macOS Lima Setup
The macOS path uses a separately signed, measured Lima appliance for macos.linux-vm.runsc; local and hosted Sigroom use the same guest trust and Gateway admission contract.
Choose Local Or Hosted
| Goal | Entry point | Server changes |
|---|---|---|
| Local development | onboard-macos-lima-hacp.sh --mode local | Writes a protected local override, enables one workspace, starts the local stack/proxy, and adds the runtime to the seeded room. |
| Hosted Sigroom | onboard-macos-lima-hacp.sh --mode hosted | None from the client. An operator must enable the exact workspace on API first. |
| Read-only verification | setup-l4-macos.sh --check-only --json | None; verifies signed appliance integrity and endpoint reachability. |
Completion Gate
HTTP readiness is not enough.Require measured L4 evidence and hacp service status --json after enrollment; that confirms Gateway accepted the macOS session over WebSocket.
Complete Commands
The runtime guide contains prerequisites, local and hosted commands, API rollout flags, private-PKI handling, evidence locations, troubleshooting, and explicit removal steps.
- Open macOS Lima runtime guide — Review the macOS section and source guide before enabling a workspace.
Source Material
- docs/deployment/runtimes/macos-hacp-control-runtime.md
- ops/hacp-control/onboard-macos-lima-hacp.sh
- ops/hacp-control/setup-l4-macos.sh
- ops/hacp-control/appliance/complete-managed-onboarding.sh
- ops/hacp-control/appliance/verify-appliance-integrity.sh
- apps/api/src/modules/enrollment/routes.ts
- apps/gateway/src/server.ts