Passphrase-less reboots using kexec under NixOS
Encrypted hard drives are essential for data security, even in cases of theft or server room theft. However, enforcing encryption adds time and error risk to the reboot process. Reboots often become necessary for software updates, requiring manual decryption steps that introduce complexity and potential security vulnerabilities.
Kexec is a mechanism that allows the existing kernel to execute a new one without a complete system shutdown. This mechanism can pass decryption information stored in RAM from the old kernel to the new kernel. In this case, the passphrase for LUKS encryption could be passed this way, eliminating the need for a manual decryption step.
The article describes a solution implemented in NixOS to reboot servers without a manual decryption step, while retaining the security of full-disk encryption. The solution generates a temporary keyslot with a temporary passphrase, assigns that passphrase to the keyslot, and deletes the keyslot after a successful kexec. The temporary passphrase is embedded in a special initramdisk image, preventing potential security risks from the key being exposed in the kernel command line.
The process involves extending systemd.services.prepare-kexec with custom steps. After mounting the root filesystem, the key slot is removed via a custom systemd unit defined in boot.initrd.systemd.services. Upon rebooting using systemctl start kexec.target, the server comes back up fully functional and ready for use in under 2 minutes.
Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.