r/NixOS • • 1d ago

[AYUDA] initrd con systemd-cryptenroll + lanzaboote + impermanence sobre ZFS se cuelga en stage 1

Llevo 3 días con esto y ya no sé qué más probar.

Uso NixOS con flakes, boot.initrd.systemd.enable = true, root en tmpfs con impermanence y /persist en ZFS con cifrado nativo, desbloqueado por TPM2 con systemd-cryptenroll.

El problema: sops-nix intenta leer la age key de /persist antes de que el dataset esté montado, y encima el PCR 7 cambia con cada actualización de firmware, así que el TPM2 deja de desbloquear y me cae en el emergency shell.

Ya descarté un problema de ZFS porque, como está en el kernel mainline, no debería haber incompatibilidades con mi kernel parcheado con linux-hardened.

Probé la misma config en Gentoo con OpenRC y funciona perfecto, pero no pienso volver a eso.

¿Alguien lo ha resuelto sin usar Secure Boot con claves propias? Ya me estoy planteando que la solución real es instalar Arch. 😔

4 Upvotes

4 comments sorted by

3

u/daluca0x2F 1d ago

fileSystems."/persist".neededForBoot = true; This will mount the partition earlier so sops-nix can read secrets

3

u/Old_Switch_1122 1d ago

Gracias, neededForBoot es justo lo que hacía falta para ese pedazo. Lo dejo anotado.

3

u/ElvishJerricco 1d ago

How could you be using systemd-cryptenroll with ZFS native encryption? That's a LUKS thing and isn't usable for ZFS native encryption. Also, just FYI, most people get the TPM stuff very wrong and are vulnerable to this type of issue: https://oddlama.org/blog/bypassing-disk-encryption-with-tpm2-unlock/ And it's even harder to do right with ZFS native encryption because it's not just the disk that can move / have its identifier copied, but datasets on the disk can also be moved.

2

u/Old_Switch_1122 1d ago

Tienes razón, cryptenroll es de LUKS2 y no aplica al cifrado nativo de ZFS. Gracias por el enlace, está muy bueno.