SecureBoot support implementation Currently Kairos supports SecureBoot based on the upstream artifacts. We piggyback on the upstream artifacts to be properly signed in order to support SecureBoot. Before this was supported, we shipped a single set of artifacts that were signed by one of the upstream distros. That meant that only that distro was supported under SecureBoot as we needed all artifacts in the chain to be signed with the same key.