I’m happy to announce that we have sealed bootable container images ready for testing for the Fedora Atomic Desktops!

Sealed bootable container images include all the components needed to create a fully verified boot chain, from the firmware to the operating system composefs image. This relies on Secure Boot and thus only supports system booting with UEFI on x86_64 & aarch64.

The components are:

systemd-boot as bootloader

a Unified Kernel Image (UKI) which includes the Linux kernel, an initrd and the kernel command line