The coverage is calculated into a PCR on the Confidential VM's vTPM (that's matched in The important thing launch policy to the KMS Using the expected plan hash for that deployment) and enforced by a hardened https://kathrynhjgs880073.blogofoto.com/61542153/the-smart-trick-of-is-ai-actually-safe-that-no-one-is-discussing