,discardto the fourth column on relevant lines in
/etc/crypttabFor me, this meant the fourth column should be
luks,discardbut you may have other options in there.
issue_discards = 0to
issue_discards = 1
sudo update-initramfs -u
To test it, run:
sudo fstrim -av
When it works you can use systemd to have fstrim run on a regular schedule.
sudo systemctl enable fstrim.timer. systemd will now run fstrim weekly.
A word of caution
Please note that using TRIM on an encrypted volume is discouraged. This is due to the fact that TRIM may leak information about what goes on inside the encrypted volume. For example stuff like how much free space vs. used space there is. Which areas of the volume data is changing frequently, etc. This is all knowledge that an attacker may use to attack the encryption.
man 5 crypttab:
WARNING: Assess the specific security risks carefully before enabling this option. For example, allowing discards on encrypted devices may lead to the leak of information about the ciphertext device (filesystem type, used space etc.) if the discarded blocks can be located easily on the device later.