Requirements and network access
Supported systems
| System | Versions | Architectures |
|---|---|---|
| Ubuntu | 18.04, 20.04, 22.04, 24.04 | x86-64, ARM64 |
| Debian | Current releases | x86-64, ARM64 |
| RHEL, Rocky Linux, AlmaLinux, Oracle Linux | 8 and 9 | x86-64, ARM64 |
| CentOS | 7 | x86-64 |
| Windows | Verified on Windows 10 and Windows Server 2022. Other 64-bit Windows versions use the same Windows Update service | x64, ARM64 |
| macOS | In testing | Intel, Apple silicon |
32-bit systems are not supported.
Vulnerability data is available for Ubuntu, Debian and the RHEL family. CentOS 7 still gets patched, but CentOS publishes no security advisories, so PatchPilot cannot tell which CVEs its updates fix. Ubuntu 18.04 and CentOS 7 no longer receive public updates from their vendors.
What the host needs
Linux
- Root access (
sudo) to install. curlorwget.sha256sumis used to verify the download.- systemd, for the agent to run as a service. Without systemd (in a container, for example) the installer starts the agent as a background process instead.
Windows
- An elevated PowerShell (Run as administrator). Windows PowerShell 5.1, included with Windows, is enough.
- The Windows Update service must be allowed to run.
macOS (In testing)
- An administrator account (
sudo).
Network access
The agent only makes outbound HTTPS connections. Nothing connects in to your hosts; no inbound port has to be opened.
| From the host to | Why |
|---|---|
| Your portal address, port 443 | Enrollment, reporting every minute, receiving jobs, downloading the agent |
| The host's own update sources | apt or dnf/yum repositories, Windows Update or your WSUS server, Apple's software update service. PatchPilot uses whatever the host is already configured with |
ipinfo.io, or ifconfig.me if that fails |
Once an hour, to learn the host's public IP address, shown on the device page. Set PATCHPILOT_PUBLIC_IP_LOOKUP=off in the agent's environment to turn this off |
| winget's sources (Windows) | Third-party program updates through winget |
| The vendors' download sites (Windows) | Only when a program is updated from PatchPilot's own app catalogue: dl.google.com (Chrome), download.mozilla.org (Firefox), github.com (7-Zip, Notepad++, Git for Windows, and winget itself if you choose to install it), get.videolan.org (VLC), vscode.download.prss.microsoft.com and update.code.visualstudio.com (Visual Studio Code) |
If the host cannot reach the portal, the installer stops with "download failed: is … reachable from this host?".
What the agent can do on the host
The agent runs with administrator rights, because installing updates needs them. It only acts on jobs from your portal, and every job is recorded in the Audit log with who started it. Installers downloaded for the app catalogue must carry the vendor's valid signature, and package signatures are never bypassed.