{tree, ...}: { imports = with tree; [ presets.nixos.encryptedDrive ]; boot = { loader = { systemd-boot.enable = true; efi.canTouchEfiVariables = true; }; initrd.availableKernelModules = [ # defaults from nixos-generate-config "xhci_pci" "nvme" "usb_storage" "usbhid" "sd_mod" "rtsx_pci_sdmmc" ]; kernelModules = ["kvm-intel"]; encryptedDrive.mode = "password"; }; hardware.cpu.intel.updateMicrocode = true; }