> you're worried that the NSA will tap intra-DC traffic but not that it will try to install software or hardware on your hosts to spy traffic at the NIC level

It might not be able to, if you use secure boot and your server is locked in a cage.