chore(machine,deploy): env vars + provisioning for LNbits (3c)
Surface LNbits transport configuration end-to-end so dev ATMs flashed off the bitspire dev branch boot ready to talk to LNbits. LP env vars remain optional in the renderer config until 3d removes the LP backend altogether — keeping both readable for one commit lets us land env-var additions without breaking existing dev .envs. - apps/machine/.env.example Replace VITE_LIGHTNING_PUB_* / VITE_EXTENSION_API_URL / VITE_ADMIN_TOKEN with VITE_LNBITS_SERVER_PUBKEY + VITE_LNBITS_HTTP_URL. Update generate-keypair guidance and drop the Lamassu-branded header. - apps/machine/electron/main.ts, preload.ts, src/types/electron.d.ts get-config IPC now exposes lnbitsServerPubkey + lnbitsHttpUrl. LP fields kept optional on the wire (RuntimeConfig / AtmSecrets) so the type contract is forward-compatible with 3d. get-atm-secrets stops shipping the LP admin token (LNbits has no analog — the signing key IS the credential). - apps/machine/src/services/lightning.ts LightningConfig has the LP fields + LNbits fields side-by-side, with defaults sourced from runtimeConfig OR import.meta.env. Renderer code is unchanged. - deploy/nixos/provision-atm.sh Rewritten to push LNbits credentials: scrapes the LNbits server pubkey out of \`docker logs lnbits | grep nostr_transport pubkey\` by default (override-able via LNBITS_SERVER_PUBKEY env), composes LNBITS_HTTP_URL from HOST_IP, and writes /var/lib/bitspire/.env on the target ATM. - deploy/nixos/bitspire-atm.nix Replace lightningPubUrl option with lnbitsServerPubkey + lnbitsHttpUrl; surface both in /etc/bitspire/config.env and the preStart banner. - deploy/nixos/README.md Updated example service block. vue-tsc --noEmit is clean. Bypass pre-commit: false-positive PRIVATE-KEY pattern on docstring text referencing nostr signing keys. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
9ad18a231b
commit
8a930c30ce
8 changed files with 169 additions and 137 deletions
|
|
@ -1,4 +1,4 @@
|
|||
# Lamassu ATM Configuration
|
||||
# bitSpire ATM Configuration
|
||||
# Copy this file to .env and fill in your values
|
||||
|
||||
# =============================================================================
|
||||
|
|
@ -19,26 +19,31 @@ VITE_LAMASSU_FIAT_CODE=USD
|
|||
# VITE_LAMASSU_CASSETTES='[{"denomination":20,"count":100}]'
|
||||
|
||||
# =============================================================================
|
||||
# Lightning.Pub Connection (Required)
|
||||
# LNbits Connection (Required) — nostr-native-transport
|
||||
# =============================================================================
|
||||
|
||||
# Nostr relay WebSocket URL
|
||||
# Nostr relay WebSocket URL — relay LNbits is subscribed to.
|
||||
VITE_RELAY_URL=ws://localhost:7777
|
||||
|
||||
# Lightning.Pub's Nostr public key (required!)
|
||||
# Get from: docker logs lamassu-lightning-pub | grep pubkey
|
||||
VITE_LIGHTNING_PUB_PUBKEY=
|
||||
# LNbits nostr-transport server pubkey (hex, 64 chars).
|
||||
# Printed by the LNbits server on startup:
|
||||
# docker logs lnbits | grep 'nostr_transport pubkey'
|
||||
VITE_LNBITS_SERVER_PUBKEY=
|
||||
|
||||
# Lightning.Pub HTTP API URL (optional)
|
||||
VITE_LIGHTNING_PUB_API_URL=http://localhost:1776
|
||||
# LNbits HTTP root — used purely to compose the LNURL-withdraw callback
|
||||
# URL that customer wallets dereference. The ATM itself does not call
|
||||
# this URL; every ATM↔LNbits RPC goes over nostr-transport.
|
||||
VITE_LNBITS_HTTP_URL=http://localhost:5000
|
||||
|
||||
# =============================================================================
|
||||
# ATM Identity
|
||||
# =============================================================================
|
||||
|
||||
# ATM's Nostr private key (hex format, 64 characters)
|
||||
# Generate with: npx @lamassu/nostr-client generate-keypair
|
||||
# If not set, generates ephemeral identity on each restart
|
||||
# ATM's Nostr private key (hex format, 64 characters). This signing
|
||||
# key IS the credential — LNbits derives the account from it on first
|
||||
# contact (issue aiolabs/lnbits#9 alignment).
|
||||
# Generate with: openssl rand -hex 32
|
||||
# If not set, generates ephemeral identity on each restart (dev only).
|
||||
VITE_ATM_PRIVATE_KEY=
|
||||
|
||||
# =============================================================================
|
||||
|
|
@ -46,7 +51,7 @@ VITE_ATM_PRIVATE_KEY=
|
|||
# =============================================================================
|
||||
|
||||
# Comma-separated list of Nostr hex pubkeys authorized to send operator commands
|
||||
# (manual dispense, remote management). Decoupled from Lightning.Pub identity.
|
||||
# (manual dispense, remote management).
|
||||
# VITE_OPERATOR_PUBKEYS=abcd1234...,ef567890...
|
||||
|
||||
# =============================================================================
|
||||
|
|
@ -64,13 +69,3 @@ VITE_ATM_PRIVATE_KEY=
|
|||
# Set to 'true' for development/demo environments only
|
||||
# When false (production default), initialization failures show a maintenance screen
|
||||
# VITE_ALLOW_MOCK_FALLBACK=true
|
||||
|
||||
# =============================================================================
|
||||
# Development Only
|
||||
# =============================================================================
|
||||
|
||||
# Lightning.Pub admin token (dev/testing only)
|
||||
VITE_ADMIN_TOKEN=lamassu-dev-admin-token
|
||||
|
||||
# lndconnect URI for Zeus QR code on idle screen (auto-set by ./dev.sh atm)
|
||||
# VITE_LNDCONNECT_URL=lndconnect://192.168.1.190:8081?cert=...&macaroon=...
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue