Hello everyone, I just discovered something really odd regarding the encrypted backups to pbs and I wanted to share.
I have setup my encrypted backup to a locally hosted pbs instance.
The encryption key is stored in client at
etc/pve/priv/storage/<STORAGE-ID>.enc.
If you remove this file, backups still complete without error. I'm not sure at this point if the backups are encrypted. If backups are being sent as clear text just because the encryption file is missing for some reason, this seems like a terrible thing. As the user would have no idea that their data is now exposed.
I have setup my encrypted backup to a locally hosted pbs instance.
The encryption key is stored in client at
etc/pve/priv/storage/<STORAGE-ID>.enc.
If you remove this file, backups still complete without error. I'm not sure at this point if the backups are encrypted. If backups are being sent as clear text just because the encryption file is missing for some reason, this seems like a terrible thing. As the user would have no idea that their data is now exposed.