EncFS inside LXC with password prompt

oliwel

Well-Known Member
Feb 11, 2018
38
1
48
49
Hi All,

I am running PVE 5.4 with a remote storage system, LXC containers are provisioned using LVM based disks.

For a new project I want to add a "file based encryption" such as enfcs to one mountpoint inside the container. As it looks like adding fuse inside the container is not a good idea (https://forum.proxmox.com/threads/enable-fuse-in-lxc-container.27278/) I am looking for a solution to mount the encrypted volume on container start on the active node while providing the password on the shell.

I am aware that this will require an admin to log into the node via CLI but this is accepted.

Is there any possibility to either add encfs to the containers mountpoints or have some "callback script" on startup that adds the mountpoint after starting the container?

best regards

Oliver
 
If logging in to the node via SSH is accepted anyway, why not just create a bindmount to a directory from your LXC and then, before starting, execute the encfs mount commands to that directory? Then LXC doesn't need FUSE at all.
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!