OK, fair enough. I guess you can minimally complicate this by updating an exactly identical machine/boot drive first, and then immediately alerting if health checks fail on that. But it really doesn't seem that bad to me. I've run a VPS that's been self-updating continuously since Feb 2019, and I've not had many breaking issues with the OS.