Looking for advice on pool replacement with encryption

Apollo

Wizard
Joined
Jun 13, 2013
Messages
1,458
Hi,

I currently have a reliable system running 10 4TB WD RED in 2 VDEV with GELI (Legacy) encryption on TrueNAS 13.
Recently, I had to perform a disk replacement on a young disk (less than 5 years, I think).
My pool is currently showing the following statistics:

4 of them have reach 9+ year Power-on Time.
3 of them have reach 6+ year Power-on Time.
1 of them have reach 5+ year Power-on Time.
2 of them are below 5 year Power-on Time.

So to summarize, the pool is getting a bit old.
I don't really see any benefit with replacing the disk with 4TB drives anymore as I am keeping an eye on as not to exceed 80% used space (currently at 75% read from Dashboard).
4TB WD RED aren't that affordable anymore.
I am thinking of making the move to EXOS X18 18TB drives with 7 disks in RAIDZ2.

This will buy me extra storage space with faster and newer disks (albeit switching from 2 VDEV to 1 VDEV).

One of the main concern I have is related to the encryption scheme.

I am currently using GELI encryption but I have been replicating the pool to a few pools based on the new encryption standard.
This has been a bit more tricky to maintain replication due to having to reload the replication (remote backup on local LAN) server with the remote passphrase and reallocate dataset structure. Personaly, I don't see the new encryption to be that appealing as it shows the dataset name in clear text.

Nevertheless, I am looking for advice. Should I creeate a new GELI encrypted pool (using FreeNAS) and migrate the data through replication or should I go with the new Pool/dataset structure so that I can benefit from the new encryption scheme.
I am using some VM's and a few iocage jails and as such, moving with the new encryption mechanism requires I changes how the pool/dataset structure is configured.
As much as I would like to use Key for the Pool and Passphrase on dataset, the new encryption mechanism makes management of Passphrase so difficult.

I haven't performed any replication on a system based on the new encryption. It is possible the passphrase issue will disappear when replicating to a remote system.

Any recommendation/feedbacks, would be much appreciated.
 

Apollo

Wizard
Joined
Jun 13, 2013
Messages
1,458
Still awaiting for some feedback. Anyone?
 

Paul5

Contributor
Joined
Jun 17, 2013
Messages
117
My 2 cents as my set up is basic and nothing like yours, Not long ago I changed over from GELI to ZFS encryption, In future you will have no choice (I also don't thing there is yet a way of doing it in situ without loosing all data so you will need backups) anyway, I reworked how I used the passphrases including the ability to only encrypt individual datasets and decrypt on request. Though I have forgotten what I did, I did it by creating another Truenas setup with a cheap $20 mother board and a few old HDDs and USBs acting as HDDs. Once I got the hang of It and how I wanted it to work I then applied the changes to each of my GELI encrypted drives one at a time on my NAS converting all to ZFS encryption. It takes time.

From what you discribed that would probably be your best bet, create a testing NAS. This tesing NAS can also serve to see if you may want to change over to SCALE.
 
Top