Fedora Cloud Atomic, initramfs are built server-side, are no-hostonly, and therefore could be signed. These are a bit more than double the size of hostonly initramfs. Which is easier, setting up verifiable initrds for non-atomic installations? Or eliminating initrd boots?
atomic initrds