> instead of having it as a layer which you can install and enable if you need so is a bit sinister
I don't really get it. If you don't want systemd, you can install your own OpenRC-based immutable OS. I don't know if that currently exists (Android does, I suppose? maybe ChromeOS?) but it's not like systemd is forbidding everyone from doing anything.
The biggest difference between systemd and alternatives is that systemd builds out the architecture that makes things like building immutable distros easy. If you have a thousand different components, all with slightly different roles, the amount of coordination necessary to get everything to play nice together makes it near impossible to achieve the same things a coordinated system can achieve.
I'm sure that if someone would build an alternative to systemd-sysext and prepare a prebuilt set of tooling and configuration that does what systemd does, there will be distros that will use them.
Secure boot can be overridden by just adding your own keys. At worst, Microsoft will refuse to boot Windows because you added a key yourself. The exception is extra expensive, specially labeled Enterprime (TM) hardware built for Windows sysadmins and Microsoft tablets built for consumers, but I don't know why you'd buy either if you don't want to give MS that much control.