feat(uno-q): board self-register on boot + QR claim prefill (onboarding slice 3)

Board-side half of "preloaded + self-register + claim", plus the QR flow.

- apess-selfregister.sh (on-board): pairs locally for a token, discovers
  the LAN IP, and announces {kitId, url, token, claimCode} to APESS
  /nodes/self-register (x-fleet-secret gated). Retries until APESS is up;
  idempotent, safe on boot and on a timer.
- systemd/apess-selfregister.{service,timer}: self-register After the
  daemon, re-announce every 5 min so a DHCP lease change can't strand a
  board.
- apess-node.env.example: per-board identity (KIT_ID, CLAIM_CODE,
  FLEET_SECRET, APESS_URL).
- gen-kit-codes.sh (host): mint per-kit 6-digit codes, write the
  per-board env files, and emit the QR sticker CSV
  (…/workshop?kit=KIT-NN&code=NNNNNN).
- web: BoardClaim accepts initialCode; TeamRegistration pre-fills it from
  ?code= so scanning the kit QR fills kit + code — one tap to claim.
- deploy/uno-q/README: documents the whole self-serve onboarding path.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
This commit is contained in:
Omar Sobh
2026-07-07 09:36:37 -07:00
co-authored by Claude Opus 4.8
parent 0442f7e865
commit 3f6c6ab399
9 changed files with 195 additions and 2 deletions
@@ -0,0 +1,11 @@
[Unit]
Description=Re-announce this board into APESS (keeps the pool entry fresh)
[Timer]
# Once shortly after boot, then every 5 minutes. Re-registering is idempotent
# (announce resets the entry's url/token/claimCode) and cheap.
OnBootSec=30s
OnUnitActiveSec=5min
[Install]
WantedBy=timers.target