How do you handle key and/or certificate storage at the client side? Depending on the threat model, the update verification step can be subverted.
Once the device has been installed, there is always at least one working partition on the device - the partition that was last booted. So you don't need a minimal recovery partition or anything. (You could build a recovery command-line option in, if you want, but it's just a custom way of booting the normal partition.)
In particular, for all my use cases, there's already some mechanism for the device gaining a secure channel to the rest of the infrastructure, so if you're worried about keeping updates secret (which you may or may not be!), just protect updates by that mechanism.
Signing and verification in Mender is covered here: https://docs.mender.io/artifacts/signing-and-verification