Local Mac Mini Setup Guide
Why local beats cloud, recommended hardware, and how to harden an always-on Mac Mini before you hand an agent the keys. Skip the EC2 nightmare I went through.
Note: How to Read This Guide
This guide is about the machine, not the agent software. My agents run on Hermes and Claude Code today, and they ran on OpenClaw before that. The hardware, the macOS hardening, and the remote-access setup below carried over unchanged. Follow your runtime's own install docs for the software itself; this guide covers everything around it.
Why a Mac Mini
An always-on agent needs a machine that is always on. I tried an Amazon EC2 instance first: latency, SSH complexity, dropped sessions, and a monthly bill that kept climbing. Moving to a Mac Mini on my desk fixed all four.
The Mac Mini has become the default hardware for running personal agents. Its compact size, Apple Silicon efficiency (3–7 watts at idle), and unified memory make it a quiet, always-on server at a fraction of cloud hosting costs. This guide walks you from unboxing to a hardened machine that is ready for an agent.
Critical: The Risk You're Taking On
A capable agent can run shell commands, read and write files, browse the web, and send messages as you. That same access is what makes it useful and what makes it a target. A prompt injection hidden in an email or web page can turn an eager agent against you. Treat the setup with the same caution you'd give root SSH access to a stranger.
Part 1: Hardware & Prerequisites
Recommended Hardware
| Component | Minimum | Recommended |
|---|---|---|
| Mac Mini | M2 / 8 GB / 256 GB | M4 / 16 GB / 256 GB ($599) |
| Network | Wi-Fi | Ethernet (more stable for 24/7) |
| UPS | None | Small UPS for clean shutdown |
| HDMI Dummy Plug | None | $8–10 dongle (prevents headless display issues) |
| Keyboard w/ Touch ID | For initial setup | Convenient for physical auth |
The base M4 Mac Mini at $599 is enough if your agents call cloud models. Buy more memory only if you plan to run local models (see Part 7). At roughly $1–2/month in electricity, it pays for itself within months versus equivalent cloud hosting.
What You'll Need Before Starting
- An Anthropic API key or subscription (recommended), or access to another frontier model provider
- A messaging channel for talking to your agent, such as a Telegram bot token from @BotFather
- A Tailscale account (free tier) for secure remote access
- Approximately 2 hours of dedicated setup time
Part 2: Initial macOS Configuration
Fresh Install or Factory Reset
If you're repurposing an existing Mac Mini, perform a full factory reset: System Settings → General → Transfer or Reset → Erase All Content and Settings. Starting clean eliminates leftover software and credentials that an agent could inadvertently access.
Create Two Accounts: Separation of Privilege
Before installing any agent software, create a separation of privilege on the Mac Mini itself. This is one of the most effective containment strategies you can implement, and most guides skip it entirely.
Admin Account (for installs only): Used exclusively for installing software (Homebrew packages, runtimes, macOS updates). It does not run your agents.
Standard (Non-Admin) Account (for running agents): This is where your agents live and run. A standard account cannot install system software, modify system files, or escalate privileges. If an agent gets tricked by a prompt injection or a malicious plugin, the blast radius is contained.
Note: Why This Matters
Agents are eager to please by default. If a prompt injection convinces one to run a destructive command, a non-admin account prevents it from modifying system files, installing rootkits, or escalating to root. This is your single best containment layer.
macOS Setup Wizard Decisions
| Setting | Recommendation | Rationale |
|---|---|---|
| FileVault Encryption | ENABLE | AES-256 full disk encryption via Secure Enclave |
| Location Services | Disable | Not needed; reduces data leakage |
| Siri | Disable | Unnecessary background processing |
| Apple Intelligence | Disable | Sends data to Apple servers |
| Analytics Sharing | Decline all | Minimizes telemetry |
| Screen Time | Skip | Not applicable for a server |
| iCloud Sign-In | Skip or minimal | Skip for air-gap isolation |
| Touch ID | Enable | Stored locally in Secure Enclave; useful for physical auth |
| Apple Pay | Skip | Not needed |
Configure for 24/7 Operation
Prevent the Mac Mini from sleeping and ensure it auto-restarts after power failures:
sudo pmset -a sleep 0 disksleep 0 displaysleep 0
sudo pmset -a hibernatemode 0 powernap 0
sudo pmset -a standby 0 autopoweroff 0
sudo pmset -a autorestart 1Verify with: pmset -g — all sleep-related values should be 0. Enable wake for network access so Tailscale stays connected: System Settings → Battery → Options → Wake for network access: ON.
Enable the macOS Firewall
The built-in firewall is off by default. Turn it on:
- System Settings → Network → Firewall → Toggle ON
- Click Options: Block all incoming connections: ON
- If you later need Tailscale or SSH, add exceptions specifically for those apps
Disable SSH Password Authentication
If Remote Login (SSH) is enabled, disable password-based authentication and allow only key-based auth:
sudo nano /etc/ssh/sshd_config
# Set these values:
PasswordAuthentication no
ChallengeResponseAuthentication no
UsePAM no
# Restart SSH:
sudo launchctl unload /System/Library/LaunchDaemons/ssh.plist
sudo launchctl load /System/Library/LaunchDaemons/ssh.plistPart 3: Install Prerequisites
Install Homebrew
/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)"Follow the on-screen instructions to add Homebrew to your PATH.
Install Your Runtime's Dependencies
Most agent runtimes need Node.js, Python, or both. Install whatever yours requires from the admin account, on current LTS versions, and keep them patched. Security fixes land in the runtime as often as in the agent software.
brew install node python git
node --version
python3 --versionInstall Tailscale
Tailscale provides secure, zero-configuration VPN access to your Mac Mini from anywhere:
brew install tailscale
# Also install the Tailscale app from the Mac App Store for GUI managementPlug In the HDMI Dummy Plug
On recent macOS versions, headless mode causes issues with Screen Recording permissions and screen capture functionality. Plug an HDMI dummy dongle ($8–10) into one of the HDMI ports before proceeding. This tricks macOS into thinking a display is connected.
Part 4: Principles for the Agent Install
Install the agent software itself by following its own docs. Whatever you run, these are the decisions that matter:
Run it as the standard user. Install with the admin account if you must, but the agent process runs under the non-admin account you created in Part 2.
Use a frontier model. Stronger models resist prompt injection better. Weaker or older models are more easily manipulated, and when your agent has shell access, that matters.
Bind to localhost only (critical). If your runtime exposes a local server or dashboard, it must only be reachable from the Mac Mini itself, never from the network. Loopback, not 0.0.0.0. Remote access comes through Tailscale in Part 5, not an open port.
Lock the messaging channel to you. Allowlist your own user ID on Telegram (or whatever channel you use) so strangers can't talk to your agent. Unknown senders should be ignored or require explicit approval.
Warning: WhatsApp Personal Number
If you connect WhatsApp using your personal phone number, a compromised agent could message your real contacts as you. Use a dedicated prepaid SIM number, not your primary number.
Start it on boot. Run the agent as a LaunchAgent (or whatever service mode your runtime provides) so it starts on boot and restarts on crash.
Set the Agent's Identity
The first instructions you give an agent shape its behavior going forward. Be deliberate:
Your name is [Agent Name]. I'm [Your Name].
Be direct, concise, and honest.
If I ask you to do something risky, push back and tell me why.
Don't sugarcoat or over-explain.
Core rules:
- Never delete files, send messages, or run commands with side
effects without confirming with me first.
- Ask before acting on anything destructive or irreversible.
- Keep responses short unless I ask for detail.
- Flag security concerns proactively.Note: Why “Push Back” Matters
By default, AI agents are eager to please. They'll cheerfully execute whatever you ask — including instructions injected by a malicious email, web page, or plugin. You want an assistant that challenges risky requests, not one that complies without thinking.
Lock Down Config and Credential Files
Agent config directories hold API keys, bot tokens, and session data. Restrict them to the account that runs the agent:
chmod 700 ~/path/to/agent-config
find ~/path/to/agent-config -type f -exec chmod 600 {} \;Set API Spending Limits
An out-of-control agent or a prompt injection attack could rack up enormous API bills. Set spending limits directly with your model provider as a safety net. Anthropic: set monthly usage limits in the Anthropic Console under Billing. OpenAI: set hard monthly caps in the OpenAI dashboard.
API Key Management
Never scatter API keys across .env files or shell history. Two recommended approaches:
Option A: Bitwarden CLI (Recommended). Install the Bitwarden CLI, log in, and unlock your vault. Your agents pull secrets on demand.
Option B: macOS Keychain. Store API keys in the local Keychain (encrypted via the Secure Enclave). Credentials never leave the device if iCloud Keychain is disabled.
Warning: Shell Environment Warning
A shell-level ANTHROPIC_API_KEY environment variable can silently override your agent's configured credentials and cause auth failures or surprise bills. Make sure there are no conflicting environment variables in your shell profile.
Network Security Checklist
- ✓Agent server or dashboard bound to localhost only — never 0.0.0.0
- ✓macOS firewall is ON with incoming connections blocked
- ✓No agent ports forwarded to the internet via your router
- ✓Remote access is exclusively via Tailscale or SSH tunnel
- ✓Your home router's admin password has been changed from the default
- ✓UPnP is disabled on your router
Part 5: Secure Remote Access with Tailscale
You'll want to reach your Mac Mini and any agent dashboard from your phone or laptop. Never expose a port directly to the internet. Use Tailscale instead.
Set Up Tailscale
- Install Tailscale (done in Part 3) and sign in
- On your Mac Mini, authenticate:
tailscale up - Install Tailscale on your phone/laptop and sign in with the same account
- Verify connectivity:
tailscale status
Configure Tailscale Serve
If your agent has a local dashboard, publish it to your tailnet only. Replace PORT with the port your runtime uses:
tailscale serve http://127.0.0.1:PORT
# Access from any device on your tailnet:
# https://[mac-mini-hostname].tail[xxxxx].ts.netCritical: Serve, Not Funnel
Use tailscale serve (private to your tailnet) — NOT tailscale funnel (which exposes to the public internet).
Alternative: SSH Tunnel
ssh -N -L PORT:127.0.0.1:PORT user@your-mac-mini.local
# Then open http://localhost:PORTPart 6: Plugin & Skill Security
Skills, plugins, and MCP servers extend what your agent can do. They also run with your agent's access. Community marketplaces have shipped malicious packages designed to steal credentials, and vetting is thin.
Golden Rules for Skills
- Read the source code before installing anything. Treat community skills with the same skepticism as random npm packages from an unknown author.
- Start with zero third-party skills. Use only the built-in tools initially. Add third-party skills one at a time after thorough review.
- Check the author and track record. Popularity alone doesn't guarantee safety, but brand-new packages from new accounts are especially risky.
- Look for credential access. If a skill requests API keys or file system access disproportionate to its stated purpose, do not install it.
- Sandbox anything you don't fully trust.
Part 7: Ongoing Maintenance & Monitoring
Update Schedule
| Task | Frequency | Action |
|---|---|---|
| Update agent software | Weekly | Follow your runtime's stable channel |
| Update macOS | When available | System Settings → Software Update |
| Update Node.js / Python | Monthly | brew upgrade |
| Rotate API keys | Quarterly | Update in Bitwarden / Keychain |
| Review agent logs | Weekly | Scan for unexpected commands or senders |
| Verify Tailscale peers | Monthly | tailscale status |
Backups
Time Machine will back up the whole machine, including your agents' config and memory. Additionally, keep periodic exports of your config on an encrypted external drive, back up API keys separately in your password manager, and document your skill setup so you can rebuild quickly if needed.
What to Do If Compromised
- Stop the agent process immediately
- Disconnect from the network (Wi-Fi and Ethernet)
- Review the agent's logs for suspicious activity
- Rotate ALL credentials: API keys, bot tokens, and any accounts the agent accessed
- Check your messaging channel for senders you didn't approve
- Rebuild in an isolated environment with proper security controls before restarting
Part 8: Optional Enhancements
Local AI Models with Ollama
Run AI models entirely on your Mac Mini with no cloud API costs. Apple Silicon's Metal GPU acceleration makes local inference surprisingly fast.
| RAM | Model Size | Examples |
|---|---|---|
| 8 GB | 7B parameters | Llama 3.1 7B, Mistral 7B |
| 16–24 GB | 13B–34B parameters | Ideal for most use cases |
| 48+ GB | 70B parameters | Near-cloud-quality responses |
brew install ollama
ollama pull llama3.1Note: Privacy Advantage
Running local models means your prompts and data never leave your machine. Though note that local models currently offer weaker prompt-injection resistance compared to frontier cloud models like Claude.
Container Isolation
For an extra layer of isolation, run your agent inside a container using Docker Desktop or OrbStack. Run it as a non-root user and mount only the directories the agent actually needs.
Scheduled Routines
The biggest unlock of an always-on machine is that agents can work on a schedule: a morning brief, an inbox sweep, a weekly memory rollup. Use your runtime's scheduler, or plain cron or launchd, to run them in isolated sessions.
Security Checklist
- ✓Dedicated non-admin macOS user for running agents
- ✓FileVault encryption: ON
- ✓macOS firewall: ON
- ✓Agent server bound to localhost only
- ✓Messaging channel allowlisted to your IDs only
- ✓Frontier model (Claude or equivalent)
- ✓API spending limits set with provider
- ✓No agent ports exposed to the internet
- ✓Remote access: Tailscale Serve or SSH tunnel only
- ✓Agent software and runtimes on current versions
- ✓File permissions: 700 on config directories, 600 on config files
- ✓Third-party skills: Source code reviewed before installation
- ✓API keys: Stored in password manager, not .env files
- ✓Router UPnP: Disabled
Final Word
An always-on agent is genuinely useful. It's also genuinely risky if you're careless. Prompt injection, malicious plugins, and exposed instances are all real, and all have happened to people who skipped the boring parts of setup.
Every configuration decision in this guide was filtered through one question: what's the worst that could happen? Set it up right the first time. Start locked down. Open things up only when you understand exactly what you're exposing.
Go Deeper
Want hands-on help with this?
I'll walk you through exactly how I set this up and run it every day.