idiosyn/nixos/module/physical.nix
2024-08-21 21:06:51 +02:00

19 lines
401 B
Nix

{ self, lanzaboote, ... }: { config, lib, pkgs, ... }: {
imports = [
lanzaboote.nixosModules.lanzaboote
] ++ (with self.nixosModules; [
nitrokey-random
]);
boot = {
loader.efi.canTouchEfiVariables = true;
lanzaboote = {
enable = true;
pkiBundle = lib.mkDefault "/etc/keys/secureboot";
};
};
security.tpm2.enable = true;
services.fwupd.enable = true;
}