PatchManager

Features

Everything you need to manage OS patches at scale.

Scheduling & Automation

Cron-style patch windows

Define recurring patch schedules using standard cron expressions. Set maintenance windows per server group or environment.

One-time scheduled jobs

Schedule a patch job to run once at a specific date/time. Useful for emergency security patches.

Automatic dispatch

Approved jobs dispatch automatically at the scheduled time. No human action needed once approved.

Reboot control

Configure whether servers reboot after patching. Supports never / if-required / always modes.

Approval Workflows

Multi-stage approvals

Require sign-off from one or more users before a patch job runs. Approval state tracked per job.

Full audit trail

Every approval, rejection, and comment is logged with timestamp and user. Exportable for auditors.

Role separation

Requesters and approvers can be different roles, enforcing four-eyes control.

Server Management

Agentless via SSH

No software installed on target servers. Uses your existing SSH keys. Works behind NAT if you have bastion access.

CSV bulk import

Import hundreds of servers from a spreadsheet in one step. Supports hostname, IP, environment, OS columns.

Environment tagging

Tag servers by environment (prod/staging/dev), OS type, or custom labels. Filter and target by tag.

Platform health view

Real-time dashboard showing reachability and last patch status for every managed server.

Hook Scripts

Pre-patch scripts

Run a shell script on the target server before patching starts. Stop your app, drain the load balancer, snapshot a disk.

Post-patch scripts

Run a script after patching completes. Restart services, warm caches, send a Slack notification.

Per-server configuration

Each server has its own hook scripts. A web server's pre-hook differs from a database server's.

App Owner / DBA self-service

App owners and DBAs can configure their own hook scripts without needing admin access to server settings.

Timeout control

Set a timeout for hook scripts. Jobs fail-fast if a hook hangs instead of blocking indefinitely.

Access Control

5 built-in roles

Admin, OS Admin, App Owner, DBA, Viewer. Granular permissions per role — no custom RBAC configuration needed.

Multi-tenant

Run multiple isolated tenants on one deployment. Each tenant sees only their own servers and jobs.

Admin-managed credentials

Admins create usernames and passwords directly. Share credentials out-of-band — no magic link email required.

Hard user deletion

Remove users completely, freeing their username and email for reuse. No ghost accounts.

Compliance & Reporting

Patch history per server

Full log of every patch job: packages updated, duration, exit status, hook output.

Compliance dashboard

At-a-glance view of patch coverage across your fleet. See which servers are behind.

Export patch logs

Download patch history as CSV for upload into your GRC tool or for inclusion in audit evidence.

AuditLog events

User actions (login, user creation, server changes, approvals) written to AuditLog with tenant isolation.

Operations & Deployment

Single Docker Compose install

One command deploys the full stack: API, scheduler, frontend, PostgreSQL, Redis, monitoring.

In-place upgrades

Run upgrade.sh to pull the new image and migrate the database. No data loss. Rollback via image tag.

Prometheus + Alertmanager

Built-in metrics and alerting. Scrape from your existing Grafana or use the bundled dashboards.

License key activation

Paste your PMGR-... license key in the UI. Takes effect immediately in the running process — no restart.

Ready to try it?

Community tier is free forever. Deploy in under 10 minutes.