It'd be great if we could Certify or Quote the TPM PCRs and publish these as selectors.
When building appliance images it's possible to predict many of the PCRs and you could say something like "Only the postgres appliance image can take the postgres spiffe ID"