feat(deploy): add NixOS live USB ISO for ATM hardware testing

Add NixOS configuration to build a bootable live USB ISO that runs the
ATM Electron app in kiosk mode on physical hardware (UpBoard). The ISO
boots from squashfs, auto-starts X11/openbox, and launches Electron in
production mode.

Key changes:
- deploy/nixos/live.nix: Live USB module (squashfs+tmpfs, no disk install)
- deploy/nixos/flake.nix: Nix flake with ISO build output
- deploy/nixos/provision-atm.sh: Auto-provision LP credentials via API
- deploy/nixos/build-iso.sh: End-to-end build workflow script
- apps/machine: Fix Electron production mode (ELECTRON_FORCE_PROD),
  Vue Router hash mode for file:// protocol, relative asset paths

Build: cd deploy/nixos && bash build-iso.sh
Test:  qemu-system-x86_64 -enable-kvm -m 2G -cdrom result/iso/*.iso

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Patrick Mulligan 2026-02-18 20:11:23 -05:00
commit 19d43c2939
13 changed files with 1203 additions and 3 deletions

View file

@ -0,0 +1,107 @@
# UP Board Hardware Configuration
# Supports UP Board, UP Squared, and similar Intel Atom/Celeron boards
# commonly used in Lamassu ATM machines
{ config, lib, pkgs, ... }:
{
# Boot configuration for UP Board
# UP Board uses 64-bit CPU but some models have 32-bit UEFI
boot = {
loader = {
# Use systemd-boot for UEFI systems
systemd-boot.enable = true;
efi.canTouchEfiVariables = true;
# Timeout for boot menu (useful for remote debugging)
timeout = 3;
};
# Kernel modules needed for UP Board hardware
initrd.availableKernelModules = [
"xhci_pci" # USB 3.0
"ahci" # SATA
"usb_storage" # USB mass storage
"sd_mod" # SCSI disk
"sdhci_pci" # SD card (eMMC)
"i915" # Intel graphics
];
kernelModules = [
"kvm-intel" # Virtualization (if needed)
"i2c-dev" # I2C for hardware control
"spi-dev" # SPI for hardware control
];
# UP Board specific kernel parameters
kernelParams = [
# Intel graphics
"i915.enable_psr=0"
# Serial console for debugging (UP Board has debug UART)
"console=ttyS4,115200n8"
"console=tty0"
# Quiet boot for kiosk mode
"quiet"
"splash"
];
};
# Filesystem configuration
# Adjust these to match your actual disk layout
fileSystems."/" = {
device = "/dev/disk/by-label/nixos";
fsType = "ext4";
};
fileSystems."/boot" = {
device = "/dev/disk/by-label/boot";
fsType = "vfat";
};
# Hardware-specific packages
hardware = {
# Intel GPU support
graphics = {
enable = true;
extraPackages = with pkgs; [
intel-media-driver # VAAPI driver for newer Intel
vaapiIntel # VAAPI driver (legacy)
vaapiVdpau
libvdpau-va-gl
];
};
# Enable firmware for Intel hardware
enableRedistributableFirmware = true;
# CPU microcode updates
cpu.intel.updateMicrocode = true;
};
# Power management
powerManagement = {
enable = true;
cpuFreqGovernor = "performance"; # ATM should be responsive
};
# Disable suspend/hibernate for kiosk
systemd.targets = {
sleep.enable = false;
suspend.enable = false;
hibernate.enable = false;
hybrid-sleep.enable = false;
};
# Serial port access for bill validator/dispenser
# UP Board GPIO/UART pins
services.udev.extraRules = ''
# UP Board serial ports
KERNEL=="ttyS[0-9]*", MODE="0666"
# USB serial adapters (common for bill validators)
KERNEL=="ttyUSB[0-9]*", MODE="0666"
KERNEL=="ttyACM[0-9]*", MODE="0666"
'';
}