The coverage is calculated into a PCR from the Confidential VM's vTPM (which happens to be matched in The real key launch coverage within the KMS with the anticipated policy hash with the deployment) and enforced by a https://abelvlod063420.livebloggs.com/36808307/the-5-second-trick-for-confidential-ai