"""Remote-unlockable LUKS boot configuration. Distro-agnostic orchestration; the init-system-specific steps live in the initramfs backends (mkinitcpio for Arch/Manjaro, initramfs-tools for Debian/Raspberry Pi OS). See lim/image/initramfs/. """ from pathlib import Path from lim import packages, ui from lim.image.initramfs import get_backend from lim.image.plan import ImagePlan from lim.image.session import ImageSession, install_packages def configure_encryption(plan: ImagePlan, session: ImageSession, authorized_keys: Path) -> None: root = session.root_mount_path backend = get_backend(plan.distribution) ui.info("Setup encryption...") ui.info("Installing neccessary software...") install_packages( plan.distribution, root, " ".join(packages.get_packages(backend.luks_package_collection())), ) backend.install_authorized_key(root, authorized_keys) if plan.tor_unlock: # Hook files and onion keys must exist before the initramfs is baked. backend.install_tor_unlock(plan, root) # crypttab must be written before the initramfs is (re)generated so the # Debian cryptsetup hook can bake the mapping in. backend.register_encrypted_root(plan, session, root) backend.configure_initramfs(plan, root) backend.configure_bootloader(plan, session, root)