Andrew Mercer
on this page

KVM disk encryption

Part of the KVM overview. Encrypt guest storage with LUKS inside the guest or in qcow2.

The old qemu-img -o encryption (qcow2 "AES") mode has been removed from QEMU and was weak anyway. Options today:

  • Use LUKS inside the guest (the installer's "encrypt disk" option). Simple, and works with every hypervisor.
  • Use qcow2 with LUKS encryption handled by QEMU:
printf '%s' 'passphrase' > secret.txt && chmod 600 secret.txt
qemu-img create -f qcow2 --object secret,id=sec0,file=secret.txt \
  -o encrypt.format=luks,encrypt.key-secret=sec0 encrypted.qcow2 10G

Attach it to a libvirt domain through a virsh secret-define / secret-set-value secret referenced from the disk's <encryption format='luks'> element (libvirt docs).