Self-hosted Linux fleet operations
Patch your whole Linux fleet from one place.
See what's installed, what's out of date, and what's drifted from your baseline, then fix it in staged rollouts and keep the record. Praxis puts inventory, patching, repository control, drift detection, and audit evidence on one self-hosted plane, with no call-home. It governs administrative access to those same hosts, so what the system changed and who logged in by hand land in the same store, on the same clock.
Praxis 1.0 is available now. Run it on your own infrastructure, with no call-home.
Know what drifted before someone asks.
Praxis inventories every package across mixed Debian and Enterprise Linux hosts, tells you what's out of date, and compares each box against a baseline you define. When something has stopped matching, you see which host and what changed.
Fixing it runs in staged rollout rings: push to the innermost ring, watch how it behaves, then roll outward. Managed apt and dnf repositories, with rollback.

From package inventory to exported evidence
Inventory hosts
Enroll Linux servers over SSH or the optional agent, track OS versions, end-of-life status, baselines, and drift, and see package inventory across the fleet.
Manage repositories and plan updates
Control the repository content your hosts can see, review available OS package updates, and stage patch plans against the hosts that need them.
Approve and stage execution
Patch runs go through explicit approval, roll out through staged rings, and respect maintenance windows. No unreviewed changes reach production hosts.
Reboot and roll back safely
Coordinate reboots, roll back failed updates, and keep a complete record of what ran, where, and when.
Export evidence
Retain audit trails and session recordings, export compliance evidence in bulk, and schedule recurring reports for auditors and leadership.
Platform support
Server access, without the side channels
A terminal where the audit trail is
Praxis includes a full terminal in the app, so operators reach servers through the same platform that governs them: no scattered SSH keys and no separate bastion to run alongside it. One-off commands run on demand, with command policy and whitelists deciding what may run. File transfers go through governed upload and download operations.
Short-lived identity, not shared keys
Session identity comes from short-lived SSH certificates signed through OpenBao, a Vault-compatible secrets service, so access expires on its own instead of living in a forgotten authorized_keys file. OpenBao holds the secrets; the Praxis database stores metadata, not key material. Every certificate carries the operator's identity into the audit record.
Sessions recorded, stored locally
SSH sessions are captured as asciicast recordings and stored in your deployment; nothing leaves your network. Play a session back inside the app to review what an operator saw and typed, for incident review and operational history.
Time-bound access, approval gates
Access is requested, approved, and expires: just-in-time instead of standing. Paid editions add session locks, session approvals, command approvals, and formal access reviews, so sensitive hosts require a second set of eyes and access rights get re-certified instead of accumulating forever.
Praxis brokers administrative SSH access to the same hosts it patches, issuing short-lived certificates from OpenBao instead of distributing persistent keys. The certificate principal is an immutable identifier, so the trail survives a username change. Patching and human access write to the same store, on the same clock, keyed to the same host and the same user.

Why Praxis
One plane, less overhead
Stop juggling an inventory tool, an SSH bastion, a credential store, patch scripts, a repo mirror, and hand-built reporting. Praxis is all of it in one app: less to run, less to maintain, less to babysit.
Self-hosted
Your deployment, your data, your network. Praxis runs where your servers run.
Linux-focused
Built for apt and dnf fleets: the package managers, repositories, advisories, and reboot semantics that come with them.
Built for audit trails
Approvals, session recordings, and operational history are core workflows, not add-ons.
Offline and airgapped
Designed for environments where hosts cannot reach the public internet.
Four capabilities, one self-hosted deployment
Patch operations
Controlled change for OS packages, from inventory to rollback.
- Fleet inventory, baselines, and drift detection
- Distribution lifecycle and end-of-life tracking
- Patch policies with staged rollout rings
- Maintenance windows and scheduled execution
- Approval-gated update plans with preflight checks
- Reboot control and rollback evaluation
Access governance
Operator access to your servers runs through Praxis: identified, controlled, and recorded.
- Full terminal built into the app
- Short-lived SSH certificates via OpenBao
- Just-in-time access requests with expiry
- Command execution with policy and whitelists
- Session recordings, stored locally
- OIDC / SSO, unlimited users, TOTP step-up
- No standing root or break-glass; managed accounts are no-sudo by default
- Grants recompute and revoke deterministically on role, user, or OIDC change
- Session locks and session approvals
- Command approvals and command metrics
- Formal access reviews
Repository content & air-gap
Curate what your hosts install instead of trusting upstream directly.
- Debian and RPM repository mirrors
- Signed content with staged key rotation
- Content channels and profiles per host
- Signed air-gap bundles for disconnected fleets
- Fully offline deployments, no call-home
Compliance & remediation
Evidence accumulates as you operate, and failed findings feed a governed fix loop.
- Versioned compliance policies and checks
- Evidence, verdicts, and severity per host
- Governed remediation with separation of duties
- Audit events delivered to syslog or HTTP sinks
- Bulk compliance exports
- Scheduled reports
Available in paid editions. Everything else is included free up to 15 hosts.
One deployment, free to start
Praxis runs free on up to 15 managed hosts with unlimited users, OIDC/SSO, session recordings, and core patching and compliance workflows, with a license key unlocking paid mode on the same install. Leave your email to hear about new releases.