Many virtual disks are thin-provisioned so physical storage is only created when the Linux or Windows filesystem allocates and writes new blocks. Encrypting disk partitions can increase the amount of storage required and can, at times, essentially convert thin-provisioned disks to thick-provisioned. The following table describes what will happen for Windows and Linux depending on the disk type and the filesystem that uses it.

Linux Disks

The effect of encryption, decryption, and rekeying on Linux data disk provisioning depends on whether you used the -s option with the hcl encrypt , hcl decrypt, or hcl rekey commands. The -s option tells hcl to only encrypt, decrypt, or rekey the allocated blocks on the disk, and it retains thin-provisioning where possible.

Note: The -s option is not supported for root drives, data drives that use the XFS filesystem, or any Linux data drives that have the Online Encryptionfeature enabled. For more information, see Encrypting a Disk Using the CLI.

Filesystem Type

Root Drives

Data Drives
with -s Option

Data Drives
without -s Option

ext2

Always become thick-provisioned (-s not supported).

Thin-provisioned disks remain thin after encryption.

Always become thick-provisioned.

ext3

Always become thick-provisioned (-s not supported).

Thin-provisioned disks remain thin after encryption.

Always become thick-provisioned.

ext4

Always become thick-provisioned (-s not supported).

Thin-provisioned disks remain thin after encryption.

Always become thick-provisioned.

XFS

Always become thick-provisioned (-s not supported).

Always become thick-provisioned (-s not supported).

Always become thick-provisioned.

Windows Disks

The effect of data encryption, decryption, or rekeying on Windows disk provisioning depends on the filesystem type and whether the target is a boot drive or a data drive. For each filesystem, the results are the same for MBR and GPT partitions.

Filesystem Type

Boot Drives

Data Drives

NTFS

Always become thick-provisioned as all blocks on the boot drive are encrypted.

Data drive encryption, decryption, and rekeying preserves thin disks. We have measured around 5% increase in thin volume space utilization when the drive is first encrypted.

ReFS

Boot drive encryption is not supported for ReFS.

Data drive encryption, decryption, and rekeying preserves thin disks. We have measured around 5% increase in thin volume space utilization when the drive is first encrypted.