I use a 12600H MS-01 with 5x4tb nvme. Love the SFP+ ports since the DAC cable doesn't need ethernet to SFP adapters. Intel vPro is not perfect but works just fine for remote management access. I also plug a bus powered dual ssd enclosure to it which is used for Minio object storage.
It's a file server (when did we started calling these "NAS"?) with Samba, NFS but also some database stuff. No VMs or dockers. Just a file and database server.
It has full disk encryption with TPM unlocking with my custom keys so it can boot unattended. I'm quote happy with it.
Can you expand on the TPM unlocking? Wouldn't this be vulnerable to evil maid attacks?