Include the LUKS Header in an Encrypted-Drive Recovery Inventory
An encrypted Linux drive needs a recovery plan for both its files and its encryption metadata. A remembered passphrase does not reconstruct a damaged LUKS header, while a header backup does not contain a separate copy of all your documents.
Before planned encryption maintenance, identify the exact volume and the person responsible for it. Record its stable identity and storage location in the recovery inventory. Do not identify a disk only by a temporary device name that could refer to different hardware on another boot.
Preserve the right recovery artifact
Cryptsetup documents luksHeaderBackup as creating a binary copy of the LUKS header and keyslot area. Have the administrator use the documented command for the confirmed volume and save the result to protected storage separate from that drive. A detached-header setup requires its actual header location to be understood as well.
Record the backup date, volume identity and relevant key-maintenance history alongside the file, keeping secrets out of the ordinary inventory. Retain a separate, tested backup of the user data. The two artifacts address different failures.
Do not test the header by restoring it over the live working volume. A recovery rehearsal belongs on a correctly identified disposable copy under someone who understands the format and its replacement consequences.
Treat old header copies as sensitive
The cryptsetup manual warns that a header backup plus a passphrase valid when it was made can still decrypt the corresponding data area after that passphrase has been changed or removed from the live header. Rotating a passphrase therefore does not make old header files harmless.
Include those copies in access control, retention and decommissioning decisions. Keep them out of public support tickets, casual file-sharing folders and unprotected repair notes. When retiring a drive or revoking access, ask the administrator to account for retained header backups as part of the plan.
The finished inventory should show a protected header artifact, separately recoverable files, a known authorised unlock route and an appropriate recovery-test record. None of those can be inferred merely from the drive mounting successfully today.
Sources: Ubuntu documentation, Ubuntu documentation.