!tCyGickeVqkHsYjWnh:nixos.org

NixOS Networking

898 Members
on your Router! Declaratively manage your switching, routing, wireless, tunneling and more.262 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
30 Jul 2025
@hexa:lossy.networkhexathe threat modelling on this is pretty clear19:38:24
@emilazy:matrix.orgemilywell, that's the less effective option :D19:38:28
@emilazy:matrix.orgemilybut yes19:38:30
@emilazy:matrix.orgemilywe have had support for this in NixOS for years19:38:39
@hexa:lossy.networkhexaright19:38:41
@denkn:denkn.atDenKnthan you could also install a second system with a full nixos, which will be booted first. than you use containers for the encrypted services.19:39:35
@hexa:lossy.networkhexathe discussion is about bringing parity for network configuration options between the running system and the initrd, no need to question everything from first principles19:41:08
@denkn:denkn.atDenKnyes, than you have only one network config19:48:42
@emilazy:matrix.orgemilythis is initrd except worse19:50:09
@emilazy:matrix.orgemilysince you can easily verify initrd with secure boot/attestation19:50:18
@hexa:lossy.networkhexaor at least the one you are already familiar with19:51:38
@hexa:lossy.networkhexa* or at least the configuration stack one you are already familiar with19:51:47
@denkn:denkn.atDenKnThere are a filesystem/dm-module with no encryption, but with signing?20:12:57
@k900:0upti.meK900There are options, yes20:14:35
@emilazy:matrix.orgemily(with complicated trade-offs)20:16:13
@emilazy:matrix.orgemily(and not ones that are easy to deploy mutable NixOS systems to)20:16:19
@denkn:denkn.atDenKnI do not need encryption, but signing would be interesting in such cases. I only want to mount encrypted data, but mostly the system could be only signed20:18:30
@emilazy:matrix.orgemilydm-verity is used for this in production20:20:33
@emilazy:matrix.orgemilybut is only really suitable for image deploys20:20:37
@emilazy:matrix.orgemilyfs-verity has potential for mutable systems but is complicated to close the gap with20:20:47

Show newer messages


Back to Room ListRoom Version: 6