Skip to content

Instantly share code, notes, and snippets.

@the-machinist
Last active August 20, 2026 20:14
Show Gist options
  • Select an option

  • Save the-machinist/14a1079c905bb2d5067347b145118906 to your computer and use it in GitHub Desktop.

Select an option

Save the-machinist/14a1079c905bb2d5067347b145118906 to your computer and use it in GitHub Desktop.
Minion Gist
#!/bin/bash
# This file is hosted publicly (a gist behind the short URL) so a fresh
# machine can fetch it without any GitHub credential:
# /bin/bash -c "$(curl -fsSL https://go.acceleron.wiki/minion)"
set -euo pipefail
read -r -p "worker name (kevin/stuart/bob): " W
[ -n "$W" ] || { echo "no name given" >&2; exit 1; }
echo "==> hostname + network time (runner auth fails past 5 min drift)"
sudo scutil --set ComputerName "$W"
sudo scutil --set HostName "$W"
sudo scutil --set LocalHostName "$W"
sudo systemsetup -setusingnetworktime on
echo "==> patch before anything else"
sudo softwareupdate -ia
if ! command -v brew >/dev/null; then
echo "==> Homebrew (also pulls in the Xcode Command Line Tools)"
/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)"
# Intel installs to /usr/local (already on PATH); Apple silicon needs this:
[ -x /opt/homebrew/bin/brew ] && eval "$(/opt/homebrew/bin/brew shellenv)"
fi
echo "==> Tailscale (headless daemon — the only flavour that can be an SSH server)"
brew list tailscale >/dev/null 2>&1 || brew install tailscale
sudo brew services start tailscale
# The auth key is entered here, on the machine itself — it never transits
# another channel. Create it pre-authorized with tag:minion (docs/tailscale.md).
read -r -s -p "Tailscale auth key (tskey-auth-…): " TSKEY; echo
if ! sudo tailscale up --ssh --hostname="$W" \
--authkey="$TSKEY" --advertise-tags=tag:minion; then
echo >&2
echo "Tailscale refused the tag. tag:minion must exist in the tailnet policy" >&2
echo "*before* the key is issued — admin console → Access Controls:" >&2
echo ' "tagOwners": { "tag:minion": ["autogroup:admin"] }' >&2
echo "Save that, mint a fresh auth key with the tag:minion tag, re-run." >&2
exit 1
fi
echo
echo "done. From your laptop, confirm the way in works before unplugging"
echo "the display:"
echo " ssh gru@$W hostname"
echo "then bring the worker up:"
echo " bin/minion $W up"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment