feat: seed-driven pairing over the LNbits nostr-transport (#70) #73

Merged
padreug merged 17 commits from feat/seed-driven-pairing into dev 2026-07-02 21:54:11 +00:00
2 changed files with 22 additions and 19 deletions
Showing only changes of commit 7896c122da - Show all commits

fix(deploy): relay + LNbits pubkey are seed-provided, not env-pinned (#70)

The bitspire-env activation seeded VITE_RELAY_URL from the relayUrl option
(default wss://relay.aiolabs.dev). Because env wins over the pairing seed, every
fresh machine pinned itself to that relay — which is dead — so a scanned seed's
relay was ignored ("No connected relays"; hit live on the aio-demo USB). Default
relayUrl to "" so both relay and server pubkey come from the seed; a non-empty
option now pins a machine (an explicit override) rather than being the default.
Descriptions updated to match.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Padreug 2026-07-02 15:38:14 +02:00 • committed by padreug

View file

@ -20,18 +20,17 @@ in
relayUrl = mkOption { relayUrl = mkOption {
type = types.str; type = types.str;
default = "wss://relay.aiolabs.dev"; default = "";
description = '' description = ''
Nostr relay URL the ATM and LNbits both subscribe to. Optional override for the Nostr relay the ATM uses. Empty by
default (aiolabs/bitspire#70): the relay comes from the pairing
On a fresh-boot disk image this value is seeded into SEED, not from provisioning — a fresh machine boots blank, scans a
`/var/lib/bitspire/.env` as `VITE_RELAY_URL=…` (see flake.nix spire-seed, and the seed's relay drives the connection. A non-empty
`bitspire-env` activation script). The operator can override value here is seeded into `/var/lib/bitspire/.env` as
the seeded value at runtime by editing `.env` directly or by `VITE_RELAY_URL=…` and WINS over the seed (env-first precedence), so
re-running `deploy/nixos/provision-atm.sh` with a different only set it to pin a machine to a specific relay. The renderer's
`RELAY_URL`. The renderer's resolution order is: resolution order is: `VITE_RELAY_URL` (this / .env) → the pairing
`/var/lib/bitspire/.env` → this NixOS default → renderer seed's relay → a dev-only `ws://localhost:7777` fallback.
hardcoded fallback (`ws://localhost:7777`).
''; '';
}; };
@ -39,10 +38,13 @@ in
type = types.str; type = types.str;
default = ""; default = "";
description = '' description = ''
LNbits nostr-transport server pubkey (hex, 64 chars). Published Optional override for the LNbits nostr-transport server pubkey
by the LNbits server on startup. Required for the ATM to talk (hex, 64 chars). Empty by default (aiolabs/bitspire#70): the
to its wallet. Provisioned by provision-atm.sh; can be left pubkey comes from the pairing SEED (the seed's `lnbits_npub`), so
empty on disk-image builds. a seed-paired machine needs nothing here. A non-empty value is
seeded into `.env` as `VITE_LNBITS_SERVER_PUBKEY=…` and WINS over
the seed (env-first precedence) — set it only to pin a machine to
a specific server. Mirrors `relayUrl`.
''; '';
}; };

View file

@ -191,10 +191,11 @@
# boots cleanly into the "needs provisioning" state; provision- # boots cleanly into the "needs provisioning" state; provision-
# atm.sh SSHes in and overwrites with real values. # atm.sh SSHes in and overwrites with real values.
# #
# VITE_RELAY_URL seeds from `config.services.bitspire.relayUrl` # VITE_RELAY_URL + VITE_LNBITS_SERVER_PUBKEY seed EMPTY by default
# so the NixOS module's `relayUrl` option becomes the default # (relayUrl defaults to ""), so the pairing seed drives the relay
# without losing the operator's ability to override via .env # + server pubkey (aiolabs/bitspire#70). A non-empty `relayUrl`
# (edit the file or re-run provision-atm.sh). # option pins a machine to a specific relay (seeded here, wins over
# the seed via env-first precedence) — otherwise leave it blank.
system.activationScripts.bitspire-env = '' system.activationScripts.bitspire-env = ''
mkdir -p /var/lib/bitspire mkdir -p /var/lib/bitspire
if [ ! -f /var/lib/bitspire/.env ]; then if [ ! -f /var/lib/bitspire/.env ]; then