nixos-config/nixos/profiles/system/boot/secure-boot.nix
2024-11-28 01:14:34 +08:00

14 lines
285 B
Nix

{ pkgs, lib, ... }:
{
environment.systemPackages = with pkgs; [ sbctl ];
boot.loader.systemd-boot.enable = lib.mkForce false;
boot.lanzaboote = {
enable = true;
pkiBundle = "/etc/secureboot";
};
environment.globalPersistence.directories = [ "/etc/secureboot" ];
}