Skip to article

Mac pre-release: OpalSpan Agent CLI and Daemon

OpalSpan has separate Apple-silicon and Intel pre-releases for testing. The portable Agent CLI and its diagnostic helper are 0.18.2; Daemon and attended Rescue are 0.17.0. These builds are not Apple Developer ID signed or notarized and have not yet run on Mac hardware. They are not a supported general release. macOS may block first launch or ask for a per-app security decision. Do not disable Gatekeeper or strip quarantine. The device owner makes any local security decision.

Choose the matching architecture

On the Mac, run uname -m in Terminal. Choose Apple silicon (arm64) for an M-series Mac or Intel (x86_64) for an Intel Mac. Download only that architecture from OpalSpan downloads. Do not mix an Intel CLI with an Apple-silicon Host package. The public page shows version and SHA-256 for each available archive; compare the downloaded archive with shasum -a 256 <archive> before use. A checksum on the same website is an integrity cross-check, not independent publisher authentication.

Agent CLI on the technician's Mac

The CLI preview is a portable tar.gz archive, not an installer. Keep its contents together in a private, architecture-matched folder; do not run it with sudo. The local agent operates forge and forge-transport-helper. The technician authorizes normal browser login and any Keychain prompts. forge --version, forge credentials status and forge doctor are useful first checks. OpenSSH client tools (ssh, scp, ssh-keygen) are needed for device access. After the owner's normal first-launch decision, the local agent may run ./forge update from the extracted folder. That command verifies the architecture-matched signed catalog and archive, probes the new binary, then activates a private per-user installation. Use the returned shim_path or add its parent directory to the agent runner's PATH. forge setup repair and forge setup uninstall are also available with the signed archive/manifest or installation root as applicable; no standalone Mac installer or background update is claimed. A Mac CLI does not grant access by itself: Bridge membership, selected-device authority and normal login still apply.

Daemon enrollment and attended Rescue

Create the device's own Mac enrollment link in Forge. On the intended Mac, download the architecture-matched package and follow its README.txt with the owner's consent and administrator approval. The package contains a private, one-use code; keep the whole folder private and do not paste that code into chat or command arguments. The Host verifies Forge's pinned release manifest and binary hash before registration. It runs as a root-owned launchd service using the outbound HTTPS relay; it does not install a LAN listener, Tailscale, OpenSSH server or support account.

Attended Rescue has its own temporary package and explicit cleanup. Mac Host previews are excluded from automatic updates; use a separately reviewed manual update path. macOS privacy controls may independently deny protected files even to the service. Do not grant Full Disk Access, Accessibility or Screen Recording merely to complete enrollment.

An explicit Mac diagnostic snapshot covers running-OS identity, hardware, local storage, network, processes and uptime. It omits unified logs, SMART tests and protected-file inspection; missing evidence appears as a warning, not a healthy-system verdict. If a pre-release fails, retain the package and report the exact version, architecture and error without the one-use code or private file contents. See troubleshooting.