Sharing a drive grants another user access to that drive's encryption key. Sharing is not a
filesystem permission that the server enforces on your behalf: because tiCrypt stores only
ciphertext it cannot decrypt, the only way for someone else to read a drive is for them to hold a
key for it. This is why sharing requires the View drive keys permission, and why the effect of
sharing is different from what a shared folder does elsewhere.
The server cannot grant access on your behalf. On a conventional system, an administrator can
add someone to an access list and the filesystem enforces it. In tiCrypt the data at rest is
opaque to the server, so access is granted by giving out a key rather than by editing a list. The
practical consequence is that sharing is an act by the data owner, not by an administrator.
Revoking access stops future mounts, not past reads. Unsharing removes a user's ability to
mount the drive from that point on. It cannot retract what they have already decrypted and read.
Treat sharing as a disclosure decision, not a reversible toggle.
Co-owning a VM implies drive access. Adding a user as a co-owner of a VM configuration gives
them access to that VM's drives, because co-owners need drive access to manage the machine. If you
want a colleague to use a machine without reading everything on it, give them a lower VM role
rather than co-ownership.
Project tags on a drive are a classification, not a label. Tagging a drive with a project
records which regulatory regime its contents fall under, which is what makes the audit trail
meaningful. Removing or forcing a project tag is a declassification action and requires the
corresponding project-management permission.
Go to the Virtual Machines icon in the top left taskbar.
Click the Drives section on the top left panel.
Select the drive to share.
Click the Open Full Menu button by the selected drive in the left panel list.
Select Share.
In the prompt, click the Share with a user button in the top right corner.
In the pop-up, enter and select the user names to share the drive with.
Click Share.
Once done, click Close.
Confirmations, Errors & Solutions
Shared Drive Successfully
Shared with total-number-of-users user(s).
No Users to Share in Drive Share Prompt
This drive cannot be shared.
Attach the Drive to a Virtual Machine
The drive must be initialized and attached to a virtual machine before it can be shared.
Unable to Click Drive Share Button
Failed to look up keys for drive-name: Insufficient permissions to list drive keys for drive drive-string-id.
Ask Drive Owner(s) to Share the Drive
You must ask the drive owner(s) to share the drive with the user(s).
To Drive Owner Your drive users cannot further share a home drive that is read-write attached to a running VM. Only you can perform the drive share action.
Take extra caution: Verify that the drive keys were generated correctly upon VM creation.
Go to the Virtual Machines icon in the top left taskbar.
Click the VMs section on the top left panel.
In the left panel, click the virtual machine to view its logs.
Click the VM Settings and Details option in the bottom center.
In the new window, select the Logs section in the left panel.
View the last 50 log entries.
Click Load Older to view older logs.
Look for an early error upon VM creation "error in homedriveattached function: failed to generate ssh host keys:failed to generate host key-id key: failed to generate key: exit status 255".
Once done, click Close.
Contact the system administrator for further inspection.
Give Full-Access (Read-Write) of a Drive to a User
Go to the Virtual Machines icon in the top left taskbar.
Click the Drives section on the top left panel.
Select the drive to give full-access to.
Click the Share button in the top panel.
In the prompt, select Full-access next to the shared user(s) in the right column.
Once done, click Close.
Confirmations, Errors & Solutions
Shared Drive Successfully
Shared with total-number-of-users user(s).
Cannot Change Drive Owner Share Status to Full-Access
Failed to share drive: Failed to execute 'encrypt' on 'SubtleCrypto': The provided value is not of type '(ArrayBuffer or ArrayBufferView)'.
Ask the Drive Owner to Change Their Own Status
Regardless of the user role, only the drive owner can change their drive status.
Change Own Share Status to Full-Access in a Shared Ready Drive
Failed to share drive: Only users who own keys to a Drive may add additional keys.
Ask the Drive Owner to Reshare Drive With You
The drive owner shares a ready drive with you so you can attach it to a VM as instructed. If you change your share status to full-access before attaching the drive, you will lose access and the drive will disappear from your drive list. Either attach the ready drive to a VM yourself or ask the drive owner to do it for you.
Go to the Virtual Machines icon in the top left taskbar.
Click the Drives section on the top left panel.
Select the drive to give read-only access to.
Click the Share button in the top panel.
In the prompt, select Read-Only next to the shared user(s) in the right column.
Once done, click Close.
Confirmations, Errors & Solutions
Shared Drive Successfully
Shared with total-number-of-users user(s).
Cannot Change Drive Owner Share Status to Read-Only
Failed to share drive: Failed to execute 'encrypt' on 'SubtleCrypto': The provided value is not of type '(ArrayBuffer or ArrayBufferView)'.
Ask the Drive Owner to Change Their Own Status
Regardless of the user role, only the drive owner can change their drive status.
Change Own Share Status to Read-Only in a Shared Ready Drive
Failed to share drive: Only users who own keys to a Drive may add additional keys.
Ask the Drive Owner to Reshare Drive With You
The drive owner shares a ready drive with you so you can attach it to a VM as instructed. If you change your share status to read-only before attaching the drive, you will lose access and the drive will disappear from your drive list. Either attach the ready drive to a VM yourself or ask the drive owner to do it for you.
Go to the Virtual Machines icon in the top left taskbar.
Click the Drives section on the top left panel.
Select the drive to migrate.
Click the Migrate drive button in the top panel list.
In the prompt, select the destination pool.
Click Migrate.
Confirmations, Errors & Solutions
Migrated Drive Successfully
Migrate drive-nametotal-migration-time.
Failed to Migrate Drive
Migrate drive-name Failed at migration-failure-time: migration-destination-pool-name.
Migrate Drive to a Different Migration Pool
The migration pool did not receive your drive. Ask the system administrator to review the migration pool and temporarily migrate the drive to a different migration pool.
Migration Button Inactive in Migrate Drive Prompt
The "Migrate" button in prompt is inactive for certain migration pools.
Ask the System Administrator To Create A New Migration Pool
The migration pool has reached its full space quota or is unable to receive additional drive migrations. Contact the system administrator to create a new migration pool for your existing drive.
Migration Button Inactive in Migrate Drive Prompt
Migrate drive-nametotal-migration-time Failed at failure-time: the server took longer than 30s to reply.
View The Drive State in Drive Table
In the State column, review the drive status. If the drive is transferring to an existing migration pool, the transfer process cannot be interrupted or redirected to another migration pool until completion.
Change Own Share Status to Read-Only in a Shared Ready Drive
Failed to share drive: Only users who own keys to a Drive may add additional keys.
Ask the Drive Owner to Reshare Drive With You
The drive owner shares a ready drive with you so you can attach it to a VM as instructed. If you change your share status to read-only before attaching the drive, you will lose access and the drive will disappear from your drive list. Either attach the ready drive to a VM yourself or ask the drive owner to do it for you.