feat(deploy): provision VITE_SPIRE_SEED for bunker pairing (Phase E)

provision-atm.sh now writes VITE_SPIRE_SEED (the spire-seed:v1: pairing seed
from spirekeeper) as the production identity, validating the scheme prefix;
the generated nsec path is kept only as a dev fallback when SPIRE_SEED is
unset. Relay default moved to the LNbits bundled nostrrelay
(ws://$HOST_IP:5001/nostrrelay/test). .env templates (live.nix + the flake's
installed-default) swap VITE_ATM_PRIVATE_KEY → VITE_SPIRE_SEED and drop the
dead LP-era vars. README notes state.db now also holds the bunker binding
(keep it or re-pair).

Part of Phase E, aiolabs/bitspire#52. Unblocks the Sintra live-pairing smoke.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Padreug 2026-06-21 09:56:00 +02:00
commit 8a02d72bd1
4 changed files with 39 additions and 21 deletions

View file

@ -22,16 +22,15 @@ let
}.${machineModel} or "USD";
# .env template — runtime secrets are provisioned later via provision-atm.sh.
# Only non-secret defaults and display vars go here.
# Only non-secret defaults and display vars go here. VITE_SPIRE_SEED (the
# NIP-46 bunker pairing seed) is written at provision time; the dev-only
# VITE_ATM_PRIVATE_KEY fallback is omitted here on purpose.
envTemplate = pkgs.writeText "bitspire-env" ''
VITE_RELAY_URL=
VITE_LIGHTNING_PUB_PUBKEY=
VITE_LIGHTNING_PUB_API_URL=
VITE_ADMIN_TOKEN=
VITE_ATM_PRIVATE_KEY=
VITE_EXTENSION_API_URL=
VITE_LNBITS_SERVER_PUBKEY=
VITE_SPIRE_SEED=
VITE_APP_ID=
VITE_LNDCONNECT_URL=
VITE_OPERATOR_PUBKEYS=
VITE_LAMASSU_MACHINE_MODEL=${machineModel}
VITE_LAMASSU_FIAT_CODE=${fiatCodeForModel}
ELECTRON_FORCE_PROD=1