Find your favorite reference (e.g. CIS Benchmark Level 1/2, etc) and look for an open source implementation in configuration management code from a credible source. You can pear back from there. You’ll likely find they’ve implemented the configuration as well as the auditing.
I use to download the Cookbooks for CIS benchmark from Chef’s repos.
An important detail is that these frameworks will typically word a control as "Disable X, unless it is required by the application or not used”. Don’t beat yourself up for removing controls that are not applicable to your situation.
Once your application is installed and configured, with configuration management of course, set AppArmor or SELinux into permissive but logging mode. After profiling the application in use for a period, write a policy to allow those events for your application and enable enforcing mode.
Systemd offers some very simple to use controls as well. You can update your application unit to do sandboxing things like block access to system directories, block system capabilities, and even limit network access. These additions are very easy with significant rewards.
If you can bake it all into a machine image, glorious. If you need last mile configuration or personalization, use cloud-init to make those changes on first boot. If you need to save state, externalize it with an additional volume or network storage. Log to an external system, and disable remote access. Enforce a maximum life for a server to a couple of days and replace. Of course, many applications can’t survive as cattle and need to live longer or have difficult replacement procedures.