fingerprint

This commit is contained in:
2026-07-27 20:57:15 +09:00
parent fcd0d75537
commit 9bb95535cf
5 changed files with 46 additions and 31 deletions
+5 -4
View File
@@ -38,15 +38,16 @@ when removing it from any supported host would make that host invalid.
| `workload.server` | NixOS, macOS with Home Manager |
| `networking.tailscale-client` | NixOS, macOS |
| `networking.tailscale-subnet-router` | NixOS |
| `security.fingerprint` | NixOS, macOS |
| `security.secrets` | NixOS, macOS |
| `security.secure-boot` | NixOS |
| `security.tpm-storage` | NixOS with a host-defined LUKS device |
Select independent concerns independently in `hosts/default.nix`. For example,
a NixOS laptop can combine `base`, `platform.thinkpad-x1`,
`interface.cli`, and `interface.niri`, while a macOS host can combine
`base`, `interface.cli`, and cross-platform workloads. A graphical profile does
not implicitly select a CLI profile or personal applications.
a minimal NixOS laptop can combine `base`, `platform.thinkpad-x1`, and
`interface.cli`, while a daily-use macOS development machine can add
`workload.development` and `workload.personal`. Hardware support does not
implicitly select an interface or workload.
`security.tpm-storage` deliberately does not own a disk identifier. A host that
selects it must define `boot.initrd.luks.devices.cryptroot.device` in its
@@ -5,6 +5,5 @@
"profiles.platform.laptop"
"hardwares.intel-driver"
"hardwares.ipu6-camera"
"systems.fingerprint"
];
}
@@ -0,0 +1,5 @@
{
description = "Fingerprint authentication for NixOS and macOS";
includes = [ "systems.fingerprint" ];
}