Flake for my NixOS devices
at main 20 lines 446 B view raw
1{...}: { 2 inputs, 3 lib, 4 config, 5 ... 6}: { 7 imports = [inputs.lanzaboote.nixosModules.lanzaboote]; 8 9 options.cow.lanzaboote.enable = lib.mkEnableOption "Use lanzaboote for booting and secure boot"; 10 11 config.boot = lib.mkIf config.cow.lanzaboote.enable { 12 loader.systemd-boot.enable = lib.mkForce false; 13 bootspec.enable = true; 14 15 lanzaboote = { 16 enable = true; 17 pkiBundle = lib.mkDefault "/var/lib/sbctl"; 18 }; 19 }; 20}