TLDR: is it possible and will it help
to have several fdisk partitions, each encrypted individually,
instead of a single encrypted partition,
to decrease risk of (full) data corruption?


This is a NAS setup at home for personal needs.
I don't have any UPS while power outages (PO) do happen.

I have been running 24/7 a 4TB shingled (SMR) HDD with FDE
that is also a boot disk.
It runs fine for my needs,
but I have experienced (minor) data loss,
presumably from a PO.

I have just got a 14TB conventional (CMR) HDD
to put it in place of the 4TB HDD.

I can deal with some files lost or corrupted, but
I really shudder to think the whole disk might get
undecryptable/unbootable. Even having data and dotfile backups,
14TB is so big that putting all back is a hurdle.

The idea is: split the HDD into three or four fdisk partitions,
fill certain partition then make it read-only,
leave other partitions RW.
Eventually PO corrupts certain RW partition to undecryptability
maybe leaving another RW partition decryptable,
and almost certainly leaving RO partition decryptable.

So something lost and something kept instead of all lost.

1. Do I understand the way how it works right?
2. Can the FDE partition become undecryptable and unbootable?
3. Is it possible to split the HDD into a few encrypted partitions?
4. Will it help against corruption?
5. If yes, how to split?
   Esp. given that for large disks one probably wants GPT, not MBR.
6. What are the recommendations to lessen PO impact of a FDE
   except UPS and backups?


Reply via email to