What we really need is simple tooling that handles just the case of "I want to sign kernels for my own machine(s)".
Of course, some tools do exist for this case, but I'm not aware of one that is totally generic. Lanzaboote for NixOS seems interesting (disclaimer: have not tried.)
Please, people, if you release software that overlaps or competes with another existing in the space, take the 3 minutes to write a comparison note or "why this exists". Please.
Unfortunately, unlike many of their projects, they don't seem to have a blog post yet for it.
It seems like a natural conclusion to spend a fraction of the energy to author, to detail it's reason to exist.
Anyway, no one owes me anything but I trust that Determinate Systems has a grander vision than I can see, I just want to be clued in, to be honest ;).
https://wiki.archlinux.org/title/Unified_kernel_image#Prepar...
> Ideally signing and enrolling in the UEFI the key to a signed Unified Kernel Image (UKI) makes more sense
(It's much more useful to have a link to it, so thank you!)
It gives you the "here, run these commands" version if that's what you want.
[1] https://wiki.debian.org/SecureBoot#MOK_-_Machine_Owner_Key
Step 0: deploy your own PKI, install certificates on your motherboard firmware, sign your kernel, sign your modules.
Step 0.5: Sign your DKMSs from Broadcom, Nvidia, and Intel.
Step 0.75: Re-sign everything because you missed a step.
Maybe I need to write it a little more clearly, but perhaps that will get you there.
My hacky script has more lines to fetch the signer name from the kernel (once it's been signed) than to just sign the vmlinuz image.