[email protected] wrote: 
> I am not sure if this is the correct format for this question, but if this is 
> the incorrect forum, and can point me to a forum or other that maybe can 
> offer better advice I would surely appreciate it.
> 
> I run a small HP Elite Desk Mini G2, behind a CGNAT running Debian/ Zerotier 
> (a software defined network) to get around the CGNAT, and Immich. The box 
> sits on the shelf as a headless unit. Ideally I can SSH into it when my 
> girlfriend accidentally restarts it so I'm not having to enter the NVMe's 
> password after restarts- requiring me to hook up a monitor and keyboard, but 
> more important actually be present, and I travel often.
 
> Is their a solution other than not having an encrypted NVMe? My other idea 
> was separate partitions on the NVMe so my photos collection is stored on the 
> encrypted partition and Debian on the encrypted partition. I see there is a 
> solution for SSH before the password prompt for the NVMe encryption, but that 
> wouldn't run the Zerotier software.. so then SSH would not work because can't 
> see the machine outside the local network. Of course, the simplest solution 
> is just to not have the drive encrypted but I am using it as a learning 
> opportunity and stepping stone to increase my knowledge. Maybe at some point 
> my setup is good enough for family or friends to utilize my drive space, so 
> security, backups of course are very important, and building them well. And I 
> will at some point have an uninterrupted power supply, but that still doesn't 
> solve the issue of occasional restarts for updates, or accidentally having 
> the power turned off.
>


Easiest: have a second box which runs ZeroTier and can ssh in to
the first box. This can be as small as an old phone, a Raspberry
Pi, an old laptop... you aren't asking it to do much.

-dsr-

Reply via email to