diff --git a/hosts/sachiel/configuration.nix b/hosts/sachiel/configuration.nix index 5380db8..17d37a1 100644 --- a/hosts/sachiel/configuration.nix +++ b/hosts/sachiel/configuration.nix @@ -11,7 +11,7 @@ # You can import other NixOS modules here imports = with inputs; [ # If you want to use modules your own flake exports (from modules/nixos): - # outputs.nixosModules.example + outputs.nixosModules.boot outputs.nixosModules.agenix # Or modules from other flakes (such as nixos-hardware): @@ -37,27 +37,12 @@ ./hardware-configuration.nix ]; - environment.persistence."/persistent" = { - enable = true; - hideMounts = true; - directories = [ - "/var/log" - "/var/lib/nixos" - "/var/lib/sbctl" - "/var/lib/systemd/coredump" - "/var/lib/systemd/timers" - "/var/lib/systemd/timesync" - "/var/lib/bluetooth" - "/var/lib/dbus" - "/etc/NetworkManager" - ]; - files = [ - "/etc/machine-id" - "/etc/ssh/ssh_host_ed25519_key" - "/etc/ssh/ssh_host_ed25519_key.pub" - "/etc/ssh/ssh_host_rsa_key" - "/etc/ssh/ssh_host_rsa_key.pub" - ]; + system = { + impermanence.enable = true; + boot = { + enable = true; + secureBoot = true; + }; }; swapDevices = [ { @@ -122,17 +107,19 @@ boot.lanzaboote = { enable = true; - pkiBundle = "/var/lib/sbctl"; + pkiBundle = "/etc/secureboot"; autoGenerateKeys.enable = true; - autoEnrollKeys = { - includeMicrosoftKeys = false; - allowBrickingMyMachine = true; - enable = true; - autoReboot = true; - }; + # autoEnrollKeys = { + # includeMicrosoftKeys = false; + # allowBrickingMyMachine = true; + # enable = true; + # autoReboot = true; + # }; }; - boot.initrd.systemd.enable = true; + # Load the TPM drivers in the initram to allow for decryption of agenix + # secrets. + boot.initrd.availableKernelModules = ["tpm_crb" "tpm_tis"]; boot.initrd.systemd.services.rollback = { description = "Rollback BTRFS root subvolume to a pristine state"; wantedBy = ["initrd.target"]; @@ -375,7 +362,6 @@ environment.systemPackages = with pkgs; [ binutils git - sbctl uutils-coreutils-noprefix wget ]; diff --git a/modules/nixos/boot/default.nix b/modules/nixos/boot/default.nix new file mode 100644 index 0000000..475b74e --- /dev/null +++ b/modules/nixos/boot/default.nix @@ -0,0 +1,53 @@ +{ + config, + lib, + pkgs, + ... +}: +with lib; let + cfg = config.system.boot; +in { + options.system.boot = { + enable = + mkEnableOption "Enable boot"; + + secureBoot = mkEnableOption "Enable secure boot"; + }; + + config = mkIf cfg.enable { + boot = { + lanzaboote = mkIf cfg.secureBoot { + enable = true; + pkiBundle = "/etc/secureboot"; + + autoGenerateKeys.enable = true; + autoEnrollKeys = { + includeMicrosoftKeys = false; + # TODO: only enable on VM's, VM module coming soon + allowBrickingMyMachine = true; + enable = true; + autoReboot = true; + }; + }; + loader.systemd-boot = { + enable = !cfg.secureBoot; + configurationLimit = 10; + editor = false; + }; + }; + environment.systemPackages = with pkgs; + [ + # efibootmgr + # efitools + # efivar + ] + ++ optionals cfg.secureBoot [sbctl]; + environment.persistence = mkIf (cfg.secureBoot && config.system.impermanence.enable) { + "/persist" = { + directories = [ + "/etc/secureboot" + ]; + }; + }; + }; +} diff --git a/modules/nixos/default.nix b/modules/nixos/default.nix index 63eba8c..8d5ba3b 100644 --- a/modules/nixos/default.nix +++ b/modules/nixos/default.nix @@ -4,4 +4,5 @@ # List your module files here # my-module = import ./my-module.nix; agenix = import ./agenix/default.nix; + boot = import ./boot/default.nix; }