nixfiles/nixos/profiles/secureboot.nix

20 lines
294 B
Nix

{
pkgs,
lib,
...
}: let
inherit (lib.modules) mkForce;
in {
environment.systemPackages = with pkgs; [
sbctl
];
boot = {
loader = {
systemd-boot.enable = mkForce false;
};
lanzaboote = {
enable = true;
pkiBundle = "/etc/secureboot";
};
};
}