feat(deploy): provision VITE_SPIRE_SEED for bunker pairing (Phase E)

provision-atm.sh now writes VITE_SPIRE_SEED (the spire-seed:v1: pairing seed
from spirekeeper) as the production identity, validating the scheme prefix;
the generated nsec path is kept only as a dev fallback when SPIRE_SEED is
unset. Relay default moved to the LNbits bundled nostrrelay
(ws://$HOST_IP:5001/nostrrelay/test). .env templates (live.nix + the flake's
installed-default) swap VITE_ATM_PRIVATE_KEY → VITE_SPIRE_SEED and drop the
dead LP-era vars. README notes state.db now also holds the bunker binding
(keep it or re-pair).

Part of Phase E, aiolabs/bitspire#52. Unblocks the Sintra live-pairing smoke.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Padreug 2026-06-21 09:56:00 +02:00
commit 8a02d72bd1
4 changed files with 39 additions and 21 deletions

View file

@ -11,9 +11,15 @@
# LNBITS_HTTP_URL Origin LNbits is reachable at over HTTP, used only
# to compose the LNURL-withdraw callback URL that
# customer wallets dereference. Default: http://10.0.2.2:5000
# RELAY_URL Nostr relay LNbits subscribes on. Default uses host gateway.
# ATM_PRIVATE_KEY 32-byte hex key, ATM's nostr identity. If unset, a
# fresh key is generated and saved in the .env.
# RELAY_URL Nostr relay LNbits + the bunker subscribe on.
# Default: ws://$HOST_IP:5001/nostrrelay/test (LNbits
# bundled nostrrelay). Override for a separate relay.
# SPIRE_SEED The spire pairing seed (`spire-seed:v1:<base64url>`)
# minted by spirekeeper. THIS is the production
# identity under the NIP-46 bunker (aiolabs/bitspire#52).
# ATM_PRIVATE_KEY DEV-ONLY 32-byte hex nsec fallback, used only when
# SPIRE_SEED is unset (no bunker). Generated if unset
# AND no SPIRE_SEED is provided.
#
# Usage:
# bash provision-atm.sh # defaults: SSH to localhost:2222 (QEMU)
@ -74,14 +80,28 @@ echo "LNbits server pubkey: ${LNBITS_SERVER_PUBKEY:0:16}..."
# Step 3: Pin LNbits HTTP origin.
LNBITS_HTTP_URL="${LNBITS_HTTP_URL:-http://$HOST_IP:5000}"
# Step 4: Relay URL.
RELAY_URL="${RELAY_URL:-ws://$HOST_IP:7777}"
# Step 4: Relay URL. Defaults to the LNbits bundled nostrrelay.
RELAY_URL="${RELAY_URL:-ws://$HOST_IP:5001/nostrrelay/test}"
# Step 5: ATM identity. Generate if unset.
if [ -z "${ATM_PRIVATE_KEY:-}" ]; then
ATM_PRIVATE_KEY=$(openssl rand -hex 32)
# Step 5: Signing identity. Prefer the spire pairing seed (bunker). Only fall
# back to a generated dev nsec when no seed is supplied.
if [ -n "${SPIRE_SEED:-}" ]; then
echo ""
echo "--- Generated fresh ATM_PRIVATE_KEY (save this if you want it persisted) ---"
echo "--- Using spire pairing seed (bunker-backed identity) ---"
case "$SPIRE_SEED" in
spire-seed:v1:*) : ;;
*) echo "ERROR: SPIRE_SEED must start with 'spire-seed:v1:'"; exit 1 ;;
esac
IDENTITY_LINES="# Spire pairing seed — bunker-backed identity (aiolabs/bitspire#52)
VITE_SPIRE_SEED=$SPIRE_SEED"
else
if [ -z "${ATM_PRIVATE_KEY:-}" ]; then
ATM_PRIVATE_KEY=$(openssl rand -hex 32)
echo ""
echo "--- No SPIRE_SEED; generated a DEV-ONLY ATM_PRIVATE_KEY (no bunker) ---"
fi
IDENTITY_LINES="# DEV-ONLY local nsec (no bunker pairing) # pragma: allowlist secret
VITE_ATM_PRIVATE_KEY=$ATM_PRIVATE_KEY"
fi
# Step 6: Write .env to the ATM via SSH.
@ -95,8 +115,7 @@ VITE_RELAY_URL=$RELAY_URL
VITE_LNBITS_SERVER_PUBKEY=$LNBITS_SERVER_PUBKEY
VITE_LNBITS_HTTP_URL=$LNBITS_HTTP_URL
# ATM identity (signing key IS the credential under nostr-transport)
VITE_ATM_PRIVATE_KEY=$ATM_PRIVATE_KEY
$IDENTITY_LINES
# Machine configuration
VITE_LAMASSU_MACHINE_MODEL=$MODEL