I am not sure if this is the correct format for this question, but if this is the incorrect forum, and can point me to a forum or other that maybe can offer better advice I would surely appreciate it.
I run a small HP Elite Desk Mini G2, behind a CGNAT running Debian/ Zerotier (a software defined network) to get around the CGNAT, and Immich. The box sits on the shelf as a headless unit. Ideally I can SSH into it when my girlfriend accidentally restarts it so I'm not having to enter the NVMe's password after restarts- requiring me to hook up a monitor and keyboard, but more important actually be present, and I travel often. Is their a solution other than not having an encrypted NVMe? My other idea was separate partitions on the NVMe so my photos collection is stored on the encrypted partition and Debian on the encrypted partition. I see there is a solution for SSH before the password prompt for the NVMe encryption, but that wouldn't run the Zerotier software.. so then SSH would not work because can't see the machine outside the local network. Of course, the simplest solution is just to not have the drive encrypted but I am using it as a learning opportunity and stepping stone to increase my knowledge. Maybe at some point my setup is good enough for family or friends to utilize my drive space, so security, backups of course are very important, and building them well. And I will at some point have an uninterrupted power supply, but that still doesn't solve the issue of occasional restarts for updates, or accidentally having the power turned off. Thanks for any ideas or input. Georges Sent with [Proton Mail](https://proton.me/mail/home) secure email.

