Thanks, Rudy. FWIW, we did a policy fix: in more sensitive environments, we will wipe, per policy. In less sensitive environments, which tend to have slower hardware, we won't wipe.
I think one could substantially fulfill the objective of a wiped disk by kicking off something like dd if=/dev/zero of=/tmp/full ; rm /tmp/full as a part of the VM host bootstrap process. Since we don't commission VMs often, there's little expectation of rapid availability, so the more robust "wait for ganeti to wipe a VM during creation" is fine for us.
Cheers,
-danny