Configuration
gwm reads .gwm.toml from the repo root. Without a config, it falls back to sensible defaults (~/cc-worktree/<repo>/<type>-<issue>-<desc>, no bootstrap). With one, it can copy files, run lifecycle hooks, refuse to inherit dangerous secrets, configure the TUI launchers / keymap / theme, and declare GitHub labels, milestones, and issue / PR templates. The same schema can also live at a user-level global config merged underneath every repo.
.gwm.tomlschema: every section, from[worktree],[[bootstrap.copy]],[[bootstrap.guard]],[bootstrap.fallback.*],[[bootstrap.no_symlink]],[[hooks.*]](+ legacy[[bootstrap.command]]),[theme],[tui],[tui.keys],[tui.open],[git_tui],[review],[gitmoji],[[labels]],[[milestones]],[issue_template],[pr_template],[aliases],[doctor].- User-level global config:
~/.config/gwm/config.tomlmerged underneath each repo’s.gwm.toml; deep-overlay semantics and theGWM_NO_GLOBAL_CONFIG=1opt-out. - Bootstrap pipeline: execution order, with lifecycle hooks around copies → guards → fallbacks → no-symlink check.
- Regex guards: deny-list patterns on copied files (the original “no AWS RDS in
.env” incident). whenpredicates:file_exists:,cmd_exists:,env_set:,env_eq:,glob_exists:, with!,&&,||composition.- TOFU trust ledger: the gate that fires before the bootstrap pipeline (issue #95). Threat model, CLI surface (
gwm trust list / revoke / show), TUI behaviour, ledger format, CI bypass. - Config presets:
gwm init --preset <stack>seeds an opinionated.gwm.tomlfor a known stack (laravel,symfony,node/nuxt,rust,go,python-uv,generic) instead of the generic template;--list-presetsand--show.
Run gwm init in a fresh repo to write a default .gwm.toml. For the full annotated example with every field commented, see examples/gwm.toml.example in the repo.