Audit LVM Configuration Safely with lvmconfig

lvmconfig shows exactly which LVM settings are active and where each one came from. By the end of this guide you will be able to separate local changes from defaults, validate the configuration cascade, and save a reviewable snapshot without changing storage. The examples target lvm2 2.03.16(2), installed here as package version 2.03.16-3ubuntu3.2. Allow about 10 minutes for a read-only audit.

Before you start

You need the lvmconfig command from the lvm2 package and a shell account that can read the LVM configuration. The inspection commands do not normally need sudo. Use elevated privileges only when your host's file permissions require them. This guide does not create, remove, resize or activate a logical volume.

The aliases lvm-config and lvm-dumpconfig are compatibility names for the same tool. Prefer lvmconfig in new scripts. The installed command reports its version with:

$ lvmconfig --version
  LVM version:     2.03.16(2) (2022-05-18)

Checkpoint: if the command is missing, stop and install or repair lvm2 through your normal package-management process. Do not copy a configuration file from another host just to make this command run.

1. See the settings that differ from defaults

Start with the smallest useful report. diff prints settings changed from their defaults in the LVM configuration files:

$ lvmconfig --typeconfig diff

The output is LVM configuration syntax. A quiet system may print only a few sections. That is not the same as an empty configuration: many defaults are internal to LVM and are not written into the files.

For a quick view of the settings an ordinary LVM command would apply, use current:

$ lvmconfig --typeconfig current

current includes settings modified in configuration files, settings whose defaults come from configuration files, and defaults explicitly uncommented there. Command-line overrides still win, so this report describes the command without additional overrides.

2. Choose the report that matches the question

Do not use default as if it were a live configuration dump. It deliberately ignores changes made in LVM configuration files. Use this short map when a report name is easy to forget:

QuestionReportWhat it shows
What is active?currentEffective settings from the configuration cascade
What did an administrator change?diffSettings changed from defaults in configuration files
What would LVM use if files were unchanged?defaultAll known settings with their defaults
What is explicitly set, including internal defaults?fullEvery uncommented setting and its current value
Which names exist without values?listConfiguration names, without values
What is absent from the files?missingSettings missing from LVM configuration files

The short option --list is equivalent to --typeconfig list --withsummary. Add --withcomments or --withversions when you need context for a setting during review:

$ lvmconfig --typeconfig diff --withcomments
$ lvmconfig --typeconfig list --withversions | sed -n '1,30p'

Checkpoint: record whether you are reviewing current, diff or a different report. Comparing unlike reports is a common source of false alarms.

3. Inspect one setting with a temporary override

Use --config when you want to see the result of a command-line setting without editing /etc/lvm/lvm.conf. The option uses LVM configuration syntax and overrides file settings for this invocation. For example:

$ lvmconfig --config 'devices/issue_discards=1' --typeconfig current | grep -A2 '^devices {'

This is a read-only inspection of the command's configuration input. It does not write lvm.conf. Quoting the argument prevents the shell from interpreting punctuation. Replace the setting only with a real section and field that you have checked in lvm.conf(5); an invented name is not a safe experiment.

Configuration can come from several layers, including lvm.conf, local settings, command profiles and metadata profiles. Without --mergedconfig, a report using an override can show only the front of that cascade. To inspect the combined result:

$ lvmconfig --config 'devices/issue_discards=1' --mergedconfig --typeconfig current

--ignorelocal excludes the local section. That can help when preparing a portable review, but it also hides host-specific settings. Never copy a report containing local values to another machine without checking that distinction.

4. Validate the configuration you actually use

Run the validator before changing a configuration file or during incident triage:

$ lvmconfig --validate
  LVM configuration valid.

The exit status is the useful result for automation:

$ lvmconfig --validate
$ status=$?
$ printf 'lvmconfig validation status: %s\n' "$status"

Validation checks the front of the configuration cascade. If profiles or a command-line configuration are involved, validate the merged tree as well:

$ lvmconfig --mergedconfig --validate

This option validates even when the config/checks setting disables normal checks. A successful validation means the configuration is acceptable to this installed LVM version; it does not prove that a planned storage operation is safe.

5. Save a snapshot without overwriting anything

Redirecting output to a new filename gives you an audit artefact that can be diffed later. The --file option is also available, but a shell redirection makes the destination obvious:

$ snapshot="lvmconfig-$(date +%Y%m%d-%H%M%S).conf"
$ lvmconfig --typeconfig current --withcomments > "$snapshot"
$ test -s "$snapshot" && sed -n '1,24p' "$snapshot"

Choose a directory where your account can write. Do not redirect straight to /etc/lvm/lvm.conf: that would replace the live configuration and could disrupt later LVM commands. If you need to install a reviewed change, preserve the original first and use your site's change-control procedure. Recovery from an accidental edit is to restore the verified backup, then run lvmconfig --validate before relying on LVM again.

6. Compare versions and avoid misleading output

When reviewing a configuration for another LVM release, use --atversion with a complete x.y.z version. It limits displayed settings to those recognised by that version:

$ lvmconfig --atversion 2.03.16 --typeconfig default

To find settings introduced since a known version, combine --sinceversion with --typeconfig new:

$ lvmconfig --sinceversion 2.03.15 --typeconfig new

The installed manual says that --sinceversion currently applies only to the new report. Do not assume it filters current or diff. Deprecated and unsupported settings are normally filtered for most report types, while current and diff include them by default. Add --ignoreunsupported or --showdeprecated deliberately when comparing reports across releases. Some report types reject version filters rather than silently doing something different, so check the exit status.

Common traps

Done means