aboutsummaryrefslogtreecommitdiff
path: root/profiles/secureboot.nix
blob: 53df8e3c5503d007e07bf5443ecb917ee32271d5 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
{ pkgs, lib, ... }:
{
  environment.persistence."/persist/save".directories = [
    "/var/lib/sbctl"
  ];

  environment.systemPackages = [
    pkgs.sbctl
  ];

  boot.loader.systemd-boot.enable = lib.mkForce false;

  boot.lanzaboote = {
    enable = true;
    pkiBundle = "/var/lib/sbctl";
  };
}