1.0Praxis 1.0 is live. Self-hosted Linux fleet operations, generally available.

Download

Self-hosted Linux fleet operations

Patch your whole Linux fleet from one place.

See what's installed, what's out of date, and what's drifted from your baseline, then fix it in staged rollouts and keep the record. Praxis puts inventory, patching, repository control, drift detection, and audit evidence on one self-hosted plane, with no call-home. It governs administrative access to those same hosts, so what the system changed and who logged in by hand land in the same store, on the same clock.

Praxis 1.0 is available now. Run it on your own infrastructure, with no call-home.

v1.0 available·self-hosted·no call-home·drift detection·apt / dnf·x86_64 / arm64

Know what drifted before someone asks.

Praxis inventories every package across mixed Debian and Enterprise Linux hosts, tells you what's out of date, and compares each box against a baseline you define. When something has stopped matching, you see which host and what changed.

Fixing it runs in staged rollout rings: push to the innermost ring, watch how it behaves, then roll outward. Managed apt and dnf repositories, with rollback.

Praxis patch update plan: an approved scheduled round across the web tier, showing wave staging, 124 selected packages, per-host success and failure with the failure reason, and a rollback panel.
Screenshot from a seeded demo lab.

From package inventory to exported evidence

01

Inventory hosts

Enroll Linux servers over SSH or the optional agent, track OS versions, end-of-life status, baselines, and drift, and see package inventory across the fleet.

02

Manage repositories and plan updates

Control the repository content your hosts can see, review available OS package updates, and stage patch plans against the hosts that need them.

03

Approve and stage execution

Patch runs go through explicit approval, roll out through staged rings, and respect maintenance windows. No unreviewed changes reach production hosts.

04

Reboot and roll back safely

Coordinate reboots, roll back failed updates, and keep a complete record of what ran, where, and when.

05

Export evidence

Retain audit trails and session recordings, export compliance evidence in bulk, and schedule recurring reports for auditors and leadership.

Platform support

Debian familyUbuntu LTS 22.04 / 24.04 / 26.04 · Debian 13
Enterprise LinuxRHEL 8–10 · Rocky Linux 8–10 · AlmaLinux 8–10
Architecturesx86_64 / amd64 · aarch64 / arm64
Package servicingapt / deb · dnf / rpm
Host transportSSH (default) · outbound-only mTLS agent (optional)

Server access, without the side channels

A terminal where the audit trail is

Praxis includes a full terminal in the app, so operators reach servers through the same platform that governs them: no scattered SSH keys and no separate bastion to run alongside it. One-off commands run on demand, with command policy and whitelists deciding what may run. File transfers go through governed upload and download operations.

Short-lived identity, not shared keys

Session identity comes from short-lived SSH certificates signed through OpenBao, a Vault-compatible secrets service, so access expires on its own instead of living in a forgotten authorized_keys file. OpenBao holds the secrets; the Praxis database stores metadata, not key material. Every certificate carries the operator's identity into the audit record.

Sessions recorded, stored locally

SSH sessions are captured as asciicast recordings and stored in your deployment; nothing leaves your network. Play a session back inside the app to review what an operator saw and typed, for incident review and operational history.

Time-bound access, approval gates

Access is requested, approved, and expires: just-in-time instead of standing. Paid editions add session locks, session approvals, command approvals, and formal access reviews, so sensitive hosts require a second set of eyes and access rights get re-certified instead of accumulating forever.

Praxis brokers administrative SSH access to the same hosts it patches, issuing short-lived certificates from OpenBao instead of distributing persistent keys. The certificate principal is an immutable identifier, so the trail survives a username change. Patching and human access write to the same store, on the same clock, keyed to the same host and the same user.

Praxis session recordings: five finalized interactive session captures, each with a start time, frame count, size, and retention date.
Screenshot from a seeded demo lab.

Why Praxis

One plane, less overhead

Stop juggling an inventory tool, an SSH bastion, a credential store, patch scripts, a repo mirror, and hand-built reporting. Praxis is all of it in one app: less to run, less to maintain, less to babysit.

Self-hosted

Your deployment, your data, your network. Praxis runs where your servers run.

Linux-focused

Built for apt and dnf fleets: the package managers, repositories, advisories, and reboot semantics that come with them.

Built for audit trails

Approvals, session recordings, and operational history are core workflows, not add-ons.

Offline and airgapped

Designed for environments where hosts cannot reach the public internet.

Four capabilities, one self-hosted deployment

Patch operations

Controlled change for OS packages, from inventory to rollback.

  • Fleet inventory, baselines, and drift detection
  • Distribution lifecycle and end-of-life tracking
  • Patch policies with staged rollout rings
  • Maintenance windows and scheduled execution
  • Approval-gated update plans with preflight checks
  • Reboot control and rollback evaluation

Learn more →

Access governance

Operator access to your servers runs through Praxis: identified, controlled, and recorded.

  • Full terminal built into the app
  • Short-lived SSH certificates via OpenBao
  • Just-in-time access requests with expiry
  • Command execution with policy and whitelists
  • Session recordings, stored locally
  • OIDC / SSO, unlimited users, TOTP step-up
  • No standing root or break-glass; managed accounts are no-sudo by default
  • Grants recompute and revoke deterministically on role, user, or OIDC change

Learn more →

Repository content & air-gap

Curate what your hosts install instead of trusting upstream directly.

  • Debian and RPM repository mirrors
  • Signed content with staged key rotation
  • Content channels and profiles per host
  • Signed air-gap bundles for disconnected fleets
  • Fully offline deployments, no call-home

Learn more →

Compliance & remediation

Evidence accumulates as you operate, and failed findings feed a governed fix loop.

  • Versioned compliance policies and checks
  • Evidence, verdicts, and severity per host
  • Governed remediation with separation of duties
  • Audit events delivered to syslog or HTTP sinks

Learn more →

Available in paid editions. Everything else is included free up to 15 hosts.

One deployment, free to start

Praxis runs free on up to 15 managed hosts with unlimited users, OIDC/SSO, session recordings, and core patching and compliance workflows, with a license key unlocking paid mode on the same install. Leave your email to hear about new releases.