I have no idea what TPM is
Read Skull giver's reply or look it up.
Re-reading your post, I take you want to avoid typing long and tedious password? And that's why you want to auto-decrypt?
- (Recommended) You could use strong memorable passwords that are not difficult to type and enable autologin. Related xfcd comic:

- systemd-cryptenroll: For TPM usage, I highly recommend using secure boot. Though not sure if you can easily do that. A less secure alternative using systemd-cryptenroll would be use tpm2-pin and bind key to no pcrs (discouraged). But then you'll have to use luks2 for encryption.
Notice from
man systemd-cryptenrollregarding tpm2-pin:
Note that incorrect PIN entry when unlocking increments the TPM dictionary attack
lockout mechanism, and may lock out users for a prolonged time, depending on its
configuration. The lockout mechanism is a global property of the TPM,
systemd-cryptenroll does not control or configure the lockout mechanism. You may use
tpm2-tss tools to inspect or configure the dictionary attack lockout, with
tpm2_getcap(1) and tpm2_dictionarylockout(1) commands, respectively
Also tpm2-pin is not disk encryption password and short alphanumeric password needed so tpm decrypts the device; so encryption password should be secured in a safe place. Also check if your distro supports systemd-cryptenroll.
-
usb drive: read previous comment
-
clevis: It probably isn't as simple as systemd-cryptenroll but I guess you can use zfs and combine that with tpm2-pin if not using secure boot (discouraged).
You'll have to make a compromise somewhere between security and convenience. Even if you use pam mount, you'll have to enter the password, biometrics won't do.
Edit: remove unnecessary user tag and add img uri