docs: relay + LNbits pubkey are seed-provided, not required (#70)
Env table (CLAUDE.md), .env.example, and the deploy README still framed
VITE_RELAY_URL / VITE_LNBITS_SERVER_PUBKEY as required/provisioned; they now come
from the pairing seed and are env overrides only. Also refresh the slimmed seed
shape, the relayUrl/pubkey module examples ("" not wss://relay.aiolabs.dev), and
the stale lamassu-next autoUpgrade flake URL (→ aiolabs/bitspire).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
parent
f003483599
commit
a8b8b707be
3 changed files with 13 additions and 9 deletions
|
|
@ -82,9 +82,9 @@ Renderer reads (Electron IPC or Vite `import.meta.env`):
|
||||||
|
|
||||||
| Var | Required | Notes |
|
| Var | Required | Notes |
|
||||||
|---|---|---|
|
|---|---|---|
|
||||||
| `VITE_RELAY_URL` | yes | `ws://...` of the relay both ATM and LNbits subscribe to. Dev: `ws://localhost:5001/nostrrelay/test` (LNbits's bundled `nostrrelay` extension — no separate strfry container) |
|
| `VITE_RELAY_URL` | no (seed-provided) | Relay both ATM and LNbits subscribe to. **Comes from the pairing seed** (aiolabs/bitspire#70); set this only as an override — it WINS over the seed via env-first precedence. Dev override: `ws://localhost:5001/nostrrelay/test` (LNbits's bundled `nostrrelay` extension — no separate strfry container) |
|
||||||
| `VITE_LNBITS_SERVER_PUBKEY` | yes | 64-char hex pubkey LNbits prints on startup (`docker logs lnbits \| grep 'Public key (share this)'`) |
|
| `VITE_LNBITS_SERVER_PUBKEY` | no (seed-provided) | 64-char hex transport pubkey. **Comes from the seed's `lnbits_npub`** (#70); env override only. LNbits prints it on startup (`docker logs lnbits \| grep 'Public key (share this)'`) |
|
||||||
| `VITE_SPIRE_SEED` | yes (prod) | Spire pairing seed (`spire-seed:v1:<base64url>`) from spirekeeper. Carries a one-shot NIP-46 connect token + the spire signing pubkey + bunker URL. First boot redeems it and persists the binding to `state.db`; later boots resume by fingerprint. A changed seed re-pairs. Provisioning it up front is optional — an unpaired machine renders an on-screen QR-pairing wizard that scans the seed off the camera (see below). See aiolabs/bitspire#52. |
|
| `VITE_SPIRE_SEED` | yes (prod) | Spire pairing seed (`spire-seed:v1:<base64url>`) from spirekeeper. Carries the relay(s), the LNbits transport pubkey (`lnbits_npub`), the spire signing pubkey (`spire_npub`), and a one-shot NIP-46 connect token (#70 slimmed the shape). First boot redeems it and persists the binding to `state.db`; later boots resume by fingerprint. A changed seed re-pairs. Provisioning it up front is optional — an unpaired machine renders an on-screen QR-pairing wizard that scans the seed off the camera (see below). See aiolabs/bitspire#52. |
|
||||||
| `VITE_ATM_PRIVATE_KEY` | dev only | 64-char hex raw nsec fallback for running without a bunker. Ignored when `VITE_SPIRE_SEED` or a stored binding exists. |
|
| `VITE_ATM_PRIVATE_KEY` | dev only | 64-char hex raw nsec fallback for running without a bunker. Ignored when `VITE_SPIRE_SEED` or a stored binding exists. |
|
||||||
| `VITE_OPERATOR_PUBKEYS` | optional | Comma-separated hex pubkeys allowed to send kind-21003 management commands |
|
| `VITE_OPERATOR_PUBKEYS` | optional | Comma-separated hex pubkeys allowed to send kind-21003 management commands |
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -19,11 +19,15 @@ VITE_LAMASSU_FIAT_CODE=USD
|
||||||
# VITE_LAMASSU_CASSETTES='[{"denomination":20,"count":100}]'
|
# VITE_LAMASSU_CASSETTES='[{"denomination":20,"count":100}]'
|
||||||
|
|
||||||
# =============================================================================
|
# =============================================================================
|
||||||
# LNbits Connection (Required) — nostr-native-transport
|
# LNbits Connection (dev override — normally seed-provided) — nostr-native-transport
|
||||||
# =============================================================================
|
# =============================================================================
|
||||||
|
# On a real machine the pairing SEED (VITE_SPIRE_SEED) carries the relay AND the
|
||||||
|
# server pubkey (aiolabs/bitspire#70), so leave both blank there. Set them here
|
||||||
|
# only for browser dev without a seed/bunker — they WIN over the seed.
|
||||||
|
|
||||||
# Nostr relay WebSocket URL — relay LNbits is subscribed to.
|
# Nostr relay WebSocket URL. Dev stack uses LNbits's bundled nostrrelay:
|
||||||
VITE_RELAY_URL=ws://localhost:7777
|
# VITE_RELAY_URL=ws://localhost:5001/nostrrelay/test
|
||||||
|
VITE_RELAY_URL=
|
||||||
|
|
||||||
# LNbits nostr-transport server pubkey (hex, 64 chars).
|
# LNbits nostr-transport server pubkey (hex, 64 chars).
|
||||||
# Printed by the LNbits server on startup:
|
# Printed by the LNbits server on startup:
|
||||||
|
|
|
||||||
|
|
@ -187,7 +187,7 @@ The `dev`-branch `flake.nix` pins the auto-upgrade source to `?ref=dev` so any A
|
||||||
```nix
|
```nix
|
||||||
system.autoUpgrade = {
|
system.autoUpgrade = {
|
||||||
enable = true;
|
enable = true;
|
||||||
flake = "git+ssh://forgejo@git.atitlan.io/aiolabs/lamassu-next.git?ref=dev#${machineModel}-installed";
|
flake = "git+ssh://forgejo@git.atitlan.io/aiolabs/bitspire.git?ref=dev#${machineModel}-installed";
|
||||||
dates = "04:00";
|
dates = "04:00";
|
||||||
allowReboot = false;
|
allowReboot = false;
|
||||||
};
|
};
|
||||||
|
|
@ -262,8 +262,8 @@ ls -la /dev/serial/by-id/
|
||||||
{
|
{
|
||||||
services.bitspire = {
|
services.bitspire = {
|
||||||
enable = true;
|
enable = true;
|
||||||
relayUrl = "wss://relay.aiolabs.dev"; # ATM ↔ LNbits relay
|
relayUrl = ""; # seed-provided (#70); set to PIN a relay
|
||||||
lnbitsServerPubkey = "<64-hex>"; # LNbits transport pubkey
|
lnbitsServerPubkey = ""; # seed-provided (#70); set to PIN a pubkey
|
||||||
appDir = "/opt/bitspire"; # rarely overridden — defaults via flake
|
appDir = "/opt/bitspire"; # rarely overridden — defaults via flake
|
||||||
dataDir = "/var/lib/bitspire"; # rarely overridden
|
dataDir = "/var/lib/bitspire"; # rarely overridden
|
||||||
logLevel = "info"; # error | warn | info | debug
|
logLevel = "info"; # error | warn | info | debug
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue