I went with a used ThinkPad yoga 370. It still only has a dual core while the following Gen has 4 cores, so it seemed there was a price gap. It has thunderbolt 3 for when I want to switch to a bigger screen (with a cheap USB c dock) and USB c charging. Also I wanted to try a touchscreen on a laptop. I should be able to upgrade the single ram stick in it at some point. Running arch with sway without problems.
Edit: I had a x240 for years before. It was fine but I appreciate the higher resolution of the 370, even if I ended up using fractional scaling as it was just a bit too small.
I do not know the answer, but this got me thinking: would it be easier to set up a single login for both session and decryption if /home was on a separate partition and only /home was encrypted?