What NOT to do with your hosted Mac
Your Mac is running in our data center. There is no one sitting in front of it, no monitor attached, and no finger to press the power button. Some actions that are perfectly normal on a Mac at your desk will cause serious problems on a hosted Mac. In most cases, we cannot fix these without a physical visit to the data center, which takes time and may involve costs.
This article lists the most common mistakes. Read it before you start configuring your server.
Do NOT Shut Down Your Mac
There is no way to turn on a Mac remotely. If you shut it down (intentionally or by accident), we need to physically press the power button in the data center. This is not instant and may take time.
Restarting is fine. Shutting down is not.
Do NOT Disable Remote Management
Remote Management is what gives you VNC (screen sharing) access to your Mac. If you turn it off, there is no way to turn it back on remotely. Go to System Settings > General > Sharing > Remote Management. This must stay on, unless you intend to only use SSH. For debugging it might be better to configure a firewall on port 5900 so you can still access the machine when needed.
Also make sure Remote Login (SSH) stays enabled. Losing both VNC and SSH means you are fully locked out.
Do NOT Turn On FileVault Without Reading Our Guide
FileVault encrypts your startup disk. On a hosted Mac, this means the machine will sit at a password prompt after every reboot, waiting for someone to type the unlock password on a physical keyboard. Since there is no physical keyboard, your Mac becomes unreachable.
If you need disk encryption, read our FileVault guide first. There are ways to handle this, but the default setup will lock you out.
Do NOT Turn On the Firewall Without Reading Our Guide
The built-in macOS firewall can block the exact services you need to manage your Mac: SSH, VNC, and any other remote access tools. If you enable it with the wrong settings, you will lock yourself out immediately.
Read our Firewall guide before touching this. If you do get locked out, we need physical access to fix it.
Do NOT Install a VPN With a Default Route
Installing a VPN client that routes all traffic through the VPN tunnel will break your connection to the Mac. Your SSH and VNC sessions go through our network, not through your VPN provider. Once the VPN takes over the default route, your Mac becomes unreachable from our network and from you.
If you need a VPN on your Mac, configure it with split tunneling so that only the traffic you actually need goes through the VPN.
Do NOT Enable Automatic macOS Updates
macOS updates regularly require a reboot. If automatic updates are enabled, your Mac may reboot at an unexpected time and, worse, could get stuck on a "press Enter to continue" screen during the update. This leaves your server offline until we can intervene.
Disable automatic updates in System Settings > General > Software Update > Automatic Updates. Update manually, at a time that works for you, and be prepared for a reboot and some downtime if things go wrong.
Do NOT Use "Erase All Content and Settings"
Want to start with a clean slate? That is fine, but please contact us first. If you use "Erase All Content and Settings" your Mac will be wiped, but it will not come back up on its own. Network configuration, remote access, and other settings need to be re-applied manually with physical access to the machine.
If you need a reinstall, let us know and we will coordinate it with you. If you are at the end of your contract and do want to make sure you erase all your data, feel free to use this option to bring the Mac to factory state.