Where hosts get their patches
Each device group has a Patch source:
- Straight from the vendors (the default): every host downloads its own updates from its usual sources, such as the Linux repositories and the vendors' download sites for programs.
- Through a patch cache: the group's hosts download through a patch cache you run near them. Each file crosses the internet once for the whole site instead of once per host, and hosts without internet access can still be patched.
Which to choose
| Your site | Choose |
|---|---|
| A few hosts with a good internet connection | Straight from the vendors. Nothing to set up |
| Tens or hundreds of hosts at one site, or a slow or metered link | Through a patch cache at that site |
| Hosts that may not reach the internet | Through a patch cache in a network zone that may |
Use one cache per site, and set it on that site's group: for example a group "Karachi data centre" with the Karachi cache. A host in several groups uses the first of them, by name, that has a cache.
Set a group's patch source
- On Device groups, open the group and edit it.
- Under Patch source, choose Through a patch cache and enter the
cache's address, such as
http://cache.example.internal:3128. - Save. The group's hosts use it from their next check-in, within a minute.
Choose Straight from the vendors again to switch back.
Run a patch cache
The cache is part of PatchPilot. Run it with Docker on any Linux machine at the site that the hosts can reach on port 3128 and that can reach the internet:
docker run -d --name patchpilot-cache --restart unless-stopped \
-p 3128:3128 -v patchpilot-cache:/var/cache/patchpilot \
--entrypoint /app/patchpilot-patchcache <PatchPilot API image>If you use the hosted portal, ask PatchPilot support for the image name. The cache serves only hosts on private networks, and removes files nobody has asked for in 30 days.
To limit which sites the cache may reach, add for example
-e PP_CACHE_DOMAINS=ubuntu.com,debian.org,almalinux.org.
What goes through the cache
| Updates | Through the cache |
|---|---|
| Linux packages (apt, dnf, yum, zypper, apk) and Homebrew | Yes. Files from plain-HTTP repositories, such as Ubuntu's and Debian's, are kept and served to every other host. Files from HTTPS repositories pass through without being kept |
| Programs from PatchPilot's app catalogue (Windows and macOS) | Yes, kept and served to every other host. Each host still checks the checksum and the vendor's signature |
| Windows updates | No. Use your WSUS server or Microsoft Connected Cache |
| macOS updates | No. Use Content Caching on a Mac at the site (System Settings → General → Sharing → Content Caching) |