fix(deploy): relay + LNbits pubkey are seed-provided, not env-pinned (#70)
The bitspire-env activation seeded VITE_RELAY_URL from the relayUrl option
(default wss://relay.aiolabs.dev). Because env wins over the pairing seed, every
fresh machine pinned itself to that relay — which is dead — so a scanned seed's
relay was ignored ("No connected relays"; hit live on the aio-demo USB). Default
relayUrl to "" so both relay and server pubkey come from the seed; a non-empty
option now pins a machine (an explicit override) rather than being the default.
Descriptions updated to match.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
parent
675b6bfb7c
commit
e20faa61ff
2 changed files with 22 additions and 19 deletions
|
|
@ -20,18 +20,17 @@ in
|
||||||
|
|
||||||
relayUrl = mkOption {
|
relayUrl = mkOption {
|
||||||
type = types.str;
|
type = types.str;
|
||||||
default = "wss://relay.aiolabs.dev";
|
default = "";
|
||||||
description = ''
|
description = ''
|
||||||
Nostr relay URL the ATM and LNbits both subscribe to.
|
Optional override for the Nostr relay the ATM uses. Empty by
|
||||||
|
default (aiolabs/bitspire#70): the relay comes from the pairing
|
||||||
On a fresh-boot disk image this value is seeded into
|
SEED, not from provisioning — a fresh machine boots blank, scans a
|
||||||
`/var/lib/bitspire/.env` as `VITE_RELAY_URL=…` (see flake.nix
|
spire-seed, and the seed's relay drives the connection. A non-empty
|
||||||
`bitspire-env` activation script). The operator can override
|
value here is seeded into `/var/lib/bitspire/.env` as
|
||||||
the seeded value at runtime by editing `.env` directly or by
|
`VITE_RELAY_URL=…` and WINS over the seed (env-first precedence), so
|
||||||
re-running `deploy/nixos/provision-atm.sh` with a different
|
only set it to pin a machine to a specific relay. The renderer's
|
||||||
`RELAY_URL`. The renderer's resolution order is:
|
resolution order is: `VITE_RELAY_URL` (this / .env) → the pairing
|
||||||
`/var/lib/bitspire/.env` → this NixOS default → renderer
|
seed's relay → a dev-only `ws://localhost:7777` fallback.
|
||||||
hardcoded fallback (`ws://localhost:7777`).
|
|
||||||
'';
|
'';
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|
@ -39,10 +38,13 @@ in
|
||||||
type = types.str;
|
type = types.str;
|
||||||
default = "";
|
default = "";
|
||||||
description = ''
|
description = ''
|
||||||
LNbits nostr-transport server pubkey (hex, 64 chars). Published
|
Optional override for the LNbits nostr-transport server pubkey
|
||||||
by the LNbits server on startup. Required for the ATM to talk
|
(hex, 64 chars). Empty by default (aiolabs/bitspire#70): the
|
||||||
to its wallet. Provisioned by provision-atm.sh; can be left
|
pubkey comes from the pairing SEED (the seed's `lnbits_npub`), so
|
||||||
empty on disk-image builds.
|
a seed-paired machine needs nothing here. A non-empty value is
|
||||||
|
seeded into `.env` as `VITE_LNBITS_SERVER_PUBKEY=…` and WINS over
|
||||||
|
the seed (env-first precedence) — set it only to pin a machine to
|
||||||
|
a specific server. Mirrors `relayUrl`.
|
||||||
'';
|
'';
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -191,10 +191,11 @@
|
||||||
# boots cleanly into the "needs provisioning" state; provision-
|
# boots cleanly into the "needs provisioning" state; provision-
|
||||||
# atm.sh SSHes in and overwrites with real values.
|
# atm.sh SSHes in and overwrites with real values.
|
||||||
#
|
#
|
||||||
# VITE_RELAY_URL seeds from `config.services.bitspire.relayUrl`
|
# VITE_RELAY_URL + VITE_LNBITS_SERVER_PUBKEY seed EMPTY by default
|
||||||
# so the NixOS module's `relayUrl` option becomes the default
|
# (relayUrl defaults to ""), so the pairing seed drives the relay
|
||||||
# without losing the operator's ability to override via .env
|
# + server pubkey (aiolabs/bitspire#70). A non-empty `relayUrl`
|
||||||
# (edit the file or re-run provision-atm.sh).
|
# option pins a machine to a specific relay (seeded here, wins over
|
||||||
|
# the seed via env-first precedence) — otherwise leave it blank.
|
||||||
system.activationScripts.bitspire-env = ''
|
system.activationScripts.bitspire-env = ''
|
||||||
mkdir -p /var/lib/bitspire
|
mkdir -p /var/lib/bitspire
|
||||||
if [ ! -f /var/lib/bitspire/.env ]; then
|
if [ ! -f /var/lib/bitspire/.env ]; then
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue