This encrypts a partition with LUKS and uses the TPM2 to unlock the partition during boot.
Adapt start-qemu to support tpm2.
Quirin Gylstorff (5): add tpm.cfg to the kernel use bullseye backports for systemd-cryptenroll wic/x86-efibootguard: add partition to encrypted start-qemu: If swtpm is available create a tpm2 device Add initramfs hook to encrypt a partition