From 7a6f4790282d001e2c7adbdaa4806f8beed02ddb Mon Sep 17 00:00:00 2001 From: Alejandro Soto Date: Wed, 23 Jul 2025 20:37:33 -0600 Subject: sys/boot: rename sb.nix -> secure-boot.nix --- sys/boot/sb.nix | 37 ------------------------------------- 1 file changed, 37 deletions(-) delete mode 100644 sys/boot/sb.nix (limited to 'sys/boot/sb.nix') diff --git a/sys/boot/sb.nix b/sys/boot/sb.nix deleted file mode 100644 index bdf7f0f..0000000 --- a/sys/boot/sb.nix +++ /dev/null @@ -1,37 +0,0 @@ -{ config, lib, pkgs, ... }: -with lib; let - cfg = config.local.boot.secureBoot; -in -{ - options.local.boot.secureBoot = { - enable = mkEnableOption "secure boot"; - }; - - config = mkIf cfg.enable { - assertions = [ - { - assertion = config.local.boot.efi.enable; - message = "secure boot requires EFI"; - } - { - assertion = config.local.boot.loader == "systemd-boot"; - message = "lanzaboote requires systemd-boot"; - } - ]; - - boot = { - loader.systemd-boot.enable = mkForce false; - - lanzaboote = { - enable = true; - pkiBundle = "/etc/secureboot"; - }; - }; - - environment.systemPackages = [ - pkgs.sbctl - ]; - - local.boot.impermanence.directories = [ "/etc/secureboot" ]; - }; -} -- cgit v1.2.3