User guideAgents

Requirements and network access

Supported systems

System Versions Architectures
Ubuntu 18.04, 20.04, 22.04, 24.04 x86-64, ARM64
Debian Current releases x86-64, ARM64
RHEL, Rocky Linux, AlmaLinux, Oracle Linux 8 and 9 x86-64, ARM64
CentOS 7 x86-64
Windows Verified on Windows 10 and Windows Server 2022. Other 64-bit Windows versions use the same Windows Update service x64, ARM64
macOS In testing Intel, Apple silicon

32-bit systems are not supported.

Vulnerability data is available for Ubuntu, Debian and the RHEL family. CentOS 7 still gets patched, but CentOS publishes no security advisories, so PatchPilot cannot tell which CVEs its updates fix. Ubuntu 18.04 and CentOS 7 no longer receive public updates from their vendors.

What the host needs

Linux

  • Root access (sudo) to install.
  • curl or wget. sha256sum is used to verify the download.
  • systemd, for the agent to run as a service. Without systemd (in a container, for example) the installer starts the agent as a background process instead.

Windows

  • An elevated PowerShell (Run as administrator). Windows PowerShell 5.1, included with Windows, is enough.
  • The Windows Update service must be allowed to run.

macOS (In testing)

  • An administrator account (sudo).

Network access

The agent only makes outbound HTTPS connections. Nothing connects in to your hosts; no inbound port has to be opened.

From the host to Why
Your portal address, port 443 Enrollment, reporting every minute, receiving jobs, downloading the agent
The host's own update sources apt or dnf/yum repositories, Windows Update or your WSUS server, Apple's software update service. PatchPilot uses whatever the host is already configured with
ipinfo.io, or ifconfig.me if that fails Once an hour, to learn the host's public IP address, shown on the device page. Set PATCHPILOT_PUBLIC_IP_LOOKUP=off in the agent's environment to turn this off
winget's sources (Windows) Third-party program updates through winget
The vendors' download sites (Windows) Only when a program is updated from PatchPilot's own app catalogue: dl.google.com (Chrome), download.mozilla.org (Firefox), github.com (7-Zip, Notepad++, Git for Windows, and winget itself if you choose to install it), get.videolan.org (VLC), vscode.download.prss.microsoft.com and update.code.visualstudio.com (Visual Studio Code)

If the host cannot reach the portal, the installer stops with "download failed: is … reachable from this host?".

What the agent can do on the host

The agent runs with administrator rights, because installing updates needs them. It only acts on jobs from your portal, and every job is recorded in the Audit log with who started it. Installers downloaded for the app catalogue must carry the vendor's valid signature, and package signatures are never bypassed.

Next