Answer
One big UPDATE holds locks and floods the primary (and its replicas' replication lag) while users are writing. Small, throttled batches leave room for live traffic. Starting dual writes first means every row written during the backfill already has the new shape, so the backfill only has to cover rows written before, and it ends with nothing left behind.