I've read several scary stories about ZFS encryption and have reached the same conclusion. Meanwhile, based on the accounts I've read, running ZFS on top of LUKS seems to be a more stable approach.
In any case, nice and detailed write-up. The nice thing about open source is that you can do "hacks" like you did.
I emphatically agree, unencrypted ZFS on top of GELI or LUKS encrypted block devices is the way to go for now. Plus it also has the benefit of not leaking metadata like a sieve.
My mistake was placing too much trust in ZFS's reputation for data integrity; clearly not all features hold that value in the same regard.
The openness of OpenZFS was a real saving grace. If this had occurred on a propriety SAN, that data would be gone forever.
mentalpagefault•4mo ago