Arch with LVM in LUKs
My installation notes
Introduction
This org file describes how I get Arch up and running.
To give an upfront overview of what kind of setup these steps result in:
| Mount Point | Partition | Partition type | Size |
|---|---|---|---|
/boot |
/dev/efi_system_partition |
EFI system partition | 1 GiB |
[SWAP] |
/dev/swap_partition |
Linux swap | 4 Gib |
/ |
/dev/root_partition |
Linux x86-64 root (/) |
Remainder of device |
- bootloader
grub- networking
- NetworkManager will be used for the networking [ This is a laptop install and my networking skills are non-existent. ]
- hibernation
- to the encrypted swap partition
- encryption
The root and swap The partition mounted at root
(/) will be encrypted with LUKS. That partition will then be further divided with LVM to create two virtual partitions within the encrypted LUKS partition. One of those will be the file system root, the other will be used for swap.Since hibernation will use the swap, I want the swap to be encrypted.
- login greeter
- none
- WM
- sway / wayland
Regardless of the distribution, there are common post-installation steps that often need to be done, such as setting up the firewall, configuring web browsers, etc. As these steps aren't really Arch-specific, I have separate notes for that.
Prerequisites
There are a couple of things that would be nice to have out of the way up front.
Disable SecureBoot on the installation target.
There are guides on setting up secure boot both on the gentoo wiki and the arch wiki. It does seem like you can set up secure boot to work without phoning home to microsoft, but I haven't figured out how to do this yet.- Peruse the official installation guide.
Preparing a bootable USB
These steps all occur on a separate, already working, machine. I
assume Linux and bash. Roughly the process is:
- obtain an
.isoimage along with verification hashes - verify the
.isomatches the provided verification hashes - make a bootable USB drive from the
.iso
Obtaining an OS image
Downloading and verifying the image is something that can be
scripted. So the below steps are all wrapped in a bash script I can
run whenever I need to pull a new .iso.
First, I make a working directory to provide a stable path. I didn't
put it in /tmp because I'd like to keep .iso files around until I am
sure I am ready to delete them.
ISO_RELEASE_URL='https://fastly.mirror.pkgbuild.com/iso/latest/'
ISO_AT="${ISO_AT:=$(grep -m1 -o 'archlinux-20.*.iso' <(curl -s ${ISO_RELEASE_URL}) | cut -d'-' -f 2)}"
ISO_CURRENT="archlinux-${ISO_AT}-x86_64.iso"
function create_working_dir() {
local dir=${dir:="$HOME/arch/arch-install-${ISO_AT}"}
export arch_working_dir="${dir}"
mkdir -p "${dir}"
}
create_working_dir
echo "working dir: $arch_working_dir" | sed -e "s/$USER/a-user/"
cd "${arch_working_dir}"
working dir: /home/a-user/arch/arch-install-2026.09.01
The next thing to do is download the .iso, and the associated
signatures and hashes, from the downloads page into the working
directory.
There isn't an official archlinux.org download URL like there is with
Gentoo, but there are many mirrors available on the downloads page.
function fetch_latest_iso() {
local dir="$HOME/arch/arch-install-${ISO_AT}"
for file in "${ISO_CURRENT}" "${ISO_CURRENT}.sig" "b2sums.txt" "sha256sums.txt"; do
curl --skip-existing --silent -o "$dir/$file" "$ISO_RELEASE_URL/$file"
printf 'Downloaded %s\n' "$file"
done
}
fetch_latest_iso
Downloaded archlinux-2026.09.01-x86_64.iso Downloaded archlinux-2026.09.01-x86_64.iso.sig Downloaded b2sums.txt Downloaded sha256sums.txt
Before making the bootable USB from these files, I'll do my best to
verify their authenticity using gpg and the provided checksums.
I don't have a personally verified gpg key, so the best I can do is importing from a keyserver:
gpg --auto-key-locate clear,wkd -v --locate-external-key pierre@archlinux.org
and then verifying the fingerprint matches what is published on archlinux.org:
gpg --list-public-keys --fingerprint pierre@archlinux.org | grep -A1 pub
Now I can actually verify the authenticity of the files. First
verifying that the iso file's signatur matches one of the gpg keys I
imported:
cd "$HOME/arch/arch-install-${ISO_AT}"
printf 'Verifying the iso file: %s\n\n' "$ISO_CURRENT" && gpg --verify "$ISO_CURRENT".sig "$ISO_CURRENT"
Verifying the iso file: archlinux-2026.09.01-x86_64.iso gpg: Signature made Wed 02 Sep 2026 12:12:17 AM +07 gpg: using EDDSA key 3E80CA1A8B89F69CBA57D98A76A5EF9054449A5C gpg: issuer "pierre@archlinux.org" gpg: Good signature from "Pierre Schmitz <pierre@archlinux.org>" [unknown] gpg: WARNING: The key's User ID is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Primary key fingerprint: 3E80 CA1A 8B89 F69C BA57 D98A 76A5 EF90 5444 9A5C
Unlike with Gentoo, the checksum files are not themselves signed. So I move directly to generating the checksums locally and making sure they match the provided checksums.
Because I only downloaded the latest .iso, and not the other files
listed in the checksum files, I've added the --ignore-missing flag to
the cksum command to cut down on noise in the output:
cksum --ignore-missing -a blake2b -c b2sums.txt
cksum --ignore-missing -a sha2 -c sha256sums.txt
archlinux-2026.09.01-x86_64.iso: OK archlinux-2026.09.01-x86_64.iso: OK
Now that I have confirmed that the .iso is signed by the arch release
team, and the checksums provided match up with the downloaded .iso
file, a bootable USB can be made.
Applying the image to a USB drive
The Arch wiki lists many possible ways to write the .iso to a USB. Using cat is very straightforward.
Because I need to run this as root and I am running these commands
from an org file, I've written the full path to the .iso to a temp
file in order to make it easy to work with org. [ If just running in the terminal, the path can be passed directly to sudo with the --preserve-env=list flag. ]
echo export ISO_FULL_PATH="$HOME/arch/arch-install-${ISO_AT}/${ISO_CURRENT}" > /tmp/arch-iso-path
Then as root I can use cat to write the .iso to the USB drive.
function generic_home() {
local path="$1"
echo -n "${path}" | sed -e "s/home\/.*\//home\/a-user\//"
}
function validate_iso_path() {
if [[ -v "ISO_FULL_PATH" && ! -f "$ISO_FULL_PATH" ]]; then
printf 'Found /tmp/arch-iso-path with invalid contents:\n\t%s\n' $(generic_home "${ISO_FULL_PATH}")
echo "couldn't find an iso. exiting..."
exit 1
elif [[ -v "ISO_FULL_PATH" && -f "$ISO_FULL_PATH" ]]; then
printf 'using iso found in /tmp/arch-iso-path:\n\t%s\n' $(generic_home "${ISO_FULL_PATH}")
else
echo "couldn't find an iso. exiting..."
exit 1
fi
}
function find_iso_path() {
if [[ -v "ISO_FULL_PATH" ]]; then
echo "The ISO_FULL_PATH var is set:"
validate_iso_path
elif [[ -f /tmp/arch-iso-path ]]; then
# set ISO_FULL_PATH from tmp file
. /tmp/arch-iso-path
validate_iso_path
else
echo "couldn't find an iso. exiting..."
exit 1
fi
}
find_iso_path
THIS_DRIVE_WILL_BE_WIPED='/dev/sda'
iso_msg=$(generic_home "${ISO_FULL_PATH}")
echo "the iso to be written: ${iso_msg}"
echo "the drive to be wiped: $THIS_DRIVE_WILL_BE_WIPED"
echo -n "writing in " && for i in {5..1}; do echo -n "$i .. "; sleep 1; done; echo
sudo cat "${ISO_FULL_PATH}" > "${THIS_DRIVE_WILL_BE_WIPED}"
using iso found in /tmp/arch-iso-path: /home/a-user/archlinux-2026.09.01-x86_64.iso the iso to be written: /home/a-user/archlinux-2026.09.01-x86_64.iso the drive to be wiped: /dev/sda writing in 5 .. 4 .. 3 .. 2 .. 1 ..
The USB is now ready to be plugged into the machine I'm installing arch on an booted to.
Prepare the installation target machine
After booting to the installation media, the terminal font size can be increased:
setfont ter-132b
In practice, I don't usually do this as I ssh into the machine to run
through the installation.
ssh to the laptop over wifi
- run
iwctlstation listto get a list of stations (usually justwlan0on a laptop)station wlan0 scanstation wlan0 connect <my wifi network>exit
- get the ip address with
ip addr - add a root password
passwd[ This is a laptop install and my networking skills are non-existent. ] - from another laptop on the network:
ssh root@the_ip_from_2
If there are issues getting wifi working, the arch wiki has a more
detailed iwctl guide.
networking issues I have encountere
- When installing on a VM on my laptop, DNS from the VM was blocked by my host's firewall
- to fix: disable host firewall temporarily src_sh { # systemctl stop ufw.service }
- restart DHCP on guest src_sh { # systemctl restart dhcpcd.service }
- When installing on a VPS, static networking needed to be set up
- When installing directly on a laptop, wifi must be configured
Sync the system clock
timedatectl
Local time: Sun 2026-09-06 17:02:30 UTC
Universal time: Sun 2026-09-06 17:02:30 UTC
RTC time: Sun 2026-09-06 17:02:30
Time zone: UTC (UTC, +0000)
System clock synchronized: yes
NTP service: active
RTC in local TZ: no
Disks and Filesystems
Overview
For these notes, I am running on a virtual machine which has a disk layout like this:
lsblk
NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINTS loop0 7:0 0 1018.8M 1 loop /run/archiso/airootfs sr0 11:0 1 1.5G 1 rom /run/archiso/bootmnt vda 254:0 0 50G 0 disk
The vda drive is what I am using for this example. When installing on
my laptop directly the drive will likely be something like
/dev/nvme0n1.
I like to set up some variables ahead of time, so I can keep the majority of the guide unchanged regardless of the disk:
# For laptop
# ════════════════════
# DISK=/dev/nvme0n1
# BOOT_PART=/dev/nvme0n1p1
# LUKS_PART=/dev/nvme0n1p2
# For VM
# ════════════════════
DISK=/dev/vda
BOOT_PART=/dev/vda1
LUKS_PART=/dev/vda2
# LVM setup
# ════════════════════
VOLUME_GROUP=vgArch
The Arch installation wiki is very open ended for this section, which makes sense as your disk partitioning is going to be very dependent on what you're ultimately trying to do and what kind of hardware you have.
For me, I have laptops with very similar setups, so I am targeting an LVM on LUKS setup.
This means I will have 2 partitions on my drive.
- An unencrypted
1Gboot partition - The rest of the space is an encrypted LUKS partition
During installation, I will open the LUKS partition and set up LVM
within it. I will then create a swap partition and a root partition
within that.[ If this is an install on a machince on a local network and not exposed to the internet (e.g. a laptop or PC), then don't sweat this password. This is the password for root on the live cd, not on the target machine. It doesn't persist across live CD boots, so I usually go with 1234. If this install is on a machine that will need to be connected to the internet in order to get ssh access (or even a large intranet) then you will still want this password to be secure… but I'm not and if you're reading this you likely aren't either. ]
This allows me to easily have hibernation with and encrypted swap.
The end result looks something like:
NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINTS
vda 254:0 0 20G 0 disk
├─vda1 254:1 0 1G 0 part /mnt/boot
└─vda2 254:2 0 19G 0 part
└─cryptlvm 253:0 0 19G 0 crypt
├─vgArch-swap 253:1 0 4G 0 lvm [SWAP]
└─vgArch-root 253:2 0 14.7G 0 lvm /mnt
The name "cryptlvm" is arbitrary here, but the arch wiki uses it and it is descriptive, so I stick with it.
- note on The boot partition
- The boot partition must be mounted at
/boot. Previously I had been mounting it at/efi, but I couldn't get this working with an encrypted setup. I believegrubrequires using/bootin this scenario.
- The boot partition must be mounted at
Disk Partitions
For partitionig the disk, I like using cfdisk. Since it is a TUI, I
run the following in a terminal.[ As opposed to most of these commands which are directly run from my org file in Emacs. ]
cfdisk $DISK
1Gfor boot- rest of space for LUKS
After partitioning the layout is:
lsblk $DISK
NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINTS vda 254:0 0 50G 0 disk ├─vda1 254:1 0 1G 0 part └─vda2 254:2 0 49G 0 part
Boot partition/EFI setup
mkfs.fat -F 32 "$BOOT_PART"
mkfs.fat 4.2 (2021-01-31)
LUKS Setup
The encrypted root partition is interactive, so I also run these
commands in a terminal.[ Most commands support non-interative/script modes. I should look into the cryptsetup manual to see if it does. It would be nice to be able to do this all from org-mode. ]
cryptsetup luksFormat $LUKS_PART
# follow the prompts, after that run
cryptsetup open $LUKS_PART cryptlvm
After the above cyptsetup commands, the layout is:
lsblk $DISK
NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINTS vda 254:0 0 50G 0 disk ├─vda1 254:1 0 1G 0 part └─vda2 254:2 0 49G 0 part └─cryptlvm 253:0 0 49G 0 crypt
LVM (in LUKS) Setup
Now that the LUKS partition is set up, I can create an LVM physical
volume, encompassing the whole LUKS drive. Then create a virtual
group, call vgArch below.[ Don't use hypens in the name, it turns out weird ]
pvcreate /dev/mapper/cryptlvm
vgcreate vgArch /dev/mapper/cryptlvm
Physical volume "/dev/mapper/cryptlvm" successfully created. Volume group "vgArch" successfully created
Then make the logical volumes
lvcreate -L 4G -n swap $VOLUME_GROUP
lvcreate -l 100%FREE -n root $VOLUME_GROUP
Logical volume "swap" created. Logical volume "root" created.
For an ext4 filesystem specifically, the are wiki mentions that you
will want to shrink the partition by 256MiB. This is because the
e2scrub tool (an ext4 filesystem diagnostic tool) requires at least
that much space to run. From its man page:
The LVM volume group must have at least 256MiB of unallocated space to dedicate to the snapshot or the logical volume will be skipped.
The shrinking can be done with:
lvreduce -L -256M "$VOLUME_GROUP/root"
No file system found on /dev/vgArch/root. Size of logical volume vgArch/root changed from 44.98 GiB (11515 extents) to 44.73 GiB (11451 extents). Logical volume vgArch/root successfully resized.
Then make the filesystems:
mkfs.ext4 "/dev/$VOLUME_GROUP/root"
mkswap "/dev/$VOLUME_GROUP/swap"
mke2fs 1.47.4 (6-Mar-2025) Creating filesystem with 11725824 4k blocks and 2932736 inodes Filesystem UUID: 09c3fb86-6119-42e3-99d2-d87b707efc0b Superblock backups stored on blocks: 32768, 98304, 163840, 229376, 294912, 819200, 884736, 1605632, 2654208, 4096000, 7962624, 11239424 Allocating group tables: 0/358 done Writing inode tables: 0/358 done Creating journal (65536 blocks): done Writing superblocks and filesystem accounting information: 0/358 done Setting up swapspace version 1, size = 4 GiB (4294963200 bytes) no label, UUID=c396f80f-01ff-425e-9602-eee631e67359
Finally, get everything mounted:
mount "/dev/$VOLUME_GROUP/root" /mnt
mount --mkdir "$BOOT_PART" /mnt/boot
swapon "/dev/$VOLUME_GROUP/swap"
After all of that, the layout looks like:
lsblk $DISK
NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINTS
vda 254:0 0 50G 0 disk
├─vda1 254:1 0 1G 0 part /mnt/boot
└─vda2 254:2 0 49G 0 part
└─cryptlvm 253:0 0 49G 0 crypt
├─vgArch-swap 253:1 0 4G 0 lvm [SWAP]
└─vgArch-root 253:2 0 44.7G 0 lvm /mnt
Operating System
With the disks set up, Arch installation can continue from section 2 of the install wiki.
Package Installation
To get a base system up and running, I install the following packages:
pacstrap -K /mnt linux-firmware \
sof-firmware \
linux \
base \
base-devel \
intel-ucode \
efibootmgr \
grub \
lvm2 \
cryptsetup \
dosfstools \
xfsprogs \
nftables \
iwd \
networkmanager \
openssh \
usbutils \
udisks2-lvm2 \
udisks2 \
fwupd
For a laptop, I like to have a few additional things in place:
pacstrap -K /mnt brightnessctl \
bluez \
bluez-utils \
pipewire \
pipewire-alsa \
pipewire-docs \
pipewire-libcamera \
pipewire-pulse \
wireplumber \
wireplumber-docs \
fprintd \
power-profiles-daemon \
easyeffects \
cups \
hplip \
power-profiles-daemon
Generate fstab
genfstab -U /mnt >> /mnt/etc/fstab && cat /mnt/etc/fstab
# Static information about the filesystems. # See fstab(5) for details. # <file system> <dir> <type> <options> <dump> <pass> # /dev/mapper/vgArch-root UUID=09c3fb86-6119-42e3-99d2-d87b707efc0b / ext4 rw,relatime 0 1 # /dev/vda1 UUID=DA1F-04F3 /boot vfat rw,relatime,fmask=0022,dmask=0022,codepage=437,iocharset=ascii,shortname=mixed,utf8,errors=remount-ro 0 2 # /dev/mapper/vgArch-swap UUID=c396f80f-01ff-425e-9602-eee631e67359 none swap defaults 0 0
chroot to the new filesystem
arch-chroot /mnt
Dates and time
Within the chroot, the first thing to do is set the new system's
clocks. Usually this is just a matter of setting the localtime,
syncing the hardware clock and the system clock, and then setting up
an NTP daemon to sync periodically to prevent clock drift.
That can all be accomplished with straightforward commands:
# use whatever timezone is needed
ln -sf /usr/share/zoneinfo/Antarctica/Troll /etc/localtime
# sync the system and hardware clocks
hwclock --systohc
# enable NTP clock syncing via systemd
timedatectl set-ntp true
There can be an added wrinkle if the system originally had another OS, such as windows, installed.
The standard used by the hardware clock (CMOS clock, the BIOS time) is set by the operating system. By default, Windows uses localtime, macOS uses UTC, other UNIX and UNIX-like systems vary.
This can be checked by running
timedatectl | grep local
RTC in local TZ: no
If this had come back as "yes", then it is a good idea to set the hardware clock to use UTC:
timedatectl set-local-rtc 0
A lot more details and guidance around dealing with multiple operating systems can be read in the Arch wiki "System Time" article.
Set up locales:
# uncomment desired locales
sed -i.original -E 's/#en_US\.U/en_US\.U/ ; s/#th_TH\.U/th_TH\.U/' /etc/locale.gen
# then run script
locale-gen && \
echo "LANG=en_US.UTF-8" >> /etc/locale.conf
Generating locales... en_US.UTF-8... done th_TH.UTF-8... done Generation complete.
Set hostname
Some basic networking can be taken care of at this point:
- Set the new system's
hostname - populate
/etc/hostswith the known local network - Configure the default DNS as desired[ I normally set firefox to use quad9 DNS, so it makes sense to have system connections use the same. ]
The hostname is straightforward enough:
echo "somehost" >> /etc/hostname
+RESULTS[a5ae1514aae1f12e7395cf1dd59515864df4d664]:
configure mkinitcpio
While the standard arch guide just has you run mkinitcpi, since we are
doing an LVM on LUKS setup there are a few extra steps documented
here:
# make sure lvm2 is install
pacman -Syu --noconfirm lvm2
Then I will need to modify the HOOKS in the /etc/mkinitcpio.conf file.
The desired HOOKS look like:
HOOKS=(base udev autodetect microcode modconf kms keyboard keymap consolefont encrypt lvm2 block filesystems resume fsck)
- note that
encryptcomes beforelvm2 - I am using the
encryptmodule, as opposed to thesd-encryptmodule- this is selected for due to the lack of the main
systemdmodule being loaded earlier in the hooks - this means I should reference the
busyboxflow when reading the arch wiki info about kernel modules
- this is selected for due to the lack of the main
- I removed
vconsolemodule as I haveuskeyboard layouts - I added
resumein order to be able to use hibernation
To easily replace the line, the following sed command will replace the
hooks while creating a backup of the original file:
current_hooks='^HOOKS=\(.*\)$'
new_hooks='base udev autodetect microcode modconf kms keyboard keymap consolefont encrypt lvm2 block filesystems resume fsck'
sed -i.original -E "s/${current_hooks}/HOOKS=\(${new_hooks}\)/" /etc/mkinitcpio.conf
diff -u1 /etc/mkinitcpio.conf.original /etc/mkinitcpio.conf
--- /etc/mkinitcpio.conf.original 2026-08-11 17:52:11.000000000 +0200
+++ /etc/mkinitcpio.conf 2026-09-06 19:27:33.426653419 +0200
@@ -54,3 +54,3 @@
usr and fsck hooks.
-HOOKS=(base systemd autodetect microcode modconf kms keyboard sd-vconsole block filesystems fsck)
+HOOKS=(base udev autodetect microcode modconf kms keyboard keymap consolefont encrypt lvm2 block filesystems resume fsck)
Assuming the above diff looks correct, the backup file can be removed:
rm /etc/mkinitcpio.conf.original
You can set a default font based on the system fonts available. As I don't install a login manager, this is nice. Plus it removes a warning from the mkinitcpio output.
more info here: https://aicsx.github.io/ax/blog/2022/01/08/consolefont-no-font-found-in-configuration.html
echo "FONT=solar24x32" > /etc/vconsole.conf
And finally regenerate the file:
mkinitcpio -P
Building image from preset: /etc/mkinitcpio.d/linux.preset: 'default' Using default configuration file: '/etc/mkinitcpio.conf' -k /boot/vmlinuz-linux -g /boot/initramfs-linux.img Starting build: '7.2.3-arch1-2' Running build hook: [base] Running build hook: [udev] Running build hook: [autodetect] Running build hook: [microcode] Running build hook: [modconf] Running build hook: [kms] Running build hook: [keyboard] Running build hook: [keymap] Running build hook: [consolefont] Running build hook: [encrypt] WARNING: Possibly missing firmware for module: 'qat_6xxx' Running build hook: [lvm2] Running build hook: [block] Running build hook: [filesystems] Running build hook: [resume] Running build hook: [fsck] Generating module dependencies Creating zstd-compressed initcpio image: '/boot/initramfs-linux.img' Early uncompressed CPIO image generation successful Initcpio image generation successful
GRUB for bootloader
This is another spot that differs a bit due to LVM on LUKS. The UUID
of the encrypted partition (or label, if there is one) needs to be set
as a crypdevice in the grub commandline.
With the following layout, the UUID I need is 214d84d0-afdb-492b-9c83-9389d1cd9c25
# Encrypted partition is: vda2 vda2 9e72a83d-8f1f-4943-ac2b-37425299e727 └─cryptlvm F7T3XW-vvnt-KTOK-34Lp-ZIBs-pkA6-fQdrXV ├─vgArch-swap c396f80f-01ff-425e-9602-eee631e67359 └─vgArch-root 09c3fb86-6119-42e3-99d2-d87b707efc0b
The desired GRUB_CMDLINE_LINUX look like:
GRUB_CMDLINE_LINUX="cryptdevice=UUID=9e72a83d-8f1f-4943-ac2b-37425299e727:cryptlvm root=/dev/vgArch/root rootfstype=ext4 resume=/dev/vgArch/swap"
Similair to how I used sed to modify /etc/mkinitcpio.conf, the same
thing can be done here to update /etc/default/grub.
crypt_uuid=9e72a83d-8f1f-4943-ac2b-37425299e727
current_grub_cmdline='^GRUB_CMDLINE_LINUX=\"\"'
new_grub_cmdline="cryptdevice=UUID=${crypt_uuid}:cryptlvm root=\/dev\/vgArch\/root rootfstype=ext4 resume=\/dev\/vgArch\/swap"
sed -i.original -E "s/${current_grub_cmdline}/GRUB_CMDLINE_LINUX=\"${new_grub_cmdline}\"/" /etc/default/grub
diff -u1 /etc/default/grub.original /etc/default/grub
--- /etc/default/grub.original 2026-01-15 09:03:21.000000000 +0000
+++ /etc/default/grub 2026-09-06 19:29:20.178031967 +0200
@@ -6,2 +6,1 @@
GRUB_CMDLINE_LINUX_DEFAULT="loglevel=3 quiet"
-GRUB_CMDLINE_LINUX=""
+GRUB_CMDLINE_LINUX="cryptdevice=UUID=9e72a83d-8f1f-4943-ac2b-37425299e727:cryptlvm root=/dev/vgArch/root rootfstype=ext4 resume=/dev/vgArch/swap"
Assuming the above diff looks correct, the backup file can be removed:
rm /etc/default/grub.original
Install grub and generate the config using the new default file:
grub-install --target=x86_64-efi --efi-directory=/boot --bootloader-id=GRUB
grub-mkconfig -o /boot/grub/grub.cfg
Installing for x86_64-efi platform. Installation finished. No error reported. Generating grub configuration file ... Found linux image: /boot/vmlinuz-linux Found initrd image: /boot/intel-ucode.img /boot/initramfs-linux.img Warning: os-prober will not be executed to detect other bootable partitions. Systems on them will not be added to the GRUB boot configuration. Check GRUB_DISABLE_OS_PROBER documentation entry. Adding boot menu entry for UEFI Firmware Settings ... done
Set up users [0/4]
[ ]First, a root password:passwd[ ]Then create my user:useradd -m -G wheel -s /bin/bash a-user[ ]Then a user password:passwd a-user[ ]Then edit the sudo file to makewheelgroupsudo:EDITOR=vim visudo
set up systemd services
I will want networking and ssh enabled before rebooting into the new install. I also make sure
systemctl enable NetworkManager
systemctl enable sshd
systemctl enable nftables.service
For a laptop, I will also enable bluetooth
systemctl enable bluetooth
As my user, I will also want pipewire:
systemctl --user enable pipewire
systemctl --user enable wireplumber
Reboot [0/3]
exit
umount -R /mnt && reboot
Footnotes:
This is a laptop install and my networking skills are non-existent.
If just running in the terminal, the path can be passed directly to sudo with the --preserve-env=list flag.
If this is an install on a machince on a local network and not exposed to the internet (e.g. a laptop or PC),
then don't sweat this password. This is the password for root on the live cd, not on the target machine. It doesn't
persist across live CD boots, so I usually go with 1234. If this install is on a machine that will need to be connected
to the internet in order to get ssh access (or even a large intranet) then you will still want this password to be
secure… but I'm not and if you're reading this you likely aren't either.
As opposed to most of these commands which are directly run from my org file in Emacs.
Most commands support non-interative/script modes. I should
look into the cryptsetup manual to see if it does. It would be nice to
be able to do this all from org-mode.
Don't use hypens in the name, it turns out weird
I normally set firefox to use quad9 DNS, so it makes sense to have system connections use the same.