!JQvnJacrwKgtkGHYHO:matrix.org

NixOS + Framework

225 Members
Discussing NixOS in the context of the Framework laptop50 Servers

Load older messages


SenderMessageTime
10 May 2026
@sudoforge:matrix.orgsudoforgei didn't see encryption configuration in the config you shared earlier. did i miss it?21:01:38
@sudoforge:matrix.orgsudoforgeoh, so i did21:01:51
@sudoforge:matrix.orgsudoforgeoops21:01:51
@albertlarsan68:albertlarsan.frAlbert LarsanThere is luks, but with default-iish configs21:02:10
@sudoforge:matrix.orgsudoforgeyeah, which will just ask for a passphrase21:02:24
@sudoforge:matrix.orgsudoforgei'm tracking now21:02:32
@sudoforge:matrix.orgsudoforge trumee the fido2 support landed 3 weeks ago, and unfortunately a release hasn't been cut yet 21:03:18
@sudoforge:matrix.orgsudoforgewhich is why "latest" didn't work for you21:03:25
@albertlarsan68:albertlarsan.frAlbert LarsanEven the second disk is crypted. I would have loved to make a key file work, but despite trying for a week I couldn’t, so it also has a passphrase and unlocks from tpmk21:03:35
@sudoforge:matrix.orgsudoforgein multi-disk systems i just use the same passphrase21:03:54
@sudoforge:matrix.orgsudoforgecryptsetup caches it when unlocking, so, it's not too painful if i ever do need to manually enter it21:04:24
@sudoforge:matrix.orgsudoforge* in multi-disk systems i just use the same passphrase for all of the disks21:04:44
@albertlarsan68:albertlarsan.frAlbert LarsanIt is the same passphrase, but it must boot automatically, without passphrases.21:05:07
@sudoforge:matrix.orgsudoforgeyep21:05:24
@sudoforge:matrix.orgsudoforgefor that, i use clevis + tang21:05:29
@albertlarsan68:albertlarsan.frAlbert LarsanAnd I use not enough PCRs on my TPM.21:19:19
@sudoforge:matrix.orgsudoforge:(21:24:56
@sudoforge:matrix.orgsudoforgePCRs that are a little looser for a server make a certain sense, but21:27:27
@sudoforge:matrix.orgsudoforgei would strongly encourage you to research clevis+tang and move to that21:27:39
@albertlarsan68:albertlarsan.frAlbert LarsanI am really unsure of which ones to use with lanzaboote21:27:46
@albertlarsan68:albertlarsan.frAlbert LarsanMy servers are in multiple locations, with independant internet accesses21:28:08
@sudoforge:matrix.orgsudoforgemy servers are all onprem (in a rack in my home). my tang server is my laptop21:28:54
@albertlarsan68:albertlarsan.frAlbert LarsanSo they all are on a single LAN21:29:44
@sudoforge:matrix.orgsudoforgei'm always able to have my laptop "on the network" even when i'm traveling, so even if a machine goes down and needs to reboot, i can start the tang server (this is ephemeral by design; it is not always available) and voila, the servers can decrypt the disks21:29:52
@albertlarsan68:albertlarsan.frAlbert LarsanMine are across 4 LANs, with ISP-provided routers.21:30:36
@sudoforge:matrix.orgsudoforgeand yep, all my servers are in a single LAN21:30:45
@sudoforge:matrix.orgsudoforgeinteresting - family homes?21:30:49
@sudoforge:matrix.orgsudoforgei'm "netflix" for my family, and have a small node with some storage that acts as a pull-through cache to my storage cluster (ceph) via a persistent wg tunnel21:31:38
@sudoforge:matrix.orgsudoforgeso, even those remote nodes are "on the LAN"21:31:45
@albertlarsan68:albertlarsan.frAlbert LarsanMy home, my grandparents’ home, and a school/work server room (this one I can touch the router, and I might grab a free IPv4 for the laptop there)21:32:11

Show newer messages


Back to Room ListRoom Version: 10