Ask everything first, then run without needing anybody

sunhat's failure mode was a question twenty minutes into a run. Walking away
from an install meant coming back to a prompt that had been waiting an hour.

So the questions move to the front. A new interview stage asks what Panama needs
to be told -- hostname, git identity, whether to sign in to GitHub, whether to
make an SSH key -- shows the answers back, and asks once to proceed. After that
nothing asks again. gum is bootstrapped before it runs, because the interview is
built on gum and gum arrives with a stage that has not run yet.

Answers reach the stages through a mktemp file that install sources and the
existing trap deletes, since a child process cannot export into its siblings.
They are not remembered between runs: there is no state file to go stale, and
one of the answers is an email address.

The interview asks only what a stage in this repository actually consumes.
Extras, hardware and debloat questions arrive with the stages that act on them
-- a prompt whose answer nothing reads is a control that lies. The new contract
pins that in both directions, and four deliberate mutations confirmed it catches
a question nobody reads, a stage reading something nobody asks, an answers file
left on disk, and a declined interview that fails to stop the run.

The run now ends with panama-doctor, because a failed-stage count says nothing
about a service that did not start. It never changes the exit code: on a fresh
machine, unconfigured is the honest answer, not a failure.

espanso and oh-my-posh stop being exceptions -- Terra packages espanso-wayland
and Fedora packages oh-my-posh, so the curl installer is gone. bun is now the
only remaining one.

Claude-Session: https://claude.ai/code/session_01Q84axqUE5inJhf5Jz9CFy1
This commit is contained in:
Gabriel Brown
2026-08-20 19:22:36 -04:00
parent 96e4085919
commit 15d54b16f6
8 changed files with 369 additions and 32 deletions
+3
View File
@@ -3,6 +3,9 @@ akmods
alsa-plugins-pulseaudio
cascadiamono-nerd-fonts
decibels
# The Wayland build specifically; the x11 one cannot inject into this session.
# Its config is linked by link-dotfiles.
espanso-wayland
desktop-file-utils
dnf-plugins-core
ffmpeg
+4
View File
@@ -18,6 +18,10 @@ kitty
ksshaskpass
libselinux-utils
neovim
# config/bash/shell initialises the prompt with this.
oh-my-posh
# ssh-keygen, which setup-identity uses to create a key on request.
openssh
openssl
pciutils
python3-dnf
-10
View File
@@ -8,7 +8,6 @@ exists() { command -v "$1" >/dev/null 2>&1; }
# --- Defined Paths ---
PANAMA_PATH="$HOME/.local/share/Panama"
LOCAL_BIN_PATH="$HOME/.local/bin"
echo -e "\n--- Installing Repositories ---"
log "Installing RPM Fusion Free and Nonfree Repositories"
@@ -70,15 +69,6 @@ else
log "Package list was not in specified path: $DESKTOP_FILE"
fi
# --- Install oh-my-posh if not already installed. ---
mkdir -p "$LOCAL_BIN_PATH"
if [[ -x "$LOCAL_BIN_PATH/oh-my-posh" ]]; then
log "oh-my-posh already installed at \"$LOCAL_BIN_PATH/oh-my-posh\""
else
log "Installing oh-my-posh via curl..."
curl -s https://ohmyposh.dev/install.sh | bash -s -- -d "$LOCAL_BIN_PATH" > /dev/null 2>&1
fi
# --- Install Development Packages needed for Neovim ---
DEV_FILE="$PANAMA_PATH/setup/packages/development-packages"
if [[ -f "$DEV_FILE" ]]; then
+107
View File
@@ -0,0 +1,107 @@
#!/usr/bin/env bash
# Everything Panama needs to be told, asked before anything is installed.
#
# sunhat's failure mode was a question -- or a failure -- twenty minutes into a
# run, with a person needed at the keyboard to get past it. Walking away from an
# install meant coming back to a prompt that had been waiting an hour.
#
# So Panama asks first and then runs untouched. Everything interactive lives
# here, at the front, where the answers are cheap to change and nothing has been
# installed yet.
#
# Answers are NOT remembered between runs. There is no state file to go stale, and
# nothing personal is committed, which is what keeps this repository something
# somebody else could clone. Re-answering a handful of questions costs less than
# maintaining an answers file that drifts out of date.
#
# This asks only what a stage in this repository actually consumes. Extras,
# hardware and debloat questions arrive with the stages that act on them; a prompt
# whose answer nothing reads is a control that lies.
set -uo pipefail
# install passes the path. Refusing to guess one keeps the answers where the
# caller can delete them, rather than somewhere this script invented.
answers="${PANAMA_ANSWERS:-}"
[[ -n "$answers" ]] || { printf 'interview: PANAMA_ANSWERS is not set; run this through ./install\n' >&2; exit 1; }
: >"$answers"
# %q so a value containing a space, a quote or a dollar sign survives being
# sourced by install exactly as it was typed.
record() { printf '%s=%q\n' "$1" "$2" >>"$answers"; }
heading() { gum style --bold --foreground 4 "$1"; }
ask() { gum input --header "$1" --placeholder "${2:-}"; }
yes_no() { gum confirm --default=false "$1"; }
# ── Machine ──────────────────────────────────────────────────────────────────
heading "This machine"
current_hostname="$(hostname)"
printf 'Current hostname: %s\n' "$current_hostname"
new_hostname=""
if yes_no "Change the hostname?"; then
new_hostname="$(ask "Hostname" "$current_hostname")"
fi
record PANAMA_HOSTNAME "$new_hostname"
# ── Identity ─────────────────────────────────────────────────────────────────
#
# Left blank, each of these keeps whatever git already has. That matters on a
# re-run: the prompts start empty every time by design, and an empty answer must
# not wipe a name that was already correct.
heading "Git identity"
printf 'Leave any of these blank to keep the current setting.\n'
git_name="$(ask "Git user.name")"
git_email="$(ask "Git user.email")"
git_editor="$(ask "Git editor" "nvim")"
record PANAMA_GIT_NAME "$git_name"
record PANAMA_GIT_EMAIL "$git_email"
record PANAMA_GIT_EDITOR "$git_editor"
# ── Accounts and keys ────────────────────────────────────────────────────────
#
# These two are asked only when they would do something. Checking whether a
# credential already exists is not the same as remembering a previous answer --
# it is refusing to ask a question whose answer is already on the machine.
heading "Accounts"
gh_login=no
if command -v gh >/dev/null 2>&1 && gh auth status >/dev/null 2>&1; then
printf 'GitHub CLI is already signed in.\n'
elif yes_no "Sign in to GitHub after packages are installed?"; then
gh_login=yes
fi
record PANAMA_GH_LOGIN "$gh_login"
ssh_key=no
if compgen -G "$HOME/.ssh/id_*.pub" >/dev/null 2>&1; then
printf 'An SSH key already exists.\n'
elif yes_no "Generate an SSH key?"; then
ssh_key=yes
fi
record PANAMA_SSH_KEY "$ssh_key"
# ── Confirm ──────────────────────────────────────────────────────────────────
#
# The last chance to catch a typo before twenty minutes of package work that
# nobody is watching.
shown() { [[ -n "$1" ]] && printf '%s' "$1" || printf 'unchanged'; }
heading "Ready"
gum style --border rounded --padding "0 1" "$(
printf 'Hostname %s\n' "${new_hostname:-"$current_hostname (unchanged)"}"
printf 'Git name %s\n' "$(shown "$git_name")"
printf 'Git email %s\n' "$(shown "$git_email")"
printf 'Git editor %s\n' "$(shown "$git_editor")"
printf 'GitHub %s\n' "$([[ "$gh_login" == yes ]] && echo "sign in" || echo "no change")"
printf 'SSH key %s' "$([[ "$ssh_key" == yes ]] && echo "generate" || echo "no change")"
)"
if ! gum confirm --default=true "Install with these answers?"; then
printf 'interview: cancelled; nothing was installed.\n' >&2
exit 1
fi
+67
View File
@@ -0,0 +1,67 @@
#!/usr/bin/env bash
# Who this machine belongs to: git identity, GitHub, and an SSH key.
#
# Runs last, because gh and git-all arrive with install-packages. Everything here
# is driven by answers the interview collected before the run started, so nothing
# in this stage blocks waiting for input -- except `gh auth login`, which is an
# interactive browser flow by nature and only runs when it was asked for.
#
# Every value is optional. A blank answer means "keep whatever is already set",
# which is what makes this safe to re-run: the interview's prompts start empty
# every time by design, and an empty answer must never erase a correct name.
set -uo pipefail
log() { echo -e "\033[1;34m[INFO]\033[0m $*"; }
git_name="${PANAMA_GIT_NAME:-}"
git_email="${PANAMA_GIT_EMAIL:-}"
git_editor="${PANAMA_GIT_EDITOR:-}"
if [[ -n "$git_name" ]]; then
git config --global user.name "$git_name"
log "git user.name set to $git_name"
fi
if [[ -n "$git_email" ]]; then
git config --global user.email "$git_email"
log "git user.email set to $git_email"
fi
if [[ -n "$git_editor" ]]; then
git config --global core.editor "$git_editor"
log "git core.editor set to $git_editor"
fi
# Aliases and pull behaviour, carried over from sunhat. Setting these is
# idempotent, so they are applied unconditionally rather than asked about.
git config --global alias.co checkout
git config --global alias.br branch
git config --global alias.ci commit
git config --global alias.st status
git config --global pull.rebase true
log "git aliases and pull.rebase applied"
if [[ "${PANAMA_GH_LOGIN:-no}" == yes ]]; then
if command -v gh >/dev/null 2>&1; then
log "Signing in to GitHub"
gh auth login || log "GitHub sign-in did not complete; run 'gh auth login' later"
else
log "gh is not installed; skipping GitHub sign-in"
fi
fi
if [[ "${PANAMA_SSH_KEY:-no}" == yes ]]; then
key="$HOME/.ssh/id_ed25519"
if [[ -e "$key" ]]; then
log "An SSH key already exists at $key; leaving it alone"
else
mkdir -p "$HOME/.ssh"
chmod 700 "$HOME/.ssh"
# No passphrase prompt: this stage runs inside an install that was
# promised to need no attention. A key can be given a passphrase later
# with ssh-keygen -p.
ssh-keygen -t ed25519 -N "" -C "${git_email:-$USER@$(hostname)}" -f "$key" >/dev/null
log "SSH key generated at $key"
log "Public key: $(cat "$key.pub")"
fi
fi