Nixos, ext4 under luks2 on lvm, luks encrypted boot [1], apparmor, sleep & hibernation support.
Monitor (primarily disk state) & send local mails & check up on zsh login.
Future: RAID 1, deniable encryption.
Daily used apps go through the global config. All the rest goes through nix-shell, zero nix-env -i. Screen locking. Apparmor.