I think the way I am going to overcome this issue of not being able to encrypt root is to enable encrypted swap, create an encrypted partition where applications can run in a chrooted environment.
I still have a few things to work out, but I think it should be an acceptable substitution
|