fix(deploy): relay + LNbits pubkey are seed-provided, not env-pinned (#70)

The bitspire-env activation seeded VITE_RELAY_URL from the relayUrl option
(default wss://relay.aiolabs.dev). Because env wins over the pairing seed, every
fresh machine pinned itself to that relay — which is dead — so a scanned seed's
relay was ignored ("No connected relays"; hit live on the aio-demo USB). Default
relayUrl to "" so both relay and server pubkey come from the seed; a non-empty
option now pins a machine (an explicit override) rather than being the default.
Descriptions updated to match.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Padreug 2026-07-02 15:38:14 +02:00 • committed by padreug
commit 7896c122da
2 changed files with 22 additions and 19 deletions

View file

@ -191,10 +191,11 @@
# boots cleanly into the "needs provisioning" state; provision-
# atm.sh SSHes in and overwrites with real values.
#
# VITE_RELAY_URL seeds from `config.services.bitspire.relayUrl`
# so the NixOS module's `relayUrl` option becomes the default
# without losing the operator's ability to override via .env
# (edit the file or re-run provision-atm.sh).
# VITE_RELAY_URL + VITE_LNBITS_SERVER_PUBKEY seed EMPTY by default
# (relayUrl defaults to ""), so the pairing seed drives the relay
# + server pubkey (aiolabs/bitspire#70). A non-empty `relayUrl`
# option pins a machine to a specific relay (seeded here, wins over
# the seed via env-first precedence) — otherwise leave it blank.
system.activationScripts.bitspire-env = ''
mkdir -p /var/lib/bitspire
if [ ! -f /var/lib/bitspire/.env ]; then