3. Stay awake & auto-recover
- Script
- setup-power.sh
- Key commands
- pmset, systemsetup, fdesetup
- Big decision
- FileVault vs auto-login
Three things stop an “always-on” Mac from being always on:
- Sleep. By default a Mac sleeps when idle, and sleeping Macs don’t run agents.
- Power loss. After an outage, a Mac stays off unless told otherwise.
- The login screen. After any restart, nothing you installed runs until someone logs in — and with FileVault on, until someone unlocks the disk.
This page fixes the first two completely and helps you choose how to handle the third.
Never sleep
Section titled “Never sleep”In System Settings
Section titled “In System Settings”On an Apple silicon Mac mini, open System Settings → Energy and turn on:
- Prevent automatic sleeping when the display is off
- Wake for network access
- Start up automatically after a power failure
In Terminal with pmset
Section titled “In Terminal with pmset”pmset is the command-line tool behind those switches, and it exposes a few more. The -a flag applies a
setting to all power sources.
sudo pmset -a sleep 0 # never sleep the systemsudo pmset -a disksleep 0 # never power down diskssudo pmset -a displaysleep 10 # the display may still turn off after 10 minutessudo pmset -a womp 1 # Wake for network accesssudo pmset -a autorestart 1 # Start up automatically after a power failuresudo pmset -a tcpkeepalive 1 # keep network connections aliveCheck the result:
pmset -gLook for sleep 0 and autorestart 1. If sleep shows something like
0 (sleep prevented by …), that’s fine — it’s telling you which processes are also holding the Mac awake.
Newer macOS also lists autorestartatconnect (start up when power is connected); that’s a separate
setting, so make sure you’re reading the plain autorestart line.
Why is it still sleeping?
Section titled “Why is it still sleeping?”pmset -g assertions # what is (or isn't) holding the Mac awake right nowpmset -g log | grep -E "\b(Sleep|Wake)\b" | tail -n 20 # recent sleep and wake eventscaffeinate is handy for keeping a laptop awake during one long command (caffeinate -dimsu -- your-command)
but you don’t need it on a server once sleep 0 is set.
Restart after a power failure or a freeze
Section titled “Restart after a power failure or a freeze”pmset -a autorestart 1 (above) is the same setting as Start up automatically after a power failure.
The equivalent systemsetup command is sudo systemsetup -setrestartpowerfailure on.
There’s one more safety net that has no switch in System Settings — restart automatically if macOS freezes:
sudo systemsetup -setrestartfreeze onsudo systemsetup -getrestartfreeze # → Restart After Freeze: OnA daily power-on as a backstop
Section titled “A daily power-on as a backstop”If the Mac ever ends up shut down rather than crashed — say a UPS shut it down cleanly and power came
back later — autorestart won’t fire. A repeating schedule will:
sudo pmset repeat wakeorpoweron MTWRFSU 04:30:00 # every day at 04:30pmset -g sched # check itsudo pmset repeat cancel # remove itsetup-power.sh --apply --daily-poweron 04:30 sets this for you.
With a UPS
Section titled “With a UPS”When a UPS is connected over USB, System Settings → Energy gains UPS options such as Shut down the computer after using UPS battery for…. Pick a value that leaves the UPS some charge. Together with the daily power-on above, the Mac shuts down cleanly in a long outage and starts again the next morning at the latest.
Unattended restarts: FileVault vs automatic login
Section titled “Unattended restarts: FileVault vs automatic login”After a restart, macOS shows a login window. Until an account logs in:
- Login Items don’t open — Cursor, Claude, Google Drive and so on stay closed.
- LaunchAgents don’t run — they belong to a logged-in user’s session.
- With FileVault on, the data volume is still encrypted, so nothing of yours can run, not even LaunchDaemons, until someone unlocks it with a password.
You have to decide what should happen after an unplanned restart. There are two workable options.
| Option A: FileVault on | Option B: FileVault off + auto-login | |
|---|---|---|
| Disk encrypted if the Mac is stolen | Yes | No |
| Comes back fully by itself after a power cut | No — needs a password (can be over SSH on macOS 26+) | Yes |
| Planned reboots without being there | Yes, with fdesetup authrestart |
Yes |
| Keychain and signed-in apps exposed to anyone at the keyboard | No | Yes |
| Good for | Most people | A physically secure location, with nothing sensitive on the Mac |
Option A: FileVault on (recommended)
Section titled “Option A: FileVault on (recommended)”Keep FileVault on and plan for the few restarts that need a password.
Check the status:
fdesetup status # → FileVault is On.Planned restarts (maintenance, after installing updates): use an authenticated restart, which unlocks the disk once on the next boot so the Mac comes all the way back to the login window without anyone typing the FileVault password:
fdesetup supportsauthrestart # → truesudo fdesetup authrestart # asks for your password, then restartsfdesetup temporarily keeps an unlock key in memory to do this; it’s used once and removed. Because
FileVault is on, automatic login is off, so after an authenticated restart the Mac stops at the login
window: Login Items and LaunchAgents still wait for someone to log in (Screen Sharing works at the
login window). Anything that must run with no one logged in belongs in a LaunchDaemon instead — see
step 5.
Updates you start from Software Update usually restart without asking for the FileVault password too, but don’t rely on it for a machine you can’t reach — install macOS updates when you can get to it, or at least to its network.
Unplanned restarts (power cut, crash): on macOS 26 Tahoe or later, if Remote Login is on, you can unlock FileVault over SSH before anyone logs in. From another computer on the same network:
ssh you@your-mac-mini.local# "This system is locked. To unlock it, use a local account name and password."Enter your account password. The Mac unlocks the disk, drops the SSH connection while it finishes booting, and then works normally — you can reconnect with SSH or Screen Sharing.
Things to know about SSH unlock:
- It accepts passwords only — your SSH keys live on the still-locked disk.
- It needs the Mac’s local network. Tailscale isn’t running yet, so you must be on the same LAN or reach it through another always-on device there (for example a router VPN or a Tailscale subnet router).
- Use Ethernet. Early reports showed Wi-Fi wasn’t available at this stage; later 26.x releases improved this, but a cable removes the doubt.
- Read the details on the Mac itself with
man apple_ssh_and_filevault.
On macOS 15 and earlier there is no remote unlock: someone must type the password at the Mac after an unplanned restart. A UPS makes that rare.
Option B: FileVault off + automatic login
Section titled “Option B: FileVault off + automatic login”If the Mac lives somewhere physically secure and holds nothing you’d mind losing to a burglar, you can trade encryption for a fully unattended restart.
- System Settings → Privacy & Security → FileVault → Turn Off… (decryption runs in the background;
fdesetup statusshows progress). - System Settings → Users & Groups → Automatically log in as → choose the account that runs your agents, and enter its password.
After every restart the Mac logs straight in, your Login Items open and your LaunchAgents start.
Verify
Section titled “Verify”Restart the Mac on purpose, then run:
~/bin/health-check.shIt shows uptime, the power settings above, FileVault and auto-login state, and whether your apps and background jobs came back.
Then test the power-failure restart for real: pull the Mac’s power cable (or switch off the socket it’s plugged into), wait ten seconds, and plug it back in. It should start by itself. Better to find out now than during a real outage.