bitspire/apps/machine/.env.example
Padreug bf2b9427aa refactor(config): rename VITE_LAMASSU_* machine-config env vars to VITE_BITSPIRE_*
MACHINE_MODEL, FIAT_CODE, VALIDATOR_DEVICE, DISPENSER_DEVICE and CASSETTES
carried the old brand in their names. Renamed everywhere they are read
(device.ts, electron/main.ts), written (flake.nix, mkAtmApp.nix, live.nix,
provision-atm.sh, factory-reset-atm.sh) and documented (.env.example,
docs/device-configuration.md). No compatibility fallback in code: the
machine reads VITE_BITSPIRE_* and nothing else.

The deployed .env files are the one place the old names persist — sintra's
/var/lib/bitspire/.env holds all three keys today — and the machine reads
MACHINE_MODEL / FIAT_CODE / CASSETTES from that file on every boot. Renaming
the keys in code alone would boot a live machine on preset defaults (wrong
bays, wrong fiat) at the next nightly pull. So configuration.nix gains an
activation script, beside the existing lamassu→bitspire user migration,
that rewrites VITE_LAMASSU_* → VITE_BITSPIRE_* in that file. Idempotent;
runs before bitspire.service starts.
2026-10-09 21:57:38 +02:00

123 lines
5.7 KiB
Bash

# bitSpire ATM Configuration
# Copy this file to .env and fill in your values
# =============================================================================
# Hardware Configuration
# =============================================================================
# Machine model preset (sintra, gaia, or custom)
VITE_BITSPIRE_MACHINE_MODEL=sintra
# Fiat currency code (ISO 4217)
VITE_BITSPIRE_FIAT_CODE=USD
# Custom device paths (optional - uses preset defaults if not set)
# VITE_BITSPIRE_VALIDATOR_DEVICE=/dev/ttyJ5
# VITE_BITSPIRE_DISPENSER_DEVICE=/dev/ttyJ7
# Cassette configuration (optional - JSON array)
# VITE_BITSPIRE_CASSETTES='[{"denomination":20,"count":100}]'
# =============================================================================
# LNbits Connection (dev override — normally seed-provided) — nostr-native-transport
# =============================================================================
# On a real machine the pairing SEED (VITE_SPIRE_SEED) carries the relay AND the
# server pubkey (aiolabs/bitspire#70), so leave both blank there. Set them here
# only for browser dev without a seed/bunker — they WIN over the seed.
# Nostr relay WebSocket URL. Dev stack uses LNbits's bundled nostrrelay:
# VITE_RELAY_URL=ws://localhost:5001/nostrrelay/test
VITE_RELAY_URL=
# LNbits nostr-transport server pubkey (hex, 64 chars).
# Printed by the LNbits server on startup:
# docker logs lnbits | grep 'nostr_transport pubkey'
VITE_LNBITS_SERVER_PUBKEY=
# (LNbits HTTP URL is no longer needed on the ATM side — the
# nostr-transport RPC `lnurlw_create_link` now returns `link.lnurl`
# populated from `settings.lnbits_baseurl` on the LNbits server. See
# aiolabs/withdraw#1 / commit e9d911e.)
# =============================================================================
# ATM Identity — spire pairing seed (NIP-46 bunker; aiolabs/bitspire#52)
# =============================================================================
# The spire pairing seed produced by the operator dashboard (spirekeeper):
# spire-seed:v1:<base64url>
# It carries a one-shot NIP-46 connect token + the spire's signing pubkey +
# the bunker URL. On first boot the ATM redeems the token, generates its own
# transport key, and persists the binding to state.db; thereafter it resumes
# from the binding (the seed can stay set — it's matched by fingerprint).
# A changed seed re-pairs (and re-publishes the cassette-state hello).
VITE_SPIRE_SEED=
# pragma: allowlist secret
# DEV ONLY fallback — a raw Nostr private key (hex, 64 chars) for running
# without a bunker. Ignored when VITE_SPIRE_SEED or a stored binding exists.
# Generate with: openssl rand -hex 32
# VITE_ATM_PRIVATE_KEY=
# =============================================================================
# Operator Identity
# =============================================================================
# Comma-separated list of Nostr hex pubkeys authorized to send operator commands
# (manual dispense, remote management).
# VITE_OPERATOR_PUBKEYS=abcd1234...,ef567890...
# =============================================================================
# Maintenance Mode
# =============================================================================
# Show "Under Service" screen and block all transactions
# VITE_MAINTENANCE_MODE=true
# =============================================================================
# Public Web Demo
# =============================================================================
# Set ONLY for the browser demo build (atm.demo.aiolabs.dev). Leave blank on
# every real machine. When set it:
# - keeps the mouse cursor visible (kiosk builds hide it)
# - mints one extra, never-used LNbits wallet named with this exact string,
# so the throwaway accounts the demo creates (one per page load, each with
# its own ephemeral identity) can be swept by name instead of guessed at.
# VITE_DEMO_TAG=bitspire-web-demo
# =============================================================================
# Mock Fallback (Production Safety)
# =============================================================================
# Allow fallback to mock services when hardware/Lightning fails (default: false)
# Set to 'true' for development/demo environments only
# When false (production default), initialization failures show a maintenance screen
# VITE_ALLOW_MOCK_FALLBACK=true
# =============================================================================
# Access Control (ADR-003)
# =============================================================================
# Tap-to-enter gate. When disabled (default), the machine boots straight to
# idle exactly as before. When enabled, it boots into a locked screen and a
# Bolt Card tap (read by the main-process NFC service over pcscd) unlocks it
# and loads the card for the session, so buy/sell finish with one Complete.
# ACCESS_CONTROL_ENABLED=true
# Admit ANY Bolt Card when the allow-list has no match. With this on the gate
# only keeps casual users off the menu — any NDEF tag with a /scan/<id> URL
# unlocks it; money still moves only on a valid SUN at Complete. Turn OFF once
# a real allow-list (/var/lib/bitspire/access.json) is provisioned.
# ACCESS_OPEN_ENROLLMENT=true
# Show the on-screen runtime dev/operator unlock button on the locked screen.
# Default OFF — it bypasses the gate, so enable only on a bench/dev machine.
# ACCESS_DEV_UNLOCK=true
# Per-machine salt for hashing credentials/PINs. Provision a real value in
# production (or in access.json); a fixed default is used if unset.
# ACCESS_SALT=change-me-per-machine
# Build/dev bypass — forces the gate OPEN even when enabled (browser dev / CI).
# Renderer-side (Vite) flag, never set in a production image.
# VITE_SKIP_ACCESS_GATE=true