Skip to content

Repository files navigation

Mac Setup

My repeatable Apple Silicon macOS setup, built with Determinate Nix, nix-darwin, Home Manager, Homebrew, and the Mac App Store.

The repository contains the public machine configuration. Private identity, account metadata, keys, and sync settings are restored from the dedicated Mac Setup vault in 1Password and never stored in Git.

Set up a fresh Mac

Before starting:

  • finish macOS updates and enable FileVault;
  • use macOS 27 or later for the native menu-bar workflow;
  • use the intended local administrator account;
  • sign in to the Mac App Store; and
  • make sure the required 1Password items are recoverable.

1. Install and build

Open Terminal and paste:

/usr/bin/curl -qfsSL --proto '=https' --tlsv1.2 \
  https://raw.githubusercontent.com/philippgerard/mac-setup/main/setup.sh \
  | /bin/bash -p

This checks the Command Line Tools, creates a transactional checkout of the current main commit at ~/.config/mac-setup, installs Homebrew and Determinate Nix when needed, validates the checkout, and builds the configuration. It does not activate the build yet. Setup records the exact commit it checked out in .local/bootstrap-revision for later auditing.

The developer-tool check compiles a small C translation unit against the selected macOS SDK. After an OS upgrade, update Command Line Tools or Xcode and complete Xcode's first-launch prompts if this check fails.

If macOS opens the Command Line Tools installer, finish it and leave Terminal open; setup waits and continues automatically. The Homebrew installer remains interactive even though the outer bootstrap is piped, so follow its Terminal prompts. After the checkout exists, any Homebrew or Nix failure prints an exact local command to resume. Setup waits for the Nix daemon itself; a Terminal restart is not part of the normal flow.

2. Activate and restore

After the build succeeds and its changes look right, run:

"$HOME/.config/mac-setup/setup.sh" --provision

Provisioning validates, builds, and switches the configuration in one pass, then starts the guided prompts. These connect 1Password, restore Git identity, personal Mail and configured DAV services, check and restore any missing declared S/MIME identities in the login keychain, restore legacy GPG keys and Filen Menubar configuration, launch Filen Menubar, and open the macOS profiles that require approval. Filen authentication uses the application's in-app Login flow when needed.

The flow is resumable. If activation stops for App Management permission, enable the terminal in System Settings > Privacy & Security > App Management, quit and reopen Terminal, then run the setup command printed with the error. Once base activation has completed, an interrupted profile approval or sign-in resumes only the private restore; run the exact scripts/finish-setup command printed with that error instead of provisioning again.

That is the regular fresh-Mac setup.

Optional accounts

Provisioning selects only personal-mail by default. To add another saved account on this Mac, list every account you want:

"$HOME/.config/mac-setup/setup.sh" --provision -- \
  --mail-account personal-mail --mail-account work-mail

Run ~/.config/mac-setup/scripts/finish-setup --help for account, vault, and skip options. See Mail and account setup for profile, password, Microsoft 365, and migration details.

What it restores

  • macOS defaults, Fish, Git/SSH policy, tmux, Otty, and editable Zed settings
  • the pinned CLI and development toolchain
  • GUI and Mac App Store applications from the configured profiles
  • Filen Menubar with its bundled patched sync backend and Node runtime
  • private Git and GPG state, password-free Mail/DAV metadata, and Filen configuration from 1Password

The complete application policy is in the app inventory. App Store and application sign-ins, Apple privacy approvals, browser sessions, private repositories, and other vendor-managed state still require their supported restore flows.

Everyday use

From ~/.config/mac-setup:

# Check the repository and configuration
scripts/validate

# Build without changing the live system
scripts/rebuild build

# Review package and Homebrew/MAS declaration changes before activation
scripts/rebuild preview

# Build and activate local changes
scripts/rebuild switch

# Intentionally update pinned Nix inputs, Filen Menubar, and OMC, then build
scripts/update

# Check installed state without restoring or changing it
scripts/doctor

Homebrew and Mac App Store application removal is never automatic. Review scripts/homebrew-dry-run before removing software.

More detail

About

Bootstrap script for setting up a fresh Mac with nix, Homebrew, and 1Password integration

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Used by

Contributors

Languages