

The user is able to install new certificates.
That’s true today, but there’s no guarantee it will be true in the future. Google is already pushing for all software running on Android to be cryptographically verified and they (Google) are the only ones that control the signing keys. This means that they intend to kill off F-droid and all other software delivered outside the Google store.
If Google is able to pull it off on Android, everyone else will try to do it on desktop OSes too - Linux included.

Yes, breaking the dependency on cloud providers is already extremely hard. But breaking the dependency on mobile OSes is going to be dramatically harder. What good is digital sovereignty if all users are still tied to American products to access those systems?