[Feature]: Non-root agent mode / read-only monitoring mode
What is the installation method of your PatchMon server?
Docker
What is the version of your PatchMon server?
2.0.2
Briefly describe the feature
Ability to run the PatchMon agent as a non-root user in read-only/monitoring-only mode
Detailed description
Hi PatchMon team,
We are using PatchMon in a production environment and love the tool for package monitoring. However, we have a security concern that we'd like to raise.
Currently, the agent requires root privileges to run and explicitly refuses to start under a non-root user. This is a blocker for us from a security perspective, as our security team requires that agents running on production servers do not have root access.
What we'd like:
A "read-only" or "monitoring-only" mode where the agent can run under a dedicated non-privileged user (e.g. patchmon) with no sudo access, no remote execution capabilities, and no patching features. Just package inventory, update visibility, and reporting back to the server.
This would align with the "observability without administration" model that many security teams require.
What we're willing to lose in this mode:
- Automated patching
- Web SSH terminal
- Compliance scans requiring elevated access
- Privileged Docker actions
What we need to keep:
- Package inventory
- Pending updates visibility
- Security updates reporting
- Centralized dashboard
This would make PatchMon much more acceptable in security-conscious environments.
Thanks for the great work!
Why is this useful?
Our security team requires that agents running on production servers do not have root access. A non-root read-only mode would make PatchMon acceptable in security-conscious environments where patch execution must remain under human control.
0 Comments
No comments yet. Be the first to share your thoughts!
