diff options
Diffstat (limited to 'modules/system/nixos/boot.nix')
| -rw-r--r-- | modules/system/nixos/boot.nix | 89 |
1 files changed, 89 insertions, 0 deletions
diff --git a/modules/system/nixos/boot.nix b/modules/system/nixos/boot.nix new file mode 100644 index 0000000..b7f5266 --- /dev/null +++ b/modules/system/nixos/boot.nix @@ -0,0 +1,89 @@ +{ + pkgs, + config, + lib, + ... +}: let + cfg = config.collinux.system.boot; +in { + boot = + { + bcache.enable = false; # why is this default on? I DON'T CARE ABOUT bcachefs + initrd = { + verbose = false; + systemd.enable = true; + checkJournalingFS = false; + }; + loader = { + systemd-boot = lib.optionalAttrs (cfg.systemd-boot.enable && !cfg.secureBoot.enable) { + enable = true; + configurationLimit = 3; + }; + efi.canTouchEfiVariables = true; + timeout = cfg.timeout; # hold space to show boot menu if timeout == 0 + }; + + plymouth = lib.mkIf cfg.plymouth.enable { + enable = true; + theme = + if (cfg.plymouth.theme == "catppuccin") + then "catppuccin-macchiato" # for whatever reason catppuccin-mocha has errors + else "nixos-bgrt"; + themePackages = + if (cfg.plymouth.theme == "catppuccin") + then [pkgs.catppuccin-plymouth] + else [pkgs.nixos-bgrt-plymouth]; + }; + + # from hardened.nix + blacklistedKernelModules = [ + # Obscure network protocols + "ax25" + "netrom" + "rose" + + # Old or rare or insufficiently audited filesystems + "adfs" + "affs" + "bfs" + "befs" + "cramfs" + "efs" + # "erofs" # necessary for system.etc.overlay + "exofs" + "freevxfs" + "f2fs" + "hfs" + "hpfs" + "jfs" + "minix" + "nilfs2" + "ntfs" + "omfs" + "qnx4" + "qnx6" + "sysv" + "ufs" + ]; + } + // (lib.optionalAttrs cfg.secureBoot.enable { + lanzaboote = { + enable = true; + pkiBundle = "/var/lib/sbctl"; + }; + }); + + system.etc.overlay = { + enable = true; + mutable = true; # would love this to be false, but we're not there yet + }; + system.nixos-init.enable = true; + + # store journald logs in memory + services.journald.extraConfig = '' + Storage=volatile + RuntimeMaxUse=100M + ''; + + environment.systemPackages = [pkgs.efibootmgr] ++ lib.optional cfg.secureBoot.enable pkgs.sbctl; +} |
