I'm using Shavee to unlock a ZFS dataset as part of my boot process, and thought I'd share how I'm doing it:
/etc/systemd/system/zfs-shavee-unlock@.service
[Unit]
Description=Unlock ZFS Dataset %I with Shavee
DefaultDependencies=no
Before=systemd-user-sessions.service
Before=zfs-mount.service
After=zfs-import.target
After=systemd-vconsole-setup.service
[Service]
Type=oneshot
RemainAfterExit=yes
ExecStart=/bin/sh -c 'set -eu;keystatus="$$(/sbin/zfs get -H -o value keystatus "%I")";[ "$$keystatus" = "unavailable" ] || exit 0;count=0;while [ $$count -lt 3 ];do systemd-ask-password --id="zfs:%I" "Enter passphrase for %I"| shavee -y -s 1 -z "%I" && exit 0; count=$$((count + 1));done;exit 1'
ExecStop=/bin/sh -c 'set -eu;keystatus="$$(/sbin/zfs get -H -o value keystatus "%I")";[ "$$keystatus" = "available" ] || exit 0;/sbin/zfs unload-key "%I"'
[Install]
WantedBy=zfs-mount.service
I'm using Slot 1 for HMAC challenges on my Yubikey, so you may need to alter the Shavee command if you're using a different slot
Then just enable the service for your encrypted pool, e.g. to unlock zroot/data you'd do systemctl enable zfs-shavee-unlock@zroot-data
I'm using Shavee to unlock a ZFS dataset as part of my boot process, and thought I'd share how I'm doing it:
/etc/systemd/system/zfs-shavee-unlock@.service
I'm using Slot 1 for HMAC challenges on my Yubikey, so you may need to alter the Shavee command if you're using a different slot
Then just enable the service for your encrypted pool, e.g. to unlock
zroot/datayou'd dosystemctl enable zfs-shavee-unlock@zroot-data