chore(machine): fund-atm resumes from binding; VITE_SPIRE_SEED docs/env

fund-atm resolves its signer by resuming the bunker binding from state.db
(the connect token is already spent by the main app, so it can't re-pair);
falls back to a dev nsec via VITE_ATM_PRIVATE_KEY. better-sqlite3 marked
external in the esbuild bundle. .env.example + CLAUDE.md document
VITE_SPIRE_SEED as the prod identity, VITE_ATM_PRIVATE_KEY as dev-only.

(fund-atm is slated for deprecation in favour of the operator funding the
wallet directly via the LNbits UI — kept working for now.)

Part of Phase C, aiolabs/bitspire#52.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Padreug 2026-06-19 00:15:59 +02:00
commit 0391dbaeb0
4 changed files with 47 additions and 13 deletions

View file

@ -36,16 +36,23 @@ VITE_LNBITS_SERVER_PUBKEY=
# aiolabs/withdraw#1 / commit e9d911e.)
# =============================================================================
# ATM Identity
# ATM Identity — spire pairing seed (NIP-46 bunker; aiolabs/bitspire#52)
# =============================================================================
# The spire pairing seed produced by the operator dashboard (spirekeeper):
# spire-seed:v1:<base64url>
# It carries a one-shot NIP-46 connect token + the spire's signing pubkey +
# the bunker URL. On first boot the ATM redeems the token, generates its own
# transport key, and persists the binding to state.db; thereafter it resumes
# from the binding (the seed can stay set — it's matched by fingerprint).
# A changed seed re-pairs (and re-publishes the cassette-state hello).
VITE_SPIRE_SEED=
# pragma: allowlist secret
# ATM's Nostr private key (hex format, 64 characters). This signing
# key IS the credential — LNbits derives the account from it on first
# contact (issue aiolabs/lnbits#9 alignment).
# DEV ONLY fallback — a raw Nostr private key (hex, 64 chars) for running
# without a bunker. Ignored when VITE_SPIRE_SEED or a stored binding exists.
# Generate with: openssl rand -hex 32
# If not set, generates ephemeral identity on each restart (dev only).
VITE_ATM_PRIVATE_KEY=
# VITE_ATM_PRIVATE_KEY=
# =============================================================================
# Operator Identity