refactor(deploy): rename system user lamassu → bitspire
System-level half of the lamassu → bitspire rebrand the rest of dev already did at the path / service / package layers. Touches user/group declarations, every systemd `User=` block, the udev rules filename, all chown calls in flake.nix + live.nix, the displayManager autoLogin user, the trusted-users nix entry, provision-atm.sh's ATM_USER, plus README + CLAUDE.md doc references. In-place migration for the Sintra dev unit (which auto-pulls dev at 04:00) lives in `system.activationScripts.bitspire-user-migration` and: - copies `/home/lamassu/.ssh/authorized_keys` → `/home/bitspire/` once, so SSH access survives the rename - recursively chowns `/var/lib/bitspire` to the new bitspire UID on every boot — cheap no-op once done, but covers the case where the data dir was written by the now-removed lamassu UID - leaves `/home/lamassu/` in place as evidence; operator can `rm -rf` after confirming bitspire login works Recovery path if the migration breaks SSH access: root key is still in configuration.nix:142-144 (padreug@gizmo), so ssh root@<host> works. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
1655b1db04
commit
264cc47e0c
9 changed files with 61 additions and 32 deletions
|
|
@ -117,8 +117,8 @@ in
|
|||
config = mkIf cfg.enable {
|
||||
# Create data directory
|
||||
systemd.tmpfiles.rules = [
|
||||
"d ${cfg.dataDir} 0750 lamassu lamassu -"
|
||||
"d ${cfg.dataDir}/logs 0750 lamassu lamassu -"
|
||||
"d ${cfg.dataDir} 0750 bitspire bitspire -"
|
||||
"d ${cfg.dataDir}/logs 0750 bitspire bitspire -"
|
||||
];
|
||||
|
||||
# Environment file for ATM configuration
|
||||
|
|
@ -156,8 +156,8 @@ in
|
|||
|
||||
serviceConfig = {
|
||||
Type = "simple";
|
||||
User = "lamassu";
|
||||
Group = "lamassu";
|
||||
User = "bitspire";
|
||||
Group = "bitspire";
|
||||
WorkingDirectory = cfg.appDir;
|
||||
|
||||
# Environment
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue