main/modules
mk 0cfe10e387 packages(debian): fix eza+starship+zoxide installs
- eza: apt.fury.io PPA is dead (401 Unauthorized); install the single binary from the upstream GitHub release tarball (eza_x86_64-unknown-linux-gnu.tar.gz) into /usr/local/bin — no apt repo, system-wide
- starship: scrub $ARCH/$PLATFORM from the installer env — our lib/detect.sh exports ARCH=amd64, which the starship installer reuses (it checks ${ARCH-}) and skips its own amd64->x86_64 mapping, producing an unsupported 'amd64-unknown-linux-musl' target. Default bin dir is /usr/local/bin anyway
- zoxide: install system-wide (--bin-dir /usr/local/bin) instead of ~/.local/bin — when run as root the default landed in /root (wrong user for the create-user path) and wasn't on $PATH
2026-07-28 07:08:04 +03:00
..
00-preflight.sh modules: preflight + core packages (arch pacman + apt, yay, gh-release fallback) 2026-07-28 04:32:38 +03:00
05-create-user.sh non-interactive --yes: ask() assumes prompt default (no read); timezone defaults UTC; --username implies force-create; create-user name defaults to mk under --yes 2026-07-28 05:21:23 +03:00
10-packages.sh packages(debian): fix eza+starship+zoxide installs 2026-07-28 07:08:04 +03:00
20-docker.sh modules: target $TARGET_USER (docker group, zsh/nvim/nvm homes, chown tree) 2026-07-28 05:05:03 +03:00
25-angie.sh angie(arch): prefer angie-bin (repackaged upstream .deb, instant) over source build; verified http_acme/ssl/v2/v3/realip all compiled in; fall back to aur/angie if bin unavailable 2026-07-28 05:53:43 +03:00
30-shell-zsh.sh shell-zsh: derive ZSH/ZDOTDIR from $TARGET_HOME unconditionally — ignore inherited $ZSH env var (omz exports it, which pinned paths to the old home e.g. /root while the chown step retargeted to the new user, causing 'insecure completion dirs' owned by the wrong user) 2026-07-28 06:16:45 +03:00
35-nvm.sh modules: target $TARGET_USER (docker group, zsh/nvim/nvm homes, chown tree) 2026-07-28 05:05:03 +03:00
40-nvim.sh modules: target $TARGET_USER (docker group, zsh/nvim/nvm homes, chown tree) 2026-07-28 05:05:03 +03:00
50-hardening.sh hardening(angie): default_server needs a cert on its 443 listener or 'angie -t' fails with 'no ssl_certificate defined' — generate a one-time self-signed dummy (CN=bootstrap-default, 10y) in /etc/angie/ssl so unknown-SNI clients handshake then get 444; mark listen 443 as ssl explicitly 2026-07-28 06:55:31 +03:00
60-sanity.sh fix(sanity): hostname missing on minimal Arch (not in coreutils) — use uname -n with fallbacks; refresh TLS follow-up to angie-issue 2026-07-28 05:35:40 +03:00