

TPM2 + Secure Boot via systemd-cryptenroll is the closest to the “just works” FileVault/Android experience. Keep a recovery passphrase in your password manager. You don’t lose your data if the motherboard dies, you just use the recovery key.
I use this on my daily drive laptop. Only real hiccup is that I still keep the dual boot because fwupd does not cover my laptop BIOS firmware updates but in a Linux tablet this a no issue.

What are you about here? “Just a simple metal plate”, what exactly are you expecting? That is exactly the definition of a motherboard or a dock.
The TGX dock from Lenovo is that inside a box.
I never said TB5 is best than Oculink in performance but is better than a TB4 and reduce the gap to Oculink. Good luck with your imaginary eGPU dock and your Framework 13 with limited TB4 port.