2028508cb9
config/ssh_homelab now carries the curated alias set from ~/bin/CLAUDE.md (pve nodes, machines, key CTs, switch, tailscale hosts). Interactive auth uses a NEW key, id_ed25519_homelab, because the existing id_ed25519 is rrsync-jailed on pve173 and sshd honours the first matching authorized_keys line per key — one key can't be both a jail and a shell there. - setup.sh generates id_ed25519_homelab (idempotent) - backup.sh pins the jailed key: -o IdentitiesOnly=yes -i $HOME/.ssh/id_ed25519 - scripts/authorize-mac-key.sh (run on steel141) appends the pubkey on every LAN host via claude's aliases; wired into run.sh - bedroom alias: seth -> root (matches steel141; was undocumented) Verified from the Mac: 12 aliases land as the right user@host; the backup key is refused a shell by rrsync (checked with id — rrsync whitelists true); backup.sh still runs. Offline at push time: bedroom thinkcentre seth-pi pinail openclaw2 — re-run authorize-mac-key.sh when they're up. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
49 lines
3.1 KiB
Markdown
49 lines
3.1 KiB
Markdown
# mac
|
|
|
|
> Ops home for Seth's MacBook Pro — debloat, Linux-feel, Ableton-first.
|
|
|
|
## Start Here
|
|
|
|
**Read the latest handoff first:** `.claude/handoffs/` (most recent file).
|
|
It has session state, in-progress work, and ordered next steps.
|
|
|
|
Then check `IDEA.md` for the project brief and `DECISIONS.md` for settled choices.
|
|
|
|
## Project Identity
|
|
|
|
Configuration + scripts for Seth's MacBook Pro (arrived 2026-09-15). Three
|
|
goals, in priority order: (1) Ableton Live 12 runs clean — this is the DAW
|
|
box now that Wine on steel141 is abandoned; (2) feels like Linux to a Linux
|
|
user — GNU coreutils, `ip`, familiar shell, ssh-able from steel141; (3) stock
|
|
macOS noise turned off. Sibling of `~/bin/ableton/` (which is now an archive
|
|
of the Wine attempt) and `~/bin/thinkpad-yoga/` (same "ops home for a
|
|
laptop" shape).
|
|
|
|
## Current State
|
|
|
|
- **Phase:** shipping — `scripts/run.sh` applied & verified 2026-09-15. Manual checklist (`docs/manual-checklist.md`) pending Seth; Ableton not yet installed.
|
|
- **Repo:** `git.sethpc.xyz/Seth/mac`
|
|
- **Deploy target:** the MacBook, `ssh mac` (192.168.0.94, user seth, en0 Wi-Fi)
|
|
- **Hardware:** MacBookPro18,1 (16" 2021), M1 Pro, 32 GB, 512 GB. **macOS 26.2 Tahoe.**
|
|
- Remote Login enabled + claude key installed 2026-09-15. `ssh mac` works from steel141.
|
|
- **FileVault is on** — no SSH after a reboot until the password is typed at the lid.
|
|
- Applied: Homebrew + Brewfile (GNU userland, kitty, rectangle, tailscale-app),
|
|
bash5 login shell, hostname `mac`, Linux-feel + debloat `defaults`, Dock=2 apps,
|
|
DAW power profile (AC sleep 0 / powernap 0), nightly rsync backup agent.
|
|
Pre-change inventory: `docs/reference/inventory-2026-09-15.md`.
|
|
- Backup: `~/Music/Ableton` + `~/Documents` -> `pve173:/tank/backups/mac` nightly
|
|
03:30 via launchd; key is rrsync-jailed; sanoid keeps history (tank_media template).
|
|
- ssh aliases (`config/ssh_homelab`, included from `~/.ssh/config`) mirror the `~/bin/CLAUDE.md` set. Two keys: `id_ed25519` = backup (rrsync-jailed on pve173), `id_ed25519_homelab` = interactive. `scripts/authorize-mac-key.sh` (from steel141) pushes the interactive key; re-run it when an offline host comes back.
|
|
- SparkFun PPP service left in place (macOS won't remove the sole service on a port; harmless).
|
|
|
|
## Conventions
|
|
|
|
- All changes as scripts under `scripts/` (bash, idempotent, `set -euo pipefail`);
|
|
never one-off `defaults write` in a chat that isn't also committed.
|
|
- Before any `defaults write`: `defaults read <domain> > .backup/<domain>-$(date +%s).plist`
|
|
- Before any `launchctl disable`/`bootout`: record current `launchctl print` state to `.backup/`
|
|
- Homebrew `Brewfile` at repo root is the package manifest — `brew bundle` is the install
|
|
- macOS gotchas go in this file's Conventions; per-decision reasoning goes in `DECISIONS.md`
|
|
- **Apply everything:** `scripts/run.sh` from steel141. It installs a TEMPORARY `/etc/sudoers.d/mac-setup` (NOPASSWD) via `_install_sudoers.sh` for the run and removes it on every exit path (+40-min on-Mac self-destruct backstop). Needs `$HOMELAB_PASSWORD`. Second run is all `[skip]`.
|
|
- GUI-only steps live in `docs/manual-checklist.md` — read when something "didn't apply" (it's probably on that list).
|