Initial ssr repository

Convert the legacy system_sync.sh and system_restore.sh into a modular
shareable repository:

- bin/ssr CLI dispatcher with install/sync/restore/schedule/config/status
- lib/ split: common, cloud, brew, mackup, macos
- Cloud provider abstraction (icloud, dropbox, googledrive, onedrive, custom)
- launchd template for scheduled daily sync (renderable via sed)
- ssr.conf.example with whitelisted KEY=VALUE config loader
- macos-defaults.sh extracted from inline block, overridable
- install.sh bootstrap symlinks CLI into ~/.local/bin
- README with usage, config table, migration map, security notes
- Original scripts archived under legacy/ for reference

Fixes vs originals: set -euo pipefail, quoted vars, find -print0,
spctl --global-disable (was --master-disable), MACOS=".macos" bug,
zero-width char before ln, Apple Silicon brew shellenv, config injection
hardening.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
2026-05-11 15:05:17 +02:00
commit 539a8fc28f
23 changed files with 1171 additions and 0 deletions
+49
View File
@@ -0,0 +1,49 @@
# ssr.conf — System Sync & Restore configuration.
# Format: simple KEY=VALUE pairs. Comments (# …) and blank lines allowed.
# This file is sourced by bash; only the keys below are recognized.
# Anything else will cause ssr to abort.
# ---------------------------------------------------------------------------
# Cloud storage
# ---------------------------------------------------------------------------
# Provider: icloud | dropbox | googledrive | onedrive | custom
SSR_CLOUD_PROVIDER=icloud
# Only used when SSR_CLOUD_PROVIDER=custom. Absolute path.
# SSR_CLOUD_PATH=/Volumes/MyNAS/macos-sync
# Subfolders created inside the cloud root.
SSR_BACKUP_SUBDIR=BACKUP
SSR_MACKUP_SUBDIR=Mackup
# ---------------------------------------------------------------------------
# Homebrew behavior during `ssr sync`
# ---------------------------------------------------------------------------
SSR_BREW_UPGRADE=true
SSR_BREW_CLEANUP=true
# ---------------------------------------------------------------------------
# macOS restore behavior
# ---------------------------------------------------------------------------
# Disabling Gatekeeper allows apps from anywhere. Off by default.
SSR_DISABLE_GATEKEEPER=false
# Open every installed cask once after restore (for first-run config).
SSR_OPEN_CASKS=false
# Path to the macOS defaults script applied at the end of `ssr restore`.
# Leave commented to use the repo default (config/macos-defaults.sh).
# SSR_MACOS_DEFAULTS=/path/to/your/macos-defaults.sh
# ---------------------------------------------------------------------------
# Scheduling
# ---------------------------------------------------------------------------
SSR_LAUNCHD_LABEL=de.surke.ssr.sync
SSR_SCHEDULE_HOUR=9
SSR_SCHEDULE_MINUTE=0
# ---------------------------------------------------------------------------
# Paths
# ---------------------------------------------------------------------------
# SSR_STATE_DIR=$HOME/.local/state/ssr
# SSR_LOG_DIR=$HOME/.local/state/ssr/logs