Last time I enabled secure boot it was with a unified kernel image, there was nothing on the EFI partition that was unsigned.
Idk about the default shim setup but using dracut with uki, rolled keys and luks it'd be secure.
After this you're protected from offline attacks only though, unless you sign the UKI on a different device any program with root could still sign the modified images itself but no one could do an Evil Maid Attack or similar.
From what I understand, this either means that this will only affect laptops and similar devices, or that they want to force companies that sell windows PCs to sign a contract disallowing them from selling keyboards without a copilot key, with or without a PC. I think (hope?) they mean the former.