Andrew Mercer
on this page

dm-crypt is the kernel's transparent block-device encryption (device-mapper target). cryptsetup is its management tool, and LUKS is the standard on-disk header format that holds the key slots. References: dm-crypt (Wikipedia), cryptsetup section.

luksFormat destroys everything on the target. Confirm the device with lsblk and back up first.

# One-time: create the encrypted container on a partition
sudo cryptsetup luksFormat /dev/sdX1

# Unlock it: creates /dev/mapper/secure
sudo cryptsetup open /dev/sdX1 secure

# Create a filesystem inside (first time only) and mount it
sudo mkfs.ext4 /dev/mapper/secure
sudo mkdir -p /mnt/secure
sudo mount /dev/mapper/secure /mnt/secure

# Lock it again
sudo umount /mnt/secure
sudo cryptsetup close secure

Manage keys

sudo cryptsetup luksDump /dev/sdX1                 # header info and key slots
sudo cryptsetup luksAddKey /dev/sdX1               # add another passphrase
sudo cryptsetup luksRemoveKey /dev/sdX1            # remove a passphrase
sudo cryptsetup luksHeaderBackup /dev/sdX1 --header-backup-file luks-header.img

Back up the LUKS header and keep it offline: if the header is damaged, the data is unrecoverable even with the right passphrase.

Unlock at boot

List the device in /etc/crypttab (by UUID) and the mapped device in /etc/fstab. See mount. For secure disposal of an encrypted disk, destroying the header (luksErase) or all key slots renders the data unreadable, much faster than overwriting the whole disk. See also shred and scrub.