User guidePatching

Where hosts get their patches

Each device group has a Patch source:

  • Straight from the vendors (the default): every host downloads its own updates from its usual sources, such as the Linux repositories and the vendors' download sites for programs.
  • Through a patch cache: the group's hosts download through a patch cache you run near them. Each file crosses the internet once for the whole site instead of once per host, and hosts without internet access can still be patched.

Which to choose

Your site Choose
A few hosts with a good internet connection Straight from the vendors. Nothing to set up
Tens or hundreds of hosts at one site, or a slow or metered link Through a patch cache at that site
Hosts that may not reach the internet Through a patch cache in a network zone that may

Use one cache per site, and set it on that site's group: for example a group "Karachi data centre" with the Karachi cache. A host in several groups uses the first of them, by name, that has a cache.

Set a group's patch source

  1. On Device groups, open the group and edit it.
  2. Under Patch source, choose Through a patch cache and enter the cache's address, such as http://cache.example.internal:3128.
  3. Save. The group's hosts use it from their next check-in, within a minute.

Choose Straight from the vendors again to switch back.

Run a patch cache

The cache is part of PatchPilot. Run it with Docker on any Linux machine at the site that the hosts can reach on port 3128 and that can reach the internet:

sh
docker run -d --name patchpilot-cache --restart unless-stopped \
  -p 3128:3128 -v patchpilot-cache:/var/cache/patchpilot \
  --entrypoint /app/patchpilot-patchcache <PatchPilot API image>

If you use the hosted portal, ask PatchPilot support for the image name. The cache serves only hosts on private networks, and removes files nobody has asked for in 30 days.

To limit which sites the cache may reach, add for example -e PP_CACHE_DOMAINS=ubuntu.com,debian.org,almalinux.org.

What goes through the cache

Updates Through the cache
Linux packages (apt, dnf, yum, zypper, apk) and Homebrew Yes. Files from plain-HTTP repositories, such as Ubuntu's and Debian's, are kept and served to every other host. Files from HTTPS repositories pass through without being kept
Programs from PatchPilot's app catalogue (Windows and macOS) Yes, kept and served to every other host. Each host still checks the checksum and the vendor's signature
Windows updates No. Use your WSUS server or Microsoft Connected Cache
macOS updates No. Use Content Caching on a Mac at the site (System Settings → General → Sharing → Content Caching)