It's a hardened and closed, easy to deploy and run instance of OCUM. You don't need to maintain or add any packages to get the service running (in fact you even can't).
The vApp generally falls under 1-year full support, followed by limited support. Hence you would need to plan for yearly updates.
Security updates, also for the underlaying OS are delivered with new OCUM/vApp version only.
As the vApp has limited possibilities due to its hardening, using scripts in combination with alerts is limited to non-existent.
2) Linux & Windows - the flexible way
You install the OCUM package on the server and OS you prefer. You are responsible to maintain software and packages to keep them compatible with OCUM, but you also have the option to apply security patches to those packages as you need or your organisation forces you to do.
The OCUM packages for Lin/Win have the same support model as ONTAP, meaning 3yrs full support for odd releases and 1yr full support for even releases, both followed by limited support. Hence you may only need to plan for updates once every three years or just align with your ONTAP update strategy.
You can use any scripting language as you can install any package you like.
No preference over Linux or Windows other than your preferred scripting language (e.g. PowerShell is limited on Linux).
If this post resolved your issue, please help others by selecting ACCEPT AS SOLUTION or adding a KUDO or both.