A kernel guard I prototyped after eBPF and vTPM work for a customer, where we use the TPM to protect the private keys for mTLS. Any process running as root can open the TPM devices, and so can any process in the `tss` group, through `/dev/tpmrm0`. That means they can use those keys too. This is a prototype and some research into protecting this path.