Sigroom Docs

macOS Lima Setup

The macOS path uses a separately signed, measured Lima appliance for macos.linux-vm.runsc; local and hosted Sigroom use the same guest trust and Gateway admission contract.

draftmacOS developers and runtime operatorsVerified 2026-08-03

Choose Local Or Hosted

GoalEntry pointServer changes
Local developmentonboard-macos-lima-hacp.sh --mode localWrites a protected local override, enables one workspace, starts the local stack/proxy, and adds the runtime to the seeded room.
Hosted Sigroomonboard-macos-lima-hacp.sh --mode hostedNone from the client. An operator must enable the exact workspace on API first.
Read-only verificationsetup-l4-macos.sh --check-only --jsonNone; verifies signed appliance integrity and endpoint reachability.

Completion Gate

HTTP readiness is not enough.Require measured L4 evidence and hacp service status --json after enrollment; that confirms Gateway accepted the macOS session over WebSocket.

Complete Commands

The runtime guide contains prerequisites, local and hosted commands, API rollout flags, private-PKI handling, evidence locations, troubleshooting, and explicit removal steps.

Source Material

  • docs/deployment/runtimes/macos-hacp-control-runtime.md
  • ops/hacp-control/onboard-macos-lima-hacp.sh
  • ops/hacp-control/setup-l4-macos.sh
  • ops/hacp-control/appliance/complete-managed-onboarding.sh
  • ops/hacp-control/appliance/verify-appliance-integrity.sh
  • apps/api/src/modules/enrollment/routes.ts
  • apps/gateway/src/server.ts