macOS
Install a worker on macOS as a LaunchAgent, with Keychain credentials and the optional sandbox-exec sandbox for agents.
Terminal
node scripts/package-worker.mjs
./installers/macos/install-worker.sh- Autostart: a LaunchAgent with
KeepAlive, running as your user. - Credentials: macOS Keychain.
- Uninstall:
./installers/macos/uninstall-worker.sh(add--remove-datato delete configuration and credentials).
Verification status
The macOS installer has been syntax-checked, not yet run on a Mac.
Sandbox
With the sandbox policy set to preferred or required, agents run under sandbox-exec: the file system stays
readable, but writes are allowed only to the project, temporary folders and the agent's own state folders, and
~/.ssh, ~/.gnupg and similar folders are hidden. See Worker security. The macOS
invocation is unit-tested but has not yet run on a real Mac.