Why not include something like Ksplice so there is no need to reboot after updating?
The Ubuntu Kernel Team does not currently have the resources available to perform the additional work to create (and test!) ksplice modules for all of the supported Ubuntu kernels. Uptrack is getting used on production systems in a lot of big companies. I would not dismiss it out of hand, since staying up to date with kernel vulnerability fixes is very important. If it's a choice between ksplice (and the potential dangers of not setting /proc/sys/kernel/modules_disabled
to 1
immediately after booting), and waiting days or weeks for a good time to reboot, I'd recommend ksplice. And when you do reboot, the fresh "real" kernel will be waiting for you too.