chore(nix): thread cfg.relayUrl into fresh-boot .env stub (#57 follow-up)

The fresh-boot `/var/lib/bitspire/.env` template at flake.nix's
`bitspire-env` activation script seeded `VITE_RELAY_URL=` empty, which
forced every operator to run `provision-atm.sh` (or hand-edit .env)
before the renderer could resolve a relay. Meanwhile the NixOS option
`services.bitspire.relayUrl` was wired only to the dead-code
`/etc/bitspire/config.env` (mkForce-shadowed by `/var/lib/bitspire/.env`).

Thread the NixOS option through: seed `VITE_RELAY_URL=${cfg.relayUrl}`
on first boot. The .env override path remains intact — provision-atm.sh
or a hand edit still take precedence at runtime (the file is the
EnvironmentFile, not the activation-time template). Existing ATMs
already have a populated `.env` and aren't affected (the activation
script's `if [ ! -f ... ]` guard skips the rewrite).

Renderer resolution order:
  /var/lib/bitspire/.env → NixOS module default → renderer fallback
  (`ws://localhost:7777` in lightning.ts:63 / main.ts:284)

Also expand the `services.bitspire.relayUrl` option description so
future readers see the wire-through + the override path documented
where the option lives.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
Padreug 2026-06-01 20:42:05 +02:00
commit 055afba894
2 changed files with 21 additions and 5 deletions

View file

@ -21,7 +21,18 @@ in
relayUrl = mkOption {
type = types.str;
default = "wss://relay.aiolabs.dev";
description = "Nostr relay URL the ATM and LNbits both subscribe to";
description = ''
Nostr relay URL the ATM and LNbits both subscribe to.
On a fresh-boot disk image this value is seeded into
`/var/lib/bitspire/.env` as `VITE_RELAY_URL=…` (see flake.nix
`bitspire-env` activation script). The operator can override
the seeded value at runtime by editing `.env` directly or by
re-running `deploy/nixos/provision-atm.sh` with a different
`RELAY_URL`. The renderer's resolution order is:
`/var/lib/bitspire/.env` → this NixOS default → renderer
hardcoded fallback (`ws://localhost:7777`).
'';
};
lnbitsServerPubkey = mkOption {

View file

@ -186,14 +186,19 @@
};
# Env template — runtime secrets provisioned via provision-atm.sh.
# Fields are intentionally empty so a fresh disk image boots
# cleanly into the "needs provisioning" state; provision-atm.sh
# SSHes in and overwrites with real values.
# Identity fields are intentionally empty so a fresh disk image
# boots cleanly into the "needs provisioning" state; provision-
# atm.sh SSHes in and overwrites with real values.
#
# VITE_RELAY_URL seeds from `config.services.bitspire.relayUrl`
# so the NixOS module's `relayUrl` option becomes the default
# without losing the operator's ability to override via .env
# (edit the file or re-run provision-atm.sh).
system.activationScripts.bitspire-env = ''
mkdir -p /var/lib/bitspire
if [ ! -f /var/lib/bitspire/.env ]; then
cp ${pkgs.writeText "bitspire-env-default" ''
VITE_RELAY_URL=
VITE_RELAY_URL=${config.services.bitspire.relayUrl}
VITE_LNBITS_SERVER_PUBKEY=
VITE_ATM_PRIVATE_KEY=
VITE_APP_ID=