PatchManager
Now with per-server hook scripts for app teams

Stop patching Linux servers manually

PatchManager schedules, approves, and executes OS patches across your entire infrastructure. Agentless. Role-based. Audit-ready. Self-hosted.

No credit card required for Community tier · Self-hosted · Your data stays yours

patchmanager — upgrade log
# 3 servers · security patches · approved by ops-lead
✓ web-prod-01 pre-hook: nginx drain OK
✓ web-prod-01 42 packages updated OK · 4m 12s
✓ web-prod-01 post-hook: nginx start OK
✓ db-prod-01 pre-hook: pg_pause OK
✓ db-prod-01 18 packages updated OK · 2m 38s
✓ db-prod-01 post-hook: pg_resume OK
✓ app-prod-01 31 packages updated OK · 3m 05s
─────────────────────────────────────────────────────
✓ 3/3 servers patched · 91 packages · 0 failures · reboot: not required
5000+

Servers per deployment

5

Linux distros supported

10m

Deploy time

0

SaaS access to your infra

Everything your team needs

Built for organisations running Linux at scale — from 5 servers to 5,000.

SCHEDULE

Scheduled Patching

Define patch windows with cron-style expressions. Patches run automatically at the scheduled time across all targeted servers — no human has to remember to kick it off.

APPROVE

Approval Workflows

Require one or more sign-offs before any patch job runs. Every approval, rejection, and comment is logged with timestamp and user for auditors.

SSH

Agentless via SSH

No agent installed on servers. Connects with your existing SSH keys — Ubuntu, RHEL, Debian, SUSE, Amazon Linux.

HOOKS

Pre/Post Hook Scripts

Run a script before patching starts and another after it completes — drain a load balancer, pause replication, restart services, notify Slack. App owners and DBAs configure their own hooks per server without touching SSH keys.

RBAC

Role-Based Access

Admin, OS Admin, App Owner, DBA, and Viewer roles, enforced at the API level.

AUDIT

Compliance Reports

Instant compliance dashboard and exportable patch history by server, environment, or OS — evidence your auditor will actually accept.

Up and running in under 10 minutes

Self-hosted on your own infrastructure. No SaaS vendor access to your servers.

1

Deploy in minutes

Single Docker Compose command on any Linux server. No Kubernetes, no complex setup.

2

Import your servers

Upload a CSV or add servers one by one. SSH key auth — your keys stay yours.

3

Schedule and approve

Create patch schedules, get approvals, let PatchManager handle the rest automatically.

Supports

Ubuntu 20/22/24RHEL / CentOSDebian 11/12Amazon Linux 2/2023SUSE / openSUSE

Ready to automate your patches?

Community tier is free forever. No credit card. Deploy today.