v8.1.0 — optional kmod module-signing secret plumbing

MOK_SIGNING_KEY_B64 convention on base-build-scratch kmod jobs: decode
to tmpfile, buildah --secret id=mok; consumers opt in via
RUN --mount=type=secret,id=mok. Non-breaking. For basef#19.