메뉴
HN
Hacker News 10일 전

남는 맥을 클로드 코드 전용 머신으로 만드는 법

IMP
7/10
핵심 요약

메인 Mac에서 AI 코딩 에이전트인 Claude Code를 실행할 때 발생할 수 있는 보안 위험을 줄이기 위해, 남는 Mac을 완전히 분리된 제어 환경으로 설정하는 방법을 다룹니다. 컨테이너 환경의 한계를 벗어나 Mac 전용 앱 제어와 마우스/키보드 조작(Computer use)이 가능하며, 스마트폰 Claude 앱이나 SSH를 통해 언제 어디서나 기기에 접근할 수 있어 개발 및 연구 자동화에 매우 유용합니다.

번역된 본문

여분의 Mac을 Claude Code가 완전히 제어할 수 있는 상시 켜져 있는 머신으로 바꾸는(computer use 활성화 포함) 단계별 가이드입니다. 스마트폰의 Claude 앱이나 메인 Mac의 SSH를 통해 이 머신과 대화할 수 있습니다.

왜 이런 작업을 할까요? Claude Code가 스스로 제어할 수 있는 분리된 환경을 만들고 싶었습니다. 그래야 제 메인 머신에서 굳이 실행하고 싶지 않은 작업, 예를 들어 특정 연구 작업이나 개발 작업을 위임할 수 있기 때문입니다. 특히 --dangerously-skip-permissions 플래그를 켠 Claude Code는 메인 머신에서 실행할 때 본질적인 위험을 수반합니다. 여분의 Mac에 필요한 모든 접근 권한을 부여한 분리된 환경을 만들면 이러한 위험을 제거하거나 완화할 수 있습니다. 추가적인 장점으로 스마트폰을 통해 언제 어디서나 Claude Code와 대화할 수 있다는 것입니다. 모바일 앱에서 일반 Claude 대신 Claude Code와 대화하는 것을 종종 선호하는데(일반적으로 Claude Code가 더 유능하기 때문입니다), 이 점이 개인적으로 매우 유용했습니다.

이 가이드는 메인 Mac과 이를 위해 설정할 여분의 Mac이 있다고 가정하지만, 여기서 영감을 얻어 두 대의 컴퓨터 조합에 자유롭게 응용할 수 있습니다.

왜 이런 설정을 사용할까요? 먼저 가질 수 있는 몇 가지 질문을 빠르게 짚고 넘어가겠습니다.

왜 컨테이너(Container)에서 실행하지 않나요? 저 역시 컨테이너에서 실행하는 것을 강력히 지지하며, 그렇게 편리하게 할 수 있는 환경을 직접 구축하기도 했습니다. 하지만 몇 가지 한계가 있다는 것을 발견했습니다. 첫째, 여전히 메인 머신에서 실행되므로 완전히 분리된 것이 아닙니다. 예를 들어, 전송되는 네트워크 요청은 여전히 메인 머신을 통과합니다. 둘째, 컨테이너의 기능 자체에 한계가 있습니다. 예를 들어 게임 개발을 위해 에이전트가 Unity를 실행하게 하고 싶은데, 컨테이너에서는 이를 쉽게 할 수 있는 방법이 없습니다. Mac에서만 사용할 수 있는 다른 모든 앱도 마찬가지입니다. Claude Code가 클릭, 드래그 등의 '컴퓨터 사용(computer use)'을 통해 이러한 앱을 제어하기를 원한다면 특히 더 큰 제약이 됩니다.

왜 OpenClaw 같은 것을 사용하지 않나요? 저는 Claude Code의 완전하고 최신 기능에 접근하는 것을 좋아합니다. 또한 Claude 앱에서 이를 제어할 수 있는 것을 편리하게 여깁니다. Claude 구독 요금제를 사용 중이라면 구독 사용량을 그대로 소진할 수 있다는 추가 이점도 있습니다. 결국 광범위한 권한을 가진 에이전트를 실행하는 것은 '잃을 것이 없는 머신'에서 하는 것이 더 안전하지만, 컨테이너 대신 온전한 Mac을 사용할 수 있다는 이점을 얻을 수 있습니다.

이 가이드의 접근 방식은 다음과 같습니다: • 메인 머신이 아닌, 이전의 여분 Mac을 사용합니다. • 개인 데이터나 Apple ID 로그인이 없는 새로운 로컬 계정을 만들어 에이전트가 접근할 민감한 정보가 없도록 합니다. • 로컬 네트워크의 메인 Mac에서 SSH로 기기를 구동하고 스마트폰으로 제어합니다.

필요한 것들 • 여분 Mac (제어 대상) • 동일한 Wi-Fi에 연결된 일상용 Mac (제어 주체)

  1. 대상 Mac에서 새로 시작하기 먼저 초기화하세요 (개인 데이터가 있는 경우) 이 기기에 대한 전체 액세스 권한을 에이전트에게 부여하게 되므로, 기기에 저장된 모든 것에 접근할 수 있게 됩니다. 접근을 원치 않는 기존 데이터가 있다면 먼저 기기를 지우세요: • 지원되는 Mac: 시스템 설정 -> 일반 -> 전송 또는 재설정 -> 모든 콘텐츠 및 설정 지우기. • 이전 인텔 Mac: 복구 모드로 재부팅(부팅 시 Cmd-R 길게 누름)하고, 디스크 유틸리티를 사용하여 내장 드라이브를 지운 다음 macOS를 다시 설치하세요. • 이후 선택적으로 최신 macOS로 업데이트하세요(시스템 설정 -> 일반 -> 소프트웨어 업데이트).

새롭고 격리된 계정 만들기 새 로컬 사용자 계정을 만듭니다(시스템 설정 -> 사용자 및 그룹). 설정 중 Apple ID 로그인은 하지 않고 건너뛰는 것을 권장합니다.

계정을 관리자로 만들기 (아직 안 된 경우) 계정에는 관리자 권한이 필요하며, 그렇지 않으면 sudo가 실행되지 않습니다. 시스템 설정 -> 사용자 및 그룹 -> 해당 계정을 관리자로 설정하세요.

원문 보기
원문 보기 (영어)
claude-controls-mac How to set up your spare Mac for Claude Code to fully control - a step-by-step guide Here’s a full step-by-step guide on how to turn your spare Mac into an always-on machine Claude Code can fully control, with computer use enabled. You’ll be able to talk to it from your phone through the Claude app, or from your main Mac over SSH. In case you’re reading this on GitHub Pages, here’s the repo version . Why do this? I wanted to create a separate environment Claude Code can control on its own, so I can delegate tasks I don’t necessarily want to run on my own machine - certain types of research tasks, and development tasks. Claude Code, especially with the --dangerously-skip-permissions flag on, carries inherent risk when run on your main machine. You can eliminate / mitigate these risks by creating a separate environment on your spare Mac with everything it needs to have access to. It has an added bonus of being able to talk to Claude Code anytime, anywhere from your phone. I’ve personally found it really useful because I often prefer to talk to Claude Code instead of regular Claude on the mobile app - Claude Code is often more capable. The following guide assumes you have your main Mac as well as a spare Mac you can set up for this, but you should be able to take inspiration from it and apply it to any combination of two machines. Why this setup? First, let’s quickly address a few questions you might have. Why not run it in a container? I’m a big proponent of running it in a container - I even built an entire environment for doing so conveniently . However, I’ve found it has a few limitations. First, it still runs on your main machine, so it’s not completely separated. For example, network requests it sends still go through your main machine. Second, there are limitations to the container’s capabilities. For example, I wanted my agent to be able to run Unity for game development, and there’s no easy way to do that in a container. The same goes for any other app that’s only available on a Mac - you won’t have access to it. That’s especially relevant if you want Claude Code to control these apps through computer use - clicking, dragging, and so on. Why not use something like OpenClaw? I personally like having access to the full, latest features of Claude Code. I also like being able to control it from the Claude app - I’ve found it really convenient. And you get to use your Claude subscription usage if you happen to have one, which is an added bonus. At the end of the day, running an agent with broad permissions is safer on a machine that has nothing to lose - but you get the benefit of being able to use a full Mac instead of a container. The approach here: Use an old/spare Mac , not your main one. Create a fresh local account with no personal data and no Apple ID signed in, so the agent has nothing sensitive to reach. Drive it over SSH from your main Mac on your local network, and control it from your phone. What you’ll need A spare Mac (the target ). Your everyday Mac (the source ), on the same Wi-Fi. 1. Start fresh on the target Mac Wipe it first (if it has any personal data) You’ll be giving the agent full access to this machine, so it can reach anything stored on it. If there’s existing data you don’t want it to have access to, erase the machine first: Macs that support it: System Settings -> General -> Transfer or Reset -> Erase All Content and Settings . Older Intel Macs: restart into Recovery (hold Cmd-R at boot), use Disk Utility to erase the internal drive, then reinstall macOS. Optionally update to the latest macOS afterward (System Settings -> General -> Software Update). Create a fresh, isolated account Create a new local user account (System Settings -> Users & Groups). I recommend not signing into an Apple ID. Skip it during setup. Make the account an admin (if you haven’t already) The account needs admin rights or sudo will refuse to run. System Settings -> Users & Groups -> set the account to Allow this user to administer this computer . If you ever need to repair it from another admin account: sudo dseditgroup -o edit -a <user> -t user admin 2. Enable Remote Login (SSH) on the target Mac On the target , turn on SSH so the source Mac can connect: sudo systemsetup -setremotelogin on If the command fails with Turning Remote Login on or off requires Full Disk Access privileges , give your terminal app Full Disk Access first: System Settings -> Privacy & Security -> Full Disk Access . Click + , then in the file picker go to Applications -> Utilities -> Terminal and add it. Quit and reopen the terminal, then rerun the command. 3. Passwordless sudo for the target account This is so the agent (and your SSH commands) can run admin tasks without a password prompt each time. Run this once on the target. It asks for the login password this one time: echo "<user> ALL=(ALL) NOPASSWD: ALL" | sudo tee /etc/sudoers.d/<user>-nopasswd > /dev/null sudo chmod 440 /etc/sudoers.d/<user>-nopasswd sudo visudo -cf /etc/sudoers.d/<user>-nopasswd # validate - must print 'parsed OK' This creates a small rule file telling the Mac that <user> can run sudo without a password prompt: line 1 writes the rule into /etc/sudoers.d/ . line 2 makes it read-only - sudo ignores the file otherwise. line 3 validates the syntax; a typo in a sudoers file can lock you out of sudo entirely, so it must print parsed OK . After this, sudo runs with no prompt - test with sudo -n true , which succeeds silently if passwordless sudo works. 4. Find the target’s address (hostname or IP) You can reach the target by either a hostname or an IP. I recommend using the hostname: it stays the same, while the IP can change. Hostname (recommended). Run on the target: scutil --get LocalHostName # prints the hostname, e.g. MacBook-Pro Add .local to form the address: <target-host>.local . You can also read it from System Settings -> General -> Sharing, shown as Local hostname . Give the target a unique name. Each Mac needs a .local name that’s unique on your network. If two machines share a name, the address can point to the wrong Mac. Make sure the target’s name is unique - rename it if needed: sudo scutil --set LocalHostName newmacbook # -> newmacbook.local IP address (not recommended). Run on the target: ipconfig getifaddr en0 # e.g. 192.168.1.80 Note that the IP can change after a reboot or after a certain amount of time. Throughout the rest of this guide, replace <user> with the target account name and <target-host> with the hostname from above, so the address is <user>@<target-host>.local . You could also instead use an IP in place of <target-host>.local . 5. Set up passwordless SSH from the source Mac On the source Mac, create an SSH key (skip if you already have one): ssh-keygen -t ed25519 Install your public key on the target. This asks for the target account’s login password once: ssh-copy-id <user>@<target-host>.local Test it - this should print the target username with no password prompt: ssh <user>@<target-host>.local whoami 6. Keep the target awake By default macOS sleeps after ~10 minutes idle, even when plugged in, which takes it off the network. To make it never sleep, run this on the target (or over SSH from the source): sudo pmset -c sleep 0 # never system-sleep while plugged in (-c = on charger) sudo pmset -c disablesleep 1 # also prevents sleep with the lid closed (clamshell) sudo pmset -c displaysleep 0 # keep the display on too Verify: pmset -g | grep -iE 'sleep' sleep 0 , SleepDisabled 1 , and displaysleep 0 in the output confirm it worked. If the machine runs on battery sometimes, use -a instead of -c to apply to all power sources (at the cost of battery drain). The screen can still lock when the screen saver kicks in. Stop the screen saver from ever starting so it never locks on its own: defaults -currentHost write com.apple.screensaver idleTime 0 7. Clipboard sync over SSH macOS ships pbcopy (write clipboard) and pbpaste (read clipboard). Piped over SSH, th