Files
nix-fleet/modules/security/sys/secureboot.nix
2026-03-03 23:06:45 +01:00

17 lines
363 B
Nix

{ inputs, ... }: {
flake.nixosModules.security-sys-secureboot = { pkgs, lib, ... }: {
imports = [
inputs.lanzaboote.nixosModules.lanzaboote
];
environment.systemPackages = [ pkgs.sbctl ];
boot.loader.systemd-boot.enable = lib.mkForce false;
boot.lanzaboote = {
enable = true;
pkiBundle = "/var/lib/sbctl";
};
};
}