feat: are you feeling encrypted yet?

This commit is contained in:
etwas 2025-10-14 20:58:46 +02:00
parent 913e75cc33
commit 121da064eb
Signed by: etwas
SSH key fingerprint: SHA256:bHhIeAdn/2k9jmOs6+u6ox98VYmoHUN3HfnpV2w8Ws0

View file

@ -22,7 +22,12 @@
"usb_storage" "usb_storage"
"sd_mod" "sd_mod"
]; ];
kernelModules = [ ]; kernelModules = [
"dm-snapshot"
"cryptd"
];
luks.devices."cryptroot".device = "/dev/disk/by-label/nixos";
}; };
kernelModules = [ "kvm-amd" ]; kernelModules = [ "kvm-amd" ];
@ -31,12 +36,12 @@
}; };
fileSystems."/" = { fileSystems."/" = {
device = "/dev/disk/by-label/nix-root"; device = "/dev/disk/by-label/nixos-root";
fsType = "ext4"; fsType = "ext4";
}; };
fileSystems."/boot" = { fileSystems."/boot" = {
device = "/dev/disk/by-label/EFI"; device = "/dev/disk/by-label/nixos-boot";
fsType = "vfat"; fsType = "vfat";
options = [ options = [
"fmask=0077" "fmask=0077"
@ -44,7 +49,7 @@
]; ];
}; };
swapDevices = [ { device = "/dev/disk/by-label/swap"; } ]; swapDevices = [ { device = "/dev/disk/by-label/nixos-swap"; } ];
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
hardware.cpu.amd.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; hardware.cpu.amd.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;