@lanodan also, why need a reason, when you can develop good practices for virtually no process cost (because encryption primitives are hard-coded in any recent CPU)
@gordon The reason was more like “uh what if the SSH in the initramfs fails” (and so I would have to pass via the console, which could give the pass to Hetzner)