nixos-config/nixos/profiles/system/boot/secure-boot.nix

17 lines
325 B
Nix
Raw Normal View History

2024-11-28 01:14:34 +08:00
{ pkgs, lib, ... }:
{
environment.systemPackages = with pkgs; [ sbctl ];
boot.loader.systemd-boot.enable = lib.mkForce false;
boot.lanzaboote = {
enable = true;
pkiBundle = "/etc/secureboot";
};
environment.etc."secureboot" = {
source = "/persist/etc/secureboot";
mode = "direct-symlink";
};
2024-11-28 01:14:34 +08:00
}