refactor(nix): consolidate deploy flake into root flake with pure ISO builds

Move deploy/nixos/flake.nix into the root flake.nix, adding mkAtmApp
for pure Nix builds of the Electron app (no local pnpm needed). Simplify
build-iso.sh to a thin wrapper around `nix build .#iso-<model>`. Add
douro hardware configuration. Streamline live.nix to consume the
Nix-built app package.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Patrick Mulligan 2026-02-27 10:58:43 -05:00
commit 625cebed25
8 changed files with 832 additions and 342 deletions

View file

@ -2,6 +2,7 @@
# Build a bootable NixOS Live USB ISO for testing the ATM Electron app
# on physical hardware.
#
# The build is fully pure — no local pnpm or .env manipulation needed.
# After booting, provision credentials with: bash provision-atm.sh <atm-ip>
#
# Usage: bash build-iso.sh <model>
@ -19,100 +20,26 @@ if [ -z "$MODEL" ]; then
exit 1
fi
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
REPO_ROOT="$(cd "$SCRIPT_DIR/../.." && pwd)"
MACHINE_DIR="$REPO_ROOT/apps/machine"
ENV_FILE="$MACHINE_DIR/.env"
ENV_BACKUP=""
echo "=== Building Lamassu ATM Live USB ISO (model: $MODEL) ==="
# Step 1: Set machine-specific .env for Vite build (VITE_ vars are compile-time)
echo ""
echo "--- Step 1: Configuring .env for $MODEL ---"
if [ -f "$ENV_FILE" ]; then
ENV_BACKUP="$ENV_FILE.build-backup"
cp "$ENV_FILE" "$ENV_BACKUP"
echo "Backed up existing .env"
fi
# Write model-specific env (production endpoints baked into the build)
cat > "$ENV_FILE" << 'ENVEOF'
VITE_RELAY_URL=wss://relay.atm.aiolabs.dev
VITE_LIGHTNING_PUB_PUBKEY=64b0d9b1af689e99e4b8a23ee7b77715b394740a6830bdccf4718a060a53649a
VITE_LIGHTNING_PUB_API_URL=https://lp.atm.aiolabs.dev
VITE_ADMIN_TOKEN=lamassu-dev-admin-token
VITE_ATM_PRIVATE_KEY=f391a2c3fc734f443b0f685688a0441b5fb9805853c0023f570c5a3c6412b136
VITE_EXTENSION_API_URL=https://lp-ext.atm.aiolabs.dev
VITE_APP_ID=6016dadc6c677f131bc82cc0cb780d2b1090b83b8b7d0c972e469010270a4208
VITE_LNDCONNECT_URL=lndconnect://lnd.atm.aiolabs.dev:443?cert=&macaroon=AgEDbG5kAvgBAwoQjLYgcUni_8EKmwpX_vwOWxIBMBoWCgdhZGRyZXNzEgRyZWFkEgV3cml0ZRoTCgRpbmZvEgRyZWFkEgV3cml0ZRoXCghpbnZvaWNlcxIEcmVhZBIFd3JpdGUaIQoIbWFjYXJvb24SCGdlbmVyYXRlEgRyZWFkEgV3cml0ZRoWCgdtZXNzYWdlEgRyZWFkEgV3cml0ZRoXCghvZmZjaGFpbhIEcmVhZBIFd3JpdGUaFgoHb25jaGFpbhIEcmVhZBIFd3JpdGUaFAoFcGVlcnMSBHJlYWQSBXdyaXRlGhgKBnNpZ25lchIIZ2VuZXJhdGUSBHJlYWQAAAYgClsDux9_gPaKUK7PI54y-sTwt5WGmSzrzfKaKamwvK0
ENVEOF
# Append model-specific config
case "$MODEL" in
douro)
cat >> "$ENV_FILE" << 'EOF'
VITE_LAMASSU_MACHINE_MODEL=douro
VITE_LAMASSU_FIAT_CODE=GTQ
EOF
;;
tejo)
cat >> "$ENV_FILE" << 'EOF'
VITE_LAMASSU_MACHINE_MODEL=tejo
VITE_LAMASSU_FIAT_CODE=GTQ
EOF
;;
sintra)
cat >> "$ENV_FILE" << 'EOF'
VITE_LAMASSU_MACHINE_MODEL=sintra
VITE_LAMASSU_FIAT_CODE=EUR
EOF
;;
douro|tejo|sintra) ;;
*)
echo "ERROR: Unknown model '$MODEL'. Use 'douro', 'tejo', or 'sintra'."
# Restore backup
if [ -n "$ENV_BACKUP" ]; then
mv "$ENV_BACKUP" "$ENV_FILE"
fi
exit 1
;;
esac
echo "Set VITE_LAMASSU_MACHINE_MODEL=$MODEL"
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
REPO_ROOT="$(cd "$SCRIPT_DIR/../.." && pwd)"
# Step 2: Build the Electron app (with model-specific .env baked in)
echo "=== Building Lamassu ATM Live USB ISO (model: $MODEL) ==="
echo ""
echo "--- Step 2: Building Electron app ---"
echo "This is a pure Nix build — no local pnpm required."
echo ""
cd "$REPO_ROOT"
pnpm run build --filter=@lamassu/machine
nix build ".#iso-${MODEL}" --show-trace
# Restore original .env
if [ -n "$ENV_BACKUP" ]; then
mv "$ENV_BACKUP" "$ENV_FILE"
echo "Restored original .env"
fi
# Step 3: Verify build outputs exist
echo ""
echo "--- Step 3: Verifying build outputs ---"
if [ ! -d "$MACHINE_DIR/dist" ]; then
echo "ERROR: $MACHINE_DIR/dist not found. Build failed?"
exit 1
fi
if [ ! -d "$MACHINE_DIR/dist-electron" ]; then
echo "ERROR: $MACHINE_DIR/dist-electron not found. Build failed?"
exit 1
fi
echo "OK: dist/ and dist-electron/ present"
# Step 4: Build the NixOS ISO
echo ""
echo "--- Step 4: Building NixOS ISO for $MODEL (this takes a while) ---"
cd "$SCRIPT_DIR"
export MACHINE_DIR="$MACHINE_DIR"
nix build ".#iso-${MODEL}" --impure --show-trace
# Step 5: Print results
# Print results
ISO_PATH=$(ls result/iso/*.iso 2>/dev/null | head -1)
if [ -z "$ISO_PATH" ]; then
echo "ERROR: ISO not found in result/iso/"