Switching to systemd‑boot on NixOS: Declarative Setup, Trade‑offs, and a Step‑by‑Step Example
Learn how to enable and customize systemd‑boot in NixOS, compare it to GRUB, and follow a concrete example that keeps your boot menu tidy and secure.
06 Jul 2025, 04:51 UTC

Why switch to systemd‑boot?
systemd‑boot is a minimal UEFI‑only loader that fits NixOS’s declarative philosophy. It eliminates manual edits to /boot, automatically discovers kernels, and integrates cleanly with NixOS’s module system. If your machine boots in UEFI mode and you prefer a lightweight loader over GRUB’s feature‑rich but complex configuration, systemd‑boot is a natural fit.
Declarative Enablement
In configuration.nix add the following lines:
boot.loader.systemd-boot.enable = true;
boot.loader.efi.canTouchEfiVariables = true; # allow NixOS to create UEFI boot entries
Afterwards run sudo nixos-rebuild switch. NixOS will create /boot/loader/loader.conf and populate /boot/loader/entries/ with kernel entries.
Fine‑tuning the Loader
boot.loader.systemd-boot.configurationLimit– limits how many kernel entries appear in the menu. Typical value:5.boot.loader.systemd-boot.consoleMode– "max" forces a graphical console; "tty" uses a text console. Useful for headless servers.boot.loader.systemd-boot.enableNLS– enables locale‑specific menu text (requiresboot.loader.systemd-boot.enableNLS = true;).
Example snippet:
boot.loader.systemd-boot.configurationLimit = 5;
boot.loader.systemd-boot.consoleMode = "max";
Secure Boot Signing
When Secure Boot is enforced, the kernel and initrd must be signed. NixOS can generate the signatures automatically if you enable boot.loader.efi.canTouchEfiVariables and supply a signing key:
boot.loader.efi.keyFile = /etc/secureboot/keys/privkey.pem;
boot.loader.efi.certFile = /etc/secureboot/keys/cert.pem;
After rebuilding, bootctl list will show signed entries. If signing fails, the system will not boot under Secure Boot firmware.
Concrete Worked Example
Open
configuration.nixand add:boot.loader.systemd-boot.enable = true; boot.loader.efi.canTouchEfiVariables = true; boot.loader.systemd-boot.configurationLimit = 5; boot.loader.systemd-boot.consoleMode = "max";Run
sudo nixos-rebuild switchand confirm no errors.Verify the loader configuration:
cat /boot/loader/loader.conf # Expected output: default nixos, timeout 5Check kernel entries:
ls /boot/loader/entries/ # Should list files like nixos-2026-10-01-0000-boot.confConfirm UEFI boot entry:
bootctl list # Should list entries with labels "nixos" and the timestampReboot and observe the systemd‑boot menu. Select the desired kernel and ensure the system boots normally.
Trade‑offs & Limitations
| Aspect | systemd-boot | GRUB (default) |
|---|---|---|
| BIOS support | No – UEFI only | Yes – BIOS & UEFI |
| Encrypted root | Requires custom initrd to locate device | Handled automatically via GRUB’s cryptsetup hook |
| Multi‑OS coexistence | Works, but UEFI order may need manual adjustment | Handles complex chainloading natively |
| Secure Boot | Simple signing via NixOS module | Complex configuration, may need external tools |
Because systemd‑boot cannot modify BIOS settings, you must ensure your firmware is in UEFI mode before enabling it. If you later need to boot from legacy BIOS, you will have to re‑enable GRUB or install a separate BIOS‑compatible loader.
Actionable Checklist
- Verify firmware mode:
sudo efibootmgr -v | grep UEFI. - Add the configuration snippet above.
- Run
sudo nixos-rebuild switch. - Check
/boot/loader/loader.confand/boot/loader/entries/. - Confirm UEFI entry with
bootctl listandefibootmgr -v. - Reboot and test the menu.
- If boot fails, revert to GRUB by commenting out the loader lines and rebuilding.
With these steps you’ll have a fully declarative, UEFI‑only bootloader that stays in sync with your NixOS configuration and keeps the boot menu tidy.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.