# OS configuration use `os-conf` to save and `os-conf -r /` to restore configuration the script reads a manifest file inside `$OS_DIR`, which defaults to `$HOME/os` ## manifest syntax lines prefixed with `#` or `$` are ignored, the magic comment `#secret`, when appended to a line, marks the entry as containing data that shouldn't be checked into a public repository. Instead we use [sops](https://github.com/mozilla/sops) to encrypt and store it under `$OS_DIR/tmp/os-secret-*`. These encrypted archives are transparently handled by the restore code. Encryption requires the `SOPS_PGP_FP` environment variable (or whatever is required by any of the other supported encryption schemes).