Files
linux-image-manager/lim/image/encryption.py

38 lines
1.3 KiB
Python
Raw Normal View History

"""Remote-unlockable LUKS boot configuration.
Distro-agnostic orchestration; the init-system-specific steps live in the
initramfs backends (mkinitcpio for Arch/Manjaro, initramfs-tools for
Debian/Raspberry Pi OS). See lim/image/initramfs/.
"""
from pathlib import Path
from lim import packages, ui
from lim.image.initramfs import get_backend
from lim.image.plan import ImagePlan
from lim.image.session import ImageSession, install_packages
def configure_encryption(plan: ImagePlan, session: ImageSession, authorized_keys: Path) -> None:
root = session.root_mount_path
backend = get_backend(plan.distribution)
ui.info("Setup encryption...")
ui.info("Installing neccessary software...")
install_packages(
plan.distribution,
root,
" ".join(packages.get_packages(backend.luks_package_collection())),
)
backend.install_authorized_key(root, authorized_keys)
if plan.tor_unlock:
# Hook files and onion keys must exist before the initramfs is baked.
backend.install_tor_unlock(plan, root)
# crypttab must be written before the initramfs is (re)generated so the
# Debian cryptsetup hook can bake the mapping in.
backend.register_encrypted_root(plan, session, root)
backend.configure_initramfs(plan, root)
backend.configure_bootloader(plan, session, root)