{ lib, ... }: { | |
boot = { | |
supportedFilesystems = [ "ntfs" ]; | |
bootspec.enable = true; | |
loader.systemd-boot = { | |
enable = lib.mkForce false; | |
}; | |
lanzaboote = { | |
enable = true; | |
pkiBundle = "/etc/secureboot"; | |
settings = { | |
auto-entries = true; | |
}; | |
}; | |
loader.efi.canTouchEfiVariables = true; | |
}; | |
} |