Everything you need to manage OS patches at scale.
Cron-style patch windows
Define recurring patch schedules using standard cron expressions. Set maintenance windows per server group or environment.
One-time scheduled jobs
Schedule a patch job to run once at a specific date/time. Useful for emergency security patches.
Automatic dispatch
Approved jobs dispatch automatically at the scheduled time. No human action needed once approved.
Reboot control
Configure whether servers reboot after patching. Supports never / if-required / always modes.
Multi-stage approvals
Require sign-off from one or more users before a patch job runs. Approval state tracked per job.
Full audit trail
Every approval, rejection, and comment is logged with timestamp and user. Exportable for auditors.
Role separation
Requesters and approvers can be different roles, enforcing four-eyes control.
Agentless via SSH
No software installed on target servers. Uses your existing SSH keys. Works behind NAT if you have bastion access.
CSV bulk import
Import hundreds of servers from a spreadsheet in one step. Supports hostname, IP, environment, OS columns.
Environment tagging
Tag servers by environment (prod/staging/dev), OS type, or custom labels. Filter and target by tag.
Platform health view
Real-time dashboard showing reachability and last patch status for every managed server.
Pre-patch scripts
Run a shell script on the target server before patching starts. Stop your app, drain the load balancer, snapshot a disk.
Post-patch scripts
Run a script after patching completes. Restart services, warm caches, send a Slack notification.
Per-server configuration
Each server has its own hook scripts. A web server's pre-hook differs from a database server's.
App Owner / DBA self-service
App owners and DBAs can configure their own hook scripts without needing admin access to server settings.
Timeout control
Set a timeout for hook scripts. Jobs fail-fast if a hook hangs instead of blocking indefinitely.
5 built-in roles
Admin, OS Admin, App Owner, DBA, Viewer. Granular permissions per role — no custom RBAC configuration needed.
Multi-tenant
Run multiple isolated tenants on one deployment. Each tenant sees only their own servers and jobs.
Admin-managed credentials
Admins create usernames and passwords directly. Share credentials out-of-band — no magic link email required.
Hard user deletion
Remove users completely, freeing their username and email for reuse. No ghost accounts.
Patch history per server
Full log of every patch job: packages updated, duration, exit status, hook output.
Compliance dashboard
At-a-glance view of patch coverage across your fleet. See which servers are behind.
Export patch logs
Download patch history as CSV for upload into your GRC tool or for inclusion in audit evidence.
AuditLog events
User actions (login, user creation, server changes, approvals) written to AuditLog with tenant isolation.
Single Docker Compose install
One command deploys the full stack: API, scheduler, frontend, PostgreSQL, Redis, monitoring.
In-place upgrades
Run upgrade.sh to pull the new image and migrate the database. No data loss. Rollback via image tag.
Prometheus + Alertmanager
Built-in metrics and alerting. Scrape from your existing Grafana or use the bundled dashboards.
License key activation
Paste your PMGR-... license key in the UI. Takes effect immediately in the running process — no restart.
Community tier is free forever. Deploy in under 10 minutes.