Encrypted swap

This commit is contained in:
Nathan McCarty 2025-03-27 01:41:39 -04:00
parent ae01142320
commit c739ecd895

View file

@ -1,57 +1,66 @@
# Do not modify this file! It was generated by nixos-generate-config # Do not modify this file! It was generated by nixos-generate-config
# and may be overwritten by future invocations. Please make changes # and may be overwritten by future invocations. Please make changes
# to /etc/nixos/configuration.nix instead. # to /etc/nixos/configuration.nix instead.
{ config, lib, pkgs, modulesPath, ... }:
{ {
imports = config,
[ (modulesPath + "/installer/scan/not-detected.nix") lib,
]; pkgs,
modulesPath,
...
}: {
imports = [
(modulesPath + "/installer/scan/not-detected.nix")
];
boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "usbhid" "sd_mod" ]; boot.initrd.availableKernelModules = ["xhci_pci" "ahci" "usbhid" "sd_mod"];
boot.initrd.kernelModules = [ ]; boot.initrd.kernelModules = [];
boot.kernelModules = [ "kvm-amd" ]; boot.kernelModules = ["kvm-amd"];
boot.extraModulePackages = [ ]; boot.extraModulePackages = [];
fileSystems."/" = fileSystems."/" = {
{ device = "/dev/disk/by-uuid/e9e1adfb-feb9-4456-80a0-d8d306b36145"; device = "/dev/disk/by-uuid/e9e1adfb-feb9-4456-80a0-d8d306b36145";
fsType = "btrfs"; fsType = "btrfs";
options = [ "subvol=root" ]; options = ["subvol=root"];
}; };
fileSystems."/nix" = fileSystems."/nix" = {
{ device = "/dev/disk/by-uuid/e9e1adfb-feb9-4456-80a0-d8d306b36145"; device = "/dev/disk/by-uuid/e9e1adfb-feb9-4456-80a0-d8d306b36145";
fsType = "btrfs"; fsType = "btrfs";
options = [ "subvol=nix" ]; options = ["subvol=nix"];
}; };
fileSystems."/var" = fileSystems."/var" = {
{ device = "/dev/disk/by-uuid/e9e1adfb-feb9-4456-80a0-d8d306b36145"; device = "/dev/disk/by-uuid/e9e1adfb-feb9-4456-80a0-d8d306b36145";
fsType = "btrfs"; fsType = "btrfs";
options = [ "subvol=var" ]; options = ["subvol=var"];
}; };
fileSystems."/home" = fileSystems."/home" = {
{ device = "/dev/disk/by-uuid/e9e1adfb-feb9-4456-80a0-d8d306b36145"; device = "/dev/disk/by-uuid/e9e1adfb-feb9-4456-80a0-d8d306b36145";
fsType = "btrfs"; fsType = "btrfs";
options = [ "subvol=home" ]; options = ["subvol=home"];
}; };
fileSystems."/etc" = fileSystems."/etc" = {
{ device = "/dev/disk/by-uuid/e9e1adfb-feb9-4456-80a0-d8d306b36145"; device = "/dev/disk/by-uuid/e9e1adfb-feb9-4456-80a0-d8d306b36145";
fsType = "btrfs"; fsType = "btrfs";
options = [ "subvol=etc" ]; options = ["subvol=etc"];
}; };
fileSystems."/boot" = fileSystems."/boot" = {
{ device = "/dev/disk/by-uuid/DE13-B03B"; device = "/dev/disk/by-uuid/DE13-B03B";
fsType = "vfat"; fsType = "vfat";
options = [ "fmask=0022" "dmask=0022" ]; options = ["fmask=0022" "dmask=0022"];
}; };
swapDevices = swapDevices = [
[ { device = "/dev/disk/by-uuid/fe4935bf-ae69-4529-87cd-1a913c346876"; } {
]; device = "/dev/disk/by-partuuid/d2899053-892b-49b1-b9e9-55df9b635862";
randomEncryption = {
enable = true;
};
}
];
# Enables DHCP on each ethernet and wireless interface. In case of scripted networking # Enables DHCP on each ethernet and wireless interface. In case of scripted networking
# (the default) this is the recommended approach. When using systemd-networkd it's # (the default) this is the recommended approach. When using systemd-networkd it's