TrueNAS
Products
Support & Resources
Solutions
Company
Sign In

Adding and Managing Datasets

A TrueNAS dataset is a file system within a data storage pool. Datasets can contain files, directories, and child datasets, and have individual permissions or flags.

Datasets can also be encrypted. In TrueNAS 22.12.3 or later, the TrueNAS UI requires encryption for child datasets created in encrypted parent datasets, but you can change the encryption type from key to passphrase. You can create an encrypted dataset if the parent is not encrypted and set the type as either key or passphrase.

Read full post gdoc_arrow_right_alt

Configuring ACL Permissions

TrueNAS provides basic permissions settings and an access control list (ACL) editor to define dataset permissions. ACL permissions control the actions users can perform on dataset contents and shares.

An Access Control List (ACL) is a set of account permissions associated with a dataset that applies to directories or files within that dataset. TrueNAS uses ACLs to manage user interactions with shared datasets. When you create a dataset, TrueNAS sets the ACL type based on the dataset preset, but you must configure the ACL before it becomes active.

ACL Types in TrueNAS

TrueNAS offers two ACL types: POSIX and NFSv4. The Dataset Preset setting on the Add Dataset screen determines the type of ACL for the dataset. Datasets created with the Generic dataset preset have the ACL type set to a POSIX (Unix) ACL. Datasets created with the SMB dataset preset have the ACL type set to an NFSv4 ACL. SMB shares require the more robust configurations in an NFSv4 ACL.

Read full post gdoc_arrow_right_alt

Encrypting Datasets

TrueNAS offers ZFS encryption for your sensitive data in pools, datasets, and zvols. Encrypting pools is not recommended!

Data-at-rest encryption is available with:

The local TrueNAS system manages keys for data-at-rest. Users are responsible for storing and securing their keys.

Pool and Dataset Encryption

Encryption is for users storing sensitive data.

Read full post gdoc_arrow_right_alt

Encryption

TrueNAS supports dataset and zvol encryption to secure stored data at rest.

Contents

  • Encrypting Datasets: Provides information on TrueNAS storage encryption for pools, root datasets, datasets, and zvols.

    • Encryption Screen: Provides information on the settings and functions found on the TrueNAS storage encryption screens.

      Managing User or Group Quotas

      TrueNAS allows setting data or object quotas for datasets, or user and groups accounts cached on or connected to the system.

      Setting Up Dataset Quotas

      You can set up quotas through the Add Dataset > Advanced Options or Capacity Settings screens. Dataset quotas allocate space in the datasets by parent alone or parent and any child datasets of the parent. Use the quota settings on the Add Dataset > Advanced Options screen to set up quota alarms and set aside space in a dataset.

      Read full post gdoc_arrow_right_alt

      Permissions

      TrueNAS provides ACL-based permission controls for datasets to manage user and group access to stored data.

      Contents

      • Configuring ACL Permissions: Provides general information on ACLs, and instructions on editing and viewing ACL permissions using the ACL editor screens.

        • Edit ACL Screen: Describes the ACL permissions screens, settings for POSIX and NFSv4 ACLs, and the conditions that result in additional setting options.

          Quotas

          TrueNAS quota settings limit how much storage space a dataset, user, or group can consume.

          Contents

          Capacity Settings Screen

          The Capacity Settings screen allows users to add or edit existing quotas for the selected dataset and any of the child datasets for the selected dataset apart from the dataset creation process.

          The settings on the Capacity Settings screen are the same as those in the quota management section on the Add Dataset > Advanced Options screen.

          CapacitySettingsScreen

          SettingDescription
          Quota for this dataset
          Quota for this dataset and all children
          Sets the maximum allowed space for dataset. 0 disables quotas. # the same for This Dataset and the This Dataset and Child Datasets fields.
          Quota warning alert at, %Sets the percentage value to generate a warning level alert when consumed space reaches the defined level. By default, the dataset inherits this value from the parent dataset. Clear the Inherit checkbox to change the value.
          Quota critical alert at, %Sets the percentage value to generate a critical level alert when consumed space reaches the defined level. By default, the dataset inherits this value from the parent dataset. Clear the Inherit checkbox to change the value.
          Reserved space for this dataset
          Reserved space for this dataset and all children
          Sets a reserve of additional space for datasets that contain logs that could eventually take up all the available free space. 0 is unlimited.

          Edit ACL Screen

          TrueNAS offers two Access Control List (ACL) types: POSIX (the TrueNAS default) and NFSv4. For a more in-depth explanation of ACLs and configurations in TrueNAS, see our ACL Primer.

          The Dataset Preset option on the Add Dataset screen sets the ACL type applied for SMB shares, apps, multi-protocol shares, and general-use datasets.

          The ACL Type setting in the Advanced Options on both the Add Dataset and Edit Dataset screens, determines the ACL presets available on the ACL Select a preset ACL window. It also determines which permissions editor screens you see after you click the edit edit icon on the Dataset Permissions widget.

          Read full post gdoc_arrow_right_alt

          Encryption Screen

          The Datasets screen shows the Encryption card after selecting a datasets, root, non-root parent, and child, or zvols with encryption.

          The Datasets tree table includes lock icons and descriptions that indicate the encryption state of datasets.

          IconStateDescription
          DatasetLockedEncryptionIconLockedDisplays for locked encrypted root, non-root parent and child datasets.
          DatasetUnlockedEncryptionIconUnlockedDisplays for unlocked encrypted root, non-root parent and child datasets.
          DatasetLockedByAncestorEncryptionIconLocked by ancestorDisplays for locked datasets that inherit encryption properties from the parent.
          DatasetUnlockedbyAncestorEncryptIconUnlocked by ancestorDisplays for unlocked datasets that inherit encryption properties from the parent.

          Edit on the Encryption card opens the Edit Encryption Options for dataset namne window.

          Read full post gdoc_arrow_right_alt