{
    "mode": "man",
    "parameter": "CRYPTSETUP-ERASE",
    "section": "8",
    "url": "https://www.chedong.com/phpMan.php/man/CRYPTSETUP-ERASE/8/json",
    "generated": "2026-10-06T09:22:42Z",
    "synopsis": "cryptsetup  erase [<options>] <device>\ncryptsetup luksErase [<options>] <device>",
    "sections": {
        "NAME": {
            "content": "cryptsetup-erase, cryptsetup-luksErase - erase all keyslots\n",
            "subsections": []
        },
        "SYNOPSIS": {
            "content": "cryptsetup  erase [<options>] <device>\ncryptsetup luksErase [<options>] <device>\n",
            "subsections": []
        },
        "DESCRIPTION": {
            "content": "Erase all keyslots and make the LUKS container permanently inaccessible. Unless the device is\nconfigured with HW OPAL support you do not need to provide any password for this operation.\n\nWARNING: This operation is irreversible.\n\nWARNING: with --hw-opal-factory-reset ALL data is lost on the device, regardless of the\npartition it is ran on, if any, and regardless of any LUKS2 header backup, and does not\nrequire a valid LUKS2 header to be present on the device to run.\n\n<options> can be [--header, --disable-locks, --hw-opal-factory-reset, --key-file].\n",
            "subsections": []
        },
        "OPTIONS": {
            "content": "--key-file, -d name (LUKS2 with HW OPAL only)\nRead the Admin PIN or PSID (with --hw-opal-factory-reset) from file depending on options\nused.\n\nIf the name given is \"-\", then the secret will be read from stdin. In this case, reading\nwill not stop at newline characters.\n",
            "subsections": [
                {
                    "name": "--header <device or file storing the LUKS header>",
                    "content": "Use to specify detached LUKS2 header when erasing HW OPAL enabled data device.\n",
                    "long": "--header",
                    "arg": "LUKS"
                },
                {
                    "name": "--disable-locks",
                    "content": "Disable lock protection for metadata on disk. This option is valid only for LUKS2 and\nignored for other formats.\n\nWARNING: Do not use this option unless you run cryptsetup in a restricted environment\nwhere locking is impossible to perform (where /run directory cannot be used).\n",
                    "long": "--disable-locks"
                },
                {
                    "name": "--batch-mode, -q",
                    "content": "Suppresses all confirmation questions. Use with care!\n\nIf the --verify-passphrase option is not specified, this option also switches off the\npassphrase verification.\n",
                    "flag": "-q",
                    "long": "--batch-mode"
                },
                {
                    "name": "--debug or --debug-json",
                    "content": "Run in debug mode with full diagnostic logs. Debug output lines are always prefixed by #.\n\nIf --debug-json is used, additional LUKS2 JSON data structures are printed.\n",
                    "long": "--debug-json"
                },
                {
                    "name": "--version, -V",
                    "content": "Show the program version.\n",
                    "flag": "-V",
                    "long": "--version"
                },
                {
                    "name": "--usage",
                    "content": "Show short option help.\n",
                    "long": "--usage"
                },
                {
                    "name": "--help, -?",
                    "content": "Show help text and default parameters.\n",
                    "flag": "-?",
                    "long": "--help"
                }
            ]
        },
        "REPORTING BUGS": {
            "content": "Report bugs at cryptsetup mailing list <cryptsetup@lists.linux.dev> or in Issues project\nsection <https://gitlab.com/cryptsetup/cryptsetup/-/issues/new>.\n\nPlease attach output of the failed command with --debug option added.\n",
            "subsections": []
        },
        "SEE ALSO": {
            "content": "Cryptsetup FAQ <https://gitlab.com/cryptsetup/cryptsetup/wikis/FrequentlyAskedQuestions>\n\ncryptsetup(8), integritysetup(8) and veritysetup(8)\n",
            "subsections": []
        },
        "CRYPTSETUP": {
            "content": "Part of cryptsetup project <https://gitlab.com/cryptsetup/cryptsetup/>.\n\ncryptsetup 2.7.0                             2024-11-14                          CRYPTSETUP-ERASE(8)",
            "subsections": []
        }
    },
    "summary": "cryptsetup-erase, cryptsetup-luksErase - erase all keyslots",
    "flags": [
        {
            "flag": "",
            "long": "--header",
            "arg": "LUKS",
            "description": "Use to specify detached LUKS2 header when erasing HW OPAL enabled data device."
        },
        {
            "flag": "",
            "long": "--disable-locks",
            "arg": null,
            "description": "Disable lock protection for metadata on disk. This option is valid only for LUKS2 and ignored for other formats. WARNING: Do not use this option unless you run cryptsetup in a restricted environment where locking is impossible to perform (where /run directory cannot be used)."
        },
        {
            "flag": "-q",
            "long": "--batch-mode",
            "arg": null,
            "description": "Suppresses all confirmation questions. Use with care! If the --verify-passphrase option is not specified, this option also switches off the passphrase verification."
        },
        {
            "flag": "",
            "long": "--debug-json",
            "arg": null,
            "description": "Run in debug mode with full diagnostic logs. Debug output lines are always prefixed by #. If --debug-json is used, additional LUKS2 JSON data structures are printed."
        },
        {
            "flag": "-V",
            "long": "--version",
            "arg": null,
            "description": "Show the program version."
        },
        {
            "flag": "",
            "long": "--usage",
            "arg": null,
            "description": "Show short option help."
        },
        {
            "flag": "-?",
            "long": "--help",
            "arg": null,
            "description": "Show help text and default parameters."
        }
    ],
    "examples": [],
    "see_also": [
        {
            "name": "cryptsetup",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/cryptsetup/8/json"
        },
        {
            "name": "integritysetup",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/integritysetup/8/json"
        },
        {
            "name": "veritysetup",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/veritysetup/8/json"
        }
    ]
}