Debian provides a signed shim that trusts sdboot and can be installed without pulling in grub automatically. Install it in the debian mkosi CI job, and build a custom efivars with the mkosi cert enrolled in MOK but not DB, to test those code paths.