21.7. Creating an encrypted Stratis pool using Clevis


Starting with Stratis 2.4.0, you can create an encrypted pool using the Clevis mechanism by specifying Clevis options at the command line.

Prerequisites

Procedure

  1. Erase any file system, partition table, or RAID signatures that exist on each block device that you want to use in the Stratis pool:

    # wipefs --all block-device

    The block-device value is the path to the block device; for example, /dev/sdb.

  2. Create the encrypted Stratis pool and specify the Clevis mechanism to use for the encryption:

    # stratis pool create --clevis tpm2 my-pool block-device
    tpm2
    Specifies the Clevis mechanism to use.
    my-pool
    Specifies the name of the new Stratis pool.
    block-device

    Specifies the path to an empty or wiped block device.

    Alternatively, use the Clevis tang server mechanism by using the following command:

    # stratis pool create --clevis tang --tang-url my-url --thumbprint thumbprint my-pool block-device
    tang
    Specifies the Clevis mechanism to use.
    my-url
    Specifies the URL of the tang server.
    thumbprint

    References the thumbprint of the tang server.

    You can also specify multiple block devices on a single line by using the following command:

    # stratis pool create --clevis tpm2 my-pool block-device-1 block-device-2

Verification

  • Verify that the new Stratis pool was created:

    # stratis pool list
    참고

    You can also create an encrypted pool using both Clevis and keyring mechanisms by specifying both Clevis and keyring options at the same time during pool creation.

Red Hat logoGithubredditYoutubeTwitter

자세한 정보

평가판, 구매 및 판매

커뮤니티

Red Hat 소개

Red Hat은 기업이 핵심 데이터 센터에서 네트워크 에지에 이르기까지 플랫폼과 환경 전반에서 더 쉽게 작업할 수 있도록 강화된 솔루션을 제공합니다.

보다 포괄적 수용을 위한 오픈 소스 용어 교체

Red Hat은 코드, 문서, 웹 속성에서 문제가 있는 언어를 교체하기 위해 최선을 다하고 있습니다. 자세한 내용은 다음을 참조하세요.Red Hat 블로그.

Red Hat 문서 정보

Legal Notice

Theme

© 2026 Red Hat
맨 위로 이동