Session will focus on new LUKS2 cryptsetup reencryption designed with goal to provide better resilience when dealing with crash event. LUKS2 implementation also provides option to reencrypt live (mounted) devices and better suits HA systems emphasising minimal downtime. Both requirements were significant milestones on road to get LUKS2 reencryption deployed in future enterprise
environments.
In the talk we'll go through features of new reencryption with
description of data protection methods implemented as
safeguards against data corruption on crash event. We'll
demonstrate new reencryption tool on basic use cases including
example of automatic crash recovery after simulated system crash.
Resources:
- https://gitlab.com/cryptsetup/cryptsetup
- https://gitlab.com/cryptsetup/LUKS2-docs
https://okozina.fedorapeople.org/online-disk-reencryption-with-luks2.pdf