Create an Empty Encrypted Vault with vault init
vault init builds the vault directory and pads it with unreadable filler so real files blend in. This guide sizes the filler, runs it and explains why it always writes some.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about five minutes, plus however long your disk takes to write the filler. You need free space at least equal to the filler size. No key is needed at this stage, so run vault-genkey(1) whenever suits you, but before the first add.
1. Choose the vault directory
The default is ~/.vault/store. Override it with --vault DIR or VAULT_DIR. Pick a path on a disk with the space you need.
2. Decide on filler
Filler is unreadable data written so that real files cannot be told apart from it by anyone lacking the right passphrase. Without it, a nearly empty vault would show exactly how much you stored. --filler SIZE sets the minimum, in bytes with an optional K, M, G or T suffix. The suffixes are powers of 1024, so 500M is 500 MiB. The default is 0.
Checkpoint
Filler is always written, even when SIZE is 0, so a zero-filler vault is still not blank.
3. Run it
$ vault init
$ vault init --filler 500M
$ vault init --vault /srv/vault --filler 2GIt creates records/ and objects/, each sharded into 256 subdirectories. Big filler takes real disk time, so start small if you are only testing.
4. Size it sensibly
Choose a number you are comfortable leaving on disk, since the filler is what real files hide among. Test with a small value first, then create the real vault.
5. Carry on
Add your first file with vault-add(1). The overview and shared options are in vault(1).
Done means
- The vault directory exists with its 256-way sharded records and objects.
- The filler size was chosen deliberately.
- The vault path matches what
VAULT_DIRor--vaultwill use later. - A key has been made, or is next on the list.