Vulnerability Auditing
Automatic classification of security patches and errata by severity level (CRITICAL, IMPORTANT, MODERATE, LOW) without modifying system packages during audit.
Track inventory, audit security vulnerabilities in real time, schedule updates, and coordinate reboots with a decoupled architecture and zero heavy dependencies.
Engineered by and for Linux system administrators who demand complete control, stability, and observability.
Automatic classification of security patches and errata by severity level (CRITICAL, IMPORTANT, MODERATE, LOW) without modifying system packages during audit.
Polling-based security architecture over HTTPS/REST. Managed nodes require zero open firewall ingress ports and no shared persistent SSH keys.
Active detection of running processes and resident libraries requiring system or service restarts (native support for needs-restarting and reboot-required).
Hardened systemd units enforcing ProtectSystem=strict, least-privilege permissions, and entropy generation compatible with FIPS requirements.
Execute concurrent scheduled updates across tags, handle automated execution queues, or perform clean node decommissions with a single action.
Built-in support for TLS termination with Apache or Nginx, serving seamlessly either at root domain level or under custom subpath prefixes (e.g., /orbit-server).
Orbit enforces strict separation of concerns to keep production nodes lightweight and protected:
/var/lib.
sudoers drop-ins for DNF, YUM, and APT wrappers.