I was encouraged  to use the storage encryption mechanism of libvirt . However, it is not clear to me how to generate a corresponding encrypted volume. Preferably, I would like to use virt-install to arrive at such an encrypted volume, similar to e.g.
virt-install --connect qemu:///system -n testImage -r 2048 --os-type=linux --disk testImage.img,device=disk,bus=virtio,size=8,sparse=true,format=raw --os-variant debian10 --vnc --location ftp://ftp2.de.debian.org/debian/dists/buster/main/installer-amd64/
I already asked a related question on server fault , but this is a better targeted audience. Sorry for double-posting.