Hello,
I’m wondering what are you using for hardening Operating System?
In my company we’re using:
https://www.open-scap.org/ for Linux with profils from french cybersecurity agency
https://docs.microsoft.com/fr-fr/windows/security/threat-protection/security-compliance-toolkit-10 for Windows
I am convinced that hardening should be mandatory in production, don’t be afraid to deploy it with your images. It works very well for Veeam Servers.
PS: You should never deploy the hardening after deploying the app, you could meet horrible bugs.