Clevis and Tang LUKS Network-Bound Unlock Design Prompt
Design network-bound disk encryption with Clevis and Tang so LUKS volumes auto-unlock at boot inside the trusted network without a typed passphrase or stored key.
- Target user
- Linux administrators automating boot-time unlock for encrypted fleet disks
- Difficulty
- Advanced
- Tools
- Claude, ChatGPT
The prompt
You are a senior Linux systems engineer who has deployed Clevis/Tang network-bound disk encryption across data-center fleets and understands the SSS Shamir-secret-sharing pin and TPM2 fallback. I will provide: - My LUKS layout (cryptsetup luksDump output, devices, distro) - The Tang servers available (or that I need to stand up) and the trust model I want - Constraints: number of Tang servers, whether TPM2 should be a co-pin, and recovery expectations Your job: 1. **Confirm prerequisites** — verify LUKS2, an existing passphrase key slot, and the clevis/clevis-luks/clevis-dracut packages and dracut/initramfs integration. 2. **Stand up Tang** — give the systemd socket-activation setup, key generation (`tang-show-keys`), and firewall exposure scoping. 3. **Design the pin policy** — recommend a single Tang pin vs an SSS `t`-of-`n` policy across multiple Tang servers, optionally AND-ed with a tpm2 pin, with the exact JSON. 4. **Bind the volume** — show `clevis luks bind` per device, then `dracut -f` / initramfs rebuild so unlock happens early in boot. 5. **Plan recovery** — confirm the manual passphrase key slot survives, document `clevis luks unbind`/rebind and Tang key rotation (`/var/db/tang` rotate + advertise). 6. **Verify** — give the reboot test, `clevis luks list`, and a check that unlock fails safely (prompts for passphrase) when Tang is unreachable. Output as: a prerequisite checklist, Tang server setup block, the pin policy JSON with rationale, per-device bind commands, a key-rotation runbook, and a verification/reboot test. Never recommend removing the original passphrase key slot — if Tang is unreachable and no passphrase slot exists, the data is unrecoverable.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
LUKS Encryption Rescue Prompt
Recover access to a LUKS-encrypted volume — failed unlock, header corruption, keyslot management, header backup/restore, and TPM/clevis recovery.
-
fscrypt Per-Directory Filesystem Encryption Setup Prompt
Set up native ext4/f2fs per-directory encryption with fscrypt so individual home or data directories are encrypted with login-tied keys without full-disk encryption.
-
Linux bcache SSD Caching Setup Prompt
Design a bcache SSD-in-front-of-HDD caching tier with the right cache mode, write policy, and sequential-bypass tuning, and plan the attach/detach and failure behavior so a cache device loss never means data loss.
-
Linux fapolicyd Application Allowlisting Prompt
Design, test, and roll out fapolicyd application allowlisting so only trusted binaries and scripts execute, without locking yourself out or breaking legitimate app updates, package installs, and interpreters.
More Linux Admins prompts & error guides
Browse every Linux Admins prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.