nix/nixos/common/modules/secureboot.nix

13 lines
348 B
Nix
Raw Normal View History

2023-07-12 16:43:21 +02:00
{ lib, config, pkgs, ...}: {
2023-09-21 15:22:59 +02:00
imports = [ ./bootloader.nix ];
# SecureBoot
boot.loader.systemd-boot.enable = lib.mkForce false;
boot.lanzaboote.enable = true;
boot.lanzaboote.pkiBundle = "/etc/secureboot";
2023-09-21 14:51:42 +02:00
2023-09-21 15:22:59 +02:00
# Bootloader
boot.loader.efi.canTouchEfiVariables = true;
boot.tmp.cleanOnBoot = true;
boot.initrd.systemd.enable = true;
}