Initial .s9pk for SpacesOps, targeting StartOS 0.4.0.x with SDK 1.5.1. - Single managed daemon from spacesops/spacesops:v1.0.0 (x86_64 + aarch64), keeping the image entrypoint (/app/docker-entrypoint.sh node server.js). Forces PLATFORM_HOST=0.0.0.0 / PLATFORM_PORT=7264 so the StartOS proxy can reach the app. Single `ui` interface on 7264. - Depends on the Spaces service (>=0.0.9:3) and auto-wires the spaced RPC creds: main.ts mounts the Spaces `main` volume read-only at /spaces-data, execs a read of its store.json inside the subcontainer, and injects SPACED_RPC_USER/ PASSWORD + SPACED_RPC_URL=http://spaces.startos:7225. Throws to retry until Spaces is installed and seeded. - Generates a Nostr operator keypair (nostr-tools, bundled by ncc) and a strong session secret in idempotent init tasks (.once() reads, allowWriteAfterConst merges). Actions: show-operator-credentials, import-operator-key, show-admin-credentials (surfaces the fixed admin/Whatever! login with a warning), configure-platform (optional relay/mode/CoinGecko/SUBSD). - Install alert warns to install Spaces first and about the fixed admin credential. Backs up the `main` volume. - Icon: icon.svg (source spacesops.svg). The `spaces` dependency uses assets/spaces-icon.png for its Marketplace metadata. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
25 lines
1.0 KiB
TypeScript
25 lines
1.0 KiB
TypeScript
import { storeJson } from '../fileModels/storeJson'
|
|
import { sdk } from '../sdk'
|
|
import { secretHexToPublicHex } from '../nostr'
|
|
import { randomOperatorSecretHex } from '../utils'
|
|
|
|
// Generate the Nostr operator keypair once, if absent. SpacesOps requires
|
|
// OPERATOR_SECRET_HEX / OPERATOR_PUBLIC_HEX at startup (it exits otherwise).
|
|
// Idempotent: only acts when the secret is not yet present. Read with .once()
|
|
// — never .const() in init (it arms a write-after-const watcher).
|
|
export const taskOperatorKeys = sdk.setupOnInit(async (effects) => {
|
|
const existing = await storeJson.read((s) => s.operatorSecretHex).once()
|
|
if (existing) return
|
|
|
|
const operatorSecretHex = randomOperatorSecretHex()
|
|
// Derive before persisting; if derivation rejects the (astronomically rare)
|
|
// out-of-range scalar, nothing is written and StartOS retries init.
|
|
const operatorPublicHex = secretHexToPublicHex(operatorSecretHex)
|
|
|
|
await storeJson.merge(
|
|
effects,
|
|
{ operatorSecretHex, operatorPublicHex },
|
|
{ allowWriteAfterConst: true },
|
|
)
|
|
})
|