Encrypted VPS: Full-Disk Encryption on a Root Server

LUKS guards data at rest; a running VPS still holds keys in RAM. Where the protection stops, and the container pattern that works on KVM.
Le corps de l'article est en anglais. L'interface, le catalogue et la caisse sont traduits.
What FDE buys you
Full-disk encryption with LUKS protects the states you are not watching: a disk pulled from a decommissioned host, a snapshot parked in cold storage, a rescue mount performed without you. In those states the data is ciphertext and useless without your passphrase. On a running machine the picture changes — the kernel keeps the keys in memory and the volume is plaintext to root. So the honest boundary is: the running host's administrator is out of scope, and nearly everything else is in scope.
VPS from $3* (fund $50+), storage 1–5 TB NVMe from $24/mo annual-eff, dedicated with IPMI from $30.80/mo. Crypto invoice, no KYC.
Launch nowThe VPS caveat, stated honestly
A KVM VPS receives its decryption key over the wire at boot, which means the platform side of the boot is a place your key exists. Two patterns work around that in a no-KYC context. Pattern one, the common middle ground: keep only encrypted volumes inside the machine — LUKS on a loop file or on a secondary disk — and open them over SSH after each boot with a key only you hold. A reboot then waits for you, and nobody mounts your data by casually attaching the disk. Pattern two is metal: on a dedicated server you control the boot chain end to end and can carry the key in an initrd you own, with IPMI as the console of last resort.
Setup path (LUKS container pattern)
- Provision a plain VPS, then
cryptsetup luksFormata volume or a loop file sized for the sensitive set. - Open it with your passphrase, build the filesystem inside, and move the data in — keys, mail spools, databases, configuration secrets.
- Wire a
keyscriptor systemd unit so reboots wait for input, or open it manually over SSH each time. - Back up the LUKS header to a place you control and test that restore; a header lost without backup means a volume lost with it.
Does NulNet encrypt my disks for me?
No — root means the keys are yours end to end, and that is the only design worth having here. You configure LUKS inside your own OS; we hold no copy, offer no escrow, and cannot reset a passphrase we never saw.
Can you help if I lose my LUKS passphrase?
Not past the limit of physics and math: without the passphrase or a header backup, the volume is gone. That is the property you bought. Keep the header and the passphrase backed up somewhere that is not the same disk.
Is FDE possible on the Storage plans?
Yes — storage boxes are the same root KVM with bigger disks, from 1 TB NVMe at $30 list ($24 on the annual term) upward. For cold archives, a LUKS container opened only while you are actively writing is the usual pattern.
Which tier suits encryption best?
A VPS handles the container pattern for most sets; when the boot chain itself must hold no third party, that is the dedicated argument — own the initrd, keep IPMI for emergencies. The <a href="../dedicated-storage-server/">dedicated storage server</a> pages map disk classes to tiers.
Ready to launch?
Build the box — VPS, storage or bare metal — create the password, pay the invoice that follows.