feat(pm/redhead): enable secure boot
I want to make booting not need a PIN/security key press, and therefore
I want to make sure that I'm booting only what is explicitly permitted.
Therefore, let's use lanzaboote! I've set it up before, so it's
relatively simple
authored by
a.starrysky.fyi
and committed by