01 Comprenez exactement ce que cela protège
Protects against: physical seizure of a powered-off disk, decommissioned hardware, a datacentre incident, a technician with physical access. Does not protect against: a compromised running hypervisor, or a compromise of the running instance. The key is in memory while the machine runs.
02 Installer sur une racine chiffrée
On the Bastion line this is preconfigured. On any other instance, boot the distribution installer through the out-of-band console and choose an encrypted LVM layout.
03 Ajouter dropbear à l'initramfs
This is what lets you supply the passphrase over SSH before the root filesystem is mounted.
apt install -y dropbear-initramfs cryptsetup-initramfs
echo 'DROPBEAR_OPTIONS="-p 2222 -s -j -k"' >> /etc/dropbear/initramfs/dropbear.conf
cat ~/.ssh/id_ed25519.pub > /etc/dropbear/initramfs/authorized_keys
update-initramfs -u -k all 04 Configurer le réseau de démarrage
The initramfs has no DHCP client by default; give it a static configuration matching your instance.
# /etc/initramfs-tools/initramfs.conf
IP=203.0.113.10::203.0.113.1:255.255.255.0::eth0:off 05 Déverrouiller après chaque redémarrage
Connect on the initramfs port and supply the passphrase. The boot then continues normally.
ssh -p 2222 [email protected]
# then: cryptroot-unlock