Fleet & patch
Self-hosted Linux fleet and patch management, inventory to rollback
Enroll your Linux hosts, see their real state, and move patches through staged rings with rollback, all in one plane that runs in your own infrastructure.
Last verified: July 28, 2026
Linux patching is usually split across an inventory tool, repository mirrors, patch scripts, and a scheduler, with the reboot and rollback story left to chance. Praxis puts the whole lifecycle in one self-hosted plane: the host you discover in inventory is the same host you place in a patch ring, reboot, and can roll back. No thread lost between tools, and no data leaving your network.
What Praxis does here
- Enroll hosts over SSH or an optional outbound-only agent; collect distribution, kernel, package, uptime, and reboot-required facts.
- Inventory installed packages and available updates across the fleet; track distribution end-of-life from shipped reference data.
- Organize with static groups, tags, and fact-driven smart groups; capture baselines and detect drift.
- Mirror Debian and RPM repositories, sign content, and pin what each host is allowed to install.
- Define patch policies independent of hosts; roll out through staged rings (canary → early adopter → broad production).
- Preflight evaluation, maintenance windows, approval-gated update plans, reboot control, and rollback evaluation.
- A full record of what ran, where, and when.
Why it's different
- Self-hosted with no call-home.
- One plane instead of a stack of point tools.
- Multi-distro (Debian + Enterprise Linux), not locked to one distribution.
Honest boundary: Full patch servicing covers APT and DNF families; interactive sessions run on a single backend worker in 1.0.
