TODO for #AuroraSprint:

- get LVM and Secure Boot signing to work in my NixOS image builder framework
- ( ) ~~LVM~~ (doubtful if feasible)
- (x) Secure Boot
- ( ) ~~write a systemd-veritysetup initrd module~~ (doubtful if this even makes sense)
- ( ) refactor upstream NixOS systemd-boot ESP generation script
- (x) extend initrd secrets module
- ( ) rewrite robotnix docs
- ( ) robotnix PKCS#11 token signing
- ( ) get NixNG to boot

#nix #nixos #embeddednixos