🪴 Zero's Garden

Home

❯

notes

❯

Self Hosting

❯

Remote decryption on boot

Remote decryption on boot

Jan 07, 20261 min read

clevis

https://github.com/latchset/clevis

Tang / TPM2

zfspasskey

https://github.com/FiloSottile/mostly-harmless/tree/main/zfspasskey

See https://bsky.app/profile/filippo.abyssdomain.expert/post/3lotxpnx5ym24 for description.

Made a little web server to unlock and mount encrypted ZFS datasets using passkeys and age.

What’s neat is that the password never touches the client! Attackers need to compromise first the server, and then the passkey.


Graph View

  • clevis
  • zfspasskey

Created with Quartz v4.5.2 © 2026

  • GitHub
  • Sponsor me