Files
mac/CLAUDE.md
Mortdecai c1558d2630 feat(tank): autofs SMB mount of tank at /Volumes/tank
scripts/tank-automount.sh (run on the Mac, password on stdin) adds a /-
direct map and root-owned /etc/auto_smb pointing at //Administrator@
192.168.0.173/tank with soft. Mounts on first access, unmounts idle, so
the laptop can leave the LAN without hung Finder or login dialogs.

Findings baked in:
- macOS automount does not create direct-map trigger dirs -> mkdir -p
- automounted fs are always nobrowse (man auto_master): shows as a
  folder, not a Locations drive -> Finder Favorite (manual-checklist)
- no-tty sudo ticket is per parent pid: sudo inside $(...) fails, so the
  idempotency check is a pipeline (sudo cmp -s -)
- SMB over NFS: Mac seth is uid 501; SMB force user=root matches /mnt/Z

Also: checklist Gitea key -> id_ed25519_homelab; the smb://.../tank
'user seth' step was wrong (no such Samba user) and is now the automount.
Wired into run.sh. Verified: mount, root-owned write, two all-[skip] reruns.
Not yet verified across a reboot (FileVault).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-15 22:24:00 -04:00

3.3 KiB

mac

Ops home for Seth's MacBook Pro — debloat, Linux-feel, Ableton-first.

Start Here

Read the latest handoff first: .claude/handoffs/ (most recent file). It has session state, in-progress work, and ordered next steps.

Then check IDEA.md for the project brief and DECISIONS.md for settled choices.

Project Identity

Configuration + scripts for Seth's MacBook Pro (arrived 2026-09-15). Three goals, in priority order: (1) Ableton Live 12 runs clean — this is the DAW box now that Wine on steel141 is abandoned; (2) feels like Linux to a Linux user — GNU coreutils, ip, familiar shell, ssh-able from steel141; (3) stock macOS noise turned off. Sibling of ~/bin/ableton/ (which is now an archive of the Wine attempt) and ~/bin/thinkpad-yoga/ (same "ops home for a laptop" shape).

Current State

  • Phase: shipping — scripts/run.sh applied & verified 2026-09-15. Manual checklist (docs/manual-checklist.md) pending Seth; Ableton not yet installed.
  • Repo: git.sethpc.xyz/Seth/mac
  • Deploy target: the MacBook, ssh mac (192.168.0.94, user seth, en0 Wi-Fi)
  • Hardware: MacBookPro18,1 (16" 2021), M1 Pro, 32 GB, 512 GB. macOS 26.2 Tahoe.
  • Remote Login enabled + claude key installed 2026-09-15. ssh mac works from steel141.
  • FileVault is on — no SSH after a reboot until the password is typed at the lid.
  • Applied: Homebrew + Brewfile (GNU userland, kitty, rectangle, tailscale-app), bash5 login shell, hostname mac, Linux-feel + debloat defaults, Dock=2 apps, DAW power profile (AC sleep 0 / powernap 0), nightly rsync backup agent. Pre-change inventory: docs/reference/inventory-2026-09-15.md.
  • Backup: ~/Music/Ableton + ~/Documents -> pve173:/tank/backups/mac nightly 03:30 via launchd; key is rrsync-jailed; sanoid keeps history (tank_media template).
  • ssh aliases (config/ssh_homelab, included from ~/.ssh/config) mirror the ~/bin/CLAUDE.md set. Two keys: id_ed25519 = backup (rrsync-jailed on pve173), id_ed25519_homelab = interactive. scripts/authorize-mac-key.sh (from steel141) pushes the interactive key; re-run it when an offline host comes back.
  • tank: autofs SMB at /Volumes/tank (scripts/tank-automount.sh, password on stdin). Mounts on access, nobrowse by macOS design → a Finder Favorite, not a Locations drive. Not yet verified across a reboot.
  • SparkFun PPP service left in place (macOS won't remove the sole service on a port; harmless).

Conventions

  • All changes as scripts under scripts/ (bash, idempotent, set -euo pipefail); never one-off defaults write in a chat that isn't also committed.
  • Before any defaults write: defaults read <domain> > .backup/<domain>-$(date +%s).plist
  • Before any launchctl disable/bootout: record current launchctl print state to .backup/
  • Homebrew Brewfile at repo root is the package manifest — brew bundle is the install
  • macOS gotchas go in this file's Conventions; per-decision reasoning goes in DECISIONS.md
  • Apply everything: scripts/run.sh from steel141. It installs a TEMPORARY /etc/sudoers.d/mac-setup (NOPASSWD) via _install_sudoers.sh for the run and removes it on every exit path (+40-min on-Mac self-destruct backstop). Needs $HOMELAB_PASSWORD. Second run is all [skip].
  • GUI-only steps live in docs/manual-checklist.md — read when something "didn't apply" (it's probably on that list).