9 dracut.cmdline - dracut kernel command line options
13 The root device used by the kernel is specified in the boot configuration
14 file on the kernel command line, as always.
16 The traditional _root=/dev/sda1_ style device specification is allowed, but not
17 encouraged. The root device should better be identified by LABEL or UUID. If a
18 label is used, as in _root=LABEL=<label_of_root>_ the initramfs will search all
19 available devices for a filesystem with the appropriate label, and mount that
20 device as the root filesystem. _root=UUID=<uuidnumber>_ will mount the partition
21 with that UUID as the root filesystem.
23 In the following all kernel command line parameters, which are processed by
24 dracut, are described.
26 "rd.*" parameters mentioned without "=" are boolean parameters. They can be
27 turned on/off by setting them to {0|1}. If the assignment with "=" is missing
28 "=1" is implied. For example _rd.info_ can be turned off with _rd.info=0_ or
29 turned on with _rd.info=1_ or _rd.info_. The last value in the kernel command
30 line is the value, which is honored.
34 **init=**__<path to real init>__::
35 specify the path to the init program to be started after the initramfs has
38 **root=**__<path to blockdevice>__::
39 specify the block device to use as the root filesystem.
45 root=/dev/disk/by-path/pci-0000:00:1f.1-scsi-0:0:1:0-part1
46 root=/dev/disk/by-label/Root
48 root=/dev/disk/by-uuid/3f5ad593-4546-4a94-a374-bcfb68aa11f7
49 root=UUID=3f5ad593-4546-4a94-a374-bcfb68aa11f7
50 root=PARTUUID=3f5ad593-4546-4a94-a374-bcfb68aa11f7
53 **rootfstype=**__<filesystem type>__:: "auto" if not specified.
61 **rootflags=**__<mount options>__::
62 specify additional mount options for the root filesystem. If not set,
63 _/etc/fstab_ of the real root will be parsed for special mount options and
67 force mounting _/_ and _/usr_ (if it is a separate device) read-only. If
68 none of ro and rw is present, both are mounted according to _/etc/fstab_.
71 force mounting _/_ and _/usr_ (if it is a separate device) read-write.
74 **rootfallback=**__<path to blockdevice>__::
75 specify the block device to use as the root filesystem, if the normal root
76 cannot be found. This can only be a simple block device with a simple file
77 system, for which the filesystem driver is either compiled in, or added
78 manually to the initramfs. This parameter can be specified multiple times.
80 **rd.auto** **rd.auto=1**::
81 enable autoassembly of special devices like cryptoLUKS, dmraid, mdraid or
82 lvm. Default is off as of dracut version >= 024.
85 removes all compiled in configuration of the host system the initramfs image
86 was built on. This helps booting, if any disk layout changed, especially in
87 combination with rd.auto or other parameters specifying the layout.
90 prompts the user for additional kernel command line parameters
93 do not honor special mount options for the root filesystem found in
94 _/etc/fstab_ of the real root.
96 **resume=**__<path to resume partition>__::
97 resume from a swap partition
102 resume=/dev/disk/by-path/pci-0000:00:1f.1-scsi-0:0:1:0-part1
103 resume=/dev/disk/by-uuid/3f5ad593-4546-4a94-a374-bcfb68aa11f7
104 resume=UUID=3f5ad593-4546-4a94-a374-bcfb68aa11f7
108 skip fsck for rootfs and _/usr_. If you're mounting _/usr_ read-only and
109 the init system performs fsck before remount, you might want to use this
110 option to avoid duplication.
115 Using iso-scan/filename with a Fedora/Red Hat/CentOS Live iso should just work
116 by copying the original kernel cmdline parameters.
121 menuentry 'Live Fedora 20' --class fedora --class gnu-linux --class gnu --class os {
122 set isolabel=Fedora-Live-LXDE-x86_64-20-1
123 set isofile="/boot/iso/Fedora-Live-LXDE-x86_64-20-1.iso"
124 loopback loop $isofile
125 linux (loop)/isolinux/vmlinuz0 boot=isolinux iso-scan/filename=$isofile root=live:LABEL=$isolabel ro rd.live.image quiet rhgb
126 initrd (loop)/isolinux/initrd0.img
132 **rd.emergency=**__[reboot|poweroff|halt]__::
133 specify, what action to execute in case of a critical failure. rd.shell=0 also
136 **rd.driver.blacklist=**__<drivername>__[,__<drivername>__,...]::
137 do not load kernel module <drivername>. This parameter can be specified
140 **rd.driver.pre=**__<drivername>__[,__<drivername>__,...]::
141 force loading kernel module <drivername>. This parameter can be specified
144 **rd.driver.post=**__<drivername>__[,__<drivername>__,...]::
145 force loading kernel module <drivername> after all automatic loading modules
146 have been loaded. This parameter can be specified multiple times.
148 **rd.retry=**__<seconds>__::
149 specify how long dracut should retry the initqueue to configure devices.
150 The default is 30 seconds. After 2/3 of the time, degraded raids are force
151 started. If you have hardware, which takes a very long time to announce its
152 drives, you might want to extend this value.
154 **rd.timeout=**__<seconds>__::
155 specify how long dracut should wait for devices to appear. The
156 default is '0', which means 'forever'. Note that this timeout
157 should be longer than rd.retry to allow for proper configuration.
160 accept self-signed certificates for ssl downloads.
162 **rd.ctty=**__<terminal device>__::
163 specify the controlling terminal for the console.
164 This is useful, if you have multiple "console=" arguments.
166 [[dracutkerneldebug]]
169 If you are dropped to an emergency shell, the file
170 _/run/initramfs/rdsosreport.txt_ is created, which can be saved to a (to be
171 mounted by hand) partition (usually /boot) or a USB stick. Additional debugging
172 info can be produced by adding **rd.debug** to the kernel command line.
173 _/run/initramfs/rdsosreport.txt_ contains all logs and the output of some tools.
174 It should be attached to any report about dracut problems.
177 print informational output though "quiet" is set
180 allow dropping to a shell, if root mounting fails
183 set -x for the dracut shell.
184 If systemd is active in the initramfs, all output is logged to the systemd
185 journal, which you can inspect with "journalctl -ab".
186 If systemd is not active, the logs are written to dmesg and
187 _/run/initramfs/init.log_.
188 If "quiet" is set, it also logs to the console.
190 **rd.memdebug=[0-4]**::
191 Print memory usage info at various points, set the verbose level from 0 to 4.
193 Higher level means more debugging output:
197 1 - partial /proc/meminfo
199 3 - /proc/meminfo + /proc/slabinfo
200 4 - /proc/meminfo + /proc/slabinfo + tracekomem
201 NOTE: tracekomem is a shell script utilizing kernel trace to track
202 the rough total memory consumption of kernel modules during
203 loading. It may override other trace configurations.
207 drop to a shell at the end
209 **rd.break=**__{cmdline|pre-udev|pre-trigger|initqueue|pre-mount|mount|pre-pivot|cleanup}__::
210 drop to a shell on defined breakpoint
213 set udev to loglevel info
216 set udev to loglevel debug
220 **rd.vconsole.keymap=**__<keymap base file name>__::
221 keyboard translation table loaded by loadkeys; taken from keymaps directory;
222 will be written as KEYMAP to _/etc/vconsole.conf_ in the initramfs.
227 rd.vconsole.keymap=de-latin1-nodeadkeys
230 **rd.vconsole.keymap.ext=**__<list of keymap base file names>__::
231 list of extra keymaps to bo loaded (sep. by space); will be written as
232 EXT_KEYMAP to _/etc/vconsole.conf_ in the initramfs
234 **rd.vconsole.unicode**::
235 boolean, indicating UTF-8 mode; will be written as UNICODE to
236 _/etc/vconsole.conf_ in the initramfs
238 **rd.vconsole.font=**__<font base file name>__::
239 console font; taken from consolefonts directory; will be written as FONT to
240 _/etc/vconsole.conf_ in the initramfs.
245 rd.vconsole.font=eurlatgr
248 **rd.vconsole.font.map=**__<console map base file name>__::
249 see description of '-m' parameter in setfont manual; taken from consoletrans
250 directory; will be written as FONT_MAP to _/etc/vconsole.conf_ in the
253 **rd.vconsole.font.unimap=**__<unicode table base file name>__::
254 see description of '-u' parameter in setfont manual; taken from unimaps
255 directory; will be written as FONT_UNIMAP to _/etc/vconsole.conf_ in the
258 **rd.locale.LANG=**__<locale>__::
259 taken from the environment; if no UNICODE is defined we set its value in
260 basis of LANG value (whether it ends with ".utf8" (or similar) or not); will
261 be written as LANG to _/etc/locale.conf_ in the initramfs.
266 rd.locale.LANG=pl_PL.utf8
269 **rd.locale.LC_ALL=**__<locale>__::
270 taken from the environment; will be written as LC_ALL to _/etc/locale.conf_
276 disable LVM detection
278 **rd.lvm.vg=**__<volume group name>__::
279 only activate the volume groups with the given name. rd.lvm.vg can be
280 specified multiple times on the kernel command line.
282 **rd.lvm.lv=**__<logical volume name>__::
283 only activate the logical volumes with the given name. rd.lvm.lv can be
284 specified multiple times on the kernel command line.
287 remove any _/etc/lvm/lvm.conf_, which may exist in the initramfs
292 disable crypto LUKS detection
294 **rd.luks.uuid=**__<luks uuid>__::
295 only activate the LUKS partitions with the given UUID. Any "luks-" of the
296 LUKS UUID is removed before comparing to _<luks uuid>_.
297 The comparisons also matches, if _<luks uuid>_ is only the beginning of the
298 LUKS UUID, so you don't have to specify the full UUID.
299 This parameter can be specified multiple times.
301 **rd.luks.allow-discards=**__<luks uuid>__::
302 Allow using of discards (TRIM) requests for LUKS partitions with the given
303 UUID. Any "luks-" of the LUKS UUID is removed before comparing to
304 _<luks uuid>_. The comparisons also matches, if _<luks uuid>_ is only the
305 beginning of the LUKS UUID, so you don't have to specify the full UUID.
306 This parameter can be specified multiple times.
308 **rd.luks.allow-discards**::
309 Allow using of discards (TRIM) requests on all LUKS partitions.
311 **rd.luks.crypttab=0**::
312 do not check, if LUKS partition is in _/etc/crypttab_
314 **rd.luks.timeout=**__<seconds>__::
315 specify how long dracut should wait when waiting for the user to enter the
316 password. This avoid blocking the boot if no password is entered. It does
317 not apply to luks key. The default is '0', which means 'forever'.
319 crypto LUKS - key on removable device support
320 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
322 NB: If systemd is included in the dracut initrd, dracut's built in
323 removable device keying support won't work. systemd will prompt for
324 a password from the console even if you've supplied **rd.luks.key**.
325 You may be able to use standard systemd *fstab*(5) syntax to
326 get the same effect. If you do need **rd.luks.key** to work,
327 you will have to exclude the "systemd" dracut module and any modules
328 that depend on it. See *dracut.conf*(5) and
329 https://bugzilla.redhat.com/show_bug.cgi?id=905683 for more
332 **rd.luks.key=**_<keypath>[:<keydev>[:<luksdev>]]_::
333 _<keypath>_ is the pathname of a key file, relative to the root
334 of the filesystem on some device. It's REQUIRED. When
335 _<keypath>_ ends with '.gpg' it's considered to be key encrypted
336 symmetrically with GPG. You will be prompted for the GPG password on
337 boot. GPG support comes with the 'crypt-gpg' module, which needs to be
340 _<keydev>_ identifies the device on which the key file resides. It may
341 be the kernel name of the device (should start with "/dev/"), a UUID
342 (prefixed with "UUID=") or a label (prefix with "LABEL="). You don't
343 have to specify a full UUID. Just its beginning will suffice, even if
344 its ambiguous. All matching devices will be probed. This parameter is
345 recommended, but not required. If it's not present, all block devices will
346 be probed, which may significantly increase boot time.
348 If _<luksdev>_ is given, the specified key will only be used for
349 the specified LUKS device. Possible values are the same as for
350 _<keydev>_. Unless you have several LUKS devices, you don't have to
351 specify this parameter. The simplest usage is:
356 rd.luks.key=/foo/bar.key
359 As you see, you can skip colons in such a case.
362 ===============================
363 Your LUKS partition must match your key file.
365 dracut provides keys to cryptsetup with _-d_ (an older alias for
366 _--key-file_). This uses the entire binary
367 content of the key file as part of the secret. If
368 you pipe a password into cryptsetup *without* _-d_ or _--key-file_,
369 it will be treated as text user input, and only characters before
370 the first newline will be used. Therefore, when you're creating
371 an encrypted partition for dracut to mount, and you pipe a key into
372 _cryptsetup luksFormat_,you must use _-d -_.
374 Here is an example for a key encrypted with GPG (warning:
375 _--batch-mode_ will overwrite the device without asking for
380 gpg --quiet --decrypt rootkey.gpg | \
381 cryptsetup --batch-mode --key-file - \
382 luksFormat /dev/sda47
385 If you use unencrypted key files, just use the key file pathname
386 instead of the standard input. For a random key with 256 bits of
387 entropy, you might use:
391 head -32c /dev/urandom > rootkey.key
392 cryptsetup --batch-mode --key-file rootkey.key \
393 luksFormat /dev/sda47
395 ===============================
400 disable MD RAID detection
403 disable MD RAID for imsm/isw raids, use DM RAID instead
406 disable MD RAID for SNIA ddf raids, use DM RAID instead
409 ignore mdadm.conf included in initramfs
411 **rd.md.waitclean=1**::
412 wait for any resync, recovery, or reshape activity to finish before
415 **rd.md.uuid=**__<md raid uuid>__::
416 only activate the raid sets with the given UUID. This parameter can be
417 specified multiple times.
422 disable DM RAID detection
424 **rd.dm.uuid=**__<dm raid uuid>__::
425 only activate the raid sets with the given UUID. This parameter can be
426 specified multiple times.
431 disable multipath detection
438 **boot=**__<boot device>__::
439 specify the device, where /boot is located.
445 boot=/dev/disk/by-path/pci-0000:00:1f.1-scsi-0:0:1:0-part1
450 **rd.fips.skipkernel**::
451 skip checksum check of the kernel image. Useful, if the kernel image is not
452 in a separate boot partition.
458 =====================
459 It is recommended to either bind an interface to a MAC with the **ifname**
460 argument, or to use the systemd-udevd predictable network interface names.
462 Predictable network interface device names based on:
464 - firmware/bios-provided index numbers for on-board devices
465 - firmware-provided pci-express hotplug slot index number
466 - physical/geographical location of the hardware
467 - the interface's MAC address
470 http://www.freedesktop.org/wiki/Software/systemd/PredictableNetworkInterfaceNames
472 Two character prefixes based on the type of interface:
480 o<index>:: on-board device index number
481 s<slot>[f<function>][d<dev_id>]:: hotplug slot index number
483 [P<domain>]p<bus>s<slot>[f<function>][d<dev_id>]:: PCI geographical location
484 [P<domain>]p<bus>s<slot>[f<function>][u<port>][..][c<config>][i<interface>]:: USB port number chain
486 All multi-function PCI devices will carry the [f<function>] number in the
487 device name, including the function 0 device.
489 When using PCI geography, The PCI domain is only prepended when it is not 0.
491 For USB devices the full chain of port numbers of hubs is composed. If the
492 name gets longer than the maximum number of 15 characters, the name is not
494 The usual USB configuration == 1 and interface == 0 values are suppressed.
496 PCI ethernet card with firmware index "1"::
499 PCI ethernet card in hotplug slot with firmware index number::
502 PCI ethernet multi-function card with 2 ports::
509 USB built-in 3G modem::
514 =====================
516 **ip=**__{dhcp|on|any|dhcp6|auto6|either6}__::
517 dhcp|on|any::: get ip from dhcp server from all interfaces. If root=dhcp,
518 loop sequentially through all interfaces (eth0, eth1, ...) and use the first
519 with a valid DHCP root-path.
521 auto6::: IPv6 autoconfiguration
525 either6::: if auto6 fails, then dhcp6
527 **ip=**__<interface>__:__{dhcp|on|any|dhcp6|auto6}__[:[__<mtu>__][:__<macaddr>__]]::
528 This parameter can be specified multiple times.
530 =====================
531 dhcp|on|any|dhcp6::: get ip from dhcp server on a specific interface
532 auto6::: do IPv6 autoconfiguration
533 <macaddr>::: optionally **set** <macaddr> on the <interface>. This
534 cannot be used in conjunction with the **ifname** argument for the
536 =====================
538 **ip=**__<client-IP>__:[__<peer>__]:__<gateway-IP>__:__<netmask>__:__<client_hostname>__:__<interface>__:__{none|off|dhcp|on|any|dhcp6|auto6|ibft}__[:[__<mtu>__][:__<macaddr>__]]::
539 explicit network configuration. If you want do define a IPv6 address, put it
540 in brackets (e.g. [2001:DB8::1]). This parameter can be specified multiple
541 times. __<peer>__ is optional and is the address of the remote endpoint
542 for pointopoint interfaces and it may be followed by a slash and a decimal
543 number, encoding the network prefix length.
545 =====================
546 <macaddr>::: optionally **set** <macaddr> on the <interface>. This
547 cannot be used in conjunction with the **ifname** argument for the
549 =====================
551 **ip=**__<client-IP>__:[__<peer>__]:__<gateway-IP>__:__<netmask>__:__<client_hostname>__:__<interface>__:__{none|off|dhcp|on|any|dhcp6|auto6|ibft}__[:[__<dns1>__][:__<dns2>__]]::
552 explicit network configuration. If you want do define a IPv6 address, put it
553 in brackets (e.g. [2001:DB8::1]). This parameter can be specified multiple
554 times. __<peer>__ is optional and is the address of the remote endpoint
555 for pointopoint interfaces and it may be followed by a slash and a decimal
556 number, encoding the network prefix length.
558 **ifname=**__<interface>__:__<MAC>__::
559 Assign network device name <interface> (i.e. "bootnet") to the NIC with
562 WARNING: Do **not** use the default kernel naming scheme for the interface name,
563 as it can conflict with the kernel names. So, don't use "eth[0-9]+" for the
564 interface name. Better name it "bootnet" or "bluesocket".
566 **rd.route=**__<net>__/__<netmask>__:__<gateway>__[:__<interface>__]::
567 Add a static route with route options, which are separated by a colon.
568 IPv6 addresses have to be put in brackets.
573 rd.route=192.168.200.0/24:192.168.100.222:ens10
574 rd.route=192.168.200.0/24:192.168.100.222
575 rd.route=192.168.200.0/24::ens10
576 rd.route=[2001:DB8:3::/8]:[2001:DB8:2::1]:ens10
579 **bootdev=**__<interface>__::
580 specify network interface to use routing and netroot information from.
581 Required if multiple ip= lines are used.
583 **BOOTIF=**__<MAC>__::
584 specify network interface to use routing and netroot information from.
587 Disable BOOTIF parsing, which is provided by PXE
589 **nameserver=**__<IP>__ [**nameserver=**__<IP>__ ...]::
590 specify nameserver(s) to use
593 Disable DNS setting of DHCP parameters.
596 boolean, turn off biosdevname network interface renaming
599 boolean, bring up network even without netroot set
601 **vlan=**__<vlanname>__:__<phydevice>__::
602 Setup vlan device named <vlanname> on <phydeivce>.
603 We support the four styles of vlan names: VLAN_PLUS_VID (vlan0005),
604 VLAN_PLUS_VID_NO_PAD (vlan5), DEV_PLUS_VID (eth0.0005),
605 DEV_PLUS_VID_NO_PAD (eth0.5)
607 **bond=**__<bondname>__[:__<bondslaves>__:[:__<options>__[:<mtu>]]]::
608 Setup bonding device <bondname> on top of <bondslaves>.
609 <bondslaves> is a comma-separated list of physical (ethernet) interfaces.
610 <options> is a comma-separated list on bonding options (modinfo bonding for
611 details) in format compatible with initscripts. If <options> includes
612 multi-valued arp_ip_target option, then its values should be separated by
613 semicolon. if the mtu is specified, it will be set on the bond master.
614 Bond without parameters assumes
615 bond=bond0:eth0,eth1:mode=balance-rr
617 **team=**__<teammaster>__:__<teamslaves>__::
618 Setup team device <teammaster> on top of <teamslaves>.
619 <teamslaves> is a comma-separated list of physical (ethernet) interfaces.
621 **bridge=**__<bridgename>__:__<ethnames>__::
622 Setup bridge <bridgename> with <ethnames>. <ethnames> is a comma-separated
623 list of physical (ethernet) interfaces. Bridge without parameters assumes
628 **root=**\[_<server-ip>_:]__<root-dir>__[:__<nfs-options>__]::
629 mount nfs share from <server-ip>:/<root-dir>, if no server-ip is given, use
630 dhcp next_server. If server-ip is an IPv6 address it has to be put in
631 brackets, e.g. [2001:DB8::1]. NFS options can be appended with the prefix
632 ":" or "," and are separated by ",".
634 **root=**nfs:\[_<server-ip>_:]__<root-dir>__[:__<nfs-options>__], **root=**nfs4:\[_<server-ip>_:]__<root-dir>__[:__<nfs-options>__], **root=**__{dhcp|dhcp6}__::
635 root=dhcp alone directs initrd to look at the DHCP root-path where NFS
636 options can be specified.
641 root-path=<server-ip>:<root-dir>[,<nfs-options>]
642 root-path=nfs:<server-ip>:<root-dir>[,<nfs-options>]
643 root-path=nfs4:<server-ip>:<root-dir>[,<nfs-options>]
646 **root=**_/dev/nfs_ nfsroot=\[_<server-ip>_:]__<root-dir>__[:__<nfs-options>__]::
647 _Deprecated!_ kernel Documentation_/filesystems/nfsroot.txt_ defines this
648 method. This is supported by dracut, but not recommended.
650 **rd.nfs.domain=**__<NFSv4 domain name>__::
651 Set the NFSv4 domain name. Will override the settings in _/etc/idmap.conf_.
653 **rd.net.dhcp.retry=**__<cnt>__::
654 If this option is set, dracut will try to connect via dhcp <cnt> times before failing.
657 **rd.net.timeout.dhcp=**__<arg>__::
658 If this option is set, dhclient is called with "-timeout <arg>".
660 **rd.net.timeout.iflink=**__<seconds>__::
661 Wait <seconds> until link shows up. Default is 60 seconds.
663 **rd.net.timeout.ifup=**__<seconds>__::
664 Wait <seconds> until link has state "UP". Default is 20 seconds.
666 **rd.net.timeout.route=**__<seconds>__::
667 Wait <seconds> until route shows up. Default is 20 seconds.
669 **rd.net.timeout.ipv6dad=**__<seconds>__::
670 Wait <seconds> until IPv6 DAD is finished. Default is 50 seconds.
672 **rd.net.timeout.ipv6auto=**__<seconds>__::
673 Wait <seconds> until IPv6 automatic addresses are assigned. Default is 40 seconds.
675 **rd.net.timeout.carrier=**__<seconds>__::
676 Wait <seconds> until carrier is recognized. Default is 5 seconds.
680 **root=**cifs://[__<username>__[:__<password>__]@]__<server-ip>__:__<root-dir>__::
681 mount cifs share from <server-ip>:/<root-dir>, if no server-ip is given, use
682 dhcp next_server. if server-ip is an IPv6 address it has to be put in
683 brackets, e.g. [2001:DB8::1]. If a username or password are not specified
684 as part of the root, then they must be passed on the command line through
687 WARNING: Passwords specified on the kernel command line are visible for all
688 users via the file _/proc/cmdline_ and via dmesg or can be sniffed on the
689 network, when using DHCP with DHCP root-path.
691 **cifsuser**=__<username>__::
692 Set the cifs username, if not specified as part of the root.
694 **cifspass**=__<password>__::
695 Set the cifs password, if not specified as part of the root.
697 WARNING: Passwords specified on the kernel command line are visible for all
698 users via the file _/proc/cmdline_ and via dmesg or can be sniffed on the
699 network, when using DHCP with DHCP root-path.
703 **root=**iscsi:[__<username>__:__<password>__[:__<reverse>__:__<password>__]@][__<servername>__]:[__<protocol>__]:[__<port>__][:[__<iscsi_iface_name>__]:[__<netdev_name>__]]:[__<LUN>__]:__<targetname>__::
704 protocol defaults to "6", LUN defaults to "0". If the "servername" field is
705 provided by BOOTP or DHCP, then that field is used in conjunction with other
706 associated fields to contact the boot server in the Boot stage. However, if
707 the "servername" field is not provided, then the "targetname" field is then
708 used in the Discovery Service stage in conjunction with other associated
710 link:$$http://tools.ietf.org/html/rfc4173#section-5$$[rfc4173].
712 WARNING: Passwords specified on the kernel command line are visible for all
713 users via the file _/proc/cmdline_ and via dmesg or can be sniffed on the
714 network, when using DHCP with DHCP root-path.
719 root=iscsi:192.168.50.1::::iqn.2009-06.dracut:target0
722 If servername is an IPv6 address, it has to be put in brackets:
727 root=iscsi:[2001:DB8::1]::::iqn.2009-06.dracut:target0
730 **root=**__???__ **netroot=**iscsi:[__<username>__:__<password>__[:__<reverse>__:__<password>__]@][__<servername>__]:[__<protocol>__]:[__<port>__][:[__<iscsi_iface_name>__]:[__<netdev_name>__]]:[__<LUN>__]:__<targetname>__ ...::
731 multiple netroot options allow setting up multiple iscsi disks:
737 netroot=iscsi:192.168.50.1::::iqn.2009-06.dracut:target0
738 netroot=iscsi:192.168.50.1::::iqn.2009-06.dracut:target1
741 If servername is an IPv6 address, it has to be put in brackets:
746 netroot=iscsi:[2001:DB8::1]::::iqn.2009-06.dracut:target0
749 WARNING: Passwords specified on the kernel command line are visible for all
750 users via the file _/proc/cmdline_ and via dmesg or can be sniffed on the
751 network, when using DHCP with DHCP root-path.
752 You may want to use rd.iscsi.firmware.
754 **root=**__???__ **rd.iscsi.initiator=**__<initiator>__ **rd.iscsi.target.name=**__<target name>__ **rd.iscsi.target.ip=**__<target ip>__ **rd.iscsi.target.port=**__<target port>__ **rd.iscsi.target.group=**__<target group>__ **rd.iscsi.username=**__<username>__ **rd.iscsi.password=**__<password>__ **rd.iscsi.in.username=**__<in username>__ **rd.iscsi.in.password=**__<in password>__::
755 manually specify all iscsistart parameter (see **+iscsistart --help+**)
757 WARNING: Passwords specified on the kernel command line are visible for all
758 users via the file _/proc/cmdline_ and via dmesg or can be sniffed on the
759 network, when using DHCP with DHCP root-path.
760 You may want to use rd.iscsi.firmware.
762 **root=**_???_ **netroot=**iscsi **rd.iscsi.firmware=1**::
763 will read the iscsi parameter from the BIOS firmware
765 **rd.iscsi.login_retry_max=**__<num>__::
766 maximum number of login retries
768 **rd.iscsi.param=**__<param>__::
769 <param> will be passed as "--param <param>" to iscsistart.
770 This parameter can be specified multiple times.
775 "netroot=iscsi rd.iscsi.firmware=1 rd.iscsi.param=node.session.timeo.replacement_timeout=30"
782 iscsistart -b --param node.session.timeo.replacement_timeout=30
785 **rd.iscsi.ibft** **rd.iscsi.ibft=1**:
786 Turn on iBFT autoconfiguration for the interfaces
788 **rd.iscsi.waitnet=0**:
789 Turn off waiting for all interfaces to be up before trying to login to the iSCSI targets.
791 **rd.iscsi.testroute=0**:
792 Turn off checking, if the route to the iSCSI target IP is possible before trying to login.
797 disable FCoE and lldpad
799 **fcoe=**__<edd|interface|MAC>__:__{dcb|nodcb}__:__{fabric|vn2vn}__::
800 Try to connect to a FCoE SAN through the NIC specified by _<interface>_ or
801 _<MAC>_ or EDD settings. The second argument specifies if DCB
802 should be used. The optional third argument specifies whether
803 fabric or VN2VN mode should be used.
804 This parameter can be specified multiple times.
806 NOTE: letters in the MAC-address must be lowercase!
810 **root=**??? **netroot=**nbd:__<server>__:__<port/exportname>__[:__<fstype>__[:__<mountopts>__[:__<nbdopts>__]]]::
811 mount nbd share from <server>.
814 If "exportname" instead of "port" is given the standard port is used.
815 Newer versions of nbd are only supported with "exportname".
817 **root=dhcp** with **dhcp** **root-path=**nbd:__<server>__:__<port/exportname>__[:__<fstype>__[:__<mountopts>__[:__<nbdopts>__]]]::
818 root=dhcp alone directs initrd to look at the DHCP root-path where NBD
819 options can be specified. This syntax is only usable in cases where you are
820 directly mounting the volume as the rootfs.
823 If "exportname" instead of "port" is given the standard port is used.
824 Newer versions of nbd are only supported with "exportname".
829 same syntax as the kernel module parameter (s390 only)
833 **rd.zfcp=**__<zfcp adaptor device bus ID>__,__<WWPN>__,__<FCPLUN>__::
834 rd.zfcp can be specified multiple times on the kernel command
837 **rd.zfcp=**__<zfcp adaptor device bus ID>__::
838 If NPIV is enabled and the 'allow_lun_scan' parameter to the zfcp
839 module is set to 'Y' then the zfcp adaptor will be initiating a
840 scan internally and the <WWPN> and <FCPLUN> parameters can be omitted.
845 rd.zfcp=0.0.4000,0x5005076300C213e9,0x5022000000000000
850 ignore zfcp.conf included in the initramfs
854 **rd.znet=**__<nettype>__,__<subchannels>__,__<options>__::
855 The whole parameter is appended to /etc/ccw.conf, which is used on
856 RHEL/Fedora with ccw_init, which is called from udev for certain
858 rd.znet can be specified multiple times on the kernel command line.
863 rd.znet=qeth,0.0.0600,0.0.0601,0.0.0602,layer2=1,portname=foo
864 rd.znet=ctc,0.0.0600,0.0.0601,protocol=bar
869 Dracut offers multiple options for live booted images:
871 =====================
872 SquashFS with read-only filesystem image::: The system will boot with a
873 read-only filesystem from the SquashFS and apply a writable Device-mapper
874 snapshot or an OverlayFS overlay mount for the read-only base filesystem. This
875 method ensures a relatively fast boot and lower RAM usage. Users **must be
876 careful** to avoid writing too many blocks to a snapshot volume. Once the
877 blocks of the snapshot overlay are exhausted, the root filesystem becomes
878 read-only and may cause application failures. The snapshot overlay file is
879 marked 'Overflow', and a difficult recovery is required to repair and enlarge
880 the overlay offline. Non-persistent overlays are sparse files in RAM that only
881 consume content space as required blocks are allocated. They default to an
882 apparent size of 32 GiB in RAM. The size can be adjusted with the
883 **rd.live.overlay.size=** kernel command line option.
885 The filesystem structure is traditionally expected to be:
889 squashfs.img | SquashFS from LiveCD .iso
892 |- rootfs.img | Filesystem image to mount read-only
894 /bin | Live filesystem
900 For OverlayFS mount overlays, the filesystem structure may also be a direct
901 compression of the root filesystem:
905 squashfs.img | SquashFS from LiveCD .iso
907 /bin | Live filesystem
913 Dracut uses one of the overlay methods of live booting by default. No
914 additional command line options are required other than **root=live:<URL>** to
915 specify the location of your squashed filesystem.
917 - The compressed SquashFS image can be copied during boot to RAM at
918 `/run/initramfs/squashed.img` by using the **rd.live.ram=1** option.
919 - A device with a persistent overlay can be booted read-only by using the
920 **rd.live.overlay.readonly** option on the kernel command line. This will
921 either cause a temporary, writable overlay to be stacked over a read-only
922 snapshot of the root filesystem or the OverlayFS mount will use an additional
923 lower layer with the root filesystem.
925 Uncompressed live filesystem image:::
926 When the live system was installed with the '--skipcompress' option of the
927 __livecd-iso-to-disk__ installation script for Live USB devices, the root
928 filesystem image, __rootfs.img__, is expanded on installation and no SquashFS
929 is involved during boot.
931 - If **rd.live.ram=1** is used in this situation, the full, uncompressed
932 root filesystem is copied during boot to `/run/initramfs/rootfs.img` in the
935 - If **rd.live.overlay=none** is provided as a kernel command line option,
936 a writable, linear Device-mapper target is created on boot with no overlay.
938 Writable filesystem image:::
939 The system will retrieve a compressed filesystem image, extract it to
940 `/run/initramfs/fsimg/rootfs.img`, connect it to a loop device, create a
941 writable, linear Device-mapper target at `/dev/mapper/live-rw`, and mount that
942 as a writable volume at `/`. More RAM is required during boot but the live
943 filesystem is easier to manage if it becomes full. Users can make a filesystem
944 image of any size and that size will be maintained when the system boots. There
945 is no persistence of root filesystem changes between boots with this option.
947 The filesystem structure is expected to be:
951 rootfs.tgz | Compressed tarball containing filesystem image
953 /rootfs.img | Filesystem image at /run/initramfs/fsimg/
955 /bin | Live filesystem
961 To use this boot option, ensure that **rd.writable.fsimg=1** is in your kernel
962 command line and add the **root=live:<URL>** to specify the location
963 of your compressed filesystem image tarball or SquashFS image.
964 =====================
966 **rd.writable.fsimg=**1::
967 Enables writable filesystem support. The system will boot with a fully
968 writable (but non-persistent) filesystem without snapshots __(see notes above
969 about available live boot options)__. You can use the **rootflags** option to
970 set mount options for the live filesystem as well __(see documentation about
971 rootflags in the **Standard** section above)__.
972 This implies that the whole image is copied to RAM before the boot continues.
974 NOTE: There must be enough free RAM available to hold the complete image.
976 This method is very suitable for diskless boots.
978 **root=**live:__<url>__::
979 Boots a live image retrieved from __<url>__. Requires the dracut 'livenet'
980 module. Valid handlers: __http, https, ftp, torrent, tftp__.
985 root=live:http://example.com/liveboot.img
986 root=live:ftp://ftp.example.com/liveboot.img
987 root=live:torrent://example.com/liveboot.img.torrent
990 **rd.live.debug=**1::
991 Enables debug output from the live boot process.
993 **rd.live.dir=**__<path>__::
994 Specifies the directory within the boot device where the squashfs.img or
995 rootfs.img can be found. By default, this is `/LiveOS`.
997 **rd.live.squashimg=**__<filename of SquashFS image>__::
998 Specifies the filename for a SquashFS image of the root filesystem.
999 By default, this is __squashfs.img__.
1002 Copy the complete image to RAM and use this for booting. This is useful
1003 when the image resides on, e.g., a DVD which needs to be ejected later on.
1005 **rd.live.overlay={**__<devspec>__[:__{<pathspec>|auto}__]|__none__}::
1006 Manage the usage of a permanent overlay.
1009 * _<devspec>_ specifies the path to a device with a mountable filesystem.
1010 * _<pathspec>_ is the path to a file within that filesystem, which shall be
1011 used to persist the changes made to the device specified by the
1012 **root=live:__<url>__** option.
1014 The default _pathspec_, when _auto_ or no _:<pathspec>_ is given, is
1015 `/<+++<b>rd.live.dir</b>+++>/overlay-<label>-<uuid>`, where _<label>_ is the
1016 device LABEL, and _<uuid>_ is the device UUID.
1017 * _none_ (the word itself) specifies that no overlay will be used, such as when
1018 an uncompressed, writable live root filesystem is available.
1020 If a persistent overlay __is detected__ at the standard LiveOS path, the
1021 overlay & overlay type detected, whether Device-mapper or OverlayFS, will be
1028 rd.live.overlay=/dev/sdb1:persistent-overlay.img
1029 rd.live.overlay=UUID=99440c1f-8daa-41bf-b965-b7240a8996f4
1032 **rd.live.overlay.size=**__<size_MiB>__::
1033 Specifies a non-persistent Device-mapper overlay size in MiB. The default is
1036 **rd.live.overlay.readonly=**1::
1037 This is used to boot with a normally read-write persistent overlay in a
1038 read-only mode. With this option, either an additional, non-persistent,
1039 writable snapshot overlay will be stacked over a read-only snapshot,
1040 `/dev/mapper/live‑ro`, of the base filesystem with the persistent overlay, or a
1041 read-only loop device, in the case of a writable __rootfs.img__, or an OverlayFS
1042 mount will use the persistent overlay directory linked at `/run/overlayfs‑r` as
1043 an additional lower layer along with the base root filesystem and apply a
1044 transient, writable upper directory overlay, in order to complete the booted
1047 **rd.live.overlay.reset=**1::
1048 Specifies that a persistent overlay should be reset on boot. All previous root
1049 filesystem changes are vacated by this action.
1051 **rd.live.overlay.thin=**1::
1052 Enables the usage of thin snapshots instead of classic dm snapshots.
1053 The advantage of thin snapshots is that they support discards, and will free
1054 blocks that are not claimed by the filesystem. In this use case, this means
1055 that memory is given back to the kernel when the filesystem does not claim it
1058 **rd.live.overlay.overlayfs=**1::
1059 Enables the use of the *OverlayFS* kernel module, if available, to provide a
1060 copy-on-write union directory for the root filesystem. OverlayFS overlays are
1061 directories of the files that have changed on the read-only base (lower)
1062 filesystem. The root filesystem is provided through a special overlay type
1063 mount that merges the lower and upper directories. If an OverlayFS upper
1064 directory is not present on the boot device, a tmpfs directory will be created
1065 at `/run/overlayfs` to provide temporary storage. Persistent storage can be
1066 provided on vfat or msdos formatted devices by supplying the OverlayFS upper
1067 directory within an embedded filesystem that supports the creation of trusted.*
1068 extended attributes and provides a valid d_type in readdir responses, such as
1069 with ext4 and xfs. On non-vfat-formatted devices, a persistent OverlayFS
1070 overlay can extend the available root filesystem storage up to the capacity of
1071 the LiveOS disk device.
1073 If a persistent overlay is detected at the standard LiveOS path, the overlay &
1074 overlay type detected, whether OverlayFS or Device-mapper, will be used.
1076 The **rd.live.overlay.readonly** option, which allows a persistent overlayfs to
1077 be mounted read-only through a higher level transient overlay directory, has
1078 been implemented through the multiple lower layers feature of OverlayFS.
1083 **rd.zipl=**__<path to blockdevice>__::
1084 Update the dracut commandline with the values found in the
1085 _dracut-cmdline.conf_ file on the given device.
1086 The values are merged into the existing commandline values
1087 and the udev events are regenerated.
1092 rd.zipl=UUID=0fb28157-99e3-4395-adef-da3f7d44835a
1097 **rd.cio_accept=**__<device-ids>__::
1098 Remove the devices listed in <device-ids> from the default
1099 cio_ignore kernel command-line settings.
1100 <device-ids> is a list of comma-separated CCW device ids.
1101 The default for this value is taken from the
1102 _/boot/zipl/active_devices.txt_ file.
1107 rd.cio_accept=0.0.0180,0.0.0800,0.0.0801,0.0.0802
1110 Plymouth Boot Splash
1111 ~~~~~~~~~~~~~~~~~~~~
1112 **plymouth.enable=0**::
1113 disable the plymouth bootsplash completely.
1116 disable the plymouth bootsplash only for the initramfs.
1120 **masterkey=**__<kernel master key path name>__::
1121 Set the path name of the kernel master key.
1126 masterkey=/etc/keys/kmk-trusted.blob
1129 **masterkeytype=**__<kernel master key type>__::
1130 Set the type of the kernel master key.
1135 masterkeytype=trusted
1138 **evmkey=**__<EVM key path name>__::
1139 Set the path name of the EVM key.
1144 evmkey=/etc/keys/evm-trusted.blob
1147 **ecryptfskey=**__<eCryptfs key path name>__::
1148 Set the path name of the eCryptfs key.
1153 ecryptfskey=/etc/keys/ecryptfs-trusted.blob
1156 Deprecated, renamed Options
1157 ~~~~~~~~~~~~~~~~~~~~~~~~~~~
1158 Here is a list of options, which were used in dracut prior to version 008, and
1159 their new replacement.
1166 rd_DASD_MOD:: rd.dasd
1170 rdinitdebug rdnetdebug:: rd.debug
1174 rd_DM_UUID:: rd.dm.uuid
1176 rdblacklist:: rd.driver.blacklist
1178 rdinsmodpost:: rd.driver.post
1180 rdloaddriver:: rd.driver.pre
1182 rd_NO_FSTAB:: rd.fstab=0
1186 check:: rd.live.check
1188 rdlivedebug:: rd.live.debug
1190 live_dir:: rd.live.dir
1192 liveimg:: rd.live.image
1194 overlay:: rd.live.overlay
1196 readonly_overlay:: rd.live.overlay.readonly
1198 reset_overlay:: rd.live.overlay.reset
1200 live_ram:: rd.live.ram
1202 rd_NO_CRYPTTAB:: rd.luks.crypttab=0
1204 rd_LUKS_KEYDEV_UUID:: rd.luks.keydev.uuid
1206 rd_LUKS_KEYPATH:: rd.luks.keypath
1208 rd_NO_LUKS:: rd.luks=0
1210 rd_LUKS_UUID:: rd.luks.uuid
1212 rd_NO_LVMCONF:: rd.lvm.conf
1214 rd_LVM_LV:: rd.lvm.lv
1216 rd_NO_LVM:: rd.lvm=0
1218 rd_LVM_SNAPSHOT:: rd.lvm.snapshot
1220 rd_LVM_SNAPSIZE:: rd.lvm.snapsize
1222 rd_LVM_VG:: rd.lvm.vg
1224 rd_NO_MDADMCONF:: rd.md.conf=0
1226 rd_NO_MDIMSM:: rd.md.imsm=0
1230 rd_MD_UUID:: rd.md.uuid
1232 rd_NO_MULTIPATH: rd.multipath=0
1234 rd_NFS_DOMAIN:: rd.nfs.domain
1236 iscsi_initiator:: rd.iscsi.initiator
1238 iscsi_target_name:: rd.iscsi.target.name
1240 iscsi_target_ip:: rd.iscsi.target.ip
1242 iscsi_target_port:: rd.iscsi.target.port
1244 iscsi_target_group:: rd.iscsi.target.group
1246 iscsi_username:: rd.iscsi.username
1248 iscsi_password:: rd.iscsi.password
1250 iscsi_in_username:: rd.iscsi.in.username
1252 iscsi_in_password:: rd.iscsi.in.password
1254 iscsi_firmware:: rd.iscsi.firmware=0
1256 rd_NO_PLYMOUTH:: rd.plymouth=0
1262 rd_NO_SPLASH:: rd.splash
1264 rdudevdebug:: rd.udev.debug
1266 rdudevinfo:: rd.udev.info
1268 rd_NO_ZFCPCONF:: rd.zfcp.conf=0
1274 KEYMAP:: vconsole.keymap
1276 KEYTABLE:: vconsole.keymap
1278 SYSFONT:: vconsole.font
1280 CONTRANS:: vconsole.font.map
1282 UNIMAP:: vconsole.font.unimap
1284 UNICODE:: vconsole.unicode
1286 EXT_KEYMAP:: vconsole.keymap.ext
1288 Configuration in the Initramfs
1289 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
1291 Any files found in _/etc/conf.d/_ will be sourced in the initramfs to
1292 set initial values. Command line options will override these values
1293 set in the configuration files.
1296 Can contain additional command line options. Deprecated, better use
1297 /etc/cmdline.d/*.conf.
1299 _/etc/cmdline.d/*.conf_::
1300 Can contain additional command line options.
1308 *dracut*(8) *dracut.conf*(5)