diff --git a/deploy/nixos/bitspire-atm.nix b/deploy/nixos/bitspire-atm.nix index 51daf42..43f4d3c 100644 --- a/deploy/nixos/bitspire-atm.nix +++ b/deploy/nixos/bitspire-atm.nix @@ -21,7 +21,18 @@ in relayUrl = mkOption { type = types.str; default = "wss://relay.aiolabs.dev"; - description = "Nostr relay URL the ATM and LNbits both subscribe to"; + description = '' + Nostr relay URL the ATM and LNbits both subscribe to. + + On a fresh-boot disk image this value is seeded into + `/var/lib/bitspire/.env` as `VITE_RELAY_URL=…` (see flake.nix + `bitspire-env` activation script). The operator can override + the seeded value at runtime by editing `.env` directly or by + re-running `deploy/nixos/provision-atm.sh` with a different + `RELAY_URL`. The renderer's resolution order is: + `/var/lib/bitspire/.env` → this NixOS default → renderer + hardcoded fallback (`ws://localhost:7777`). + ''; }; lnbitsServerPubkey = mkOption { diff --git a/flake.nix b/flake.nix index 720c167..dc69891 100644 --- a/flake.nix +++ b/flake.nix @@ -186,14 +186,19 @@ }; # Env template — runtime secrets provisioned via provision-atm.sh. - # Fields are intentionally empty so a fresh disk image boots - # cleanly into the "needs provisioning" state; provision-atm.sh - # SSHes in and overwrites with real values. + # Identity fields are intentionally empty so a fresh disk image + # boots cleanly into the "needs provisioning" state; provision- + # atm.sh SSHes in and overwrites with real values. + # + # VITE_RELAY_URL seeds from `config.services.bitspire.relayUrl` + # so the NixOS module's `relayUrl` option becomes the default + # without losing the operator's ability to override via .env + # (edit the file or re-run provision-atm.sh). system.activationScripts.bitspire-env = '' mkdir -p /var/lib/bitspire if [ ! -f /var/lib/bitspire/.env ]; then cp ${pkgs.writeText "bitspire-env-default" '' - VITE_RELAY_URL= + VITE_RELAY_URL=${config.services.bitspire.relayUrl} VITE_LNBITS_SERVER_PUBKEY= VITE_ATM_PRIVATE_KEY= VITE_APP_ID=