Can I contain VMs within veracrypt inside dom0?

I would like to be able to use Qubes without certain VMs being accessible unless password is entered.

Is possible to install Veracrypt in dom0 with large file (500 GB) and then mount this as directory containing VMs and dismount when not in use without breaking Qubes?

You can configure secondary storage:

The qubes stored in the secondary storage will be seen in the system at all times, but the qubes volumes won’t be accessible without decrypting the secondary storage.

2 Likes

Would it be against Qubes philosophy if I partitioned a large drive, installed Qubes on the first partition, and made the second partition the secondary storage?

No, it won’t have any additional security issues.

1 Like