refactor(nix): consolidate deploy flake into root flake with pure ISO builds
Move deploy/nixos/flake.nix into the root flake.nix, adding mkAtmApp for pure Nix builds of the Electron app (no local pnpm needed). Simplify build-iso.sh to a thin wrapper around `nix build .#iso-<model>`. Add douro hardware configuration. Streamline live.nix to consume the Nix-built app package. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
parent
f5f00108aa
commit
625cebed25
8 changed files with 832 additions and 342 deletions
267
flake.nix
267
flake.nix
|
|
@ -2,85 +2,226 @@
|
|||
description = "Lamassu Next - Nostr-Native Lightning ATM";
|
||||
|
||||
inputs = {
|
||||
nixpkgs.url = "github:NixOS/nixpkgs/nixpkgs-unstable";
|
||||
# Stable NixOS for the ATM OS base
|
||||
nixpkgs.url = "github:NixOS/nixpkgs/nixos-24.05";
|
||||
|
||||
# Unstable for Electron, Node.js, pnpm (latest versions)
|
||||
nixpkgs-unstable.url = "github:NixOS/nixpkgs/nixpkgs-unstable";
|
||||
|
||||
flake-utils.url = "github:numtide/flake-utils";
|
||||
|
||||
rust-overlay = {
|
||||
url = "github:oxalica/rust-overlay";
|
||||
inputs.nixpkgs.follows = "nixpkgs";
|
||||
inputs.nixpkgs.follows = "nixpkgs-unstable";
|
||||
};
|
||||
|
||||
devenv = {
|
||||
url = "github:cachix/devenv";
|
||||
inputs.nixpkgs.follows = "nixpkgs";
|
||||
inputs.nixpkgs.follows = "nixpkgs-unstable";
|
||||
};
|
||||
};
|
||||
|
||||
outputs = { self, nixpkgs, flake-utils, rust-overlay, devenv }:
|
||||
flake-utils.lib.eachDefaultSystem (system:
|
||||
let
|
||||
overlays = [ (import rust-overlay) ];
|
||||
pkgs = import nixpkgs { inherit system overlays; };
|
||||
outputs = { self, nixpkgs, nixpkgs-unstable, flake-utils, rust-overlay, devenv }:
|
||||
let
|
||||
system = "x86_64-linux";
|
||||
|
||||
rustToolchain = pkgs.rust-bin.stable.latest.default.override {
|
||||
extensions = [ "rust-src" "rust-analyzer" ];
|
||||
targets = [ "wasm32-unknown-unknown" ];
|
||||
pkgs = import nixpkgs {
|
||||
inherit system;
|
||||
config.allowUnfree = true;
|
||||
};
|
||||
|
||||
pkgs-unstable = import nixpkgs-unstable {
|
||||
inherit system;
|
||||
config.allowUnfree = true;
|
||||
overlays = [ (import rust-overlay) ];
|
||||
};
|
||||
|
||||
# Pure ATM app builder (no --impure needed)
|
||||
mkAtmApp = import ./nix/mkAtmApp.nix {
|
||||
inherit pkgs pkgs-unstable;
|
||||
src = self;
|
||||
};
|
||||
|
||||
# Fiat code per machine model
|
||||
fiatCodeForModel = {
|
||||
douro = "GTQ";
|
||||
tejo = "GTQ";
|
||||
sintra = "EUR";
|
||||
};
|
||||
|
||||
lib = nixpkgs.lib;
|
||||
|
||||
# Helper to create a live USB NixOS config for a specific machine model
|
||||
mkLiveConfig = machineModel:
|
||||
let
|
||||
atm-app = mkAtmApp {
|
||||
model = machineModel;
|
||||
fiatCode = fiatCodeForModel.${machineModel} or "USD";
|
||||
};
|
||||
in
|
||||
nixpkgs.lib.nixosSystem {
|
||||
inherit system;
|
||||
specialArgs = {
|
||||
inherit pkgs-unstable nixpkgs machineModel atm-app;
|
||||
};
|
||||
modules = [ ./deploy/nixos/live.nix ];
|
||||
};
|
||||
|
||||
# Helper to create a disk-installed NixOS config for a specific machine model.
|
||||
# Unlike live configs (squashfs + tmpfs), installed configs use ext4 root
|
||||
# and support `nixos-rebuild switch` for in-place updates.
|
||||
mkInstalledConfig = machineModel: hardwareModule:
|
||||
let
|
||||
atm-app = mkAtmApp {
|
||||
model = machineModel;
|
||||
fiatCode = fiatCodeForModel.${machineModel} or "USD";
|
||||
};
|
||||
fiatCode = fiatCodeForModel.${machineModel} or "USD";
|
||||
in
|
||||
nixpkgs.lib.nixosSystem {
|
||||
inherit system;
|
||||
specialArgs = {
|
||||
inherit pkgs-unstable atm-app;
|
||||
};
|
||||
modules = [
|
||||
hardwareModule
|
||||
./deploy/nixos/configuration.nix
|
||||
./deploy/nixos/lamassu-atm.nix
|
||||
({ config, lib, pkgs, ... }: {
|
||||
services.lamassu-atm = {
|
||||
enable = true;
|
||||
appDir = "${atm-app}";
|
||||
};
|
||||
|
||||
# Electron sandbox needs unprivileged user namespaces
|
||||
boot.kernel.sysctl."kernel.unprivileged_userns_clone" = 1;
|
||||
|
||||
# Env template — runtime secrets provisioned via provision-atm.sh
|
||||
system.activationScripts.lamassu-env = ''
|
||||
mkdir -p /var/lib/lamassu-atm
|
||||
if [ ! -f /var/lib/lamassu-atm/.env ]; then
|
||||
cp ${pkgs.writeText "lamassu-atm-env-default" ''
|
||||
VITE_RELAY_URL=
|
||||
VITE_LIGHTNING_PUB_PUBKEY=
|
||||
VITE_LIGHTNING_PUB_API_URL=
|
||||
VITE_ADMIN_TOKEN=
|
||||
VITE_ATM_PRIVATE_KEY=
|
||||
VITE_EXTENSION_API_URL=
|
||||
VITE_APP_ID=
|
||||
VITE_LNDCONNECT_URL=
|
||||
VITE_LAMASSU_MACHINE_MODEL=${machineModel}
|
||||
VITE_LAMASSU_FIAT_CODE=${fiatCode}
|
||||
ELECTRON_FORCE_PROD=1
|
||||
DISPLAY=:0
|
||||
''} /var/lib/lamassu-atm/.env
|
||||
chmod 600 /var/lib/lamassu-atm/.env
|
||||
chown lamassu:lamassu /var/lib/lamassu-atm/.env
|
||||
fi
|
||||
'';
|
||||
|
||||
# Override systemd service for Electron runtime
|
||||
systemd.services.lamassu-atm = {
|
||||
serviceConfig = {
|
||||
EnvironmentFile = lib.mkForce "/var/lib/lamassu-atm/.env";
|
||||
Environment = "LD_LIBRARY_PATH=${pkgs.stdenv.cc.cc.lib}/lib";
|
||||
ExecStart = lib.mkForce "${pkgs-unstable.electron}/bin/electron --no-sandbox --disable-gpu-sandbox --disable-gpu --enable-logging ${atm-app}";
|
||||
NoNewPrivileges = lib.mkForce false;
|
||||
ProtectSystem = lib.mkForce false;
|
||||
ProtectHome = lib.mkForce false;
|
||||
PrivateTmp = lib.mkForce false;
|
||||
DevicePolicy = lib.mkForce "auto";
|
||||
DeviceAllow = lib.mkForce [ "char-* rw" ];
|
||||
};
|
||||
};
|
||||
|
||||
# Reset eDP display output after X starts
|
||||
systemd.services.display-reset = {
|
||||
description = "Reset eDP display output";
|
||||
after = [ "display-manager.service" ];
|
||||
requires = [ "display-manager.service" ];
|
||||
wantedBy = [ "graphical.target" ];
|
||||
before = [ "lamassu-atm.service" ];
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
User = "lamassu";
|
||||
Environment = "DISPLAY=:0";
|
||||
ExecStart = "${pkgs.bash}/bin/bash -c '${pkgs.xorg.xrandr}/bin/xrandr --output eDP-1 --off; sleep 1; ${pkgs.xorg.xrandr}/bin/xrandr --output eDP-1 --auto'";
|
||||
};
|
||||
};
|
||||
|
||||
# SSH with password for initial provisioning
|
||||
services.openssh.settings.PasswordAuthentication = lib.mkForce true;
|
||||
})
|
||||
];
|
||||
};
|
||||
in
|
||||
{
|
||||
# ── NixOS Configurations (top-level, not per-system) ──────────
|
||||
|
||||
nixosConfigurations = {
|
||||
# Ergonomic names: `nixos-rebuild switch --flake .#douro`
|
||||
douro = mkLiveConfig "douro";
|
||||
tejo = mkLiveConfig "tejo";
|
||||
sintra = mkLiveConfig "sintra";
|
||||
|
||||
# Backwards compat
|
||||
lamassu-live-douro = mkLiveConfig "douro";
|
||||
lamassu-live-tejo = mkLiveConfig "tejo";
|
||||
lamassu-live-sintra = mkLiveConfig "sintra";
|
||||
lamassu-live = mkLiveConfig "douro";
|
||||
|
||||
# Installed-to-disk configs (proper GPT + systemd-boot, supports nixos-rebuild)
|
||||
douro-installed = mkInstalledConfig "douro" ./deploy/nixos/hardware/douro.nix;
|
||||
|
||||
# UP Board (tejo) installed config
|
||||
lamassu-atm = mkInstalledConfig "tejo" ./deploy/nixos/hardware/upboard.nix;
|
||||
};
|
||||
|
||||
# ── Standalone NixOS module ───────────────────────────────────
|
||||
|
||||
nixosModules.default = import ./deploy/nixos/lamassu-atm.nix;
|
||||
nixosModules.lamassu-atm = import ./deploy/nixos/lamassu-atm.nix;
|
||||
|
||||
# ── Packages (x86_64-linux only for ATM hardware) ─────────────
|
||||
|
||||
packages.${system} = {
|
||||
# Pure ATM app derivations
|
||||
atm-app-douro = mkAtmApp { model = "douro"; fiatCode = "GTQ"; };
|
||||
atm-app-tejo = mkAtmApp { model = "tejo"; fiatCode = "GTQ"; };
|
||||
atm-app-sintra = mkAtmApp { model = "sintra"; fiatCode = "EUR"; };
|
||||
|
||||
# ISO images
|
||||
iso-douro = self.nixosConfigurations.douro.config.system.build.isoImage;
|
||||
iso-tejo = self.nixosConfigurations.tejo.config.system.build.isoImage;
|
||||
iso-sintra = self.nixosConfigurations.sintra.config.system.build.isoImage;
|
||||
|
||||
# Raw disk images (dd-able to mSATA/eMMC, proper GPT + ESP)
|
||||
disk-image-douro = import (nixpkgs + "/nixos/lib/make-disk-image.nix") {
|
||||
inherit pkgs lib;
|
||||
config = self.nixosConfigurations.douro-installed.config;
|
||||
format = "raw";
|
||||
partitionTableType = "efi";
|
||||
diskSize = "auto";
|
||||
};
|
||||
|
||||
# Backwards compat
|
||||
iso = self.nixosConfigurations.douro.config.system.build.isoImage;
|
||||
};
|
||||
}
|
||||
//
|
||||
# ── Dev shells (per-system via flake-utils) ───────────────────
|
||||
flake-utils.lib.eachDefaultSystem (sys:
|
||||
let
|
||||
dev-pkgs = import nixpkgs-unstable {
|
||||
system = sys;
|
||||
overlays = [ (import rust-overlay) ];
|
||||
};
|
||||
in
|
||||
{
|
||||
# Development shell via devenv
|
||||
devShells.default = devenv.lib.mkShell {
|
||||
inherit pkgs;
|
||||
pkgs = dev-pkgs;
|
||||
modules = [ ./devenv.nix ];
|
||||
};
|
||||
|
||||
# Packages
|
||||
packages = {
|
||||
# HAL Rust crate
|
||||
hal = pkgs.rustPlatform.buildRustPackage {
|
||||
pname = "lamassu-hal";
|
||||
version = "0.1.0";
|
||||
src = ./packages/hal;
|
||||
cargoLock.lockFile = ./packages/hal/Cargo.lock;
|
||||
|
||||
nativeBuildInputs = with pkgs; [
|
||||
pkg-config
|
||||
];
|
||||
|
||||
buildInputs = with pkgs; [
|
||||
openssl
|
||||
libudev-zero
|
||||
];
|
||||
};
|
||||
|
||||
# Full application (TODO)
|
||||
default = self.packages.${system}.hal;
|
||||
};
|
||||
|
||||
# NixOS module for deployment
|
||||
nixosModules.default = { config, lib, pkgs, ... }: {
|
||||
options.services.lamassu-atm = {
|
||||
enable = lib.mkEnableOption "Lamassu ATM service";
|
||||
|
||||
relayUrl = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
description = "Nostr relay URL";
|
||||
};
|
||||
|
||||
lightningPubUrl = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
description = "Lightning.Pub connection URL";
|
||||
};
|
||||
|
||||
identityPath = lib.mkOption {
|
||||
type = lib.types.path;
|
||||
default = "/etc/lamassu/machine.nsec";
|
||||
description = "Path to machine identity (nsec)";
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf config.services.lamassu-atm.enable {
|
||||
# TODO: systemd service, firewall rules, etc.
|
||||
};
|
||||
};
|
||||
}
|
||||
);
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue