LUKS is only one part of the boot chain 2026-10-07 1. Map what starts first 2. Separate keys from integrity 3. Prove recovery on a VM BLANK WORKSHEET Boot components and their locations: ____________________ Threat and protection being claimed: ____________________ Evidence and recovery result: ____________________ ILLUSTRATIVE EXAMPLE Boot components and their locations: Firmware → EFI loader → kernel/initrd → encrypted store. Threat and protection being claimed: Offline disk reading is different from tampering with boot files. Evidence and recovery result: Not tested on this machine: preserve a passphrase recovery route. Primary context and limits NixOS stable manual: encrypted filesystems — https://nixos.org/manual/nixos/stable/ Official NixOS Wiki: Secure Boot — https://wiki.nixos.org/wiki/Secure_Boot