As far as I can understand, only /boot has to be on a fat/ext4/iso9660 partition (apart from efi which has to be on a fat by itself). As efi is mounted on /boot/efi, I figure we'll need 2 separate partitions besides / (and whatever other partitions we might want to separate / into).
I start to worry that more and more of the system has to be uncovered to an attacker: if you keep the distro's kernel, it'll be easy to figure out the system installed on / so 90% of the data on disk will be known. No need for luks except for /home.
Is there a way to have whole disk encryption on linux and secure boot at the same time? efi already has to be unencrypted right? Now /boot...
Can systemd-boot save the day?