So "yes" – what would you do if you had, say, several hundred (or several thousand) servers?
I would make a password entering automation system. Ensure that that system is dead-simple and secured to death. It must run no other services, firewalled to death even from the intranet, physically secured in a cage, and must be off most of the time. It is only to be turned on when booting a system, and turning it on not only requires a password but also physically walking to the cage, opening it with a physical key, and pressing the "on" button. All target servers must be configured in such a way that they can obtain network access before mounting the encrypted part.
But I'm not a security expert. Maybe I've overlooked something.
Properly hard problem, as you've pointed out.