Current code allow the user to choose between encrypted -e and decrypted prepared SIF image. The encrypted flag will run SIF image creation as for an non-encrypted image and then encrypt it because LUMI doesn't ATM support encrypted SIF image.
We could implement a supplementary flag specifying is we want the image to be encrypted at runtime or only at rest (depending on the destination cluster ...)