Orbit Enterprise
Built for production and mission-critical workloads

Linux Fleet Patch Management & Orchestration

Track inventory, audit security vulnerabilities in real time, schedule updates, and coordinate reboots with a decoupled architecture and zero heavy dependencies.

bash β€” one-command deployment
#curl -sSL https://raw.githubusercontent.com/ramonromancastro/orbit-server/main/get-orbit.sh | sudo bash
< 60 MB
Agent RAM Footprint
0 Ports
Inbound Ingress on Nodes
RPM & DEB
Multi-Distribution Support
100% FHS
Native Linux Standard

Core Operational Capabilities

Engineered by and for Linux system administrators who demand complete control, stability, and observability.

Vulnerability Auditing

Automatic classification of security patches and errata by severity level (CRITICAL, IMPORTANT, MODERATE, LOW) without modifying system packages during audit.

Outbound-Only Communication

Polling-based security architecture over HTTPS/REST. Managed nodes require zero open firewall ingress ports and no shared persistent SSH keys.

Pending Reboot Tracking

Active detection of running processes and resident libraries requiring system or service restarts (native support for needs-restarting and reboot-required).

Systemd Sandboxing & FIPS

Hardened systemd units enforcing ProtectSystem=strict, least-privilege permissions, and entropy generation compatible with FIPS requirements.

Batch Operations

Execute concurrent scheduled updates across tags, handle automated execution queues, or perform clean node decommissions with a single action.

Reverse Proxy & Context Ready

Built-in support for TLS termination with Apache or Nginx, serving seamlessly either at root domain level or under custom subpath prefixes (e.g., /orbit-server).

Two-Tier Architecture

Orbit enforces strict separation of concerns to keep production nodes lightweight and protected:

  • Orbit Enterprise Server (AGPLv3): FastAPI REST API with administrative UI, PBKDF2-HMAC-SHA256 session authentication, and FHS storage in /var/lib.
  • Orbit Agent (Apache 2.0): Non-intrusive local daemon with isolated execution boundaries via sudoers drop-ins for DNF, YUM, and APT wrappers.
# Server Filesystem Structure (FHS Compliant)
/opt/orbit-server/ # Binaries & virtualenv
/etc/orbit-server/ # config.json (policies)
/etc/sysconfig/orbit-server # Environment & secrets (0600)
/var/lib/orbit-server/ # Persistent node telemetry
/var/log/orbit/ # Service logs & rotation

# Fleet Communication Flow
Agent ──[ HTTPS POST Telemetry / Tasks ]──▢ Server (8000)
Admin ──[ HTTPS / Web UI + REST API ]───▢ Reverse Proxy

Start orchestrating your fleet today

Open source, modular, and ready for deployment on Debian, Ubuntu, RHEL, or Rocky Linux instances.

Explore Orbit Server on GitHub Explore Orbit Agent