The management tools are fairly decent, and the question "which CVEs are we vulnerable to our production environment" or "were are we still using Java 6" shouldn't be more than a keypress away.
Neither deb/rpm nor containers are an excuse for not using configuration management tools however. Don't believe anyone who says so.