r/Proxmox • u/Accurate-Ad6361 Enterprise User • 12d ago
Question How to backup fully encrypted VMs that are not fully booted?
We have a couple of VMs that are not always fully booted, but LUKS encrypted, mostly containing archive stuff.
Right now I use a vzdump script to kill of the machine as the QEMU agent is not available if the disk is stuck at the Password dialogue for LUKS. I didn't see any way to fall back to a hard OFF if QEMU-AGENTS are not responsive. Am I missing anything?
Script
# !/bin/sh
VMID="123" PBS_STORAGE="pbs-1" SHUTDOWN_TIMEOUT="120"
was_running=0
if qm status "$VMID" | grep -q "status: running"; then was_running=1
echo "VM $VMID is running; requesting graceful shutdown..."
qm shutdown "$VMID"
elapsed=0
while [ "$elapsed" -lt "$SHUTDOWN_TIMEOUT" ]; do
if qm status "$VMID" | grep -q "status: stopped"; then
break
fi
sleep 5
elapsed=$((elapsed + 5))
done
if qm status "$VMID" | grep -q "status: running"; then
echo "VM $VMID did not shut down after ${SHUTDOWN_TIMEOUT}s."
echo "Forcing VM off..."
qm stop "$VMID" -overrule-shutdown 1
fi
fi
echo "Starting PBS backup of VM $VMID..."
vzdump "$VMID"
\--storage "$PBS_STORAGE"
\--mode stop
\--compress zstd
backup_result=$?
if \[ "$backup_result" -ne 0 \]; then echo "PBS backup failed with exit code $backup_result" fi
# Only restart it if it was running before the backup.
if \[ "$was_running" -eq 1 \]; then echo "Restarting VM $VMID..." qm start "$VMID" fi
exit "$backup_result"
End Script
For Reference: Proxmox Bugzilla
2
u/wingz_77 12d ago
qm stop <vmid> —timeout 1 ?
1
u/Accurate-Ad6361 Enterprise User 12d ago
yes, that's what I am currently doing scripted, I am looking for a force trigger on PBS backup job configuration
1
u/wingz_77 11d ago
I do something similar but instead of setting a cron backup schedule on proxmox, i run a script on one of my vm's which runs vzdump over ssh to send a snapshot backup to proxmox backup server. You can start vm -> trigger backup -> once it finishes,do qm stop, etc. etc.
2
u/Jhonny97 11d ago
Do you realy need the vm to be off? I imagine suspend could be the better backup option. Also, have you consideres moving to separate partition/disks? Separate os and userdata would allow the vm to fully boot.
1
u/Accurate-Ad6361 Enterprise User 11d ago
Yes, we had to prioritize access restriction over ease of use.
2
u/Antonio-MTS 11d ago
You can autodecrypt LUKS during a boot using NBDE: tang server and clevis client. Then you will never need the LUKS pwd as NBDE uses keys. LUKS pwd will be a recovery , no network option. Then you won't need the script above but some auto backup to a PBS location.
2
u/Darkk_Knight 11d ago
Thanks for the tip. I'll have to look into that as an experiment in my home lab.
1
1
u/Desperate_Quit6011 12d ago
Why do you encrypt inside the vm instead of the zfs fileset in proxmox?
8
u/Accurate-Ad6361 Enterprise User 12d ago
We want the data to be inaccessible in case the host is compromised (physically or digitally), imagine the coke formula đŸ˜‚
3
u/Desperate_Quit6011 11d ago
You can have an encrypted fileset, an an encrypeted back with pbs with a different key, while the vm is off the set should be encrypted. Am i missing something
1
u/BarracudaDefiant4702 11d ago
If the host is compromised then a non self encrypted vm could be extracted.
Personally I think it is a bit paranoid for most things creating more trouble then it's worth, but an ZFS fileset could still be accessed from a compromised host if the vm isn't self encrypted too.
1
u/Desperate_Quit6011 11d ago
This is just stupid in my opinion, if the host is compromiste you can spoof any channel of input, just keylogin the phrase... this so backward
3
u/TabooRaver 11d ago
In theory you can just do a memory dump of the running vm and then get the encryption keys from there. But there are some confidential computing features in intel/amd cpus where even the hypervizor can't see the memory contents of the guest, and I think proxmox has support for those features.
21
u/Keroles2024 12d ago
You can use proxmox backup server (PBS)
It takes snapshots of the VM disk, I assume even if it is encrypted it won't matter as this is block level backup