Hey all, this may be a silly or obvious question but I’m fairly new around here (relatively speaking) so here goes…
I am looking to have my HDDs encrypted so that all data cannot be easily accessed if the drives are pulled out of my server.
I have the following configuration:
|Server
|-HDD1 (Proxmox)
|-HDD2 (VMs)
|-HDD3 (Data available to VMs)
If I encrypt the 3x HDDs (LUKS/EXT4) in full, and unlock the first to access Proxmox, followed by the other two once logged into Proxmox, would all VMs then be able to boot up without needing an individual unlock (seems like an obvious YES)? Would the extra Data drive (HDD3) also be accessible to VMs via passthrough without needing unlocking (this I’m not so sure about)? I’m thinking once the initial unlock has taken place Proxmox will be able to “see” and use everything on the drives. Correct?
My current setup has only HDD1 encrypted, with each VM on HDD2 setup with individual encryption (meaning a lot of individual unlocking).
|Server
|-HDD1 (Proxmox (encrypted))
|-HDD2 (VMs)
|—VM1 (encrypted)
|—VM2 (encrypted)
|—VM3 (encrypted)
…etc
|-HDD3
Which is the better method? Or should I ask what is the best way to encrypt everything with minimum fuss/issues? (Best practice)
I am looking to have my HDDs encrypted so that all data cannot be easily accessed if the drives are pulled out of my server.
I have the following configuration:
|Server
|-HDD1 (Proxmox)
|-HDD2 (VMs)
|-HDD3 (Data available to VMs)
If I encrypt the 3x HDDs (LUKS/EXT4) in full, and unlock the first to access Proxmox, followed by the other two once logged into Proxmox, would all VMs then be able to boot up without needing an individual unlock (seems like an obvious YES)? Would the extra Data drive (HDD3) also be accessible to VMs via passthrough without needing unlocking (this I’m not so sure about)? I’m thinking once the initial unlock has taken place Proxmox will be able to “see” and use everything on the drives. Correct?
My current setup has only HDD1 encrypted, with each VM on HDD2 setup with individual encryption (meaning a lot of individual unlocking).
|Server
|-HDD1 (Proxmox (encrypted))
|-HDD2 (VMs)
|—VM1 (encrypted)
|—VM2 (encrypted)
|—VM3 (encrypted)
…etc
|-HDD3
Which is the better method? Or should I ask what is the best way to encrypt everything with minimum fuss/issues? (Best practice)