The agent on macOS
The macOS agent runs as a LaunchDaemon inside Caryvane.app, with a menu-bar item and an FSKit extension for the cloud drive. It needs macOS 26 — the drive is built on FSKit, which needs it — and Full Disk Access, which root alone does not give.
Requirements #
- macOS 26 or later; Apple silicon (
arm64) or Intel (x64) build. Both are Developer ID-signed and notarised. - Outbound HTTPS to
console.caryvane.com. - An administrator to install and to grant Full Disk Access (or an MDM profile that does).
Install and enrol #
# Install (interactive: double-click the .pkg; unattended:)
sudo installer -pkg CaryvaneAgent-arm64.pkg -target /
# Enrol unattended: the daemon reads setup.json on start
sudo mkdir -p "/Library/Application Support/Caryvane"
echo '{"DeploymentToken":"<token>"}' | sudo tee "/Library/Application Support/Caryvane/setup.json" >/dev/null
sudo launchctl kickstart -k system/com.caryvane.agent
# Check
sudo launchctl print system/com.caryvane.agent | head -20
Place setup.json before running the package and the first start enrols; place it afterwards and kickstart the daemon. Without a token the package installs and prints where to put one; the menu-bar item also offers enrolment.
Full Disk Access — required #
macOS will not let even root read Mail, Messages, Safari data, Time Machine backups or another user's home without Full Disk Access granted to the application. Without it the agent sees only its own files and every backup reports its sources as empty. Grant it once:
- By hand: System Settings → Privacy & Security → Full Disk Access → add
/Applications/Caryvane.app, then restart the daemon (sudo launchctl kickstart -k system/com.caryvane.agent). - By MDM: push a Privacy Preferences Policy Control profile granting
SystemPolicyAllFilesto the app's bundle identifier and code requirement. The installer shipsmake-pppc-profile.shto generate one with the exact requirement string.
What lands where #
| Item | Location |
|---|---|
| Application (daemon, menu bar, FSKit module) | /Applications/Caryvane.app |
| Daemon | system/com.caryvane.agent (/Library/LaunchDaemons/com.caryvane.agent.plist) |
| Token, database, manifests, cache | /Library/Application Support/Caryvane/ (700 root:wheel) |
| Logs | /Library/Application Support/Caryvane/logs/; also launchctl print for the daemon's state |
What is deliberately not backed up #
A Files job on a Mac skips what Time Machine skips, because nobody wants a copy of macOS in their bucket: cloud-synced placeholders (~/Library/CloudStorage, iCloud Drive files not downloaded), ~/Library caches and derived state (Biome, IntelligencePlatform, Spotlight indexes), the system volume, and the ._* AppleDouble sidecars the Finder writes to non-Apple filesystems. What remains is the user's data.
The cloud drive #
Mounted by an FSKit file-system extension inside the app, running in the user's session, so it appears after login. macOS 26 is the floor because earlier releases have no FSKit resource type for a network-backed volume. Check it is enabled under System Settings → General → Login Items & Extensions → File System Extensions.
Self-update and upgrades #
The agent downloads the new .pkg, verifies its notarisation, and hands it to launchd as a one-shot job so that stopping the old daemon does not kill the installer. The installer unmounts any cloud volumes, stops the daemon and waits for it, replaces the app, and starts it again. Manual installer -pkg gets the same treatment. Uninstall with the bundled uninstall.sh, which removes the app, daemon and data (logs kept).