Flake for my NixOS devices
1{...}: {
2 inputs,
3 lib,
4 config,
5 ...
6}: {
7 imports = [inputs.lanzaboote.nixosModules.lanzaboote];
8
9 options.cow.lanzaboote.enable = lib.mkEnableOption "Use lanzaboote for booting and secure boot";
10
11 config.boot = lib.mkIf config.cow.lanzaboote.enable {
12 loader.systemd-boot.enable = lib.mkForce false;
13 bootspec.enable = true;
14
15 lanzaboote = {
16 enable = true;
17 pkiBundle = lib.mkDefault "/var/lib/sbctl";
18 };
19 };
20}