However, it is still possible to get _some_ degree of protection with automounting encrypted drives:
You can setup SecureBoot with encryption keys stored in TPM.
Under SecureBoot security assumptions (motherboard firmware and TPM chip don't have backdors, etc.), this setup will release encryption keys and decrypt your drives only if your OS wasn't tampered with.
However, there are some _caveats_.)
gnabgib•2h ago