Files
mw-pfeddersheim-workstation/AGENTS.md
T
ja d746d76530 migrate secrets management from KWallet to gnome-keyring + Bitwarden
Architecture: Bitwarden (central vault) → rbw CLI → gnome-keyring
(local cache via org.freedesktop.secrets D-Bus). All apps (himalaya,
git, ssh-agent, JetBrains IDEs, browsers) now read secrets via
libsecret/secret-tool through gnome-keyring.

Changes:
- Install gnome-keyring + rbw, enable as systemd user service
- Configure rbw → bitwarden.jantec.xyz (ironmikechw+bitwarden@gmail.com)
- Migrate 45 meaningful entries from KWallet → BW + GK
- Switch git credential.helper from store to libsecret
- Document: one-pager, ADR, migration checklist, NEXT_STEPS update
- Skill: devops/secrets-migration for reuse

Post-reboot manual: himalaya IMAP passwords (4 accounts, were not in
KWallet) and GitHub CLI token re-auth.

See docs/product/passwords.md for the full guide.
2026-05-21 12:58:38 +02:00

34 lines
1.6 KiB
Markdown

# AGENTS.md (mw-pfeddersheim-workstation)
## Project Overview
This repository manages the infrastructure, configuration, and maintenance for Michael Wegener's primary workstation at satware AG (Pfeddersheim location). It uses Ansible for system configuration and shell scripts for maintenance.
## Key Directories
- `ansible/`: Configuration-as-Code via Ansible roles and playbooks.
- `docs/`: PARA-structured documentation (Product, ADR, Learnings, Tech).
- `scripts/`: Automation and maintenance scripts.
- `config/`: Templates for system configuration files.
## Essential Commands
| Task | Command |
|------|---------|
| Apply Configuration | `ansible-playbook ansible/workstation.yml` |
| System Maintenance | `bash scripts/maintenance.sh` |
| Verify Ansible | `ansible-playbook ansible/workstation.yml --check` |
## Standards
- **Baby Steps™**: Small, verifiable changes (<200 LOC per commit).
- **PARA Documentation**: Keep documentation updated in the `docs/` folder.
- **Zero-Trust**: Secrets must be handled via Ansible Vault or environment variables.
## Guardrails
- **NEVER** commit raw secrets to the repository.
- **ALWAYS** run Ansible with `--check` before applying changes.
- **NEVER** modify system configuration directly if it can be managed via Ansible.
- **Secrets Management**: All secrets stored in Bitwarden (`bitwarden.jantec.xyz`) and cached locally in `gnome-keyring` (D-Bus secrets service). See `docs/product/passwords.md` for details.
## Rules Hierarchy
- Global rules: `Rules/`
- Project rules: `.clinerules/`
- Agent instructions: `AGENTS.md` (this file)