Per Mark in T82576#902820, the blocker to enabling STARTTLS was that in the past doing so "would use up (starve) all random entropy because of the many deliveries, and then block. But with newer hardware and potentially hw RNGs, the situation may be better now. We can test it again."
It is possible that no action is explicitly needed, if there is a hardware RNG on the virtualization host and if the individual VMs are able to utilize it as a source for entropy. If this is not the case, one possible solution would be to have haveged running on the virtualization host and the virtio-rng kernel module loaded in guests.