3 ms·
If you look for 'kitchen sink included' currently maintained, and supported by redhat,debian and others, look for dracut: https://mirrors.edge.kernel.org/pub/li
by rdslw 7y ago
If you look for 'kitchen sink included' currently maintained, and supported by redhat,debian and others, look for dracut: https://mirrors.edge.kernel.org/pub/linux/utils/boot/dracut/dracut.html https://mirrors.edge.kernel.org/pub/linux/utils/boot/dracut/...
If you look for really FAST and streamline solution (one binary), check this post:
https://michael.stapelberg.ch/posts/2020-01-21-initramfs-from-scratch-golang/ https://michael.stapelberg.ch/posts/2020-01-21-initramfs-fro...
- djsumdog 7y agoI kept running into constantly problems configuring and building dracut, which is why I switched to better-initramfs. It's just a much more modern and better built initramfs and it's easier to modify for custom tooling as well.
- markandrewj 7y agoThe graph at the bottom of the Dracut page is somewhat interesting/useful.
- anon9001 7y agoDracut works pretty well. I managed to get it to auth me with sshd using an ed25519 key stored on my yubikey. I then use gpg-agent in dracut to decrypt my keyfile and use that to unlock the root partition, which then boots and kicks me out of ssh. It's a pretty clean answer for a fully encrypted home server. Of course, it doesn't encrypt /boot, but I keep a separate USB stick for that and put it in the server when it needs a reboot.
- rdslw 7y agoCan you share (blog? github?) more details (ideally whole dracut module :) about your implementation?
- anon9001 7y agoI haven't posted it anywhere because it's a bit of a mess, but here you go: https://pastebin.com/ZfkM2zkU https://pastebin.com/ZfkM2zkU I'm not proud, or smart, but it works. Systemd is used for networking to make it simpler. I based it on this: https://github.com/gsauthof/dracut-sshd https://github.com/gsauthof/dracut-sshd I should probably package it up with all the config options you'd need to specify drive and keyfile location and all that, but I'm a terrible member of the community and haven't actually done it yet. The real trick that took me a long time to figure out was invoking "cryptsetup luksOpen" with my mount.sh script and then using "systemctl stop systemd-cryptsetup@nvme0n1p3_crypt.service" to get the thing to keep booting. I still don't really understand the tty ask password stuff in systemd, but this seems to work fine. You just ssh in and run ./mount.sh and it decrypts/mounts/boots.