nix-conf/system/modules/secure-boot.nix
2026-01-10 12:46:40 +08:00

15 lines
273 B
Nix
Executable file

{ pkgs, lib, ... }:
{
environment.systemPackages = with pkgs; [
sbctl
];
boot = {
loader.systemd-boot.enable = lib.mkForce false;
lanzaboote = {
enable = true;
autoGenerateKeys.enable = true;
pkiBundle = "/var/lib/sbctl";
};
};
}