How to work with a secure boot stream

what's the workflow?

This is my idea.

First design a simple otpprogram.ldr, write it down to spi flash. and power on to write public key to otp memory.

And design a app.ldr, sign it and encode, write it down to spi flash, and power on to run real application?