ctucx.git: nixfiles

ctucx' nixfiles

commit dd80411f1348f0653517a99f87f49231643835df
parent bf5abfcbb4d9c7d9497e922422cf6f7b7c0b0d39
Author: Katja (ctucx) <git@ctu.cx>
Date: Sun, 1 Dec 2024 18:03:06 +0100

machines/seifenkiste: add lanzaboote
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/machines/seifenkiste/default.nix b/machines/seifenkiste/default.nix
@@ -13,9 +13,14 @@
   ctucxConfig.monitoring.exporters.enable = true;
 
   boot = {
-    loader.systemd-boot.enable = true;
+    loader.systemd-boot.enable = lib.mkForce false;
     loader.efi.canTouchEfiVariables = true;
 
+    lanzaboote = {
+      enable = true;
+      pkiBundle = "/etc/secureboot";
+    };
+
     kernelPackages = pkgs.linuxPackages_latest;
   };