PatchManager schedules, approves, and executes OS patches across your entire infrastructure. Agentless. Role-based. Audit-ready. Self-hosted.
No credit card required for Community tier · Self-hosted · Your data stays yours
Servers per deployment
Linux distros supported
Deploy time
SaaS access to your infra
Built for organisations running Linux at scale — from 5 servers to 5,000.
Define patch windows with cron-style expressions. Patches run automatically at the scheduled time across all targeted servers — no human has to remember to kick it off.
Require one or more sign-offs before any patch job runs. Every approval, rejection, and comment is logged with timestamp and user for auditors.
No agent installed on servers. Connects with your existing SSH keys — Ubuntu, RHEL, Debian, SUSE, Amazon Linux.
Run a script before patching starts and another after it completes — drain a load balancer, pause replication, restart services, notify Slack. App owners and DBAs configure their own hooks per server without touching SSH keys.
Admin, OS Admin, App Owner, DBA, and Viewer roles, enforced at the API level.
Instant compliance dashboard and exportable patch history by server, environment, or OS — evidence your auditor will actually accept.
Self-hosted on your own infrastructure. No SaaS vendor access to your servers.
Single Docker Compose command on any Linux server. No Kubernetes, no complex setup.
Upload a CSV or add servers one by one. SSH key auth — your keys stay yours.
Create patch schedules, get approvals, let PatchManager handle the rest automatically.
Supports
Community tier is free forever. No credit card. Deploy today.