{ config, lib, ... }: let inherit (lib) mkDefault mkEnableOption; cfg = config.unexplrd.boot.tpmDiskUnlock; in { options.unexplrd.boot.tpmDiskUnlock.enable = mkEnableOption "TPM2 disk unlock support"; config = { boot.initrd.systemd.tpm2.enable = mkDefault cfg.enable; }; }