diff --git a/hosts/default.nix b/hosts/default.nix index a5719d1..c4f429b 100644 --- a/hosts/default.nix +++ b/hosts/default.nix @@ -67,7 +67,7 @@ in "platforms/thinkpad" "workloads/dev" "workloads/personal" - "workloads/secure-boot" + "workloads/secure-storage" ]; }; }; diff --git a/hosts/x1g13/default.nix b/hosts/x1g13/default.nix index 2db9801..81f90fb 100644 --- a/hosts/x1g13/default.nix +++ b/hosts/x1g13/default.nix @@ -2,5 +2,6 @@ { imports = [ ./hardware-configuration.nix + ./disko.nix ]; } diff --git a/hosts/x1g13/disko.nix b/hosts/x1g13/disko.nix new file mode 100644 index 0000000..8f7c1f7 --- /dev/null +++ b/hosts/x1g13/disko.nix @@ -0,0 +1,97 @@ +_: +let + espPart = "/dev/disk/by-partuuid/a53e3b19-67de-40de-9ded-3eac3117689a"; + + nixosPart = "/dev/disk/by-partuuid/311d0f9c-f35f-42e6-b6fc-a4d67dd21b2e"; + + btrfsMountOptions = [ + "compress=zstd" + "noatime" + "ssd" + "space_cache=v2" + ]; +in +{ + disko.devices.disk = { + esp = { + type = "disk"; + device = espPart; + destroy = false; + + content = { + type = "filesystem"; + format = "vfat"; + mountpoint = "/boot"; + mountOptions = [ + "umask=0077" + ]; + }; + }; + + nixos = { + type = "disk"; + device = nixosPart; + destroy = false; + + content = { + type = "luks"; + name = "cryptroot"; + + askPassword = true; + + settings = { + allowDiscards = true; + }; + + extraFormatArgs = [ + "--type" + "luks2" + "--pbkdf" + "argon2id" + "--label" + "NixOS-LUKS" + ]; + + content = { + type = "btrfs"; + extraArgs = [ + "-f" + "-L" + "NixOS" + ]; + + subvolumes = { + "@root" = { + mountpoint = "/"; + mountOptions = btrfsMountOptions; + }; + + "@home" = { + mountpoint = "/home"; + mountOptions = btrfsMountOptions; + }; + + "@nix" = { + mountpoint = "/nix"; + mountOptions = btrfsMountOptions; + }; + + "@log" = { + mountpoint = "/var/log"; + mountOptions = btrfsMountOptions; + }; + + "@swap" = { + mountpoint = "/.swapvol"; + mountOptions = [ + "noatime" + ]; + + swap.swapfile.size = "32G"; + }; + }; + }; + }; + }; + }; +} diff --git a/modules/features/boot/default.nix b/modules/features/boot/default.nix index 57d2608..22e06ea 100644 --- a/modules/features/boot/default.nix +++ b/modules/features/boot/default.nix @@ -2,6 +2,7 @@ imports = [ ./power.nix ./secure-boot.nix + ./storage-crypto.nix ./uefi.nix ]; } diff --git a/modules/features/boot/storage-crypto.nix b/modules/features/boot/storage-crypto.nix new file mode 100644 index 0000000..d4f41b8 --- /dev/null +++ b/modules/features/boot/storage-crypto.nix @@ -0,0 +1,30 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.features.boot.storageCrypto; +in +{ + options.my.features.boot.storageCrypto = { + enable = lib.mkEnableOption "LUKS decryption via TPM2"; + }; + + config = lib.mkIf cfg.enable { + boot.initrd.systemd.enable = true; + + boot.initrd.luks.devices.cryptroot = { + crypttabExtraOpts = [ + "tpm2-device=auto" + ]; + }; + + security.tpm2.enable = true; + + environment.systemPackages = with pkgs; [ + tpm2-tools # TPM2 management tools + ]; + }; +} diff --git a/profiles/workloads/secure-boot.nix b/profiles/workloads/secure-storage.nix similarity index 50% rename from profiles/workloads/secure-boot.nix rename to profiles/workloads/secure-storage.nix index 63962a3..c3820e1 100644 --- a/profiles/workloads/secure-boot.nix +++ b/profiles/workloads/secure-storage.nix @@ -1,3 +1,4 @@ { my.features.boot.secureBoot.enable = true; + my.features.boot.storageCrypto.enable = true; }