Verified start
Before anything touches your systems, the machine proves it is what it claims to be. The image signature is checked, the root filesystem is immutable, SELinux is enforcing, the kernel is locked down, and a boot health check passes or the system rolls back to the previous image on its own. The disk unlocks only because the TPM recognises the hardware it was enrolled on.