Update secure boot certificates doesn't work, because not enough efivarfs space

Well, that theory didn’t last long. I attempted to install with TPM-backed encryption, which has Secure Boot as a hard requirement, but the installer then informed me that it must also be enabled (deployed mode). I checked with mokutil --sb and it was in setup mode, as intended.
In my search for Canonical’s signing certificate, I happened upon this:

It seems to contain info on how to do this manually, but I’ve only just started reading.