I don't know this build stuff. And my issue isn't over ssh but serial console.
I worked the old fashioned way: booting a vanilla image, installing cryptsetup & dropbear-initramfs, deal with the first 2k bytes & /boot, making crypto partition, rsync'ing the system, configure initramfs & generate a new one, edit armbianEnv & generate new boot.cmd. On ssh it automatically runs the "unlock" command and all i need to do is enter the password (over serial or SSH).
It's basically a minor nuisance, over serial console only. But i rather have everything proper, to avoid issues later and in case of network unavailable. It's a weird fluke, that seems related to authentication (whether that's login or sudo elevation).