Skip to content

Environment variables

The pomme command reads the following environment variables.

Variable Description
POMME_VM_NAME The VM that a command acts on when you omit the VM name.
POMME_AUTHORIZED_USER The existing guest owner account that authorizes a SIP or AMFI change.
POMME_AUTHORIZED_PASSWORD The password for POMME_AUTHORIZED_USER.
POMME_APP_SUPPORT_DIR An alternative directory for Pomme’s host data.

Sets the default VM for commands that accept an optional VM name, such as pomme status, pomme exec, and pomme sessions list, and for the pomme ui commands that take --vm. A name that you pass on the command line always takes precedence.

Terminal window
export POMME_VM_NAME=dev
pomme status
pomme exec -- /usr/bin/sw_vers

Pomme never selects a VM on its own, even if only one VM is running. If you omit the name and POMME_VM_NAME isn’t set, the command fails with the following message and exit code 64:

Error: Specify a VM name or set POMME_VM_NAME.

POMME_AUTHORIZED_USER and POMME_AUTHORIZED_PASSWORD

Section titled “POMME_AUTHORIZED_USER and POMME_AUTHORIZED_PASSWORD”

Authorize a SIP or AMFI change on a VM that already has an owner account, including the security changes that pomme mdm makes before it enrolls. Set both variables. If you set only one, Pomme rejects the command.

Pomme passes the password to its credential boundary separately. It never puts the password in command arguments or in a workflow journal.

For details, see Security workflows.

Replaces ~/Library/Application Support/pomme as the directory where Pomme stores VMs, templates, restore images, and other host data. Pomme ignores an empty value.

This variable is intended for isolated testing. VMs and templates in one data directory are invisible to commands that use another, so a VM that you create with this variable set doesn’t appear in pomme list without it.

Some flags take the name of an environment variable instead of a value:

  • pomme ui type --text-env VARIABLE types the value of VARIABLE into the guest. Use it to keep secrets out of the command line and shell history.