Coloured pencil diagram showing the Arch Linux boot process using systemd-boot, UKI, TPM2 unlock, and Btrfs subvolumes.

A Sealed Deal: TPM2, UKI, and the Arch Install Script That Nearly Broke Me

Most Arch install guides read like someone dumped their terminal history into a blog and called it a day. I wanted more than that. I wanted a system that was secure, fast, and didn’t ask me for a password every time I booted. I wanted TPM2-backed full-disk encryption, a modern boot process with UKI, and a layout that respected my time. And I wanted it to be repeatable — no more tinkering for hours every six months. ...

May 1, 2025 · 6 min · Oliver Daff