Fresh FDE zfs-mirror installation

bea

Active Member
Dec 25, 2020
40
1
28
25
Hello!

I have a computer with 2 disks of similar size. I would like to have them LUKS-encrypted and then install PVE on them with ZFS mirror.

What steps should I follow?

Thank you!
 
Last edited:
Hey @news , you seem to be a very funny person, as much as smart, but the game we play here is about helping each other, that's why I asked for help.

Anyone knows if what I ask is possible?

I have been reading many different things on Proxmox encryption but I have not understood how I could install (on my 2-disk computer) PVE with ZFS mirror on the top of LUKS. Or if that is possible at all.
 
I saw that post before but I did not go through the whole thread where it comes the interesting part... Thank you!
There I see a step-by-step guide made by @Dunuin and then @Anotheruser announcing they managed to do it.

Unfortunately that guide is a bit too advanced for me, I would have questions on most of its steps.

Perhaps they want to publish a more detailed guide : )

Otherwise I guess I'll look for something else.
 
Why not do pve unencrypted (server everytime able to boot for any troubleshooting)
and later all further option disk for vm/lxc and any (nfs/smb/..) data encrypting which is much easier to do and handle ?
 
Yes, that's what I have now, LUKS-encrypted VMs. The main problem I find is I can't (or don't know how to) encrypt LXC containers, so I end up having heavy VMs and the host quickly runs out of resources. If I had an encrypted host, I could use containers and have many diferent services I cannot afford now.
 
?? If you have an encrypted zpool for vm+lxc(+data) you cannot start your lxc without encrypting the pool before by pw.
 
Maybe I did not explain correctly, or I don't exactly understand what you mean. I currently have encrypted VMs because I configured LUKS through the installer of each guest OS (Debian).

ZFS encryption would be nice, but I don't use it. I discarded it because I think it was problematic -if I remember properly- with ZFS replication and I need ZFS replication for the cluster "pseudo" HA.

By the way, what's "pw"?
 
pw=password.
Maybe you just install pve on 1 ssd. Then partition the 2nd one for pve and an additional image use, "mirror" pve over, config with proxmox-boot-tool, test by removing the 1st ssd. When iO do the same to 1st ssd. After having unencrypted pve and free partition, doing luks onto, setup 2nd pool (rpool still exists).
 
Sorry, I got lost, I'm not any expert, but I'd like to know the proposal!
The only thing I clearly understood is the first sentence: install pve on 1 ssd : )
Would you please elaborate on the other steps?
And, what is iO?
Thank you.
 
Mit NomadBSD fahre ich unregelmäßig auch nen dd der systemdisks von cluster-nodes. Nicht geil, aber es tutet. ;) Bisher noch nicht die Muse gehabt, da weiter rumzuprobieren.
 
Thank you. According to what I have read in this forum, Proxmox replication does not work with ZFS encryption. I want to run a ZFS-based cluster. So it seems the solution @mr44er proposed is not valid for my case. Please correct me if I am wrong.
 
Maybe need some fix for send raw in the 1 pve code file after any pve update, automatically by systemd, might be not impossible I think.
 
Thank you very much for your help. It all looks too headache-inducer for me. I think for the time being I'll stick with my one-by-one LUKS-encrypted VMs on my non-encrypted PVE.
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!