I thought it's some people defending LTT/LMG after their latest stunt (possibly single-handedly killing a startup)
Linked post is also locked for some reason
Follow the Arch wiki. Just make sure that your distro has a hook for the package manager for signing the kernel. Eg. for Arch there's the systemd-boot-pacman-hook aur package.
It's not hard to set it up with a LUKS-enabled system, just put the relevant kernel parameters in your /esp/loader/entries/entry.conf file.
For example, here's my arch.conf entry (with LVM on LUKS):
title Arch Linux
linux /vmlinuz-linux
initrd /intel-ucode.img
initrd /initramfs-linux.img
options loglevel=2 quiet splash cryptdevice=PARTLABEL=partlabel-from-blkid:pvname root=/dev/mapper/rootlvname rw
If your keys are already enrolled, you can just use sbctl sign-all once, your package manager hook should do the rest.
Overall, the general directory structure should look like this in the end (files omitted):
I've tried to set up rEFInd but couldn't get the proper configs / kernel parameters to work for my LUKS-enabled setup. If you're willing to try another loader out, I was able to make systemd-boot work with both plymouth (flicker-less loading), luks (with graphical prompt), and secure boot too.
Tumbleweed solves the first issue as well by running BTRFS by default on root with snapper configured. I’ve done a few rollbacks in the 3-4 years I’ve used it, and it’s way better than trying to fix an Arch system with pacman. I could get the same effect with Arch, but most users aren’t going to consider BTRFS or ZFS on root with Arch (I had BTRFS on /home on Arch, but that didn’t help much).
What about LVM snapshots? I assume everyone sets up LVM nowadays anyway.
Reading the docs it feels close to markdown, but most markdown implementations have a much simpler format for code blocks with syntax specified:
``javascript
$var = "ooh, cool code, bro.";
``
Will turn into:
js
$var = "ooh, cool code, bro.";
(Though lemmy-ui doesn't seem to support syntax highlighting.)
I thought it's some people defending LTT/LMG after their latest stunt (possibly single-handedly killing a startup)
Linked post is also locked for some reason