~/dotgibson · layered ecosystem

One Core.
Every machine.
clone-and-go.

A portable, layered dotfiles system. A single vendored Core — zsh, tmux, Neovim, git, starship, mise — shared across every box, with thin OS-native layers per platform and operator role layers — offensive for Kali, defensive for Defense. Audited, benchmarked, reproducible.

No install —launch the Kali environment in your browser (opens in a new tab) a Codespace boots straight into the offensive shell — htp, ipp, lhost, ttyup live

  • ∞machines
  • 3layers
  • 1vendored Core
  • 0submodule flags
zsh — ~/dotfiles-MacBook
# clone — Core is already vendored, no flags
$git clone …/dotfiles-MacBook ~/df && cd ~/df
$./bootstrap.sh --links-only --dry-run
✓ plan: 24 symlinks, 0 conflicts
$./bootstrap.sh
✓ Homebrew · brew bundle · symlinks
$exec zsh
~/df on main via v22
12
public repos
one Core, vendored into all but the Windows host
3
clean layers
Core · OS-native · Role
14
Core zsh modules
one canonical load order
7,483
lines of Core zsh
authored once, synced out
57
git aliases
OMZ-style, in 25-git.zsh
8
SHA-pinned plugins
no floating master clones

Core 7.14.0 · derived from source on 2026-09-30

Why it’s built this way

A system, not a pile of config

12 repositories, one philosophy: if it changes with the operating system it isn’t Core; if it changes with you as an operator it isn’t Core. Everything left over is Core — and it lives in exactly one place.

Authored once, everywhere

Core lives in one repo and is vendored into every OS repo — except Windows, which replicates it natively. No N-way reconciliation, no drift — edit once, fan it out.

Clone-and-go

Vendoring copies the actual files in, so a fresh clone just works. No submodule init, no flags. Perfect for public portfolio repos.

Same shell, every OS

The zsh module chain loads in one canonical order on macOS, Linux, and WSL — PowerShell mirrors it. Muscle memory transfers everywhere.

Audited & benchmarked

A manifest-driven audit gate, hermetic behavioral tests, pinned plugin SHAs, and a startup-perf budget keep every sync honest.

Three clean layers

Core (identical everywhere), OS-native (changes with the OS), and Role (offensive scaffolding for Kali, defensive tooling for Defense). Every file has exactly one home.

Discoverable by design

core-help cheat sheets, core-doctor health checks, did-you-mean command handling, and first-party completions for every verb.

The three-layer model

Core → OS-native → Role

Each layer answers a different question. Drawing the boundary precisely is what lets one Core serve every machine without special-casing.

01

Core

zsh modules, tmux base, Neovim, git, starship, mise, clip. Vendored into each OS repo under core/ — except Windows, which replicates it natively.

Authored once, vendored everywhere, fanned out on release.
02

OS-native

Package manager, paths, clipboard backend, OS tmux/git tweaks. One thin layer per platform.

Package manager, paths, clipboard — what changes with the OS.
03

Role

Operator tooling stacked on an OS layer — offensive on Kali, defensive (detections, hunt/triage) on Defense.

Operator role — offensive or defensive — stacked on top of an OS layer.
Theme highlights

One palette, every surface

The whole fleet wears Tokyo Night (Storm) — the same colours light up Neovim, tmux, starship, and this page, and they are generated from one table in Core rather than copied. 8 accents over a five-step surface ramp, and in Neovim it’s a one-line flip to the other built-in styles.

Blue#7aa2f7primary · links · keywords
Cyan#7dcfffhover · inline code
Purple#bb9af7accent · eyebrows · keywords
Green#9ece6astrings · git add
Teal#73dacatypes · regex
Red#f7768eerrors · git del
Orange#ff9e64numbers · params
Yellow#e0af68warnings · modified
Surfaces
bg#1a1b26
bg-dark#16161e
surface#1f2335
surface-2#292e42
border#3b4261
Styles · nvim theme.lua
StormdefaultMoonsofterNightdarkerDaylight
The fleet

Repository map

All 12 repositories are public today — one Core, vendored into 10 of the 11 machine repos (Windows replicates Core natively in PowerShell). Each card links straight to its repo, with live stars, last-push, and CI status pulled from GitHub at build time.

CoreStable

◆dotfiles-core

The keystone. Single source of truth for everything identical on every machine — shell modules, tmux base, Neovim, git, starship, mise.

★ 2⟳ today● CI
  • zsh module chain
  • lazy.nvim tree
  • tmux + starship + mise
  • audited & benchmarked
View on GitHub ↗
OS-nativeStable

⌘dotfiles-MacBook

macOS (Apple Silicon / Intel) terminal environment. Homebrew + brew bundle, Ghostty, 1Password agent, native pbcopy clipboard — plus a committed tiling-desktop layer: AeroSpace, SketchyBar, and Karabiner.

★ 0⟳ today● CI
  • Homebrew + Brewfile
  • Ghostty + 1Password
  • AeroSpace · SketchyBar · Karabiner
  • macOS defaults
77 pkgsView on GitHub ↗
Native hostStable

⊞dotfiles-Windows

The native Windows host: PowerShell 7 as daily driver, Windows Terminal, scoop/winget, psmux, and the bridge into WSL2.

★ 1⟳ today● CI
  • pwsh profile loader
  • scoop + winget
  • psmux multiplexer
  • WSL2 bridge
View on GitHub ↗
RoleStable

⚔dotfiles-Offense

The offensive role layer for authorized engagements — stacked on whatever OS-native layer the box already runs. The red twin of dotfiles-Defense.

★ 0⟳ today● CI
  • engagement scaffolding
  • scope-first workflow
  • NetExec / BloodHound CE
  • installs nothing by default
View on GitHub ↗
OS-nativeStable

◈dotfiles-Debian

Debian-family apt layer targeting Ubuntu 24.04 LTS. The fleet’s only frozen release — so most of the modern-CLI stack arrives as pinned, checksum-verified upstream assets.

★ 0⟳ today● CI
  • apt + vendor repos
  • SHA-256 pinned assets
  • version-floor CI gate
  • Ubuntu 24.04 + Debian trixie
47 pkgsView on GitHub ↗
RoleStable

⛨dotfiles-Defense

The blue mirror of dotfiles-Offense — the defensive role. Detection engineering & investigation: hunt/triage tooling, version-controlled detection content (Sigma, Sysmon, Zeek/Suricata, SIEM), and a Dockerized detection lab. Distro-agnostic.

★ 1⟳ today● CI
  • Sigma / Sysmon / Zeek
  • mkcase hunt workflow
  • Dockerized detection lab
  • distro-agnostic + Core
View on GitHub ↗
OS-nativeStable

◉dotfiles-Fedora

The Linux template every other distro repo is stamped from. dnf + RPM Fusion, Flathub, Wayland clipboard, SELinux helpers.

★ 0⟳ today● CI
  • dnf package layer
  • distro template
  • Wayland/X11 clip
  • SELinux helpers
39 pkgsView on GitHub ↗
OS-nativeStable

▲dotfiles-Arch

Rolling-release Arch. pacman + AUR + multilib, with a bare-metal stage-0 SETUP guide for a minimal install.

★ 1⟳ today● CI
  • pacman + AUR
  • multilib + mirrors
  • stage-0 SETUP.md
  • rolling release
47 pkgsView on GitHub ↗
OS-nativeStable

❖dotfiles-openSUSE

zypper with the best dependency solver of the bunch. Packman, AppArmor, Btrfs/snapper, Tumbleweed (dup) + Leap (up) aware.

★ 0⟳ today● CI
  • zypper + Packman
  • Btrfs / snapper
  • AppArmor
  • Tumbleweed + Leap
48 pkgsView on GitHub ↗
OS-nativeStable

❄dotfiles-Alpine

The lean outlier: musl libc, busybox, doas. The small-footprint / container / rescue layer — bootstrap detects doas vs sudo.

★ 0⟳ today● CI
  • musl + busybox
  • apk + doas
  • container / rescue
73 pkgsView on GitHub ↗
OS-nativeStable

◢dotfiles-Gentoo

Source-based capstone. emerge + full category/name atoms + USE flags — the most educational build in the fleet.

★ 0⟳ today● CI
  • emerge from source
  • USE flags
  • full atoms
  • --no-sync re-runs
41 pkgsView on GitHub ↗
OS-nativeBeta

λdotfiles-NixOS

The one declarative host. nix owns the packages, PATH and the login-shell declaration (nixos-rebuild + home-manager); bootstrap.sh installs nothing and only wires the links.

★ 0⟳ today● CI
  • nixos-rebuild
  • home-manager
  • declarative
  • installs nothing
View on GitHub ↗
Kick the tires

Try the shell in your browser

A sandboxed, in-browser simulation of the dotfiles shell — the real aliases and the modern-CLI stack (eza, bat, zoxide,fd, ripgrep). No install, nothing leaves the page.

Try it

Up and running in three commands

Pick your platform, clone, bootstrap. The installer is idempotent and ships a dry-run so you can preview every change before it touches your machine.

Build your install command

Pick a platform, toggle the options you want — get the exact command: clone the repo and run its idempotent bootstrap, so you can read everything first. No curl | bash; every flag is one the bootstrap actually accepts.

Options