PatchManager
On this page

Documentation

Quick Start

Get PatchManager running on a Linux server in under 10 minutes.

Requirements

Install

Download the latest installer and run it as root:

curl -fsSL https://github.com/vnettur/patchmgr-install/releases/latest/download/install.sh \
  | sudo bash

The installer will:

  1. Pull the Docker images
  2. Create /opt/patchmgr/ with all config files
  3. Generate a random SECRET_KEY and database password
  4. Start all services via Docker Compose
  5. Print the URL and default admin credentials

First Login

After install, open http://<your-server-ip> in a browser. Log in with the admin username and the password printed by the installer. Change the admin password immediately under Profile → Change Password.

Add Servers

Navigate to Servers → Add Server. You need:

To import many servers at once, use Servers → Import CSV. Download the template, fill in your servers, upload. All timestamps in the CSV must be UTC (ISO 8601 with Z suffix, e.g. 2026-08-01T02:00:00Z).

Schedule Patches

Go to Schedules → New Schedule:

  1. Select target servers (individual or by environment tag)
  2. Set the scheduled date/time (stored as UTC)
  3. Choose patch type: security only or all updates
  4. Set reboot policy
  5. Submit for approval

An approver (admin or os_admin role) must approve the schedule before it runs. Approved schedules dispatch automatically at the scheduled time.

Hook Scripts

Hook scripts run on the target server via SSH before and after patching:

# Example pre-patch hook (stop your app)
#!/bin/bash
systemctl stop myapp
sleep 5
# Example post-patch hook (restart and verify)
#!/bin/bash
systemctl start myapp
sleep 10
systemctl is-active --quiet myapp || exit 1

Configure hooks per server under Servers → ⋯ → Configure Hooks. App owners and DBAs can configure hooks for their servers without needing admin access.

Upgrade

To upgrade to a new version:

sudo bash /opt/patchmgr/scripts/upgrade.sh --version 1.0.31 --yes

The script pulls the new image, runs database migrations, and restarts services. Existing data is preserved.

To upgrade from a local bundle (useful when the installed upgrade script is old):

VER=1.0.31
curl -fsSL https://github.com/vnettur/patchmgr-install/releases/download/v${VER}/patchmgr-${VER}.tar.gz \
  | tar -xz -C /tmp && sudo bash /tmp/patchmgr-${VER}/scripts/upgrade.sh --version ${VER} --yes

License Key

Community tier requires no license. To activate Professional or Enterprise:

  1. Purchase a license at patchmanager.co.in/pricing
  2. You will receive a PMGR-... key by email
  3. In PatchManager, go to Administration → License
  4. Paste the key and click Activate License
  5. Takes effect immediately — no restart needed

Backup

The installer sets up a daily cron backup to /opt/patchmgr/backups/. To trigger manually:

sudo bash /opt/patchmgr/scripts/backup.sh

Backups are gzipped PostgreSQL dumps. Copy them off-host (S3, NFS, rsync) for disaster recovery.

Roles Reference

Role Can do
Admin Everything — manage users, servers, schedules, approve jobs, activate license
OS Admin Full server management + approvals, cannot manage users or license
App Owner View servers, configure hook scripts on assigned servers, view jobs
DBA Same as App Owner — configure hook scripts on DB servers
Viewer Read-only — view servers, jobs, and compliance reports

Need help? Email support@patchmanager.co.in or open an issue on GitHub.