The installer's environment variables kept the ThoughtSync-era TS_ prefix
after the rename to Inkwell. They are now INKWELL_*, as is the
INKWELL_SERVER_DEFAULT line the server fills in when it serves the script.
The old names are not read any more; the operator approved the clean cut.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Milestone 325 step 5 (Scribe #3253).
curl -fsSL https://notes.example.com/install.sh | sh
The server serves the installer at /install.sh with its own address written
into it (installer.py). Settings → Public address when set, the request's own
address otherwise. The substitution is one variable, given a value that has
passed a strict shape check, and the script checks it again; an address that
cannot pass makes the route refuse rather than serve a script pointed
elsewhere. `public_url` joins the live settings cache so the route needs no
database.
From a server, the script:
- resolves each Linux bundle from the public /api/client/<platform>, and
builds the download URL from the platform id rather than reading it from
the reply;
- asks for a device token (from the terminal, since stdin is the script),
or takes TS_TOKEN, and sends it from a file rather than the command line;
- checks the sha256 the server published before anything installs;
- revokes a prompted token once the download is done;
- records `install-server` for the updater (step 6) instead of the channel.
The forge path is unchanged, and stays the default for the copy the forge
serves. The Account page's downloads card shows the one-line command
whenever the server holds a Linux client.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>