In part 6 of the Year of the Linux Desktop series the host introduces Shmua, a Go command-line tool that manages dot files across machines and operating systems with optional templating, and explains he chose it over GNU STO because it copies files after showing diffs instead of relying on sim links.
He walks through the quick start (shimwa init, add, edit, diff, apply, cd, then adding a git remote and pushing to main) and stresses that diff compares the source directory with home while git compares the source with the remote, two distinct operations.
For secrets he generates an age key with hkeygen into .config/shimwa-key-txt, keeps encrypted files in a templates/secrets directory with a .H extension, and sets encryption, identity, recipient and a data variable has age private key in the config file, which is itself tracked as a template that prompts once for the key path and extracts the public key with a regex.
The fish config uses that variable to conditionally include the decrypted MAC address of his home lab, host name DeLorean, in a wake DeLorean abbreviation, and he demonstrates adding, editing, diffing and applying testing.conf and turning it into a template.
His dot files repo is public on DataLab Tech TV; shimwa init --apply with the repo name reproduces the configs on a fresh Fedora toolbox container without the key, and he closes by comparing GnusTow and YAdmin, pointing to the blog post and cheat sheet, and announcing a podcast on open source, decentralized governance and living with AI.
Brief overview
Shmua manages dot files across machines with diffs, templates and age-encrypted secrets, so a public repo stays usable.
Shmua copies after a diff instead of sim linkingThe host picked it over GNU STO for cross-platform flexibility and because you review shimwa diff, then shimwa apply copies the files.
A has-private-key template variable keeps a public repo safeThe config template sets has age private key from whether the key file exists, so templates render secrets only when the key is present and init --apply never crashes without it.
Only encrypt low-stakes secrets you can replaceHe commits age-encrypted files for a home lab MAC address, not credentials that would give access to anything major.
Questions this recording answers
9 questions, each answered where it is said
Why choose Shmua over GNU Stow for managing dotfiles?
GNU Stow simply symlinks all files from a folder into your home directory. The presenter chose Shmua for its cross-platform flexibility and because it does not rely on symlinks: it lets you check diffs between current and edited files, then copies the changes into your real config files when you apply.
What is the basic Shmua workflow for tracking and editing a file?
Run Shmua init to create the repo, then Shmua add to track a file without changing it. Shmua edit opens it in your default editor, set via the EDITOR and VISUAL variables. Shmua diff shows the differences, and only Shmua apply copies the change over to your actual configs.
How do I push my Shmua dotfiles to a git remote?
Shmua init initializes a git repo with a .git directory but no remote. Run Shmua cd to enter the source directory and use regular git: add the remote, rename the branch to main and push to origin main. Git operations are separate from Shmua diff, which compares against your home files.
How do I encrypt secrets in Shmua with age?
Generate a key with age-keygen, either from the age binaries or built into Shmua, and store it, for example in .config shimwa-key.txt. Keep the private key safe. Move the plaintext secret to tmp, encrypt it into a secrets directory under templates with a .age extension, and set age identity and recipient in the config file.
Which password managers and secret tools does Shmua integrate with?
Shmua integrates with 1Password, Bitwarden, ProtonPass, the system keyring, the pass command line utility, HashiCorp Vault, AWS Secrets Management and many more. It also supports encryption via age, which replaced GPG; the built-in version only supports asymmetric encryption, without post-quantum encryption or passphrases.
How can I share public dotfiles while keeping some parts secret?
The config template checks whether the age private key file exists and sets a global data variable, has age private key, to true or false. Templates, such as the fish config, render secrets like the DeLorean home lab MAC address only when it is true, so others can apply the repo without crashing.
How do I set up someone's dotfiles on a new machine with Shmua?
Run Shmua init with --apply and the repo, such as DataLab Tech TV slash .files; add --ssh if it is your own repo so the remote uses git instead of https, and --source to put files elsewhere. In a Fedora toolbox the presenter installed it with dnf, pressed enter at the key prompt, and got a minimal config.
How do I escape template syntax like podman info format inside a Shmua template?
Within a template, such blocks would be interpreted, though regular files need no worry. The workaround is to define a variable holding what you need as a string in double quotes, since it is not escaped when assigned that way, then render that variable directly where you need the value.
What other dotfile managers did the presenter consider?
He considered GNU Stow, which suits people who just want symlinks, and yadm, which is very similar to Shmua. He chose Shmua because it has a lot more GitHub stars, is more widely used, does everything he wanted, and can be as simple or as complex as you desire.
Key Quote
“because Shmua doesn't rely on sim links but instead it's lets you check the diffs between your current files and your edited files”
— Host
Key Quote
“I'm not going to show it to you because it's a private key, right? It will decrypt all my secrets. So keep it safe and”
— Host
Key Quote
“the easiest way to you know keep your own dot files public so everybody can use them but keep”