feat(deploy): provision VITE_SPIRE_SEED for bunker pairing (Phase E)
provision-atm.sh now writes VITE_SPIRE_SEED (the spire-seed:v1: pairing seed from spirekeeper) as the production identity, validating the scheme prefix; the generated nsec path is kept only as a dev fallback when SPIRE_SEED is unset. Relay default moved to the LNbits bundled nostrrelay (ws://$HOST_IP:5001/nostrrelay/test). .env templates (live.nix + the flake's installed-default) swap VITE_ATM_PRIVATE_KEY → VITE_SPIRE_SEED and drop the dead LP-era vars. README notes state.db now also holds the bunker binding (keep it or re-pair). Part of Phase E, aiolabs/bitspire#52. Unblocks the Sintra live-pairing smoke. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
904dae5a17
commit
8a02d72bd1
4 changed files with 39 additions and 21 deletions
|
|
@ -22,16 +22,15 @@ let
|
|||
}.${machineModel} or "USD";
|
||||
|
||||
# .env template — runtime secrets are provisioned later via provision-atm.sh.
|
||||
# Only non-secret defaults and display vars go here.
|
||||
# Only non-secret defaults and display vars go here. VITE_SPIRE_SEED (the
|
||||
# NIP-46 bunker pairing seed) is written at provision time; the dev-only
|
||||
# VITE_ATM_PRIVATE_KEY fallback is omitted here on purpose.
|
||||
envTemplate = pkgs.writeText "bitspire-env" ''
|
||||
VITE_RELAY_URL=
|
||||
VITE_LIGHTNING_PUB_PUBKEY=
|
||||
VITE_LIGHTNING_PUB_API_URL=
|
||||
VITE_ADMIN_TOKEN=
|
||||
VITE_ATM_PRIVATE_KEY=
|
||||
VITE_EXTENSION_API_URL=
|
||||
VITE_LNBITS_SERVER_PUBKEY=
|
||||
VITE_SPIRE_SEED=
|
||||
VITE_APP_ID=
|
||||
VITE_LNDCONNECT_URL=
|
||||
VITE_OPERATOR_PUBKEYS=
|
||||
VITE_LAMASSU_MACHINE_MODEL=${machineModel}
|
||||
VITE_LAMASSU_FIAT_CODE=${fiatCodeForModel}
|
||||
ELECTRON_FORCE_PROD=1
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue