I'm looking to improve the security posture by stripping the kernel off unwanted stuff (ebpf, zillion different file systems, drivers) that introduce CVEs into the kernel.
There are probably better approaches; for example you could disable loading modules for code you don't use - without the need to rebuild the whole thing.
I guess it comes down to understanding your threat model.