I am planning to implement authenticated boot inspired from Pid Eins' blog.
I'll be using pam mount for /home/user. I need to check integrity of all partitions.
I have been using luks+ext4 till now. I am hesistant hesitant to switch to zfs/btrfs, afraid I might fuck up.
A while back I accidently purged '/' trying out timeshift which was my fault.
Should I use zfs/btrfs for /home/user?
As for root, I'm considering luks+(zfs/btrfs) to be restorable to blank state.
@unhinge I run a simple 48TiB zpool, and I found it easier to set up than many suggest and trivial to work with. I don't do anything funky with it though, outside of some playing with snapshots and send/receive when I first built it.
I think I recall reading about some nuance around using LUKS vs ZFS's own encryption back then. Might be worth having a read around comparing them for your use case.