From e20faa61ff65f2c50484afae0a0ba56996b034a8 Mon Sep 17 00:00:00 2001 From: Padreug Date: Thu, 2 Jul 2026 15:38:14 +0200 Subject: [PATCH] fix(deploy): relay + LNbits pubkey are seed-provided, not env-pinned (#70) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The bitspire-env activation seeded VITE_RELAY_URL from the relayUrl option (default wss://relay.aiolabs.dev). Because env wins over the pairing seed, every fresh machine pinned itself to that relay — which is dead — so a scanned seed's relay was ignored ("No connected relays"; hit live on the aio-demo USB). Default relayUrl to "" so both relay and server pubkey come from the seed; a non-empty option now pins a machine (an explicit override) rather than being the default. Descriptions updated to match. Co-Authored-By: Claude Opus 4.8 --- deploy/nixos/bitspire-atm.nix | 32 +++++++++++++++++--------------- flake.nix | 9 +++++---- 2 files changed, 22 insertions(+), 19 deletions(-) diff --git a/deploy/nixos/bitspire-atm.nix b/deploy/nixos/bitspire-atm.nix index 43f4d3c..a46e9b4 100644 --- a/deploy/nixos/bitspire-atm.nix +++ b/deploy/nixos/bitspire-atm.nix @@ -20,18 +20,17 @@ in relayUrl = mkOption { type = types.str; - default = "wss://relay.aiolabs.dev"; + default = ""; description = '' - Nostr relay URL the ATM and LNbits both subscribe to. - - On a fresh-boot disk image this value is seeded into - `/var/lib/bitspire/.env` as `VITE_RELAY_URL=…` (see flake.nix - `bitspire-env` activation script). The operator can override - the seeded value at runtime by editing `.env` directly or by - re-running `deploy/nixos/provision-atm.sh` with a different - `RELAY_URL`. The renderer's resolution order is: - `/var/lib/bitspire/.env` → this NixOS default → renderer - hardcoded fallback (`ws://localhost:7777`). + Optional override for the Nostr relay the ATM uses. Empty by + default (aiolabs/bitspire#70): the relay comes from the pairing + SEED, not from provisioning — a fresh machine boots blank, scans a + spire-seed, and the seed's relay drives the connection. A non-empty + value here is seeded into `/var/lib/bitspire/.env` as + `VITE_RELAY_URL=…` and WINS over the seed (env-first precedence), so + only set it to pin a machine to a specific relay. The renderer's + resolution order is: `VITE_RELAY_URL` (this / .env) → the pairing + seed's relay → a dev-only `ws://localhost:7777` fallback. ''; }; @@ -39,10 +38,13 @@ in type = types.str; default = ""; description = '' - LNbits nostr-transport server pubkey (hex, 64 chars). Published - by the LNbits server on startup. Required for the ATM to talk - to its wallet. Provisioned by provision-atm.sh; can be left - empty on disk-image builds. + Optional override for the LNbits nostr-transport server pubkey + (hex, 64 chars). Empty by default (aiolabs/bitspire#70): the + pubkey comes from the pairing SEED (the seed's `lnbits_npub`), so + a seed-paired machine needs nothing here. A non-empty value is + seeded into `.env` as `VITE_LNBITS_SERVER_PUBKEY=…` and WINS over + the seed (env-first precedence) — set it only to pin a machine to + a specific server. Mirrors `relayUrl`. ''; }; diff --git a/flake.nix b/flake.nix index a09ffdd..aa8b4c8 100644 --- a/flake.nix +++ b/flake.nix @@ -191,10 +191,11 @@ # boots cleanly into the "needs provisioning" state; provision- # atm.sh SSHes in and overwrites with real values. # - # VITE_RELAY_URL seeds from `config.services.bitspire.relayUrl` - # so the NixOS module's `relayUrl` option becomes the default - # without losing the operator's ability to override via .env - # (edit the file or re-run provision-atm.sh). + # VITE_RELAY_URL + VITE_LNBITS_SERVER_PUBKEY seed EMPTY by default + # (relayUrl defaults to ""), so the pairing seed drives the relay + # + server pubkey (aiolabs/bitspire#70). A non-empty `relayUrl` + # option pins a machine to a specific relay (seeded here, wins over + # the seed via env-first precedence) — otherwise leave it blank. system.activationScripts.bitspire-env = '' mkdir -p /var/lib/bitspire if [ ! -f /var/lib/bitspire/.env ]; then