On this page
Documentation
Quick Start
Get PatchManager running on a Linux server in under 10 minutes.
Requirements
- Linux host (Ubuntu 22+, Debian 12, RHEL 9, Amazon Linux 2023)
- Docker 24+ and Docker Compose v2
- 2 CPU / 4 GB RAM minimum (t3.medium or equivalent)
- Ports 80 and 443 open (or just 80 if no TLS yet)
- SSH access from the host to your managed servers
Install
Download the latest installer and run it as root:
curl -fsSL https://github.com/vnettur/patchmgr-install/releases/latest/download/install.sh \
| sudo bash The installer will:
- Pull the Docker images
- Create
/opt/patchmgr/with all config files - Generate a random
SECRET_KEYand database password - Start all services via Docker Compose
- Print the URL and default admin credentials
First Login
After install, open http://<your-server-ip> in a browser.
Log in with the admin username and the password printed by the installer.
Change the admin password immediately under Profile → Change Password.
Add Servers
Navigate to Servers → Add Server. You need:
- Hostname / IP — reachable from the PatchManager host
- SSH port — default 22
- SSH username — a user with
sudoor root access - SSH private key — paste the key directly in the UI
To import many servers at once, use Servers → Import CSV.
Download the template, fill in your servers, upload. All timestamps in the CSV must be UTC (ISO 8601 with Z suffix, e.g. 2026-08-01T02:00:00Z).
Schedule Patches
Go to Schedules → New Schedule:
- Select target servers (individual or by environment tag)
- Set the scheduled date/time (stored as UTC)
- Choose patch type: security only or all updates
- Set reboot policy
- Submit for approval
An approver (admin or os_admin role) must approve the schedule before it runs. Approved schedules dispatch automatically at the scheduled time.
Hook Scripts
Hook scripts run on the target server via SSH before and after patching:
# Example pre-patch hook (stop your app)
#!/bin/bash
systemctl stop myapp
sleep 5 # Example post-patch hook (restart and verify)
#!/bin/bash
systemctl start myapp
sleep 10
systemctl is-active --quiet myapp || exit 1 Configure hooks per server under Servers → ⋯ → Configure Hooks. App owners and DBAs can configure hooks for their servers without needing admin access.
Upgrade
To upgrade to a new version:
sudo bash /opt/patchmgr/scripts/upgrade.sh --version 1.0.31 --yes The script pulls the new image, runs database migrations, and restarts services. Existing data is preserved.
To upgrade from a local bundle (useful when the installed upgrade script is old):
VER=1.0.31
curl -fsSL https://github.com/vnettur/patchmgr-install/releases/download/v${VER}/patchmgr-${VER}.tar.gz \
| tar -xz -C /tmp && sudo bash /tmp/patchmgr-${VER}/scripts/upgrade.sh --version ${VER} --yes License Key
Community tier requires no license. To activate Professional or Enterprise:
- Purchase a license at patchmanager.co.in/pricing
- You will receive a
PMGR-...key by email - In PatchManager, go to Administration → License
- Paste the key and click Activate License
- Takes effect immediately — no restart needed
Backup
The installer sets up a daily cron backup to /opt/patchmgr/backups/. To trigger manually:
sudo bash /opt/patchmgr/scripts/backup.sh Backups are gzipped PostgreSQL dumps. Copy them off-host (S3, NFS, rsync) for disaster recovery.
Roles Reference
| Role | Can do |
|---|---|
| Admin | Everything — manage users, servers, schedules, approve jobs, activate license |
| OS Admin | Full server management + approvals, cannot manage users or license |
| App Owner | View servers, configure hook scripts on assigned servers, view jobs |
| DBA | Same as App Owner — configure hook scripts on DB servers |
| Viewer | Read-only — view servers, jobs, and compliance reports |
Need help? Email support@patchmanager.co.in or open an issue on GitHub.