I believe that the disk encryption twice thing is to prevent the so called "evil maid" attack. Where both the boot partition,
and the file system are separately encrypted. Frustratingly, the encryption in GRUB2 is painfully slow, so I normally disable that. You can do this by creating the boot partition separately from the root file system, and only encryption the OS filesystem. The downside is that if someone steals your drive, or clones it, they can hammer away at the encrypted filesystem. Not really in my threat model, so I normally go with unencrypted boot + encrypted filesystem. The kernel decryption is much faster as well.
Details here in case I have some of that wrong:
https://en.opensuse.org/SDB:Encrypted_root_file_system#Avoid...