!tCyGickeVqkHsYjWnh:nixos.org

NixOS Networking

909 Members
Declaratively manage your switching, routing, wireless, tunneling and more.271 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
30 Jul 2025
@emilazy:matrix.orgemilysince you can easily verify initrd with secure boot/attestation19:50:18
@hexa:lossy.networkhexaor at least the one you are already familiar with19:51:38
@hexa:lossy.networkhexa* or at least the configuration stack one you are already familiar with19:51:47
@denkn:denkn.atDenKnThere are a filesystem/dm-module with no encryption, but with signing?20:12:57
@k900:0upti.meK900There are options, yes20:14:35
@emilazy:matrix.orgemily(with complicated trade-offs)20:16:13
@emilazy:matrix.orgemily(and not ones that are easy to deploy mutable NixOS systems to)20:16:19
@denkn:denkn.atDenKnI do not need encryption, but signing would be interesting in such cases. I only want to mount encrypted data, but mostly the system could be only signed20:18:30
@emilazy:matrix.orgemilydm-verity is used for this in production20:20:33
@emilazy:matrix.orgemilybut is only really suitable for image deploys20:20:37
@emilazy:matrix.orgemilyfs-verity has potential for mutable systems but is complicated to close the gap with20:20:47

Show newer messages


Back to Room ListRoom Version: 6