Decide and implement disk encryption for lena and vega #37
Labels
No labels
host:electra
host:fleet
host:lyra
host:vega
host:vega
phase:cutover
phase:deploy
phase:mcp
phase:module
phase:packaging
phase:prep
phase:validation
project:attic-postgres-lyra-rollout
project:auto-update-reliability
project:declarative-purity-cleanup
project:external-review
project:host-facts-refactor
project:lyra-nixos-deploy
project:lyra-service-stack-migration
project:nebula-mesh-network
project:security-hardening
project:service-stack-migration
project:vega-sillytavern-cutover
service:auto-update
service:mem0
service:sillytavern
No milestone
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
nimmo/nixos-config#37
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Context
lenaandvegacurrently use plain Btrfs layouts. This is a physical-access weakness for a laptop and may become increasingly significant on vega as private service state moves into/srv/services.Relevant files:
hosts/lena/disko.nixhosts/vega/disko.nixhosts/electra/hardware-configuration.nixas the encrypted referenceScope
Completion criteria
Decision (2026-07-20)
Neither host will receive LUKS disk encryption at this time. The encryption decision is recorded for both hosts, satisfying the first completion criterion; implementation (criterion 2) and recovery-doc updates (criterion 3) are N/A by choice.
What would reopen this
The full rationale is recorded in private notes, not here.