2. Initial macOS setup
- You'll need
- Keyboard, mouse, display
- macOS
- Latest release (26 Tahoe+ ideal)
- Outcome
- A named, updated Mac with one admin account
Update macOS first
Section titled “Update macOS first”Go to System Settings → General → Software Update and install everything available. Being on the latest release matters for a server: macOS 26 Tahoe added FileVault unlock over SSH, which is the single biggest improvement for unattended Macs in years.
Accounts
Section titled “Accounts”During Setup Assistant you’ll create the first account, which is an administrator. You have two reasonable choices:
- One account (simplest). You log in as the admin; your apps and agents run as you. Fine for a personal machine that only you can reach.
- Admin + standard account (safer). Keep the admin account for installs and
sudo, and run your daily tools and agents in a separate standard account. An agent that goes wrong can then only damage what that account can reach. See Security hardening.
Either way, use a long password you can type from memory — you may need it at the FileVault screen.
Apple Account (iCloud). Sign in if you plan to use iCloud Drive or Find My. If this is a shared or work machine, consider a separate Apple Account rather than your personal one, since iCloud Keychain, Photos and Messages will otherwise sync to the server too. You can turn those off individually in System Settings → [your name] → iCloud.
Give it a stable name
Section titled “Give it a stable name”A predictable name makes it easy to find on your network and in Tailscale.
System Settings → General → Sharing → Local hostname → Edit…, or in Terminal:
sudo scutil --set ComputerName "your-mac-mini"sudo scutil --set LocalHostName "your-mac-mini"You can now reach it on your home network as your-mac-mini.local.
Software updates without surprise restarts
Section titled “Software updates without surprise restarts”Go to System Settings → General → Software Update → Automatic updates (ⓘ) and set:
| Setting | Recommendation | Why |
|---|---|---|
| Download new updates when available | On | Ready to install when you choose |
| Install macOS updates | Off | You decide when the server restarts |
| Install application updates from the App Store | On | Low risk |
| Install Security Responses and system files | On | Urgent fixes, rarely need a restart |
Then pick a regular time to install macOS updates yourself (for example, the first weekend of the month) and check the health report afterwards.
Screen, lock and notifications
Section titled “Screen, lock and notifications”- System Settings → Lock Screen: set Start Screen Saver when inactive to Never and Turn display off when inactive to a few minutes. Keep Require password after screen saver begins or display is turned off on — locking the screen does not stop your apps or agents.
- System Settings → Notifications: turn off banners for apps you won’t be watching, so remote Screen Sharing sessions aren’t cluttered.
- System Settings → General → AirDrop & Handoff: turn off AirPlay Receiver and Handoff; a server doesn’t need them.
Command Line Tools
Section titled “Command Line Tools”Git, make and compilers come from Apple’s Command Line Tools. Homebrew installs them for you in
step 7, or you can install them now:
xcode-select --installGrab the scripts
Section titled “Grab the scripts”Download the helper scripts now so they’re ready for the next steps:
mkdir -p ~/bin && cd ~/bin# Download setup-power.sh, health-check.sh and install-launchagent.sh from the Scripts page, then:chmod +x ~/bin/*.shSee Scripts for download links and full usage.