refactor(deploy): rename system user lamassu → bitspire
System-level half of the lamassu → bitspire rebrand the rest of dev already did at the path / service / package layers. Touches user/group declarations, every systemd `User=` block, the udev rules filename, all chown calls in flake.nix + live.nix, the displayManager autoLogin user, the trusted-users nix entry, provision-atm.sh's ATM_USER, plus README + CLAUDE.md doc references. In-place migration for the Sintra dev unit (which auto-pulls dev at 04:00) lives in `system.activationScripts.bitspire-user-migration` and: - copies `/home/lamassu/.ssh/authorized_keys` → `/home/bitspire/` once, so SSH access survives the rename - recursively chowns `/var/lib/bitspire` to the new bitspire UID on every boot — cheap no-op once done, but covers the case where the data dir was written by the now-removed lamassu UID - leaves `/home/lamassu/` in place as evidence; operator can `rm -rf` after confirming bitspire login works Recovery path if the migration breaks SSH access: root key is still in configuration.nix:142-144 (padreug@gizmo), so ssh root@<host> works. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
1655b1db04
commit
264cc47e0c
9 changed files with 61 additions and 32 deletions
|
|
@ -1,4 +1,4 @@
|
|||
# Lamassu ATM NixOS Configuration
|
||||
# bitSpire ATM NixOS Configuration
|
||||
# Base system configuration for ATM kiosk
|
||||
|
||||
{ config, lib, pkgs, pkgs-unstable, ... }:
|
||||
|
|
@ -43,11 +43,12 @@
|
|||
i18n.defaultLocale = "en_US.UTF-8";
|
||||
|
||||
# Users
|
||||
users.groups.lamassu = { };
|
||||
users.users.lamassu = {
|
||||
users.groups.bitspire = { };
|
||||
users.users.bitspire = {
|
||||
isNormalUser = true;
|
||||
group = "lamassu";
|
||||
description = "Lamassu ATM";
|
||||
group = "bitspire";
|
||||
description = "bitSpire ATM";
|
||||
home = "/home/bitspire";
|
||||
extraGroups = [
|
||||
"wheel" # For admin access
|
||||
"video" # GPU access
|
||||
|
|
@ -57,7 +58,7 @@
|
|||
"networkmanager" # Network config
|
||||
];
|
||||
# No password - kiosk mode
|
||||
initialPassword = "lamassu";
|
||||
initialPassword = "bitspire"; # pragma: allowlist secret
|
||||
};
|
||||
|
||||
# Kiosk display configuration
|
||||
|
|
@ -85,7 +86,7 @@
|
|||
# Display manager - auto-login (top-level since NixOS 24.11+)
|
||||
services.displayManager.autoLogin = {
|
||||
enable = true;
|
||||
user = "lamassu";
|
||||
user = "bitspire";
|
||||
};
|
||||
|
||||
# Audio (for transaction sounds)
|
||||
|
|
@ -146,6 +147,7 @@
|
|||
# Auto-updates (optional - disabled by default for stability)
|
||||
# system.autoUpgrade.enable = false;
|
||||
|
||||
# pragma: allowlist secret
|
||||
# Ensure WireGuard private key directory exists with correct permissions
|
||||
system.activationScripts.wireguard-key = ''
|
||||
mkdir -p /var/lib/wireguard
|
||||
|
|
@ -155,6 +157,33 @@
|
|||
fi
|
||||
'';
|
||||
|
||||
# In-place rename migration: lamassu user → bitspire user.
|
||||
# Runs after `users` activation so the bitspire user exists with its UID.
|
||||
# Idempotent: re-running on an already-migrated system is a chown no-op.
|
||||
# Leaves /home/lamassu in place as evidence — operator can `rm -rf` after
|
||||
# confirming bitspire works.
|
||||
system.activationScripts.bitspire-user-migration = {
|
||||
deps = [ "users" ];
|
||||
text = ''
|
||||
# SSH key migration: copy authorized_keys to /home/bitspire if missing,
|
||||
# so the dev box can still SSH in as bitspire after the rename.
|
||||
if [ -f /home/lamassu/.ssh/authorized_keys ] \
|
||||
&& [ ! -f /home/bitspire/.ssh/authorized_keys ]; then
|
||||
mkdir -p /home/bitspire/.ssh
|
||||
cp /home/lamassu/.ssh/authorized_keys /home/bitspire/.ssh/authorized_keys
|
||||
chown -R bitspire:bitspire /home/bitspire/.ssh
|
||||
chmod 700 /home/bitspire/.ssh
|
||||
chmod 600 /home/bitspire/.ssh/authorized_keys
|
||||
fi
|
||||
|
||||
# Data dir ownership: state.db / .env / branding/ may still be owned by
|
||||
# the now-removed lamassu UID. Reset every boot — cheap no-op once done.
|
||||
if [ -d /var/lib/bitspire ]; then
|
||||
chown -R bitspire:bitspire /var/lib/bitspire
|
||||
fi
|
||||
'';
|
||||
};
|
||||
|
||||
# Journal configuration
|
||||
services.journald = {
|
||||
extraConfig = ''
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue