feat: seed-driven pairing over the LNbits nostr-transport (#70) #73
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/seed-driven-pairing"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The #70 arc: a fresh ATM boots blank, scans a
spire-seedQR, and the seed alone drives the relay + LNbits identity — no per-machine env provisioning. Plus the remnant-hygiene (P0) work that keeps the flow clean, and two small machine cleanups. Verified end-to-end on the physical Sintra (blank → wizard → scan → pair → wallet → balance → operational).Groups (17 commits)
Seed-driven pairing core
lnbits_npub); source the LNbits transport (relay + server pubkey) from the seed, not just env; resume from binding when a stored seed won't parse; reject non-ws(s)://relays in the seed; pairing wizard review step with a relay-reachability test; don't inject a localhost relay default inget-config(the bug where env's localhost default beat the seed).#70 consistency
relayUrldefault →"");provision-atm.shwrites relay/pubkey only on explicit override; maintenance beacon uses the pairing seed's relay;DEV_DEFAULT_RELAY→ the real dev relay; docs.P0 remnant hygiene (stops stale env/db values masking real gaps — see #70 discussion)
.envtemplate (stop pre-seeding maskable vars);resetForRepair— a re-pair wipes the prior operator's fee config + replay watermarks; operator-pubkey provenance logging;factory-reset-atm.shfor a deterministic truly-fresh machine.Machine cleanups
Deploy lockstep — read before merging to a deployed host
The slimmed seed shape here matches spirekeeper #37 (the
bitspire-70-seed-lnbits-npubmint). Merging todevis fine (it doesn't deploy), but the actual rollout must be lockstepped: spirekeeper #37 merged + its catalog/deploy live before thedeploy/server-deployflake.lockbump that pulls this onto the Sintra dev unit — otherwise the deployed spirekeeper still mints the old seed shape.Known follow-up (not in this PR)
A seed-only machine now honestly reaches "awaiting configuration" because the operator pubkey isn't provisioned (previously masked by a remnant). Closing that is #70 P1 — the
get_machine_configtransport RPC (spirekeeper#41 / #71) — deliberately out of scope here.Notes
deploy: bootable slim Sintra imagePR (different files/sections; verified conflict-free).🤖 Generated with Claude Code
Completes the consumer half of bitspire-#70: a paired machine gets its LNbits transport relay(s) + server pubkey from the pairing, so a blank-.env unit reaches the backend after scanning a seed — no VITE_RELAY_URL / VITE_LNBITS_SERVER_PUBKEY provisioning. - resolveSigner now returns { signer, transport }. transport (relays + lnbitsServerPubkey) comes from the seed on a fresh pair / seeded resume, and from the binding on a seedless resume. It's threaded out of resolveSigner rather than re-parsed in loadLightningConfig because the seed arrives over the one-shot get-atm-secrets IPC — a second consumer would break that contract. - bunker_binding persists relays + lnbits_server_pubkey (state.db v11→v12, nullable so pre-#70 bindings resume and fall back to env). Mirrored into BunkerBindingRecord (preload + electron.d.ts). - initializeLightningServices resolves effective transport with env-wins precedence (explicit env override for dev, else pairing, else a dev-only localhost relay), mutating CONFIG to a single source of truth and building the Nostr/LNbits/CLINK clients from the full relay list. Strict + required-config validation now run on the resolved values. state.db round-trip test covers the new columns + their absence on a pre-#70 binding. Renderer + electron typechecks and all 38 machine tests pass. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>The bitspire-env activation seeded VITE_RELAY_URL from the relayUrl option (default wss://relay.aiolabs.dev). Because env wins over the pairing seed, every fresh machine pinned itself to that relay — which is dead — so a scanned seed's relay was ignored ("No connected relays"; hit live on the aio-demo USB). Default relayUrl to "" so both relay and server pubkey come from the seed; a non-empty option now pins a machine (an explicit override) rather than being the default. Descriptions updated to match. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>Env table (CLAUDE.md), .env.example, and the deploy README still framed VITE_RELAY_URL / VITE_LNBITS_SERVER_PUBKEY as required/provisioned; they now come from the pairing seed and are env overrides only. Also refresh the slimmed seed shape, the relayUrl/pubkey module examples ("" not wss://relay.aiolabs.dev), and the stale lamassu-next autoUpgrade flake URL (→ aiolabs/bitspire). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>0cc48652aato936fc9fb46