that’s what trixie’s netinst defaults to when i set up new desktops using encrypted lvm… root and swap volumes inside that, unlocking together at boot. my use doesn’t hit swap much, so it’s nbd. i just leave it like it is. only where an installer doesn’t support encrypted swap partitions do i use a file or ram-based swap instead.
It’s not as bad with LVM since LVM is more flexible. A swap file does still make it easier to change the size as needed though. If you need more swap, you can spin up a new swap file pretty much instantly while the system is running, without having to repartition. You can have both a swap partition and a swap file active at the same time though.
On systems where the data is encrypted, also encrypting the swap makes sense so I’m glad Debian does that.
It’s doable with a swap file instead. But some filesystems are more supportive than others.
For example BTRFS doesn’t support swapfiles over multiple devices (so my raid1c3 spanning 3 differently sized disks for example) and also swapfiles must be completely pre-allocated. (On the plus side BTRFS automatically blocks any accidently attempt to backup a subvolume containing a swap file.)
And no matter the filesystem you need to manually tell the kernel device and physical offset for the file via kernel parameters. Which can again be easier on some than on others (also causing the no-multiple-device filesystem problem mentioned above.
Generally it only happens to programs you keep running in the background and might not use for a long time that also don’t have much background activity. For example password managers.
People still use swap partitions instead of swap files?
that’s what trixie’s netinst defaults to when i set up new desktops using encrypted lvm… root and swap volumes inside that, unlocking together at boot. my use doesn’t hit swap much, so it’s nbd. i just leave it like it is. only where an installer doesn’t support encrypted swap partitions do i use a file or ram-based swap instead.
It’s not as bad with LVM since LVM is more flexible. A swap file does still make it easier to change the size as needed though. If you need more swap, you can spin up a new swap file pretty much instantly while the system is running, without having to repartition. You can have both a swap partition and a swap file active at the same time though.
On systems where the data is encrypted, also encrypting the swap makes sense so I’m glad Debian does that.
Don’t you need swap partitions to be able to use hibernation?
Nah, you can use
resume_offsetinstead.Here’s an example: https://forum.endeavouros.com/t/how-to-hibernate-with-btrfs-swapfile-luks2-systemd-boot-dracut/55620/2
It’s doable with a swap file instead. But some filesystems are more supportive than others.
For example BTRFS doesn’t support swapfiles over multiple devices (so my raid1c3 spanning 3 differently sized disks for example) and also swapfiles must be completely pre-allocated. (On the plus side BTRFS automatically blocks any accidently attempt to backup a subvolume containing a swap file.)
And no matter the filesystem you need to manually tell the kernel device and physical offset for the file via kernel parameters. Which can again be easier on some than on others (also causing the no-multiple-device filesystem problem mentioned above.
I don’t use hibernation so I’m not sure.
So you shut your pc down like a caveman when you do hardware upgrades or repairs or move apartments?
Yeah I shut down every day. It boots up fast enough that it’s really not an issue.
Nope, I hibernate with a swap file and it’s in a LUKS partition. Although IIRC that whole setup requires me to use systemd boot.
This. Swap files on LUKS encrypted partition. Also, the swapspace daemon!
I’ve seen so many setups where people encrypt their data but forget to encrypt their swap.
what’s the problem? it’s not like you dump the entire contents of your system’s ram to disk any time use hibernate /s
Even without hibernation, data in apps you have open will end up in the swap if your system is ever RAM-constrained.
Generally it only happens to programs you keep running in the background and might not use for a long time that also don’t have much background activity. For example password managers.