Skip to content

3. Stay awake & auto-recover

Script
setup-power.sh
Key commands
pmset, systemsetup, fdesetup
Big decision
FileVault vs auto-login

Three things stop an “always-on” Mac from being always on:

  1. Sleep. By default a Mac sleeps when idle, and sleeping Macs don’t run agents.
  2. Power loss. After an outage, a Mac stays off unless told otherwise.
  3. The login screen. After any restart, nothing you installed runs until someone logs in — and with FileVault on, until someone unlocks the disk.

This page fixes the first two completely and helps you choose how to handle the third.

On an Apple silicon Mac mini, open System Settings → Energy and turn on:

  • Prevent automatic sleeping when the display is off
  • Wake for network access
  • Start up automatically after a power failure

pmset is the command-line tool behind those switches, and it exposes a few more. The -a flag applies a setting to all power sources.

Terminal window
sudo pmset -a sleep 0 # never sleep the system
sudo pmset -a disksleep 0 # never power down disks
sudo pmset -a displaysleep 10 # the display may still turn off after 10 minutes
sudo pmset -a womp 1 # Wake for network access
sudo pmset -a autorestart 1 # Start up automatically after a power failure
sudo pmset -a tcpkeepalive 1 # keep network connections alive

Check the result:

Terminal window
pmset -g

Look for sleep 0 and autorestart 1. If sleep shows something like 0 (sleep prevented by …), that’s fine — it’s telling you which processes are also holding the Mac awake. Newer macOS also lists autorestartatconnect (start up when power is connected); that’s a separate setting, so make sure you’re reading the plain autorestart line.

Terminal window
pmset -g assertions # what is (or isn't) holding the Mac awake right now
pmset -g log | grep -E "\b(Sleep|Wake)\b" | tail -n 20 # recent sleep and wake events

caffeinate is handy for keeping a laptop awake during one long command (caffeinate -dimsu -- your-command) but you don’t need it on a server once sleep 0 is set.

pmset -a autorestart 1 (above) is the same setting as Start up automatically after a power failure. The equivalent systemsetup command is sudo systemsetup -setrestartpowerfailure on.

There’s one more safety net that has no switch in System Settings — restart automatically if macOS freezes:

Terminal window
sudo systemsetup -setrestartfreeze on
sudo systemsetup -getrestartfreeze # → Restart After Freeze: On

If the Mac ever ends up shut down rather than crashed — say a UPS shut it down cleanly and power came back later — autorestart won’t fire. A repeating schedule will:

Terminal window
sudo pmset repeat wakeorpoweron MTWRFSU 04:30:00 # every day at 04:30
pmset -g sched # check it
sudo pmset repeat cancel # remove it

setup-power.sh --apply --daily-poweron 04:30 sets this for you.

When a UPS is connected over USB, System Settings → Energy gains UPS options such as Shut down the computer after using UPS battery for…. Pick a value that leaves the UPS some charge. Together with the daily power-on above, the Mac shuts down cleanly in a long outage and starts again the next morning at the latest.

Unattended restarts: FileVault vs automatic login

Section titled “Unattended restarts: FileVault vs automatic login”

After a restart, macOS shows a login window. Until an account logs in:

  • Login Items don’t open — Cursor, Claude, Google Drive and so on stay closed.
  • LaunchAgents don’t run — they belong to a logged-in user’s session.
  • With FileVault on, the data volume is still encrypted, so nothing of yours can run, not even LaunchDaemons, until someone unlocks it with a password.

You have to decide what should happen after an unplanned restart. There are two workable options.

Option A: FileVault on Option B: FileVault off + auto-login
Disk encrypted if the Mac is stolen Yes No
Comes back fully by itself after a power cut No — needs a password (can be over SSH on macOS 26+) Yes
Planned reboots without being there Yes, with fdesetup authrestart Yes
Keychain and signed-in apps exposed to anyone at the keyboard No Yes
Good for Most people A physically secure location, with nothing sensitive on the Mac

Keep FileVault on and plan for the few restarts that need a password.

Check the status:

Terminal window
fdesetup status # → FileVault is On.

Planned restarts (maintenance, after installing updates): use an authenticated restart, which unlocks the disk once on the next boot so the Mac comes all the way back to the login window without anyone typing the FileVault password:

Terminal window
fdesetup supportsauthrestart # → true
sudo fdesetup authrestart # asks for your password, then restarts

fdesetup temporarily keeps an unlock key in memory to do this; it’s used once and removed. Because FileVault is on, automatic login is off, so after an authenticated restart the Mac stops at the login window: Login Items and LaunchAgents still wait for someone to log in (Screen Sharing works at the login window). Anything that must run with no one logged in belongs in a LaunchDaemon instead — see step 5.

Updates you start from Software Update usually restart without asking for the FileVault password too, but don’t rely on it for a machine you can’t reach — install macOS updates when you can get to it, or at least to its network.

Unplanned restarts (power cut, crash): on macOS 26 Tahoe or later, if Remote Login is on, you can unlock FileVault over SSH before anyone logs in. From another computer on the same network:

Terminal window
ssh you@your-mac-mini.local
# "This system is locked. To unlock it, use a local account name and password."

Enter your account password. The Mac unlocks the disk, drops the SSH connection while it finishes booting, and then works normally — you can reconnect with SSH or Screen Sharing.

Things to know about SSH unlock:

  • It accepts passwords only — your SSH keys live on the still-locked disk.
  • It needs the Mac’s local network. Tailscale isn’t running yet, so you must be on the same LAN or reach it through another always-on device there (for example a router VPN or a Tailscale subnet router).
  • Use Ethernet. Early reports showed Wi-Fi wasn’t available at this stage; later 26.x releases improved this, but a cable removes the doubt.
  • Read the details on the Mac itself with man apple_ssh_and_filevault.

On macOS 15 and earlier there is no remote unlock: someone must type the password at the Mac after an unplanned restart. A UPS makes that rare.

If the Mac lives somewhere physically secure and holds nothing you’d mind losing to a burglar, you can trade encryption for a fully unattended restart.

  1. System Settings → Privacy & Security → FileVault → Turn Off… (decryption runs in the background; fdesetup status shows progress).
  2. System Settings → Users & Groups → Automatically log in as → choose the account that runs your agents, and enter its password.

After every restart the Mac logs straight in, your Login Items open and your LaunchAgents start.

Restart the Mac on purpose, then run:

Terminal window
~/bin/health-check.sh

It shows uptime, the power settings above, FileVault and auto-login state, and whether your apps and background jobs came back.

Then test the power-failure restart for real: pull the Mac’s power cable (or switch off the socket it’s plugged into), wait ten seconds, and plug it back in. It should start by itself. Better to find out now than during a real outage.