Building encrypted images and then later using cryptsetup-reencrypt (to get a secret master key) [is not set possible](https://github.com/grml/grml-debootstrap/issues/131) and may or may not be simple to implement in grml-debootstrap.
cryptsetup-reencrypt as far as I understand (I hope I am wrong?) can only be used for already encrypted luks images.
luksipc apparently seems capable of in-place encryption of non-luks disks.
* test lukspic to encrypt a previously unencrypted installed Debian and convert it into a full disk encrypted system
* #research if there are better alternatives