disk encrypto

This commit is contained in:
2026-06-04 05:19:58 +09:00
parent 7c37e6b949
commit 03280e5c77
6 changed files with 131 additions and 1 deletions
+1
View File
@@ -2,6 +2,7 @@
imports = [
./power.nix
./secure-boot.nix
./storage-crypto.nix
./uefi.nix
];
}
+30
View File
@@ -0,0 +1,30 @@
{
pkgs,
lib,
config,
...
}:
let
cfg = config.my.features.boot.storageCrypto;
in
{
options.my.features.boot.storageCrypto = {
enable = lib.mkEnableOption "LUKS decryption via TPM2";
};
config = lib.mkIf cfg.enable {
boot.initrd.systemd.enable = true;
boot.initrd.luks.devices.cryptroot = {
crypttabExtraOpts = [
"tpm2-device=auto"
];
};
security.tpm2.enable = true;
environment.systemPackages = with pkgs; [
tpm2-tools # TPM2 management tools
];
};
}