Files
mac/CLAUDE.md
T
Mortdecai 2028508cb9 feat(ssh): full homelab alias set on the Mac + separate interactive key
config/ssh_homelab now carries the curated alias set from ~/bin/CLAUDE.md
(pve nodes, machines, key CTs, switch, tailscale hosts). Interactive auth
uses a NEW key, id_ed25519_homelab, because the existing id_ed25519 is
rrsync-jailed on pve173 and sshd honours the first matching authorized_keys
line per key — one key can't be both a jail and a shell there.

- setup.sh generates id_ed25519_homelab (idempotent)
- backup.sh pins the jailed key: -o IdentitiesOnly=yes -i $HOME/.ssh/id_ed25519
- scripts/authorize-mac-key.sh (run on steel141) appends the pubkey on every
  LAN host via claude's aliases; wired into run.sh
- bedroom alias: seth -> root (matches steel141; was undocumented)

Verified from the Mac: 12 aliases land as the right user@host; the backup key
is refused a shell by rrsync (checked with id — rrsync whitelists true);
backup.sh still runs. Offline at push time: bedroom thinkcentre seth-pi
pinail openclaw2 — re-run authorize-mac-key.sh when they're up.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-15 20:31:25 -04:00

49 lines
3.1 KiB
Markdown

# mac
> Ops home for Seth's MacBook Pro — debloat, Linux-feel, Ableton-first.
## Start Here
**Read the latest handoff first:** `.claude/handoffs/` (most recent file).
It has session state, in-progress work, and ordered next steps.
Then check `IDEA.md` for the project brief and `DECISIONS.md` for settled choices.
## Project Identity
Configuration + scripts for Seth's MacBook Pro (arrived 2026-09-15). Three
goals, in priority order: (1) Ableton Live 12 runs clean — this is the DAW
box now that Wine on steel141 is abandoned; (2) feels like Linux to a Linux
user — GNU coreutils, `ip`, familiar shell, ssh-able from steel141; (3) stock
macOS noise turned off. Sibling of `~/bin/ableton/` (which is now an archive
of the Wine attempt) and `~/bin/thinkpad-yoga/` (same "ops home for a
laptop" shape).
## Current State
- **Phase:** shipping — `scripts/run.sh` applied & verified 2026-09-15. Manual checklist (`docs/manual-checklist.md`) pending Seth; Ableton not yet installed.
- **Repo:** `git.sethpc.xyz/Seth/mac`
- **Deploy target:** the MacBook, `ssh mac` (192.168.0.94, user seth, en0 Wi-Fi)
- **Hardware:** MacBookPro18,1 (16" 2021), M1 Pro, 32 GB, 512 GB. **macOS 26.2 Tahoe.**
- Remote Login enabled + claude key installed 2026-09-15. `ssh mac` works from steel141.
- **FileVault is on** — no SSH after a reboot until the password is typed at the lid.
- Applied: Homebrew + Brewfile (GNU userland, kitty, rectangle, tailscale-app),
bash5 login shell, hostname `mac`, Linux-feel + debloat `defaults`, Dock=2 apps,
DAW power profile (AC sleep 0 / powernap 0), nightly rsync backup agent.
Pre-change inventory: `docs/reference/inventory-2026-09-15.md`.
- Backup: `~/Music/Ableton` + `~/Documents` -> `pve173:/tank/backups/mac` nightly
03:30 via launchd; key is rrsync-jailed; sanoid keeps history (tank_media template).
- ssh aliases (`config/ssh_homelab`, included from `~/.ssh/config`) mirror the `~/bin/CLAUDE.md` set. Two keys: `id_ed25519` = backup (rrsync-jailed on pve173), `id_ed25519_homelab` = interactive. `scripts/authorize-mac-key.sh` (from steel141) pushes the interactive key; re-run it when an offline host comes back.
- SparkFun PPP service left in place (macOS won't remove the sole service on a port; harmless).
## Conventions
- All changes as scripts under `scripts/` (bash, idempotent, `set -euo pipefail`);
never one-off `defaults write` in a chat that isn't also committed.
- Before any `defaults write`: `defaults read <domain> > .backup/<domain>-$(date +%s).plist`
- Before any `launchctl disable`/`bootout`: record current `launchctl print` state to `.backup/`
- Homebrew `Brewfile` at repo root is the package manifest — `brew bundle` is the install
- macOS gotchas go in this file's Conventions; per-decision reasoning goes in `DECISIONS.md`
- **Apply everything:** `scripts/run.sh` from steel141. It installs a TEMPORARY `/etc/sudoers.d/mac-setup` (NOPASSWD) via `_install_sudoers.sh` for the run and removes it on every exit path (+40-min on-Mac self-destruct backstop). Needs `$HOMELAB_PASSWORD`. Second run is all `[skip]`.
- GUI-only steps live in `docs/manual-checklist.md` — read when something "didn't apply" (it's probably on that list).