I have to admire this writeup for the sheer deranged glory of remotely unlocking your desktop's encrypted root drive on boot by setting up Tailscale and a very limited SSH server in your initrd, so you can SSH in to enter the unlock password. And of course you give your initrd a separate and limited Tailscale identity and its own set of SSH host keys.
https://jyn.dev/remotely-unlocking-an-encrypted-hard-disk/
(via https://tech.lgbt/@jyn/115939595372361611 or https://lobste.rs/s/spemfa/remotely_unlocking_encrypted_hard_disk )