — see Adding a Debugger<leader>G… for code generation (if err != nil guards, struct tags, interface stubs, test and doc-comment generation), and <leader>T… to run tests from the buffer with a summary tree and watch modev for nvim, g for ripgrep, f for fd, z for zoxide) while keeping original commands for scripts.md → mdcat, .json/.yaml → jless, .py/.sh/.bal → $EDITOR)pam-reattach)ControlEscape.spoon: tap Caps Lock for Escape, hold for Control — a Karabiner alternative that needs only Accessibility/Input Monitoring permissions, no blockable system extensionedit_secrets workflow, and automatic .env handling inside init.shBrewfile with optional category files in packages/ for modular installationtest-zsh integration tests, profile_startup quick timing, and bin/profile-zsh-startup for deep divesgit --version /bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)"
brew install --cask font-fira-code-nerd-font
Set the font once inside your terminal profile (Appearance/Text settings).
init.sh)git clone https://github.com/ThisaruGuruge/dotfiles.git ~/dotfiles
cd ~/dotfiles
./init.sh
The script is interactive; it will:
bestow)Brewfile with Brewpam-reattach).env with SOPS + age (keys stored at ~/.config/sops/age/keys.txt)bestowtest-zsh and show next stepsgit clone https://github.com/ThisaruGuruge/dotfiles.git ~/dotfiles
cd ~/dotfiles
# Install everything that is currently enabled in Brewfile
brew bundle --file=Brewfile
# Install bestow (requires Go)
go install github.com/redpierrot/bestow@latest
# Bootstrap bestow's own config (source: this repo, destination: $HOME)
bestow init --source ~/dotfiles --destination ~/
# Symlink the packages you need (add/remove as desired)
bestow stow zsh git tmux direnv bash
# Copy the env template (will be encrypted later by init/edit_secrets)
cp zsh/.env.example zsh/.env
# Reload configuration
source ~/.zshrc
Edit the Brewfile directly or use category Brewfiles in packages/ before running brew bundle if you want to customize packages.
Already have a preferred dotfiles strategy but want the curated tools? Run brew bundle --file=Brewfile and manually pick pieces (aliases, functions, etc.). Edit the Brewfile directly or use the category files in packages/ to customize your installation.
The main Brewfile contains core packages that are always installed. Optional packages are organized into category files in packages/:
packages/
├── cloud.brewfile # AWS, GCP CLIs
├── containers.brewfile # colima, Docker CLI + Compose + credential helper
├── development.brewfile # pyenv, rbenv, nvm, flutter
├── editors.brewfile # Cursor, VS Code
├── productivity.brewfile # Raycast, Rectangle, etc.
└── terminals.brewfile # iTerm2
brew bundle --file=Brewfile # Core packages
brew bundle --file=packages/development.brewfile # Add dev tools
brew bundle --file=packages/editors.brewfile # Add editors
core – powerlevel10k, zoxide, eza, bat, ripgrep, lazygit, lazydocker, tmux, direnv, atuin, gh, etc.security – sops + age for encrypted secrets (always enabled)development – pyenv, rbenv, nvm, flutter (optional)aws, gcp – cloud CLIs and helperseditors – Cursor, VS Codeterminals – iTerm2 (casks)containers – colima (container runtime), Docker CLI + Compose + credential helperproductivity – Raycast, Rectangle, TablePlus, Alfred, PostmanComment out what you do not need in the Brewfile, then rerun brew bundle.
| Path | Notes |
|---|---|
zsh/ | .zshrc, .zshrc.d/ (modular shell config), .functions.d/ (modular functions), aliases, paths |
zsh/.zshrc.d/ | 7 modules: plugins, completion, keybindings, history, integrations, environment, tmux |
zsh/.functions.d/ | 9 modules: colors, core, navigation, archives, git, system, dotfiles, docs, packages |
<tool>/.config/<tool>/ | XDG configs, one stow package per tool (ghostty, lazygit, nvim, yazi, ripgrep, typos) |
zsh/.p10k.zsh | Powerlevel10k prompt config (Catppuccin Mocha, stowed to ~/.p10k.zsh) |
git/ | .gitconfig, ignore rules, delta settings |
tmux/ | Modern tmux config + keybinds |
direnv/ | Project-specific environment automation |
packages/ | Optional category Brewfiles (cloud, containers, development, etc.) |
bin/ | Helper scripts (test-zsh-config, profile-zsh-startup, audit-configs, adopt-config) |
docs/ | Additional documentation (prompt guide, tmux keybindings, config management) |
Ghostty is configured with:
The optional containers category (packages/containers.brewfile) installs colima as the local container runtime, paired with the plain docker, docker-compose, and docker-credential-helper CLI formulae — no Docker Desktop app/VM required.
brew bundle --file=packages/containers.brewfile # colima + docker CLI + compose + credential helper
colima-start # boots the VM, sets the `colima` docker context
docker ps # talks to colima automatically
lzd # lazydocker also works unchanged — it just follows the active docker context
Colima lifecycle aliases (zsh/.aliases.sh, only defined if colima is installed):
| Alias | Command |
|---|---|
colima-start | colima start |
colima-stop | colima stop |
colima-restart | colima restart |
colima-status | colima status |
colima-list | colima list |
colima-ssh | colima ssh |
Homebrew's docker-compose formula installs as a CLI plugin, and docker-credential-helper installs docker-credential-osxkeychain to store registry credentials in the macOS Keychain instead of plaintext — but Docker only picks either up if ~/.docker/config.json says so:
{
"cliPluginsExtraDirs": ["/opt/homebrew/lib/docker/cli-plugins"],
"credsStore": "osxkeychain"
}
init.sh does not currently write these keys automatically — add them by hand (or merge into an existing ~/.docker/config.json) after installing docker-compose / docker-credential-helper.
Day-to-day package management (adding/removing symlinks after the initial install) uses bestow — a Go-based successor to GNU Stow — instead of stow directly. It replicates stow --no-folding behavior (always on, no flag needed) but is idempotent and conflict-safe with pre-existing absolute symlinks.
bestow stow zsh # Shell config (includes .p10k.zsh)
bestow stow nvim ghostty lazygit ripgrep yazi typos # Per-tool packages
bestow stow git tmux direnv # Git/Tmux/Direnv packages
# Remove a package
bestow unstow zsh
init.sh (the fresh-machine installer) still bootstraps with GNU Stow, since bestow is a personal Go build not yet packaged for distribution.
Alternative: For cross-platform dotfile management, consider Chezmoi.
test-zsh # Full validation (tools, PATH, runtimes)
./bin/profile-zsh-startup # Deep component timing (zinit plugins, SDKMAN, p10k, etc.)
help # Alias documentation entry point
docs # Interactive alias browser (alias_docs)
show_tools # Overview of installed CLI upgrades
alias_search git # Search for aliases by keyword
edit_secrets # Safely edit encrypted ~/.env via SOPS
take my-service && code . # Smart project bootstrap / clone helper
kill_by_port 3000 # Kill whatever binds to port 3000
lg # Launch lazygit with our config
lzd # Launch lazydocker for Docker management
gw build # Run Gradle build from any subdirectory
gwt # Alias for: gw test
gwc # Alias for: gw clean
gwcb # Alias for: gw clean build
Ctrl+R # Atuin search UI (fuzzy search all history)
Up arrow # Atuin prefix search (as you type)
Zsh suffix aliases automatically open files based on their extension. Just type the filename and press Enter:
# Viewing files (rendered markdown)
README.md # Opens in mdless with rendered Markdown
data.json # Opens in jless (interactive JSON viewer)
config.yaml # Opens in jless (interactive YAML viewer)
# Editing files (opens in $EDITOR/nvim)
script.py # Opens Python files in nvim
setup.sh # Opens shell scripts in nvim
service.bal # Opens Ballerina files in nvim
app.conf # Opens config files in nvim
Supported extensions:
| Extension | Tool | Purpose |
|---|---|---|
.md | mdcat -p | View rendered Markdown with paging |
.json | jless | Interactive JSON browsing with folding |
.yaml, .yml | jless | Interactive YAML browsing |
.py | $EDITOR | Edit Python files |
.sh, .bash, .zsh | $EDITOR | Edit shell scripts |
.bal | $EDITOR | Edit Ballerina files |
.conf, .config, .ini | $EDITOR | Edit configuration files |
The default editor is set to nvim via the $EDITOR environment variable in .zshenv.
~/.config/sops/age/keys.txt and are created by init.sh. Backup that file somewhere safe.~/.env (ignored by git). They remain encrypted on disk and are transparently decrypted by the shell when sourced.edit_secrets (wrapper defined in .functions.d/06-dotfiles.zsh) to decrypt, open your $EDITOR, and re-encrypt on save. sops -d ~/.env | less # View decrypted env
sops ~/.env # Edit directly
export SOPS_AGE_KEY_FILE=~/.config/sops/age/keys.txt
zsh/.env.example is copied when you first run init.sh; extend it if you need new keys for future machines.The installer configures macOS to accept Touch ID (fingerprint) for sudo prompts in the terminal. This uses /etc/pam.d/sudo_local, which persists across macOS system updates (unlike editing /etc/pam.d/sudo directly).
tmux support: The pam-reattach brew package is included so Touch ID also works inside tmux sessions — without it, macOS cannot reach the biometric sensor from a reattached session.
After running init.sh, any sudo command will show the Touch ID prompt first and fall back to password if dismissed.
To enable manually (without init.sh):
brew install pam-reattach
# Create /etc/pam.d/sudo_local (requires sudo)
sudo tee /etc/pam.d/sudo_local <<'EOF'
# sudo_local: local config for sudo (persists across macOS updates)
auth optional /opt/homebrew/lib/pam/pam_reattach.so
auth sufficient pam_tid.so
EOF
Note: On Intel Macs, replace
/opt/homebrew/lib/pam/pam_reattach.sowith/usr/local/lib/pam/pam_reattach.so.
Sample prompt (top line + prompt character on line 2):
~/dotfiles main !+ Go 1.23.4
❯
What you see:
! modified, + staged, ? untracked, * stash, ⇣⇡ ahead/behind) — no colour change on dirty, no blocking git subprocess❯ green on success, red on failure; ❮ in Vim normal mode❯ in scrollbackDesign principle: The prompt shows command context (where you are, git state, language). The tmux status bar shows session context (session name, sysinfo, battery, time). Nothing is duplicated between the two layers.
Customize the prompt at ~/.p10k.zsh (stowed from zsh/.p10k.zsh):
nvim ~/dotfiles/zsh/.p10k.zsh # Edit directly — hot-reloads automatically
p10k configure # Interactive wizard (overwrites the file)
The Catppuccin Mocha palette used by the prompt matches the tmux status bar exactly — same background (#1e1e2e), same blue (#89b4fa), same green (#a6e3a1), same accent colors throughout.
test-zsh – Runs syntax checks, ensures required tools exist, inspects PATH/env vars, and prints a summary with pass/warn/fail counts./bin/profile-zsh-startup – Detailed profiler that times individual components (Homebrew shellenv, zinit plugins, SDKMAN, pyenv, compinit, sourcing files)zsh -n ~/.zshrc – Quick syntax validation if you edit the configzsh -n ~/.p10k.zsh – Validate prompt config syntax without sourcing itbrew bundle check – Confirm Brew dependencies match Brewfile before running Bundle againCommon fixes:
source ~/.zshrc # Reload everything after edits
rm -rf ~/.local/share/zinit && bash -c "$(curl -fsSL https://raw.githubusercontent.com/zdharma-continuum/zinit/HEAD/scripts/install.sh)" # Reinstall zinit if plugins fail
which fzf zoxide atuin direnv # Confirm core binaries are on PATH
p10k configure # Re-run the interactive prompt wizard
Fonts missing? Re-open the terminal and ensure your profile uses a Nerd Font. Icons rendering as boxes means the font doesn't include Nerd Font glyphs — install a patched font (e.g. FiraCode Nerd Font) and set it in your terminal profile.
cd ~/dotfiles
git pull origin main
brew bundle --file=Brewfile # Install any new packages
test-zsh # Sanity check after upgrades
source ~/.zshrc # Reload shell config
Remember to bestow unstow packages you no longer want and re-run bestow stow after pulling to ensure new configs are linked.
Bug reports and PRs are welcome! Please run test-zsh plus any relevant profilers before opening a pull request. See CONTRIBUTING.md for commit conventions, scopes (including prompt for p10k changes), and validation expectations.
Happy hacking!
hooks/register.tsx 166 lines1import { atom, read, update } from 'claude-code'
2import type { Register } from 'claude-code'
3
4import type { AgentRec, Call } from '../types'
5
6const PANE = 'mission-control'
7const MAX_CALLS = 60
8const FILE_TOOLS = new Set(['Edit', 'Write', 'MultiEdit', 'NotebookEdit'])
9
10const calls = atom({ plugin: 'mission-control', key: 'calls' } as const, [])
11const agents = atom({ plugin: 'mission-control', key: 'agents' } as const, [])
12const files = atom({ plugin: 'mission-control', key: 'files' } as const, [])
13
14const clip = (text: string, max: number) => {
15 const one = text.replace(/\s+/g, ' ').trim()
16
17 return one.length > max ? `${one.slice(0, max - 1)}…` : one
18}
19
20const base = (path: string) => path.split('/').slice(-2).join('/')
21
22// A short, human target for a call: the file, the command, the pattern.
23export const targetOf = (input: Record<string, unknown>): string => {
24 const pick = (key: string) =>
25 typeof input[key] === 'string' ? (input[key] as string) : undefined
26
27 const path = pick('file_path') ?? pick('notebook_path')
28 if (path) return base(path)
29
30 const text =
31 pick('command') ??
32 pick('pattern') ??
33 pick('url') ??
34 pick('query') ??
35 pick('description') ??
36 pick('path')
37
38 return text ? clip(text, 48) : ''
39}
40
41export const register: Register = on => {
42 on('session.start', async ($, e, next) => {
43 await $.command.register({
44 name: 'mission-control',
45 description: 'Show live agents, tool calls and touched files in a pane',
46 })
47
48 return next(e)
49 })
50
51 on('command.run', { command: 'mission-control' }, async $ => {
52 await $.ui.open({ id: PANE, title: 'Mission control' })
53
54 return { text: 'Mission control opened.' }
55 })
56
57 on('tool.call', async ($, e, next) => {
58 const input = e as unknown as Record<string, unknown>
59 const call: Call = {
60 id: e.tool_use_id,
61 tool: e.tool,
62 target: targetOf(input),
63 status: 'run',
64 agentId: e.agentId,
65 }
66
67 await update($, calls, list => [...list, call].slice(-MAX_CALLS))
68
69 if (FILE_TOOLS.has(e.tool) && typeof input.file_path === 'string') {
70 const path = input.file_path
71 await update($, files, list =>
72 list.includes(path) ? list : [...list, path],
73 )
74 }
75
76 const ran = await next(e)
77 const hasFailed = ran.deny !== undefined || ran.isError === true
78
79 await update($, calls, list =>
80 list.map(one =>
81 one.id === call.id
82 ? { ...one, status: hasFailed ? 'fail' : 'ok' }
83 : one,
84 ),
85 )
86
87 return ran
88 }).catch(($, e, next) => next(e))
89
90 on('agent.spawn', async ($, e, next) => {
91 const started = await $.clock.now()
92 const spawned = await next(e)
93
94 if (spawned.deny === undefined && spawned.agentId !== undefined) {
95 const rec: AgentRec = {
96 id: spawned.agentId,
97 label: clip(e.description || e.prompt, 40),
98 type: e.subagentType,
99 status: 'run',
100 startedAt: started,
101 }
102 await update($, agents, list => [...list, rec])
103 }
104
105 return spawned
106 }).catch(($, e, next) => next(e))
107
108 on('turn.complete', async ($, e, next) => {
109 const ended = await $.clock.now()
110
111 if (e.agentId !== undefined) {
112 await update($, agents, list =>
113 list.map(one =>
114 one.id === e.agentId
115 ? { ...one, status: 'done', endedAt: ended }
116 : one,
117 ),
118 )
119 }
120
121 return next(e)
122 })
123
124 on('ui.render', { component: 'Pane', requestId: PANE }, async ($, e) => {
125 const { Box, Text } = $.ui.resolve(e)
126 const [callList, agentList, fileList] = await Promise.all([
127 read($, calls),
128 read($, agents),
129 read($, files),
130 ])
131 const room = Math.max(4, (e.viewport?.rows ?? 30) - 12)
132 const running = agentList.filter(a => a.status === 'run').length
133 const mark = (status: Call['status']) =>
134 status === 'run' ? '…' : status === 'ok' ? '✓' : '✗'
135
136 return (
137 <Box flexDirection="column">
138 <Text bold>
139 Agents ({running} running, {agentList.length} total)
140 </Text>
141 {agentList.length === 0 && <Text dimColor>none yet</Text>}
142 {agentList.slice(-8).map(a => (
143 <Text dimColor={a.status === 'done'}>
144 {a.status === 'run' ? '●' : '○'} {a.type}: {a.label}
145 </Text>
146 ))}
147 <Text> </Text>
148 <Text bold>Tool calls (latest last)</Text>
149 {callList.length === 0 && <Text dimColor>none yet</Text>}
150 {callList.slice(-room).map(c => (
151 <Text dimColor={c.status === 'ok'}>
152 {mark(c.status)} {c.agentId ? '↳ ' : ''}
153 {c.tool} {c.target}
154 </Text>
155 ))}
156 <Text> </Text>
157 <Text bold>Files touched ({fileList.length})</Text>
158 {fileList.length === 0 && <Text dimColor>none yet</Text>}
159 {fileList.slice(-10).map(f => (
160 <Text>{base(f)}</Text>
161 ))}
162 </Box>
163 )
164 })
165}
166types/index.d.ts 31 lines1export type CallStatus = 'run' | 'ok' | 'fail'
2
3export type Call = {
4 id: string
5 tool: string
6 target: string
7 status: CallStatus
8 agentId?: string
9}
10
11export type AgentStatus = 'run' | 'done'
12
13export type AgentRec = {
14 id: string
15 label: string
16 type: string
17 status: AgentStatus
18 startedAt: number
19 endedAt?: number
20}
21
22declare module 'claude-code' {
23 interface PluginState {
24 'mission-control': {
25 calls: Call[]
26 agents: AgentRec[]
27 files: string[]
28 }
29 }
30}
31