But it might be easier to install PVE to a small unencrypted disk and then encrypt the storage where data and vms are being stored. I'll have a LUKS device for each disk, the unlocked device mapper devices then are forming a ZFS device, so it's ZFS on top of LUKS