<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Clevis on Kohanyi News</title><link>https://kohanyi.net/tags/clevis/</link><description>Recent content in Clevis on Kohanyi News</description><generator>Hugo</generator><language>en-us</language><copyright>&lt;a href="https://creativecommons.org/licenses/by-sa/4.0/" target="_blank" rel="noopener"&gt;CC BY-SA 4.0&lt;/a&gt;</copyright><lastBuildDate>Wed, 19 Aug 2026 09:30:00 +0000</lastBuildDate><atom:link href="https://kohanyi.net/tags/clevis/index.xml" rel="self" type="application/rss+xml"/><item><title>Debian with Encrypted Root and Automatic Unlock via Tang + Clevis</title><link>https://kohanyi.net/posts/2026/08/debian-with-encrypted-root-and-automatic-unlock-via-tang--clevis/</link><pubDate>Wed, 19 Aug 2026 09:30:00 +0000</pubDate><guid>https://kohanyi.net/posts/2026/08/debian-with-encrypted-root-and-automatic-unlock-via-tang--clevis/</guid><description>&lt;p&gt;A recipe for installing Debian with a LUKS-encrypted root filesystem and&#10;configuring it to unlock automatically at boot using Tang and Clevis&#10;(Network-Bound Disk Encryption).&lt;/p&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;&lt;strong&gt;Disclaimer:&lt;/strong&gt; This process will nuke all data on the drives you&#10;target. Back up anything you want to keep before you start.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;p&gt;This works on plain ext4 on LUKS (Part 1 below) and on&#10;&lt;a href="https://kohanyi.net/posts/2026/08/debian-13-with-encrypted-zfs-root-zfs-on-luks/"&gt;ZFS on LUKS&lt;/a&gt;&#10;equally &amp;ndash; Clevis binds to the LUKS layer regardless of what is on top.&lt;/p&gt;</description></item></channel></rss>