intel-microcode was initially added to the standard packages with https://phabricator.wikimedia.org/rOPUPe6e960b69d6764f5fbe5b1bf513c8a60be008696 but later on reverted with https://phabricator.wikimedia.org/rOPUP0fccee1f88fb312069f94fa634cb2d3b8205651c due to CPU frequency problems.
I'd like to re-add intel-microcode, since it fixes both stability/correctness bugs and around 2013 Intel also used microcode updates to address security problems on the CPU level. (These vulnerabilitiesare also addressed by kernel changes, but there might be some in the future which not easily maskable by the kernel, so I'd also be good to be prepared)
One way to add this gradually would be to not add intel-microcode to standard-packages.pp, but rather to the new meta package for the 4.4 kernel, that way all systems would get it step by step as we move to 4.4 (it needs a reboot to become effective anyway).
Comments/objections?
(We have only a single server with AMD CPUs (stat1001), that one can be dealt with manually)