Automatic full disk encryption for Oracle Cloud
The supported-image table below is for one path: assisted setup on fresh, unencrypted Oracle Cloud images. It is not the full Panocrypt-managed unlock compatibility boundary.
If a Linux system already uses LUKS, or you set up LUKS yourself on another
provider or distro, you can usually bind an unused keyslot to Panocrypt with
your distro’s cryptsetup, Clevis, and the standard Clevis tang pin. No
Panocrypt host software is required for that path. Start with
Bind an existing LUKS volume or
Bind an existing encrypted root disk.
Use this page when you want the Panocrypt setup helper to run from cloud-init/user-data, set up LUKS on the root disk, bind managed boot unlock, and verify encrypted boot.
Supported Oracle Cloud images
Section titled “Supported Oracle Cloud images”| Distribution | Versions |
|---|---|
| Ubuntu | 22.04, 24.04 |
Already upgraded a host to Ubuntu 26.04?
Section titled “Already upgraded a host to Ubuntu 26.04?”Oracle Cloud does not publish an Ubuntu 26.04 image yet, so 26.04 is not a launch option and is not listed above. If you have upgraded an Oracle Cloud host in place to 26.04, Panocrypt works there — both assisted setup on the upgraded host and managed boot unlock afterwards.
Related guides
Section titled “Related guides”| Goal | Guide |
|---|---|
| Understand the two Panocrypt paths | What runs on your server |
| Understand assisted setup | Assisted fresh-server setup |
| Preserve recovery material | Assisted setup recovery material |
| Compare provider setup paths | Assisted setup providers |
| Learn how LUKS keyslots make removal simple | LUKS keyslots |