This is a collection of shell functions to build secure Linux-based operating system images. They are highly specific to my setup and probably won’t be useful to anyone else. […] The primary goal here is swappable immutable disk images that are verified by verity, which is itself verified by the kernel’s Secure Boot signature.[…]