Many virtual disks are thin-provisioned so physical storage is only created when the Linux or Windows filesystem allocates and writes new blocks. Encrypting disk partitions can increase the amount of storage required and can, at times, essentially convert thin-provisioned disks to thick-provisioned. The following table describes what will happen for Windows and Linux depending on the disk type and the filesystem that uses it.
Linux Disks
The effect of encryption, decryption, and rekeying on Linux data disk provisioning depends on whether you used the -s option with the hcl encrypt , hcl decrypt, or hcl rekey commands. The -s option tells hcl to only encrypt, decrypt, or rekey the allocated blocks on the disk, and it retains thin-provisioning where possible.
Note: The -s option is not supported for root drives, data drives that use the XFS filesystem, or any Linux data drives that have the Online Encryptionfeature enabled. For more information, see Encrypting a Disk Using the CLI.
Filesystem Type | Root Drives | Data Drives | Data Drives |
|---|---|---|---|
ext2 | Always become thick-provisioned ( | Thin-provisioned disks remain thin after encryption. | Always become thick-provisioned. |
ext3 | Always become thick-provisioned ( | Thin-provisioned disks remain thin after encryption. | Always become thick-provisioned. |
ext4 | Always become thick-provisioned ( | Thin-provisioned disks remain thin after encryption. | Always become thick-provisioned. |
XFS | Always become thick-provisioned ( | Always become thick-provisioned ( | Always become thick-provisioned. |
Windows Disks
The effect of data encryption, decryption, or rekeying on Windows disk provisioning depends on the filesystem type and whether the target is a boot drive or a data drive. For each filesystem, the results are the same for MBR and GPT partitions.
Filesystem Type | Boot Drives | Data Drives |
|---|---|---|
NTFS | Always become thick-provisioned as all blocks on the boot drive are encrypted. | Data drive encryption, decryption, and rekeying preserves thin disks. We have measured around 5% increase in thin volume space utilization when the drive is first encrypted. |
ReFS | Boot drive encryption is not supported for ReFS. | Data drive encryption, decryption, and rekeying preserves thin disks. We have measured around 5% increase in thin volume space utilization when the drive is first encrypted. |