From Preparation
The Linux Boot Chain
Not written yet. Questions to answer here: what UEFI replaced and what firmware is doing before any operating system exists, what Secure Boot checks and whose signature it checks against, what a TPM is as a piece of hardware, how measured boot differs from Secure Boot (recording what ran versus refusing to run it), what attestation lets a remote party conclude, where systemd picks up and what it means for it to be PID 1, and what a fleet operator gains from all of this that they could not get by trusting the disk image.