dots/modules/linux/secureboot.nix
Nico 584e17361c nix: enable systemd in initrd
needed for drive decryption via TPM
2025-05-03 16:34:34 +10:00

17 lines
293 B
Nix

{ config, lib, pkgs, ... }:
{
environment.systemPackages = with pkgs; [
sbctl
];
boot.loader.systemd-boot.enable = lib.mkForce false;
boot.lanzaboote = {
enable = true;
pkiBundle = "/var/lib/sbctl";
};
# needed for tpm unlock
boot.initrd.systemd.enable = true;
}