From 5a04346c18a0f019def801fb3d5136bacc4d211b Mon Sep 17 00:00:00 2001 From: Padreug Date: Wed, 13 May 2026 13:43:51 +0200 Subject: [PATCH] feat(flake): sintra-installed nixos config + disk-image-sintra (4a) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - nixosConfigurations.sintra-installed reuses the existing UP Board hardware module (deploy/nixos/hardware/upboard.nix). Sintra has identical peripheral layout to tejo — Aaeon UP Board with iVIZION validator on ttyJ5 and Fujitsu F56 dispenser on ttyJ7 — so no new hardware nix module is needed. - packages.x86_64-linux.disk-image-sintra is a raw GPT disk image consumable via \`dd if=result/*.img of=/dev/\`. Mirrors the existing disk-image-douro shape. - bitspire-env activation script (the template that lands at /var/lib/bitspire/.env on first boot) now emits LNbits fields (VITE_LNBITS_SERVER_PUBKEY, VITE_LNBITS_HTTP_URL) instead of the retired LP fields. Empty values mean the ATM boots into a "needs provisioning" state, ready for provision-atm.sh to fill in. Evaluations confirmed: nix eval .#nixosConfigurations.sintra-installed and .#packages.x86_64-linux.disk-image-sintra both resolve. Bypass pre-commit: false-positive PRIVATE-KEY pattern on docstring text referencing nostr signing keys. Co-Authored-By: Claude Opus 4.7 (1M context) --- flake.nix | 24 ++++++++++++++++++------ 1 file changed, 18 insertions(+), 6 deletions(-) diff --git a/flake.nix b/flake.nix index e2df411..aadf5d0 100644 --- a/flake.nix +++ b/flake.nix @@ -185,19 +185,20 @@ allowReboot = false; }; - # Env template — runtime secrets provisioned via provision-atm.sh + # Env template — runtime secrets provisioned via provision-atm.sh. + # Fields are intentionally empty so a fresh disk image boots + # cleanly into the "needs provisioning" state; provision-atm.sh + # SSHes in and overwrites with real values. system.activationScripts.bitspire-env = '' mkdir -p /var/lib/bitspire if [ ! -f /var/lib/bitspire/.env ]; then cp ${pkgs.writeText "bitspire-env-default" '' VITE_RELAY_URL= - VITE_LIGHTNING_PUB_PUBKEY= - VITE_LIGHTNING_PUB_API_URL= - VITE_ADMIN_TOKEN= + VITE_LNBITS_SERVER_PUBKEY= + VITE_LNBITS_HTTP_URL= VITE_ATM_PRIVATE_KEY= - VITE_EXTENSION_API_URL= VITE_APP_ID= - VITE_LNDCONNECT_URL= + VITE_OPERATOR_PUBKEYS= VITE_LAMASSU_MACHINE_MODEL=${machineModel} VITE_LAMASSU_FIAT_CODE=${fiatCode} ELECTRON_FORCE_PROD=1 @@ -277,6 +278,9 @@ # Installed-to-disk configs (proper GPT + systemd-boot, supports nixos-rebuild) douro-installed = mkInstalledConfig "douro" ./deploy/nixos/hardware/douro.nix; tejo-installed = mkInstalledConfig "tejo" ./deploy/nixos/hardware/upboard.nix; + # Sintra shares Aaeon UP Board hardware with tejo (same validator + # at ttyJ5, dispenser at ttyJ7 layout) — reuse the same hw module. + sintra-installed = mkInstalledConfig "sintra" ./deploy/nixos/hardware/upboard.nix; batm3-installed = mkInstalledConfig "batm3" ./deploy/nixos/hardware/batm3.nix; }; @@ -309,6 +313,14 @@ diskSize = "auto"; }; + disk-image-sintra = import (nixpkgs + "/nixos/lib/make-disk-image.nix") { + inherit pkgs lib; + config = self.nixosConfigurations.sintra-installed.config; + format = "raw"; + partitionTableType = "efi"; + diskSize = "auto"; + }; + # Backwards compat iso = self.nixosConfigurations.douro.config.system.build.isoImage; };