Following the discussion in coreos/ignition#2099, rather than extending Ignition to natively support Trustee, an alternative approach is to utilize Clevis pins to handle the attestation process, retrieve the disk encryption password, and encrypt the root volume.
This issue tracks the investigation into implementing a new trustee Clevis pin, integrating it into the initrd, and executing attestation during the first boot.