So wait with ZFSbootmenu, I can just install it to a USB and then install my entire distro under a zfs pool and ZFSbootmenu will find it and let me boot into it? Is that how it works?
You guys run your own vault / password manager? I stood up hashicorp vault but it's uses seem more geared towards automation with apps rather than personal. I'd almost wonder if it's more worth just standing up like a bit/vaultwarden and using its api for everything.