Adding a keyfile to be automatically used is done via the cryptsetup-initramfs package. Keyfile is only exposed to root user. When embedding the keyfile in the initrd.img /boot/ should be encrypted so the keyfile cannot be obtained without unlocking the LUKS container.
Adding a keyfile to be automatically used is done via the cryptsetup- initramfs package. Keyfile is only exposed to root user. When embedding the keyfile in the initrd.img /boot/ should be encrypted so the keyfile cannot be obtained without unlocking the LUKS container.