How to fully encrypt your Ubuntu installation with LUKS
Full-disk encryption has shifted from a niche concern to a baseline expectation for anyone carrying a portable device through airports, cafés, and conference venues. In Australia, where major breaches at telcos and health insurers have pushed data handling into public discussion, the question is less about whether to encrypt and more about how to do it cleanly on a fresh Ubuntu system.
LUKS, the Linux Unified Key Setup, sits underneath Ubuntu's installer as the default mechanism for protecting every byte written to disk. When configured properly, it forces an unlock at boot and renders the storage unreadable to anyone pulling the drive or booting from a USB stick. The trade-off, a single passphrase prompt every time the laptop wakes up, is small compared to the damage an unencrypted machine can cause if it ends up in the wrong hands.
Preparing your system and backups before you begin
Before touching the installer, gather a few practical items so the process runs without interruption. A USB stick of at least 8 GB is needed for the Ubuntu live medium, and a second drive or cloud backup is essential because encryption wipes the target disk completely. Australians working remotely often rely on the NBN for downloads, so pick a time of day with a stable connection or download the ISO at a workplace with fibre to avoid a half-finished installer.
Take an hour to back up your documents, browser profiles, and any .ssh directories. Migration from Windows to Ubuntu occasionally pulls across BitLocker-encrypted folders, which won't open on Linux without a recovery key, so note those keys down somewhere offline. The Australian Cyber Security Centre recommends keeping backups in at least two separate locations, a habit worth keeping once the new system is installed.
Battery and power matter too. Plug the laptop in, because a mid-install shutdown on a desktop that loses power can corrupt the boot loader and leave the drive inaccessible even with the correct passphrase. For those running a tower in Adelaide or Brisbane where summer storms are common, an uninterruptible power supply is a wise add-on before any major disk operation.
Choosing your encryption method in the Ubuntu installer
Recent Ubuntu releases default to LVM on top of LUKS, which provides the right balance for most users. The installer offers three storage options: erase the disk and reinstall, run alongside an existing system, or take full manual control with a custom layout. The guided option wipes the drive and applies encryption automatically, while manual mode exposes a partition table for those who want to keep an existing partition or follow a layout inspired by a talk caught at linux.conf.au. Either path works, as long as the LUKS container spans the entire root filesystem and the boot partition remains unencrypted so GRUB can do its job.
A quick comment on algorithms: Ubuntu's installer currently uses AES-256 in XTS mode, the same cipher recommended by the Australian Signals Directorate for protecting sensitive government data. There is rarely a reason to change it, though power users comfortable with cryptsetup can switch to a different cipher later without reinstalling.
Enabling LUKS during a guided install
Boot from the USB, choose the install option, and step through the language and keyboard prompts until the storage screen appears. Tick the box for full-disk encryption, then choose a security key. The passphrase screen will not show progress bars or strength meters, so type carefully.
Ubuntu also offers a checkbox to require a separate key file for unlocking. That file is stored on a USB drive and acts as a fallback if the passphrase is forgotten, similar to the recovery key you might receive from Apple or Microsoft. In a country where postal deliveries occasionally take the scenic route, the key-on-USB approach is usually more reliable than a printout mailed from a vendor.
After confirming, the installer summarises the partition layout. Read the summary, look for LVM and LUKS in the list, and check that the EFI partition remains mounted at /boot/efi. Pressing install commits the change. The whole process, from boot menu to first restart, generally takes between fifteen and thirty minutes on a typical NVMe drive.
Configuring the boot partition and unlocking on boot
The unencrypted EFI partition holds GRUB and a small initramfs that knows how to ask for the LUKS passphrase before handing control to the encrypted root. Because this region is necessary for the machine to find the kernel, it can never be encrypted. The trade-off is that an attacker could tamper with it, so enabling Secure Boot in the firmware adds a layer that helps block unsigned modifications.
On first boot, GRUB will pause with a small terminal-like prompt asking for the disk passphrase. Type the passphrase, hit Enter, and watch the usual Ubuntu splash appear. If your laptop has a TPM 2.0 chip, newer Ubuntu builds can store the key inside the chip and skip the prompt at boot, which is convenient but slightly less secure on machines that may sleep unattended in a shared Melbourne office.
If you ever need to unlock the disk from a live USB for repairs, install cryptsetup on the live environment, then run sudo cryptsetup open /dev/nvme0n1p3 ubuntu and supply the passphrase. The decrypted volume becomes /dev/mapper/ubuntu, and you can mount it normally.
Managing encryption day to day
Once the system is running, adding a new user does not affect the encryption at all; access is bound to the passphrase, not to user accounts. Changing the passphrase is done with sudo cryptsetup luksChangeKey /dev/nvme0n1p3, and you can add up to seven additional key slots if a flatmate or family member needs access to the same machine. Listing the slots with sudo cryptsetup luksDump reveals which are in use, which is handy when decommissioning an old drive and confirming nothing is left behind.
Keep a copy of the recovery key somewhere safe, ideally a password manager with Australian-based hosting, or a sealed envelope filed with the household paperwork. The Notifiable Data Breaches scheme has reshaped how organisations handle personal data, and the same care applies to recovery keys, since a leaked recovery string is as good as the passphrase itself.
For those running a home server on the NBN, accessing an encrypted headless box remotely requires a properly configured /etc/crypttab and an initramfs that knows how to drop to an SSH prompt over the network. That configuration is well documented in the Ubuntu Server Guide and is the kind of topic regularly workshopped at Brisbane and Perth Linux user groups.
Avoiding and recovering from common issues
A handful of mistakes catch first-time users. Forgetting the passphrase is the obvious one, and without the recovery key it really is game over: the data cannot be retrieved, which is the whole point of encryption. A second mishap is installing over an existing Windows BitLocker volume without exporting the recovery key first, leaving a pile of files that Linux refuses to decrypt.
Boot failures after a kernel update sometimes stop at the LUKS prompt because GRUB needs rebuilding. Holding Shift during startup reveals the menu, typing c drops into a shell, and a few well-placed commands can rescue the system. Searching the Ubuntu Discourse for the specific error usually surfaces a thread from someone in Sydney or Hobart who hit the same glitch on a ThinkPad or a Framework laptop.
Finally, treat encryption as one layer in a wider habit. Strong screen-lock policies, automatic updates, and modest caution around public Wi-Fi networks in cafés at Brisbane's South Bank or Melbourne's CBD round out a practical security posture. Encryption on its own won't stop phishing, but it makes the worst-case scenario, a lost or stolen device, far less painful to explain to your accountant, your clients, or your own peace of mind.
The most useful first move is simple: copy anything important to an external drive tonight so the install can proceed with confidence.