I would honestly just create a tiny dual boot of another linux distro with LUKS KVM encryption on the entire thing. It has its own sudo, and is locked behind your encryption password. You just boot into a small 30GB or so private session that only you have access to while leaving the main distro untouched.



Ironically American Revolutionary Thomas Paine in his Common Sense said something that explains this quite well, “A long habit of not thinking a thing wrong, gives it a superficial appearance of being right,[…] Time makes more converts than reason.”