Bugs go to GitHub Issues. Questions go to GitHub Discussions. Feature ideas belong here. Read the full guide
In our case, PatchMon communicates with Nginx Proxy Manager over an unencrypted HTTP connection (default port 3000). While HTTPS is available for external client access via Nginx Proxy Manager, the backend connection between Nginx Proxy Manager and PatchMon remains unencrypted. For corporate environments with strict security or compliance requirements, all internal traffic must also be encrypted. This currently prevents us from deploying PatchMon. It would be very helpful if PatchMon suppor...
What is the installation method of your PatchMon server? Docker ### What is the version of your PatchMon server? 2.0.2 ### Briefly describe the feature Add a PatchMon CLI to quickly interact with a PatchMon server from the terminal. ### Detailed description The goal is to provide a command-line utility for common PatchMon server actions without requiring users to go through the web interface. Initially, this CLI is not intended to cover every PatchMon server feature. Instead, it s...
Currently it's only possible to directly link to a host if it's UUID is known. Checkmk has a feature called "Custom host icons" that for example can be used to create rdp:// links to each Windows server. Using this feature for Patchmon currently requires workarounds like generating a forwarder list (for the reverse proxying Nginx) from a Patchmon host list or adding the Patchmon host UUID as host alias to Checkmk. I am sure other integrations would also benefit from such a feature because in...
What is the installation method of your PatchMon server? _No response_ ### What is the version of your PatchMon server? v2.0.2 ### Briefly describe the feature Add support for Update all and reboot manually and automatically ### Detailed description This is a cool project, but I am missing important features to update all devices and then reboot. ### Why is this useful? Right now I only use Patchmon to see pending updates. Then I use ansible to carry out these updates and reboot...
Summary: Add a generic TCP forwarding capability to PatchMon that allows local TCP services running on an agent to securely reach predefined server-side services through the existing PatchMon WebSocket connection. The feature should act as a transparent TCP transport layer, without understanding or inspecting the application protocol. A first implementation (V1) should intentionally remain simple: - no UI - file-based configuration on the agent - environment-based configuration on the ser...
There is a tool called topgrade that updates pacman/apt/nala/dnf/rpm-ostree, flatpak, snap, cargo, npm, containers, repos and more. It would be nice to have the ability to see and update those repositories from patchmon. This would allow us to patch applications and containers that are not in the standard distro repository, furthering the security on our systems
What is the installation method of your PatchMon server? Proxmox-community script ### What is the version of your PatchMon server? 2.0.0 ### Briefly describe the feature Patch multiple hosts at once ### Detailed description Love the new patching feature in 2.0.0, it's been working great so far! Unfortunately, unless I'm missing something, it seems like you need to manually patch individual hosts. It would be great to be able to select a group, or even use the checkboxes to select...
What is the installation method of your PatchMon server? Proxmox-community script ### What is the version of your PatchMon server? 2.0.2 ### Briefly describe the feature Add support to run patching on apk ### Detailed description Currently its not possible to run patches from PatchMon on Alpine. If you try to run a patch it will abort with an error: package manager "apk" not supported for patching Please enable the new patching feature from PatchMon also for apk, as this feature...
What is the installation method of your PatchMon server? Docker ### What is the version of your PatchMon server? 2.0.2 ### Briefly describe the feature Allow users to open a raw SSH tunnel to a managed host through its existing outbound PatchMon agent connection. ### Detailed description PatchMon already provides an SSH proxy for its web terminal, but this proxy acts as an SSH client inside the agent and does not expose a standard SSH transport to external tools. This feature prop...
What is the installation method of your PatchMon server? Docker ### What is the version of your PatchMon server? 2.0.2 ### Briefly describe the feature Filter the Hosts list by kernel version (exact match, "less than", or a version range), so we can quickly find hosts within an affected version range when a new kernel CVE drops, across multiple distros. ### Detailed description Is your feature request related to a problem? Please describe. When a new Linux kernel CVE drops (e.g...
What is the installation method of your PatchMon server? Proxmox-community script ### What is the version of your PatchMon server? 2.0.2 ### Briefly describe the feature Support updating containers via Proxmox Community Scripts ### Detailed description This would save a lot of time so we wouldn't need to run update on containers to upgrade the application. As it stands, it seems like only apt-based updates are performed via PatchMon, and updates that run via Community Scripts f...
What is the installation method of your PatchMon server? Docker ### What is the version of your PatchMon server? 2.0.2 ### Briefly describe the feature Improve how users access managed Linux hosts through the existing outbound PatchMon agent connection, with session recording and replay. ### Detailed description PatchMon already provides remote SSH access, but the current SSH proxy implementation is not fully transparent. Depending on the environment, users may need to manually con...
What is the installation method of your PatchMon server? Docker ### What is the version of your PatchMon server? 2.0.0 ### Briefly describe the feature Policy schedule ### Detailed description Allow to plan host patching by schedule like daily, weekly, monthly or crontab values. Not all hosts must be patched daily in production. ### Why is this useful? This will reduce the change management and risk of hosts running in production.
What is the installation method of your PatchMon server? Docker ### What is the version of your PatchMon server? 2.0.2 ### Briefly describe the feature To allow for a more granular selection of what is reported by the agent ### Detailed description Add a way to configure, per agent/host, which categories of data are reported to the server. This should be configurable: - during agent installation; - after installation in the agent config.yml; - from the server UI/API, with the c...
This likely should be lower in the list as Atomic systems are still gaining ground, but it would be nice to see support for this in the future. Currently Atomic systems show completely out of date, but they are using the latest stable version available to them.
What is the installation method of your PatchMon server? Proxmox-community script ### What is the version of your PatchMon server? 2.0.2 ### Briefly describe the feature Add Provider for self hostet AI ### Detailed description Would it be possible to provide an option for a self-hosted AI under "Provider"? ### Why is this useful? So that I can integrate our own AI
What is the installation method of your PatchMon server? Docker ### What is the version of your PatchMon server? 2.0.2 ### Briefly describe the feature Execute script or command before or after patching host ### Detailed description Extend patching policies with actions feature and fields for "script to run before/after patching" with optional and or default settings for "timeout in seconds", "command modes" like must succeed, ignore failures, run asynchronously - ignore failures....
What is the installation method of your PatchMon server? Proxmox-community script ### What is the version of your PatchMon server? 2.0.2 ### Briefly describe the feature Add "Reboot required" field in Homepage integration ### Detailed description The current Homepage integration includes a number of useful fields, but I think one that is missing is the "Reboot required" field. ### Why is this useful? It would be nice to know via widget that one or more hosts need a reboot after p...
What is the installation method of your PatchMon server? Other ### What is the version of your PatchMon server? * ### Description In accordance with the European legal requirement under the Cyber Resilience Act (CRA), the build origin attestation and the SBOM must be provided for each build.
What is the installation method of your PatchMon server? Docker ### What is the version of your PatchMon server? 2.0.2 ### Briefly describe the feature Add possibility to get notifications (emails, telegram, etc) whenever new security updates are available ### Detailed description Patchmon is great. The reason why I installed it is to improve my security posture by knowing when new security updates are available. I'd love to have PatchMon connected to e.g. https://github.com/caron...