Skip to main content

Patch Management

PatchCTL provides comprehensive patch management for your Linux fleet.

How Patching Works

  1. Detection - Agents scan for available updates every 6 hours
  2. Visibility - Updates appear in the dashboard
  3. Planning - Review and prioritize updates
  4. Execution - Install via manual action or schedule
  5. Verification - Confirm successful installation

Update Types

Security Updates

  • Patches for known vulnerabilities
  • Marked with security advisories
  • Should be prioritized

Regular Updates

  • Bug fixes and improvements
  • Feature updates
  • Can be deferred if needed

Kernel Updates

  • Linux kernel patches
  • Usually require reboot
  • Marked with reboot required flag

Patching Methods

Manual Patching

Execute patches immediately:

  1. Select server(s)
  2. Choose updates to install
  3. Configure reboot policy
  4. Execute and monitor

Scheduled Patching

Automate with schedules:

  1. Define target servers
  2. Set maintenance window
  3. Configure options
  4. Let it run automatically

Batch Operations

Patch multiple servers at once:

  1. Select servers
  2. Choose updates
  3. Execute simultaneously
  4. Monitor progress

Package Manager Support

PatchCTL works with native package managers:

DistroPackage ManagerCommands Used
Ubuntu/Debianaptapt update, apt upgrade
RHEL/Rockydnfdnf check-update, dnf upgrade
SUSEzypperzypper refresh, zypper update

Reboot Handling

Some updates require a reboot (kernel, glibc, systemd):

Reboot Policies:

  • Never - Don't reboot, flag for manual action
  • If Required - Reboot only when necessary
  • Always - Reboot after every patch operation

The dashboard shows which servers need reboot.