Skip to content

Configuration schema

~/.config/loadout/config.yaml. Every section is optional except version.

~/.config/loadout/local.yaml uses the same schema and overlays this file. It is never synced.

version: 1

Schema version. Required. The current version is 1.

paths:
project_root: ~/Projects
venv_root: ~/.venv
FieldTypeDefaultRead by
project_rootpath~/Projectsp, pv, pw, clone-sources
venv_rootpath~/.venvvenv, activate, denv, lenv

Paths are written into the generated shell in $HOME form, never as a literal tilde, because a tilde does not expand inside double quotes.

git:
main_branch: main
dev_branch: development
FieldTypeDefaultRead by
main_branchstringmainThe git aliases
dev_branchstringdevelopmentThe git aliases
ssh:
default_key: ~/.ssh/id_ed25519
default_user: root
default_host: 10.0.0.10
default_port: 22
subnet_prefix: "10.0.0."
FieldTypeDefaultNotes
default_keypath—Fallback key for msh
default_userstringrootFallback user
default_hoststring—Used when msh is called bare
default_portint22
subnet_prefixstring—Lets a bare number be the last octet: 10.0.0. plus 5 is 10.0.0.5. Empty disables the shorthand.
identities:
- id: personal
git_user: Your Name
email: you@example.com
ssh_key: ~/.ssh/id_ed25519
default: true
activates:
npm_token: personal
FieldTypeNotes
idstringWhat you pass to loadout identity activate
git_userstringgit user.name
emailstringgit user.email
ssh_keypathAdded to the agent on activation
defaultboolActive on a fresh machine
activatesmapCredential name to entry name

Every credential and entry named in activates must exist. See Identities.

credentials:
npm_token:
active: personal
entries: [personal, work]
gh_token:
env: GHP_TOKEN
active: personal
entries: [personal, work]
FieldTypeNotes
activestringMust be one of entries
entrieslistThe named entries that exist for this secret
envstringOverride the exported variable name

No values here, ever. They live in the OS keychain, addressed as loadout/<credential>/<entry>.

env defaults to the key upper-cased with -, . and / turned into underscores, so npm_token gives NPM_TOKEN. Two credentials resolving to the same variable is rejected at load time.

hosts:
- alias: staging
hostname: staging.example.com
user: deploy
port: 22
key: ~/.ssh/deploy
upload_path: /srv/app
shortcut: true
FieldTypeNotes
aliasstringWhat msh -m takes
hostnamestringHost or IP
userstring
portintDefaults to ssh.default_port
keypath
passwordstringMust be cred:<name>. A literal is rejected
upload_pathpathDestination for mpush
shortcutboolAlso emit a bare ssh <alias> alias
workspaces:
- name: api
path: ~/Projects/api/api.code-workspace
tmux_session: api
FieldTypeNotes
namestringAlso becomes an alias that opens it
pathpathWorkspace or project directory
tmux_sessionstringPairs opening the workspace with a tmux session
clone_sources:
- alias: work
org: example-org

Generates a command that clones a repository from that organisation, so work myrepo clones example-org/myrepo.

editors:
- name: code
command: code
- name: nvim
command: nvim

The first entry is the default. Read by pv and pw.

node_versions: ["20", "22"]
npm_globals: [pm2, serve, prettier, "@nestjs/cli"]

Lists used by the node and npm helpers.

binaries:
- name: duckdb
version: v1.1.3
source:
github: duckdb/duckdb
asset:
linux-amd64: duckdb_cli-linux-amd64.zip
darwin-arm64: duckdb_cli-osx-universal.zip
checksum:
linux-amd64: sha256:abc...
darwin-arm64: sha256:def...
FieldTypeNotes
namestringThe name it takes on PATH
versionstringPinned
source.githubstringowner/repo
source.assetmapPlatform key to release asset name
source.urlmapPlatform key to direct URL, instead of github
checksumstring or mapOne hash, or one per platform

Platform keys are <os>-<arch>. checksum accepts a bare string when only one platform is declared, and a map otherwise — a single hash describes one artefact and is wrong everywhere else. See Managed binaries.

scripts:
- name: csf
source: builtin
- name: deploy
source: ~/dev/scripts/deploy.sh

source is either builtin — one of the shipped scripts, written out from the binary — or a path, which is symlinked and stays where it lives.

packs: [flutter, cloudflared]

Opt-in bundles, off unless listed. See the packs reference.

aliases:
disabled: [ls, py]
custom:
- name: deploy
command: ./scripts/deploy.sh
platform: [linux]
FieldTypeNotes
disabledlistShipped aliases not to generate
custom[].namestringOverrides a shipped alias of the same name
custom[].commandstring
custom[].platformlistlinux, darwin, or omitted for both
KindBehaviour
ScalarReplaced
MapMerged key by key
ListReplaced wholesale

A local.yaml that sets packs replaces the list rather than adding to it.