docs: relay + LNbits pubkey are seed-provided, not required (#70)
Env table (CLAUDE.md), .env.example, and the deploy README still framed
VITE_RELAY_URL / VITE_LNBITS_SERVER_PUBKEY as required/provisioned; they now come
from the pairing seed and are env overrides only. Also refresh the slimmed seed
shape, the relayUrl/pubkey module examples ("" not wss://relay.aiolabs.dev), and
the stale lamassu-next autoUpgrade flake URL (→ aiolabs/bitspire).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
parent
f003483599
commit
a8b8b707be
3 changed files with 13 additions and 9 deletions
|
|
@ -82,9 +82,9 @@ Renderer reads (Electron IPC or Vite `import.meta.env`):
|
|||
|
||||
| Var | Required | Notes |
|
||||
|---|---|---|
|
||||
| `VITE_RELAY_URL` | yes | `ws://...` of the relay both ATM and LNbits subscribe to. Dev: `ws://localhost:5001/nostrrelay/test` (LNbits's bundled `nostrrelay` extension — no separate strfry container) |
|
||||
| `VITE_LNBITS_SERVER_PUBKEY` | yes | 64-char hex pubkey LNbits prints on startup (`docker logs lnbits \| grep 'Public key (share this)'`) |
|
||||
| `VITE_SPIRE_SEED` | yes (prod) | Spire pairing seed (`spire-seed:v1:<base64url>`) from spirekeeper. Carries a one-shot NIP-46 connect token + the spire signing pubkey + bunker URL. First boot redeems it and persists the binding to `state.db`; later boots resume by fingerprint. A changed seed re-pairs. Provisioning it up front is optional — an unpaired machine renders an on-screen QR-pairing wizard that scans the seed off the camera (see below). See aiolabs/bitspire#52. |
|
||||
| `VITE_RELAY_URL` | no (seed-provided) | Relay both ATM and LNbits subscribe to. **Comes from the pairing seed** (aiolabs/bitspire#70); set this only as an override — it WINS over the seed via env-first precedence. Dev override: `ws://localhost:5001/nostrrelay/test` (LNbits's bundled `nostrrelay` extension — no separate strfry container) |
|
||||
| `VITE_LNBITS_SERVER_PUBKEY` | no (seed-provided) | 64-char hex transport pubkey. **Comes from the seed's `lnbits_npub`** (#70); env override only. LNbits prints it on startup (`docker logs lnbits \| grep 'Public key (share this)'`) |
|
||||
| `VITE_SPIRE_SEED` | yes (prod) | Spire pairing seed (`spire-seed:v1:<base64url>`) from spirekeeper. Carries the relay(s), the LNbits transport pubkey (`lnbits_npub`), the spire signing pubkey (`spire_npub`), and a one-shot NIP-46 connect token (#70 slimmed the shape). First boot redeems it and persists the binding to `state.db`; later boots resume by fingerprint. A changed seed re-pairs. Provisioning it up front is optional — an unpaired machine renders an on-screen QR-pairing wizard that scans the seed off the camera (see below). See aiolabs/bitspire#52. |
|
||||
| `VITE_ATM_PRIVATE_KEY` | dev only | 64-char hex raw nsec fallback for running without a bunker. Ignored when `VITE_SPIRE_SEED` or a stored binding exists. |
|
||||
| `VITE_OPERATOR_PUBKEYS` | optional | Comma-separated hex pubkeys allowed to send kind-21003 management commands |
|
||||
|
||||
|
|
|
|||
|
|
@ -19,11 +19,15 @@ VITE_LAMASSU_FIAT_CODE=USD
|
|||
# VITE_LAMASSU_CASSETTES='[{"denomination":20,"count":100}]'
|
||||
|
||||
# =============================================================================
|
||||
# LNbits Connection (Required) — nostr-native-transport
|
||||
# LNbits Connection (dev override — normally seed-provided) — nostr-native-transport
|
||||
# =============================================================================
|
||||
# On a real machine the pairing SEED (VITE_SPIRE_SEED) carries the relay AND the
|
||||
# server pubkey (aiolabs/bitspire#70), so leave both blank there. Set them here
|
||||
# only for browser dev without a seed/bunker — they WIN over the seed.
|
||||
|
||||
# Nostr relay WebSocket URL — relay LNbits is subscribed to.
|
||||
VITE_RELAY_URL=ws://localhost:7777
|
||||
# Nostr relay WebSocket URL. Dev stack uses LNbits's bundled nostrrelay:
|
||||
# VITE_RELAY_URL=ws://localhost:5001/nostrrelay/test
|
||||
VITE_RELAY_URL=
|
||||
|
||||
# LNbits nostr-transport server pubkey (hex, 64 chars).
|
||||
# Printed by the LNbits server on startup:
|
||||
|
|
|
|||
|
|
@ -187,7 +187,7 @@ The `dev`-branch `flake.nix` pins the auto-upgrade source to `?ref=dev` so any A
|
|||
```nix
|
||||
system.autoUpgrade = {
|
||||
enable = true;
|
||||
flake = "git+ssh://forgejo@git.atitlan.io/aiolabs/lamassu-next.git?ref=dev#${machineModel}-installed";
|
||||
flake = "git+ssh://forgejo@git.atitlan.io/aiolabs/bitspire.git?ref=dev#${machineModel}-installed";
|
||||
dates = "04:00";
|
||||
allowReboot = false;
|
||||
};
|
||||
|
|
@ -262,8 +262,8 @@ ls -la /dev/serial/by-id/
|
|||
{
|
||||
services.bitspire = {
|
||||
enable = true;
|
||||
relayUrl = "wss://relay.aiolabs.dev"; # ATM ↔ LNbits relay
|
||||
lnbitsServerPubkey = "<64-hex>"; # LNbits transport pubkey
|
||||
relayUrl = ""; # seed-provided (#70); set to PIN a relay
|
||||
lnbitsServerPubkey = ""; # seed-provided (#70); set to PIN a pubkey
|
||||
appDir = "/opt/bitspire"; # rarely overridden — defaults via flake
|
||||
dataDir = "/var/lib/bitspire"; # rarely overridden
|
||||
logLevel = "info"; # error | warn | info | debug
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue