Your one-stop-cake-shop for everything Freshly Baked has to offer

feat(pm/redhead): enable secure boot #76

merged opened by a.starrysky.fyi targeting main from private/minion/push-mupytyywstsm

I want to make booting not need a PIN/security key press, and therefore I want to make sure that I'm booting only what is explicitly permitted.

Therefore, let's use lanzaboote! I've set it up before, so it's relatively simple

Labels

None yet.

requested-reviewers

None yet.

approved

None yet.

tested-working

None yet.

rejected

None yet.

assignee

None yet.

Participants 1
AT URI
at://did:plc:uuyqs6y3pwtbteet4swt5i5y/sh.tangled.repo.pull/3m2p4zwcdyi22
+6 -1
Interdiff #1 #2
packetmix/npins/sources.json

This file has not been changed.

+6 -1
packetmix/systems/redhead/lanzaboote.nix
··· 2 2 # 3 3 # SPDX-License-Identifier: MIT 4 4 5 - { project, pkgs, lib, ... }: 5 + { 6 + project, 7 + pkgs, 8 + lib, 9 + ... 10 + }: 6 11 { 7 12 imports = [ project.inputs.lanzaboote.result.nixosModules.lanzaboote ]; 8 13

History

3 rounds 0 comments
sign up or login to add to the discussion
1 commit
expand
feat(pm/redhead): enable secure boot
5/5 success
expand
expand 0 comments
pull request successfully merged
1 commit
expand
feat(pm/redhead): enable secure boot
1/5 failed, 1/5 timeout, 3/5 success
expand
expand 0 comments
1 commit
expand
feat(pm/redhead): enable secure boot
1/5 failed, 1/5 timeout, 3/5 success
expand
expand 0 comments