Gardenhouse
Tools to bootstrap an immutable Gentoo-based system.
DM-Verity
The root images are dm-verity verified by default.
Per-User encryption
The home directory of each user may be optionally encrypted.
Secureboot
Secureboot will automatically be set up during build. Just create the keys and build an image!
Measured boot
If your system has a TPM2 chip, each boot stage will automatically be measured. Allowing for verification of each boot.
Boot blessing
Define checks to be performed during boot to ensure that the system is fully functional.