I have a mini PC server that can't be physically locked away from people in the house, because I do not have the ability or space to install a rack and physically secure it.
There is a housekeeper that is sometimes not the same person.
There is a curious child in the house.
The server needs to be rebooted remotely occasionally.
Some disks are removable.
I am not concerned about an APT posing as my maid to steal the key from RAM. It's not part of my threat model.
I do want to know if my UEFI, bootloader or UKI has been fucked with without my knowledge.