Mac pre-release: OpalSpan Agent CLI and Daemon
OpalSpan has separate Apple-silicon and Intel pre-releases for testing. The portable Agent CLI and its diagnostic helper are 0.18.2; Daemon and attended Rescue are 0.17.0. These builds are not Apple Developer ID signed or notarized and have not yet run on Mac hardware. They are not a supported general release. macOS may block first launch or ask for a per-app security decision. Do not disable Gatekeeper or strip quarantine. The device owner makes any local security decision.
Choose the matching architecture
On the Mac, run uname -m in Terminal. Choose Apple silicon (arm64) for
an M-series Mac or Intel (x86_64) for an Intel Mac. Download only that
architecture from OpalSpan downloads. Do not
mix an Intel CLI with an Apple-silicon Host package. The public page shows
version and SHA-256 for each available archive; compare the downloaded archive
with shasum -a 256 <archive> before use. A checksum on the same website is an
integrity cross-check, not independent publisher authentication.
Agent CLI on the technician's Mac
The CLI preview is a portable tar.gz archive, not an installer. Keep its
contents together in a private, architecture-matched folder; do not run it
with sudo. The local agent operates forge and forge-transport-helper.
The technician authorizes normal browser login and any Keychain prompts.
forge --version, forge credentials status and forge doctor are useful
first checks. OpenSSH client tools (ssh, scp, ssh-keygen) are needed for
device access. After the owner's normal first-launch decision, the local agent
may run ./forge update from the extracted folder. That command verifies the
architecture-matched signed catalog and archive, probes the new binary, then
activates a private per-user installation. Use the returned shim_path or add
its parent directory to the agent runner's PATH. forge setup repair and
forge setup uninstall are also available with the signed archive/manifest
or installation root as applicable; no standalone Mac installer or background
update is claimed. A Mac CLI does not grant access by itself: Bridge membership,
selected-device authority and normal login still apply.
Daemon enrollment and attended Rescue
Create the device's own Mac enrollment link in Forge. On the intended Mac,
download the architecture-matched package and follow its README.txt with
the owner's consent and administrator approval. The package contains a
private, one-use code; keep the whole folder private and do not paste that code
into chat or command arguments. The Host verifies Forge's pinned release
manifest and binary hash before registration. It runs as a root-owned
launchd service using the outbound HTTPS relay; it does not install a LAN
listener, Tailscale, OpenSSH server or support account.
Attended Rescue has its own temporary package and explicit cleanup. Mac Host previews are excluded from automatic updates; use a separately reviewed manual update path. macOS privacy controls may independently deny protected files even to the service. Do not grant Full Disk Access, Accessibility or Screen Recording merely to complete enrollment.
An explicit Mac diagnostic snapshot covers running-OS identity, hardware, local storage, network, processes and uptime. It omits unified logs, SMART tests and protected-file inspection; missing evidence appears as a warning, not a healthy-system verdict. If a pre-release fails, retain the package and report the exact version, architecture and error without the one-use code or private file contents. See troubleshooting.