Unlock encrypted ZFS datasets on TrueNAS via the API
Project description
TrueNAS Unlock
Unlock encrypted ZFS datasets on TrueNAS via the API.
https://github.com/user-attachments/assets/172c8fd7-5b66-4c5b-bae0-32e378e9305a
Why?
TrueNAS supports encrypted ZFS datasets, but:
- Storing keys on the NAS defeats the purpose—if it's stolen, the thief has both the encrypted data and the keys
- Manual unlocking is tedious—after every reboot, you need to manually decrypt each dataset through the UI
This tool solves both problems with a "poor-man's second-factor" setup:
- Run
truenas-unlockon a separate device (Raspberry Pi, home server, etc.) - Store encryption keys only on that device
- Datasets auto-unlock when both devices are on the network
- If the NAS is stolen, data remains encrypted and inaccessible
Think of it as a hardware security key for your storage—hidden somewhere in your house, it automatically unlocks your datasets whenever your TrueNAS boots. No manual intervention required.
Install
# With uv (recommended)
uv tool install truenas-unlock
# With pip
pip install truenas-unlock
Setup
Create an API key at http://truenas.local/ui/credentials/users/api-keys (replace with your TrueNAS hostname).
Then create ~/.config/truenas-unlock/config.yaml:
host: 192.168.1.214:443
api_key: ~/.secrets/truenas-api-key # file path or literal
skip_cert_verify: true
# secrets: auto # auto (default) | files | inline
datasets:
tank/syncthing: ~/.secrets/syncthing-key # reads from file
tank/photos: my-literal-passphrase # used as-is (no such file)
The secrets mode controls how values are interpreted:
- auto (default): if file exists, read from it; otherwise use as literal
- files: always treat values as file paths
- inline: always treat values as literal secrets
Usage
# Run once
truenas-unlock
# Run as daemon
# (Checks every 1s if TrueNAS is unreachable, otherwise every 30s)
truenas-unlock --daemon
# Custom interval (for the "relaxed" state)
truenas-unlock --daemon --interval 60
# Dry run
truenas-unlock --dry-run
CLI
truenas-unlock --help
Usage: truenas-unlock [OPTIONS] COMMAND [ARGS]...
Unlock TrueNAS ZFS datasets
╭─ Options ────────────────────────────────────────────────────────────────────╮
│ --config -c PATH Config file path │
│ --dry-run -n Show what would be done │
│ --daemon -d Run continuously │
│ --interval -i INTEGER Seconds between checks (1s if unreachable) │
│ [default: 30] │
│ --dataset -D TEXT Filter by dataset path │
│ --help -h Show this message and exit. │
╰──────────────────────────────────────────────────────────────────────────────╯
╭─ Commands ───────────────────────────────────────────────────────────────────╮
│ lock Lock configured datasets. │
│ status Show lock status of configured datasets. │
│ service Manage system service │
╰──────────────────────────────────────────────────────────────────────────────╯
Running as a Service
Requires uv to be installed. Auto-detects Linux (systemd) or macOS (launchd):
# Install and start
truenas-unlock service install
# Check status
truenas-unlock service status
# View logs (follows by default)
truenas-unlock service logs
# Uninstall
truenas-unlock service uninstall
Development
# Clone and install
git clone https://github.com/basnijholt/truenas-unlock
cd truenas-unlock
uv sync --dev
# Run tests
uv run pytest
# Run lints
uv run ruff check .
uv run mypy truenas_unlock.py
Credits
Inspired by ThorpeJosh/truenas-zfs-unlock.
License
MIT
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file truenas_unlock-1.4.1.tar.gz.
File metadata
- Download URL: truenas_unlock-1.4.1.tar.gz
- Upload date:
- Size: 59.8 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
9b30adc3e3e411cff85c316039acdde28848f58cd0bf417587ba2b7528ed1027
|
|
| MD5 |
ac1370246b8f866ed840635d74c27ab8
|
|
| BLAKE2b-256 |
5667f3513cdce55ae506618936e9f0ca6f5f5e37b7ea011c96c760e18f692c19
|
Provenance
The following attestation bundles were made for truenas_unlock-1.4.1.tar.gz:
Publisher:
release.yml on basnijholt/truenas-unlock
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
truenas_unlock-1.4.1.tar.gz -
Subject digest:
9b30adc3e3e411cff85c316039acdde28848f58cd0bf417587ba2b7528ed1027 - Sigstore transparency entry: 763100627
- Sigstore integration time:
-
Permalink:
basnijholt/truenas-unlock@198b095a95e8a1abdca0b23e2647e573a334b25a -
Branch / Tag:
refs/tags/v1.4.1 - Owner: https://github.com/basnijholt
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@198b095a95e8a1abdca0b23e2647e573a334b25a -
Trigger Event:
release
-
Statement type:
File details
Details for the file truenas_unlock-1.4.1-py3-none-any.whl.
File metadata
- Download URL: truenas_unlock-1.4.1-py3-none-any.whl
- Upload date:
- Size: 10.2 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
6fdc8d920ba8da842ae73d89aeddb90d24bd8c1c9f1ec0ed77405f53423a170a
|
|
| MD5 |
55645ad4d9a7470acc0ce3216745c797
|
|
| BLAKE2b-256 |
253d84454746771a4452b059a29a089e3d340d50ce6629dafa2ef5c0979f6877
|
Provenance
The following attestation bundles were made for truenas_unlock-1.4.1-py3-none-any.whl:
Publisher:
release.yml on basnijholt/truenas-unlock
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
truenas_unlock-1.4.1-py3-none-any.whl -
Subject digest:
6fdc8d920ba8da842ae73d89aeddb90d24bd8c1c9f1ec0ed77405f53423a170a - Sigstore transparency entry: 763100628
- Sigstore integration time:
-
Permalink:
basnijholt/truenas-unlock@198b095a95e8a1abdca0b23e2647e573a334b25a -
Branch / Tag:
refs/tags/v1.4.1 - Owner: https://github.com/basnijholt
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@198b095a95e8a1abdca0b23e2647e573a334b25a -
Trigger Event:
release
-
Statement type: