added lanzaboote.nix for secure boot

This commit is contained in:
kenji
2025-08-14 15:13:56 -05:00
parent bc268218a5
commit e1cf3ad59d
5 changed files with 254 additions and 1 deletions
+27
View File
@@ -0,0 +1,27 @@
# file: configuration.nix
{
pkgs,
lib,
...
}: let
sources = import ./nix/sources.nix;
lanzaboote = import sources.lanzaboote;
in {
imports = [lanzaboote.nixosModules.lanzaboote];
environment.systemPackages = [
# For debugging and troubleshooting Secure Boot.
pkgs.sbctl
];
# Lanzaboote currently replaces the systemd-boot module.
# This setting is usually set to true in configuration.nix
# generated at installation time. So we force it to false
# for now.
boot.loader.systemd-boot.enable = lib.mkForce false;
boot.lanzaboote = {
enable = true;
pkiBundle = "/var/lib/sbctl";
};
}