nix/nixos/common/modules/secureboot.nix
2023-11-26 20:29:58 +09:00

14 lines
No EOL
345 B
Nix

{ lib, config, pkgs, ...}: {
imports = [ ./boot.nix ];
# SecureBoot
boot.loader.systemd-boot.enable = lib.mkForce false;
boot.lanzaboote.enable = true;
boot.lanzaboote.pkiBundle = "/etc/secureboot";
# Bootloader
boot.loader.efi.canTouchEfiVariables = true;
boot.tmp.cleanOnBoot = true;
boot.initrd.systemd.enable = true;
}