blob: a5469f43a47b4372d5d282a037bff4fab88ef4ab [file] [log] [blame]
{ pkgs, lanzaboote, lib, ... }: {
imports = [
lanzaboote.nixosModules.lanzaboote
];
config = {
boot = {
bootspec.enable = true;
loader.systemd-boot.enable = lib.mkForce false;
lanzaboote = {
enable = true;
pkiBundle = "/etc/secureboot";
};
};
environment = {
persistence."/nix/persist".directories = [
"/etc/secureboot"
];
systemPackages = [ pkgs.sbctl ];
};
};
}