nixos-config/nixos/profiles/system/boot/secure-boot.nix

14 lines
290 B
Nix
Raw Normal View History

2024-11-28 01:14:34 +08:00
{ pkgs, lib, ... }:
{
environment.systemPackages = with pkgs; [ sbctl ];
boot.loader.systemd-boot.enable = lib.mkForce false;
boot.lanzaboote = {
enable = true;
pkiBundle = "/etc/secureboot";
};
preservation.preserveAt."/persist".directories = [ "/etc/secureboot" ];
2024-11-28 01:14:34 +08:00
}