I am not sure if this is the correct format for this question, but if this is 
the incorrect forum, and can point me to a forum or other that maybe can offer 
better advice I would surely appreciate it.

I run a small HP Elite Desk Mini G2, behind a CGNAT running Debian/ Zerotier (a 
software defined network) to get around the CGNAT, and Immich. The box sits on 
the shelf as a headless unit. Ideally I can SSH into it when my girlfriend 
accidentally restarts it so I'm not having to enter the NVMe's password after 
restarts- requiring me to hook up a monitor and keyboard, but more important 
actually be present, and I travel often.

Is their a solution other than not having an encrypted NVMe? My other idea was 
separate partitions on the NVMe so my photos collection is stored on the 
encrypted partition and Debian on the encrypted partition. I see there is a 
solution for SSH before the password prompt for the NVMe encryption, but that 
wouldn't run the Zerotier software.. so then SSH would not work because can't 
see the machine outside the local network. Of course, the simplest solution is 
just to not have the drive encrypted but I am using it as a learning 
opportunity and stepping stone to increase my knowledge. Maybe at some point my 
setup is good enough for family or friends to utilize my drive space, so 
security, backups of course are very important, and building them well. And I 
will at some point have an uninterrupted power supply, but that still doesn't 
solve the issue of occasional restarts for updates, or accidentally having the 
power turned off.

Thanks for any ideas or input.

Georges

Sent with [Proton Mail](https://proton.me/mail/home) secure email.

Reply via email to