Complete Electra's post-change Secure Boot recovery archive #42

Open
opened 2026-07-01 19:37:37 +01:00 by nimmo · 0 comments
Owner

Context

Electra's Secure Boot and TPM hardening is deployed and recovery-tested. The only remaining operational handoff is to create a final post-change archive so the off-host recovery material matches the validated configuration.

Scope

  • Capture current bootctl, sbctl, systemd-pcrlock, signature, and LUKS-token status.
  • Create the post-change encrypted recovery archives, including the required Secure Boot and LUKS recovery material.
  • Restore and inspect the new archives in a temporary test location.
  • Store the verified archives off-host and record where they are held without committing sensitive details.

Completion criteria

  • Current status captures and encrypted archives exist off-host.
  • A restore test confirms the archives are readable and complete.
  • The Secure Boot recovery playbook reflects the final archive contents and verification date.
## Context Electra's Secure Boot and TPM hardening is deployed and recovery-tested. The only remaining operational handoff is to create a final post-change archive so the off-host recovery material matches the validated configuration. ## Scope - Capture current `bootctl`, `sbctl`, systemd-pcrlock, signature, and LUKS-token status. - Create the post-change encrypted recovery archives, including the required Secure Boot and LUKS recovery material. - Restore and inspect the new archives in a temporary test location. - Store the verified archives off-host and record where they are held without committing sensitive details. ## Completion criteria - Current status captures and encrypted archives exist off-host. - A restore test confirms the archives are readable and complete. - The Secure Boot recovery playbook reflects the final archive contents and verification date.
Sign in to join this conversation.
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
nimmo/nixos-config#42
No description provided.