Home / Alt manpages / vault-init(1)

  • vault-init(1)
  • User command
  • linux

Create an Empty Encrypted Vault with vault init

vault init builds the vault directory and pads it with unreadable filler so real files blend in. This guide sizes the filler, runs it and explains why it always writes some.

The route

Jump straight to the step you need, or tick off Done means at the end.

Allow about five minutes, plus however long your disk takes to write the filler. You need free space at least equal to the filler size. No key is needed at this stage, so run vault-genkey(1) whenever suits you, but before the first add.

1. Choose the vault directory

The default is ~/.vault/store. Override it with --vault DIR or VAULT_DIR. Pick a path on a disk with the space you need.

2. Decide on filler

Filler is unreadable data written so that real files cannot be told apart from it by anyone lacking the right passphrase. Without it, a nearly empty vault would show exactly how much you stored. --filler SIZE sets the minimum, in bytes with an optional K, M, G or T suffix. The suffixes are powers of 1024, so 500M is 500 MiB. The default is 0.

Checkpoint

Filler is always written, even when SIZE is 0, so a zero-filler vault is still not blank.

3. Run it

$ vault init
$ vault init --filler 500M
$ vault init --vault /srv/vault --filler 2G

It creates records/ and objects/, each sharded into 256 subdirectories. Big filler takes real disk time, so start small if you are only testing.

4. Size it sensibly

Choose a number you are comfortable leaving on disk, since the filler is what real files hide among. Test with a small value first, then create the real vault.

5. Carry on

Add your first file with vault-add(1). The overview and shared options are in vault(1).

Done means

  • The vault directory exists with its 256-way sharded records and objects.
  • The filler size was chosen deliberately.
  • The vault path matches what VAULT_DIR or --vault will use later.
  • A key has been made, or is next on the list.