feat: seed-driven pairing over the LNbits nostr-transport (#70) #73
2 changed files with 22 additions and 19 deletions
fix(deploy): relay + LNbits pubkey are seed-provided, not env-pinned (#70)
The bitspire-env activation seeded VITE_RELAY_URL from the relayUrl option
(default wss://relay.aiolabs.dev). Because env wins over the pairing seed, every
fresh machine pinned itself to that relay — which is dead — so a scanned seed's
relay was ignored ("No connected relays"; hit live on the aio-demo USB). Default
relayUrl to "" so both relay and server pubkey come from the seed; a non-empty
option now pins a machine (an explicit override) rather than being the default.
Descriptions updated to match.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
commit
7896c122da
|
|
@ -20,18 +20,17 @@ in
|
|||
|
||||
relayUrl = mkOption {
|
||||
type = types.str;
|
||||
default = "wss://relay.aiolabs.dev";
|
||||
default = "";
|
||||
description = ''
|
||||
Nostr relay URL the ATM and LNbits both subscribe to.
|
||||
|
||||
On a fresh-boot disk image this value is seeded into
|
||||
`/var/lib/bitspire/.env` as `VITE_RELAY_URL=…` (see flake.nix
|
||||
`bitspire-env` activation script). The operator can override
|
||||
the seeded value at runtime by editing `.env` directly or by
|
||||
re-running `deploy/nixos/provision-atm.sh` with a different
|
||||
`RELAY_URL`. The renderer's resolution order is:
|
||||
`/var/lib/bitspire/.env` → this NixOS default → renderer
|
||||
hardcoded fallback (`ws://localhost:7777`).
|
||||
Optional override for the Nostr relay the ATM uses. Empty by
|
||||
default (aiolabs/bitspire#70): the relay comes from the pairing
|
||||
SEED, not from provisioning — a fresh machine boots blank, scans a
|
||||
spire-seed, and the seed's relay drives the connection. A non-empty
|
||||
value here is seeded into `/var/lib/bitspire/.env` as
|
||||
`VITE_RELAY_URL=…` and WINS over the seed (env-first precedence), so
|
||||
only set it to pin a machine to a specific relay. The renderer's
|
||||
resolution order is: `VITE_RELAY_URL` (this / .env) → the pairing
|
||||
seed's relay → a dev-only `ws://localhost:7777` fallback.
|
||||
'';
|
||||
};
|
||||
|
||||
|
|
@ -39,10 +38,13 @@ in
|
|||
type = types.str;
|
||||
default = "";
|
||||
description = ''
|
||||
LNbits nostr-transport server pubkey (hex, 64 chars). Published
|
||||
by the LNbits server on startup. Required for the ATM to talk
|
||||
to its wallet. Provisioned by provision-atm.sh; can be left
|
||||
empty on disk-image builds.
|
||||
Optional override for the LNbits nostr-transport server pubkey
|
||||
(hex, 64 chars). Empty by default (aiolabs/bitspire#70): the
|
||||
pubkey comes from the pairing SEED (the seed's `lnbits_npub`), so
|
||||
a seed-paired machine needs nothing here. A non-empty value is
|
||||
seeded into `.env` as `VITE_LNBITS_SERVER_PUBKEY=…` and WINS over
|
||||
the seed (env-first precedence) — set it only to pin a machine to
|
||||
a specific server. Mirrors `relayUrl`.
|
||||
'';
|
||||
};
|
||||
|
||||
|
|
|
|||
|
|
@ -191,10 +191,11 @@
|
|||
# boots cleanly into the "needs provisioning" state; provision-
|
||||
# atm.sh SSHes in and overwrites with real values.
|
||||
#
|
||||
# VITE_RELAY_URL seeds from `config.services.bitspire.relayUrl`
|
||||
# so the NixOS module's `relayUrl` option becomes the default
|
||||
# without losing the operator's ability to override via .env
|
||||
# (edit the file or re-run provision-atm.sh).
|
||||
# VITE_RELAY_URL + VITE_LNBITS_SERVER_PUBKEY seed EMPTY by default
|
||||
# (relayUrl defaults to ""), so the pairing seed drives the relay
|
||||
# + server pubkey (aiolabs/bitspire#70). A non-empty `relayUrl`
|
||||
# option pins a machine to a specific relay (seeded here, wins over
|
||||
# the seed via env-first precedence) — otherwise leave it blank.
|
||||
system.activationScripts.bitspire-env = ''
|
||||
mkdir -p /var/lib/bitspire
|
||||
if [ ! -f /var/lib/bitspire/.env ]; then
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue