feat(deploy): add NixOS live USB ISO for ATM hardware testing

Add NixOS configuration to build a bootable live USB ISO that runs the
ATM Electron app in kiosk mode on physical hardware (UpBoard). The ISO
boots from squashfs, auto-starts X11/openbox, and launches Electron in
production mode.

Key changes:
- deploy/nixos/live.nix: Live USB module (squashfs+tmpfs, no disk install)
- deploy/nixos/flake.nix: Nix flake with ISO build output
- deploy/nixos/provision-atm.sh: Auto-provision LP credentials via API
- deploy/nixos/build-iso.sh: End-to-end build workflow script
- apps/machine: Fix Electron production mode (ELECTRON_FORCE_PROD),
  Vue Router hash mode for file:// protocol, relative asset paths

Build: cd deploy/nixos && bash build-iso.sh
Test:  qemu-system-x86_64 -enable-kvm -m 2G -cdrom result/iso/*.iso

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Patrick Mulligan 2026-02-18 20:11:23 -05:00
commit 19d43c2939
13 changed files with 1203 additions and 3 deletions

192
deploy/nixos/README.md Normal file
View file

@ -0,0 +1,192 @@
# Lamassu ATM NixOS Deployment
NixOS configuration for deploying Lamassu Next ATM software on UP Board hardware.
## Quick Start
### 1. Build Installation ISO
```bash
cd deploy/nixos
nix build .#iso
```
The ISO will be in `result/iso/`.
### 2. Install on UP Board
1. Write ISO to USB drive:
```bash
sudo dd if=result/iso/*.iso of=/dev/sdX bs=4M status=progress
```
2. Boot UP Board from USB
3. Run the installer:
```bash
sudo nixos-install --flake .#lamassu-atm
```
4. Reboot and remove USB
### 3. Post-Install Configuration
SSH into the machine and configure:
```bash
# Set up the ATM application
sudo mkdir -p /opt/lamassu-atm
sudo chown lamassu:lamassu /opt/lamassu-atm
# Copy the built Electron app
scp -r apps/machine/dist/* lamassu@<atm-ip>:/opt/lamassu-atm/
# Configure the ATM
sudo nano /etc/lamassu-atm/config.env
```
## Configuration Options
Edit `/etc/nixos/configuration.nix` to customize:
```nix
{
services.lamassu-atm = {
enable = true;
# Nostr relay for ATM communication
relayUrl = "wss://relay.lamassu.is";
# Lightning.Pub instance
lightningPubUrl = "https://lp.lamassu.is";
# Hardware configuration
billValidator = {
enable = true;
device = "/dev/ttyUSB0";
type = "id003"; # or "mei", "ccnet"
};
billDispenser = {
enable = false; # Enable for two-way machines
device = "/dev/ttyUSB1";
type = "puloon";
};
camera = {
enable = true;
device = "/dev/video0";
};
};
}
```
## Hardware Support
### Bill Validators
- **ID-003** (JCM) - Most common in Lamassu machines
- **MEI** (Mars Electronics)
- **CCNET** (CashCode)
### Bill Dispensers
- **Puloon** - LCDM series
- **Genmega**
### Cameras
- Any V4L2-compatible USB camera
## File Structure
```
deploy/nixos/
├── flake.nix # Nix flake entry point
├── configuration.nix # Base system configuration
├── lamassu-atm.nix # ATM service module
├── hardware/
│ └── upboard.nix # UP Board hardware config
├── udev/
│ └── 99-lamassu-hardware.rules # Hardware device rules
└── README.md # This file
```
## Troubleshooting
### Check ATM service status
```bash
sudo systemctl status lamassu-atm
sudo journalctl -u lamassu-atm -f
```
### Check hardware detection
```bash
# List serial devices
ls -la /dev/ttyUSB* /dev/ttyACM*
# Check for bill validator symlink
ls -la /dev/bill-validator
# Test camera
v4l2-ctl --list-devices
```
### Manual service control
```bash
sudo systemctl restart lamassu-atm
sudo systemctl stop lamassu-atm
```
### Debug mode
```bash
# Run manually with verbose output
sudo -u lamassu DISPLAY=:0 LOG_LEVEL=debug electron /opt/lamassu-atm
```
## Updating
### Update system
```bash
sudo nixos-rebuild switch --flake /etc/nixos#lamassu-atm
```
### Update ATM application
```bash
# Build new version
cd lamassu-next/apps/machine
pnpm run build
# Copy to ATM
scp -r dist/* lamassu@<atm-ip>:/opt/lamassu-atm/
# Restart service
ssh lamassu@<atm-ip> "sudo systemctl restart lamassu-atm"
```
## Development vs Production
For development/testing, you can use the regtest docker environment:
```bash
cd lamassu-next
./docker/dev.sh up --fund
./docker/dev.sh atm
```
For production, deploy this NixOS configuration and point to your production Nostr relay and Lightning.Pub instance.
## Security Notes
- The default `lamassu` user has `wheel` access for initial setup
- Remove wheel access after configuration: `sudo gpasswd -d lamassu wheel`
- SSH is enabled by default - configure key-based auth and disable password auth
- Firewall blocks all incoming connections by default