secure boot

This commit is contained in:
2025-11-05 02:13:02 +09:00
parent dfe2ab6381
commit 572a0f4811
8 changed files with 192 additions and 3 deletions
+17
View File
@@ -0,0 +1,17 @@
{ inputs, pkgs, lib, ... }:
{
imports = [
inputs.lanzaboote.nixosModules.lanzaboote
];
boot.loader = {
systemd-boot.enable = lib.mkForce false;
efi.canTouchEfiVariables = true;
efi.efiSysMountPoint = "/boot";
};
boot.lanzaboote = {
enable = true;
pkiBundle = "/var/lib/sbctl";
};
}