Skip to content

Updawg

Your servers, up to date — by proposal, with signed jobs, and never an arbitrary command.

Updawg watches what is installed on your Linux hosts, works out which updates matter, and proposes them. A person — or a rule you wrote — approves a proposal; the approved change is signed and handed to the hosts it names; each host’s agent checks the signature, does exactly that change, and reports back.

What the agent can do is a short, fixed list: report its packages, run a preflight, install approved package versions, upgrade to an approved release, reboot, take a snapshot, roll back to one, and update itself. It cannot be told to run a command. Every job is signed by your organization’s key and checked by the agent before it does anything, and the agent’s own configuration file on the host always wins: the service can narrow what a host does, never widen it.

  • It only connects out, to agents.updawg.net on port 443. No inbound ports, no SSH.
  • It runs on Debian, Ubuntu, RHEL, Rocky Linux, AlmaLinux, Oracle Linux and Amazon Linux 2023, on x86_64 and arm64.
  • It can only report, if you want that: set mode = "observe" and it never runs a job.