Sealed images: the security chain from firmware to filesystem This is the first in a series of posts about bootc sealed images. In this post we’ll take a tour through the full security chain that makes sealed images work, from the moment your system powers on through every file read at runtime. Future posts will cover key management, building sealed images, and deploying them to various environments.