In order to prepare a Linux VM for system device encryption, you must first create a separate partition for the boot drive. Because many Azure VMs are configured with the growroot option, you first need to turn off this option on the VM. Then you can increase the boot disk size and partition it.
During this procedure the VM must be powered off briefly while it is resized.
Note: If your version of ARM is different from what is described below, please see your Azure documentation.
Before You Begin
This procedure requires ssh access to the VM. To set up ssh access, see your Azure documentation.
Procedure
Log into the VM via
sshand do the following:Make sure that the boot disk is not already on a separate partition using the
df -hcommand and looking at the Mounted on column. If/bootis listed in this column, then the boot device is already running in a separate partition and you can skip to Verifying the Current VM Configuration. For example:# df -h Filesystem Size Used Avail Use% Mounted on devtmpfs 1.8G 0 1.8G 0% /dev tmpfs 1.9G 0 1.9G 0% /dev/shm tmpfs 1.9G 26M 1.8G 2% /run tmpfs 1.9G 0 1.9G 0% /sys/fs/cgroup /dev/sda1 30G 1.4G 28G 5% / /dev/sbd1 18G 53M 18G 1% /home tmpfs 370M 20K 370M 1% /run/user/467 tmpfs 370M 0 370M 0% /run/user/0
Determine the size of the current boot partition by entering the
du -sh /bootcommand.# du -sh /boot 52M /boot
The new partition you create should be about twice the size currently being used by
/boot.Turn off the
growrootoption on the VM by entering the following command:# touch /etc/growroot-disabled
- Log out of the
sshsession. - Log into the Azure Resource Manager and navigate to the VM.
- Click Stop and confirm the action at the prompt to power off the VM.
- After the VM has been fully powered off, select Settings > Disks in the left-hand tree menu.
- Click the name of the OS disk in the list.
- Click Settings > Configuration.
- In the Size field, enter the new size for the disk and click Save. You should increase the disk by at least twice the size of the current boot partition.
- Navigate back to the main server page and click Start to power the server on.
- After the server has powered on, log back into the server via
ssh. To verify that the OS disk did not automatically expand to the new disk size, enter the
df -hcommand. The size of the OS disk should be the same as it was in the first step.For example:
# df -h Filesystem Size Used Avail Use% Mounted on devtmpfs 1.8G 0 1.8G 0% /dev tmpfs 1.9G 0 1.9G 0% /dev/shm tmpfs 1.9G 26M 1.8G 2% /run tmpfs 1.9G 0 1.9G 0% /sys/fs/cgroup /dev/sda1 30G 1.4G 28G 5% / /dev/sbd1 18G 53M 18G 1% /home tmpfs 370M 20K 370M 1% /run/user/467 tmpfs 370M 0 370M 0% /run/user/0Format the new boot partition in
ext3orext4and copy the files from the existing boot partition to the new boot partition. Then you can mount the new boot partition and use that to boot the VM.How you do this depends on the version of Linux that you are using. For your convenience, we have included the instructions for formatting the new boot partition in Ubuntu, and RHEL 8. For more information, see: