Early load of microcode with only one copy in /boot

I have enabled hardware.cpu.intel.updateMicrocode.

This prepends the microcode image to the initrdfile, which enabled the kernel microcode loader as described in 23. The Linux Microcode Loader — The Linux Kernel documentation

For most bootloaders it is possible to add multiple initrd files but the microcode image have to be the first. Using system.boot.extraInitrdit should be possible to add extra initrd files to the boot command but this seems to be appended and thus not useful for the microcode update.

Is there a way to get boot loaders configured to update microcode without having to add the same 15 MB of Intel microcode to each and every initrd image?

(Yeah, I made my /boot too small)

I just notice that system.boot.extraInitrdis a recent innovation.

On a related note, if you’re using a monolithic kernel or a kernel that embeds all the modules needed to mount the real root filesystem, it should be possible to reuse a single initrd for all the kernels (as long as nothing else that needs to be copied into the initrd changes between generations), saving substantial space in /boot.

I have looked into it and it does not seem to be possible.

I can kind of see a way through adding an entry to bootspec and patching systemd-boot-installer.py and limine-installer.py just as the above patch to add extraInitrd. A minimal solution would just be adding a microcode attribute.

Not being able to add multiple initrd files is already mentioned in RFC-0125 as a weakness of the currect bootspec version. A better, but more involved, solution would be to fix this weakness.

But this seems to be a bit above a candidate for my first contribution to nixpkgs.