If you look for really FAST and streamline solution (one binary), check this post: https://michael.stapelberg.ch/posts/2020-01-21-initramfs-fro...
If you look for really FAST and streamline solution (one binary), check this post: https://michael.stapelberg.ch/posts/2020-01-21-initramfs-fro...
Of course, it doesn't encrypt /boot, but I keep a separate USB stick for that and put it in the server when it needs a reboot.
I'm not proud, or smart, but it works. Systemd is used for networking to make it simpler.
I based it on this: https://github.com/gsauthof/dracut-sshd
I should probably package it up with all the config options you'd need to specify drive and keyfile location and all that, but I'm a terrible member of the community and haven't actually done it yet.
The real trick that took me a long time to figure out was invoking "cryptsetup luksOpen" with my mount.sh script and then using "systemctl stop systemd-cryptsetup@nvme0n1p3_crypt.service" to get the thing to keep booting. I still don't really understand the tty ask password stuff in systemd, but this seems to work fine.
You just ssh in and run ./mount.sh and it decrypts/mounts/boots.