Havenform is a next-generation infrastructure OS purpose-built for declarative, secure-by-default Kubernetes clusters. Based on NixOS and K3s, it handles everything from Secure Boot and LUKS to GitOps bootstrap and network setup โ all driven from a single user-owned seed.
๐ง Key Features
- ๐งฉ Seed-based key derivation (SSH, Secure Boot, LUKS, GitOps)
- ๐ Secure Boot + LUKS from day one (TPM opt-out, Tang opt-in)
- ๐ฅ๏ธ SSH-in-initrd for emergency unlock or remote recovery
- โ๏ธ Push or pull -based update model
- ๐ฆ Built-in GitOps bootstrap (via FluxCD)
- ๐ง Root access included, full control with reproducible Nix
- ๐ Optional Cilium-powered networking, ready for policy and BPF workloads
- ๐ง Minimal magic โ fully declarative, fully auditable