Sealed bootable container images include all the components needed to create a fully verified boot chain, from the firmware to the operating system composefs image