Skip to content

2. Initial macOS setup

You'll need
Keyboard, mouse, display
macOS
Latest release (26 Tahoe+ ideal)
Outcome
A named, updated Mac with one admin account

Go to System Settings → General → Software Update and install everything available. Being on the latest release matters for a server: macOS 26 Tahoe added FileVault unlock over SSH, which is the single biggest improvement for unattended Macs in years.

During Setup Assistant you’ll create the first account, which is an administrator. You have two reasonable choices:

  • One account (simplest). You log in as the admin; your apps and agents run as you. Fine for a personal machine that only you can reach.
  • Admin + standard account (safer). Keep the admin account for installs and sudo, and run your daily tools and agents in a separate standard account. An agent that goes wrong can then only damage what that account can reach. See Security hardening.

Either way, use a long password you can type from memory — you may need it at the FileVault screen.

Apple Account (iCloud). Sign in if you plan to use iCloud Drive or Find My. If this is a shared or work machine, consider a separate Apple Account rather than your personal one, since iCloud Keychain, Photos and Messages will otherwise sync to the server too. You can turn those off individually in System Settings → [your name] → iCloud.

A predictable name makes it easy to find on your network and in Tailscale.

System Settings → General → Sharing → Local hostname → Edit…, or in Terminal:

Terminal window
sudo scutil --set ComputerName "your-mac-mini"
sudo scutil --set LocalHostName "your-mac-mini"

You can now reach it on your home network as your-mac-mini.local.

Software updates without surprise restarts

Section titled “Software updates without surprise restarts”

Go to System Settings → General → Software Update → Automatic updates (ⓘ) and set:

Setting Recommendation Why
Download new updates when available On Ready to install when you choose
Install macOS updates Off You decide when the server restarts
Install application updates from the App Store On Low risk
Install Security Responses and system files On Urgent fixes, rarely need a restart

Then pick a regular time to install macOS updates yourself (for example, the first weekend of the month) and check the health report afterwards.

  • System Settings → Lock Screen: set Start Screen Saver when inactive to Never and Turn display off when inactive to a few minutes. Keep Require password after screen saver begins or display is turned off on — locking the screen does not stop your apps or agents.
  • System Settings → Notifications: turn off banners for apps you won’t be watching, so remote Screen Sharing sessions aren’t cluttered.
  • System Settings → General → AirDrop & Handoff: turn off AirPlay Receiver and Handoff; a server doesn’t need them.

Git, make and compilers come from Apple’s Command Line Tools. Homebrew installs them for you in step 7, or you can install them now:

Terminal window
xcode-select --install

Download the helper scripts now so they’re ready for the next steps:

Terminal window
mkdir -p ~/bin && cd ~/bin
# Download setup-power.sh, health-check.sh and install-launchagent.sh from the Scripts page, then:
chmod +x ~/bin/*.sh

See Scripts for download links and full usage.