Encrypt an already-installed Linux root filesystem in place with LUKS2 — no reinstall, no second copy of your data. Idempotent, auto-detects the distro, filesystem and boot stack, GRUB or systemd-boot, rebuilds and re-signs Unified Kernel Images for systemd-boot and Secure Boot, pins argon2id, and gates the reboot behind full verification.
raspberry-pi ext4 btrfs bootloader grub disk-encryption cryptsetup secure-boot systemd-boot dm-crypt dracut initramfs full-disk-encryption argon2id mkinitcpio crypttab fde uki luks2 in-place-encryption
-
Updated
Sep 5, 2026 - Shell