Earlier quoted context omitted.
You say that as though it's easy. I've yet to find an explanation that's shorter than a book.
Ideally signing and enrolling in the UEFI the key to a signed Unified Kernel Image (UKI) makes more sense: only having SecureBoot verifying the kernel is okay'ish (and it does work: I tried modifying a single bit from my kernel and the UEFI refused to boot it) but it's not that great if the attacker can still modify the initrd etc.
https://wiki.archlinux.org/title/Unified_kernel_image#Prepar...