mirror of
https://github.com/moons-14/dotfiles.git
synced 2026-10-06 10:54:08 +09:00
disk encrypto
This commit is contained in:
+1
-1
@@ -67,7 +67,7 @@ in
|
|||||||
"platforms/thinkpad"
|
"platforms/thinkpad"
|
||||||
"workloads/dev"
|
"workloads/dev"
|
||||||
"workloads/personal"
|
"workloads/personal"
|
||||||
"workloads/secure-boot"
|
"workloads/secure-storage"
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -2,5 +2,6 @@
|
|||||||
{
|
{
|
||||||
imports = [
|
imports = [
|
||||||
./hardware-configuration.nix
|
./hardware-configuration.nix
|
||||||
|
./disko.nix
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,97 @@
|
|||||||
|
_:
|
||||||
|
let
|
||||||
|
espPart = "/dev/disk/by-partuuid/a53e3b19-67de-40de-9ded-3eac3117689a";
|
||||||
|
|
||||||
|
nixosPart = "/dev/disk/by-partuuid/311d0f9c-f35f-42e6-b6fc-a4d67dd21b2e";
|
||||||
|
|
||||||
|
btrfsMountOptions = [
|
||||||
|
"compress=zstd"
|
||||||
|
"noatime"
|
||||||
|
"ssd"
|
||||||
|
"space_cache=v2"
|
||||||
|
];
|
||||||
|
in
|
||||||
|
{
|
||||||
|
disko.devices.disk = {
|
||||||
|
esp = {
|
||||||
|
type = "disk";
|
||||||
|
device = espPart;
|
||||||
|
destroy = false;
|
||||||
|
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "vfat";
|
||||||
|
mountpoint = "/boot";
|
||||||
|
mountOptions = [
|
||||||
|
"umask=0077"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
nixos = {
|
||||||
|
type = "disk";
|
||||||
|
device = nixosPart;
|
||||||
|
destroy = false;
|
||||||
|
|
||||||
|
content = {
|
||||||
|
type = "luks";
|
||||||
|
name = "cryptroot";
|
||||||
|
|
||||||
|
askPassword = true;
|
||||||
|
|
||||||
|
settings = {
|
||||||
|
allowDiscards = true;
|
||||||
|
};
|
||||||
|
|
||||||
|
extraFormatArgs = [
|
||||||
|
"--type"
|
||||||
|
"luks2"
|
||||||
|
"--pbkdf"
|
||||||
|
"argon2id"
|
||||||
|
"--label"
|
||||||
|
"NixOS-LUKS"
|
||||||
|
];
|
||||||
|
|
||||||
|
content = {
|
||||||
|
type = "btrfs";
|
||||||
|
extraArgs = [
|
||||||
|
"-f"
|
||||||
|
"-L"
|
||||||
|
"NixOS"
|
||||||
|
];
|
||||||
|
|
||||||
|
subvolumes = {
|
||||||
|
"@root" = {
|
||||||
|
mountpoint = "/";
|
||||||
|
mountOptions = btrfsMountOptions;
|
||||||
|
};
|
||||||
|
|
||||||
|
"@home" = {
|
||||||
|
mountpoint = "/home";
|
||||||
|
mountOptions = btrfsMountOptions;
|
||||||
|
};
|
||||||
|
|
||||||
|
"@nix" = {
|
||||||
|
mountpoint = "/nix";
|
||||||
|
mountOptions = btrfsMountOptions;
|
||||||
|
};
|
||||||
|
|
||||||
|
"@log" = {
|
||||||
|
mountpoint = "/var/log";
|
||||||
|
mountOptions = btrfsMountOptions;
|
||||||
|
};
|
||||||
|
|
||||||
|
"@swap" = {
|
||||||
|
mountpoint = "/.swapvol";
|
||||||
|
mountOptions = [
|
||||||
|
"noatime"
|
||||||
|
];
|
||||||
|
|
||||||
|
swap.swapfile.size = "32G";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -2,6 +2,7 @@
|
|||||||
imports = [
|
imports = [
|
||||||
./power.nix
|
./power.nix
|
||||||
./secure-boot.nix
|
./secure-boot.nix
|
||||||
|
./storage-crypto.nix
|
||||||
./uefi.nix
|
./uefi.nix
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,30 @@
|
|||||||
|
{
|
||||||
|
pkgs,
|
||||||
|
lib,
|
||||||
|
config,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
let
|
||||||
|
cfg = config.my.features.boot.storageCrypto;
|
||||||
|
in
|
||||||
|
{
|
||||||
|
options.my.features.boot.storageCrypto = {
|
||||||
|
enable = lib.mkEnableOption "LUKS decryption via TPM2";
|
||||||
|
};
|
||||||
|
|
||||||
|
config = lib.mkIf cfg.enable {
|
||||||
|
boot.initrd.systemd.enable = true;
|
||||||
|
|
||||||
|
boot.initrd.luks.devices.cryptroot = {
|
||||||
|
crypttabExtraOpts = [
|
||||||
|
"tpm2-device=auto"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
security.tpm2.enable = true;
|
||||||
|
|
||||||
|
environment.systemPackages = with pkgs; [
|
||||||
|
tpm2-tools # TPM2 management tools
|
||||||
|
];
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -1,3 +1,4 @@
|
|||||||
{
|
{
|
||||||
my.features.boot.secureBoot.enable = true;
|
my.features.boot.secureBoot.enable = true;
|
||||||
|
my.features.boot.storageCrypto.enable = true;
|
||||||
}
|
}
|
||||||
Reference in New Issue
Block a user