the trick here is that startingpoint itself is signed with ublue-os key, but it's meant for users to
the trick here is that startingpoint itself is signed with ublue-os key, but it's meant for users to make their own (eg, my own image is signed with a personal key)...
so the policy file needs to be managed by downstream user builds and have their own bits injected
so the policy file needs to be managed by downstream user builds and have their own bits injected