Autologin, unlock the keyring with the luks password

Signed-off-by: Hadi <112569860+anotherhadi@users.noreply.github.com>
This commit is contained in:
Hadi
2026-08-14 10:43:40 +02:00
parent 9baaaa2bfe
commit e58bb947d3
2 changed files with 28 additions and 0 deletions
+27
View File
@@ -0,0 +1,27 @@
# Autologin at boot: greetd starts your session directly on the first VT
{
pkgs,
config,
lib,
...
}: {
services.greetd.settings.initial_session = {
command = "${pkgs.uwsm}/bin/uwsm start -e -D Hyprland hyprland.desktop";
user = config.var.username;
};
# Needed so the LUKS passphrase entered at boot is cached in the kernel
# keyring, where pam_fde_boot_pw can retrieve it (see below).
boot.initrd.systemd.enable = true;
security.pam.services.greetd.rules.session.fde_boot_pw = {
order = 12550; # kwallet=12500, gnome_keyring=12600: must run in between
control = "optional";
modulePath = "${pkgs.pam_fde_boot_pw}/lib/security/pam_fde_boot_pw.so";
args = ["inject_for=gkr"];
};
security.pam.services.login.enableGnomeKeyring = true;
systemd.services.greetd.serviceConfig.KeyringMode = lib.mkForce "shared";
}