From nobody Sat Jul 18 13:44:48 2026 X-Original-To: dev-commits-doc-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4h2Sh55tbmz6lTlD for ; Sat, 18 Jul 2026 13:44:53 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR1" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4h2Sh53yDXz439R for ; Sat, 18 Jul 2026 13:44:53 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1784382293; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=OoFX46b4+d216UlcYcQTF09fYREVp2eIwXDaCmoCOwA=; b=l4ElDR6GPh/vea94es77dGmJCF6Baf7xq2TajrM7z4cgnA5wQeTTBgIRBoL/EBWdhyYkYZ 5ueTgp+gizyxGtI3mDYRmDAsCxG9LRiAuOKHuX9hZTgLJ3A7++F+eXbFR4gYdVY/x3SyaV nXupKztzWJr6o6LjvSOBK9lePJk47WXrM6fWpLdX/9gOz8dKWJzyFbVGyusrm/CLq6lrjW tH71pVJDbjfflx97UPmrkeNpaXpRyUclKSpF4urppgV1Ihko2S9tp8y5ipPH8ZzIWVlYd1 ou8QxtCpTKXO2JHnv/jVzXhN7Udy3C/1M4OwDvxQCExuuCoJhRPZz3EhW4RmcA== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1784382293; a=rsa-sha256; cv=none; b=HhJth4FQn/AD4szNU7Ara/owRJVEAf4aEOVqfS+o5LN6ATjs9U2RY5u9Q6u1z8shA2PF2a 728R8CqShVSsOET4wyH3o2a973rjBC+CXokMX7d5kAof/nEVK297xnQtI5knlPJppCdVWH US6x0DmfqV0UN+6afcRQkiTA97qX2oziAmmVxJ1+mkl0BKU2rL7+Fs9w8qMZBBszwvBZtZ Eif6c7g9LDfs4EMlFxGH6AH8qRRpD6HpUhyYOQPPT74Y4WslOrensdAusElzy8f/Q7ZkOK QA/9+yFXGso0CtxaugarQOlAY0XuG06qe7Q8LtRhtFQDxcrVwsb94sDzaQUJrg== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1784382293; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=OoFX46b4+d216UlcYcQTF09fYREVp2eIwXDaCmoCOwA=; b=LwPo7nIv7Xs1sQfqpJaDCnLRILF4YtdvjiruSpDy7LwQWUs1XiCBixIqG6qECgSbwRMhYz 81vzAZXAuF1wc4xsHkbis/1Bp969LREHI3CpWFwmiEMX1z2kezgNuMdIeLnNI7UtjfMqj8 djkeNlM8rwvRetW32kPdzGzHMvNnwzBaAmIs9CRUsFBj7ZvwlV4FOuMEwq6TMomq7Aqjqh xLNANvoczpQki6tk7V97CU/vb39b2AOa8jopT3x7LLaWnpc9TZdDuENcFhbTIV3Kd/nvfd Nn9d1HqfWnUg2r2FSAbEkFeRoxVOuZAGzM3h2eEj6y+OMoPvaPgw1fMDCK8t9g== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4h2Sh52qN2zbBj for ; Sat, 18 Jul 2026 13:44:53 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 408a1 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Sat, 18 Jul 2026 13:44:48 +0000 To: doc-committers@FreeBSD.org, dev-commits-doc-all@FreeBSD.org From: Sergio Carlavilla Delgado Subject: git: f8d86635bc - main - Handbook - ZFS: how to mount encrypted zpool with geli List-Id: Commit messages for all branches of the doc repository List-Archive: https://lists.freebsd.org/archives/dev-commits-doc-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-doc-all@freebsd.org Sender: owner-dev-commits-doc-all@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: carlavilla X-Git-Repository: doc X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: f8d86635bc2f2d2706a1f084c0bbc260468e489f Auto-Submitted: auto-generated Date: Sat, 18 Jul 2026 13:44:48 +0000 Message-Id: <6a5b8350.408a1.3a23722e@gitrepo.freebsd.org> The branch main has been updated by carlavilla: URL: https://cgit.FreeBSD.org/doc/commit/?id=f8d86635bc2f2d2706a1f084c0bbc260468e489f commit f8d86635bc2f2d2706a1f084c0bbc260468e489f Author: Sergio Carlavilla Delgado AuthorDate: 2026-07-18 13:43:48 +0000 Commit: Sergio Carlavilla Delgado CommitDate: 2026-07-18 13:43:48 +0000 Handbook - ZFS: how to mount encrypted zpool with geli PR: 240421 --- .../content/en/books/handbook/zfs/_index.adoc | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/documentation/content/en/books/handbook/zfs/_index.adoc b/documentation/content/en/books/handbook/zfs/_index.adoc index 86058d1446..86f3ef473a 100644 --- a/documentation/content/en/books/handbook/zfs/_index.adoc +++ b/documentation/content/en/books/handbook/zfs/_index.adoc @@ -1736,6 +1736,24 @@ At boot, the ZFS startup scripts enabled by `zfs_enable="YES"` in [.filename]#/e Importing a pool adds it to that cache file automatically; the `cachefile` pool property controls this behavior. Pools imported with `cachefile=none` do not come back automatically after a reboot. +[[zfs-zpool-import-geli]] +==== Importing a GELI-Encrypted Pool + +The `Encrypt Disks` option of the FreeBSD installer encrypts the pool's partitions with man:geli[8], described in crossref:disks[disks-encrypting-geli,"Encrypting Disk Partitions"], rather than with crossref:zfs[zfs-native-encryption,ZFS native encryption]. +On the installed system the loader prompts for the passphrase and attaches the providers before mounting the root pool, but ZFS itself knows nothing about the encryption: when booting from rescue media or moving the disks to another host, `zpool import` does not find the pool until the GELI providers are attached. + +Attach the encrypted [.filename]#freebsd-zfs# partition of every disk in the pool, supplying the passphrase, then import the pool: + +[source,shell] +.... +# geli attach ada0p4 +Enter passphrase: +# zpool import -f -R /mnt zroot +.... + +Use `gpart show` to identify the [.filename]#freebsd-zfs# partitions; with the default installer layout the encrypted partition is [.filename]#p4#. +Systems installed with the legacy layout, which keeps a separate unencrypted boot pool, additionally store a key file in [.filename]#/boot/encryption.key# on that pool; attach those providers with `geli attach -k /path/to/encryption.key`. + [[zfs-zpool-upgrade]] === Upgrading a Storage Pool