Linux

Where Does gocryptfs Store Config and Keys?

gocryptfs keeps its config at the cipher dir root, with per-directory IV files and an encrypted view under it.

Last updated

gocryptfs has no registry, no home-directory database, no central anything. Each encrypted filesystem is self-describing: gocryptfs.conf at the cipher directory root holds the parameters, and every subdirectory carries its own gocryptfs.diriv for filename encryption.

That design makes the cipher directory the backup target and the mount point disposable. Lose gocryptfs.conf and the password alone cannot reopen the data without the printed master key, which is why init tells you to store it separately. Keep the conf and the master key in different places.

Where gocryptfs stores this, by platform

Linux
<cipherdir>/gocryptfs.conf (cipher directory root)

Holds gocryptfs.conf plus per-directory gocryptfs.diriv files. The mount point shows plaintext and holds nothing. Back up the cipher dir, and store the printed master key apart from it.

Frequently asked questions

Is backing up the encrypted folder enough?

Yes, and that is the supported backup unit. Copy the whole cipher directory; it holds config, IVs, and ciphertext together. Never back up only the mounted plaintext view.

Notice an outdated path? Let us know.