When deploying a new instance template to address a critical vulnerability across hundreds of Compute Engine instances in a multi-zone managed instance group (MIG), which MIG setting should be configured to ensure zero service disruption during the update?