refactor(config): rename VITE_LAMASSU_* machine-config env vars to VITE_BITSPIRE_*

MACHINE_MODEL, FIAT_CODE, VALIDATOR_DEVICE, DISPENSER_DEVICE and CASSETTES
carried the old brand in their names. Renamed everywhere they are read
(device.ts, electron/main.ts), written (flake.nix, mkAtmApp.nix, live.nix,
provision-atm.sh, factory-reset-atm.sh) and documented (.env.example,
docs/device-configuration.md). No compatibility fallback in code: the
machine reads VITE_BITSPIRE_* and nothing else.

The deployed .env files are the one place the old names persist — sintra's
/var/lib/bitspire/.env holds all three keys today — and the machine reads
MACHINE_MODEL / FIAT_CODE / CASSETTES from that file on every boot. Renaming
the keys in code alone would boot a live machine on preset defaults (wrong
bays, wrong fiat) at the next nightly pull. So configuration.nix gains an
activation script, beside the existing lamassu→bitspire user migration,
that rewrites VITE_LAMASSU_* → VITE_BITSPIRE_* in that file. Idempotent;
runs before bitspire.service starts.
This commit is contained in:
Padreug 2026-10-09 21:57:38 +02:00
commit bf2b9427aa
10 changed files with 68 additions and 52 deletions

View file

@ -479,6 +479,22 @@ in
'';
};
# In-place rename migration: VITE_LAMASSU_* → VITE_BITSPIRE_* in the
# provisioned .env. The machine reads MACHINE_MODEL / FIAT_CODE / CASSETTES
# from this file on every boot; renaming the keys in code without renaming
# them here would boot a live machine on preset defaults (wrong bays, wrong
# fiat) at the next nightly pull. Idempotent: a migrated file has nothing
# left to match. Runs before bitspire.service starts.
system.activationScripts.bitspire-env-migration = {
deps = [ "users" ];
text = ''
if [ -f /var/lib/bitspire/.env ] && grep -q '^VITE_LAMASSU_' /var/lib/bitspire/.env; then
sed -i 's/^VITE_LAMASSU_/VITE_BITSPIRE_/' /var/lib/bitspire/.env
echo "bitspire: migrated VITE_LAMASSU_* keys in /var/lib/bitspire/.env"
fi
'';
};
# Journal configuration
services.journald = {
extraConfig = ''