The layered-zero-trust pattern includes a python script inside the init-data-gzipper ansible job that computes expected PCR values for initdata verification. This script has been tested and confirmed working.
It should be backported into coco-pattern so the upstream pattern can use the standard imperative container image instead of requiring a custom one. This also keeps the PCR computation logic in a single place rather than diverging across patterns.