Inventory and controlled operations for Linux estates

For engineers and small infrastructure teams managing Debian and Ubuntu hosts. Vitrinode brings device identity, host visibility and signed remote jobs into one management plane, with Docker inventory and read-only Proxmox correlation.

In active development by Vitrinode Ltd. Technical evaluation is available by arrangement; no general availability date has been set.

What you can assess today

Understand host connectivity

See enrolled hosts and their last-seen state. Where Proxmox is used, correlate VM and container records with agent connectivity. The integration is read-only.

Collect inventory without checking each host by hand

Collect system, storage, network, systemd, APT and Docker facts. Collection and storage are implemented; the full per-host inventory view and change timeline remain planned.

Run a defined set of remote operations

Request host status, list services and available package updates, or dispatch a service restart subject to device trust checks. Jobs are signed, expire and produce audit records. The operation set is deliberately small.

Vitrinode device list showing managed hosts with connection, operating system, kernel and update-state columns.
Device list from the development interface. View more screenshots. Full inventory detail is still planned.

Built for a smaller Linux estate

The current scope is Debian and Ubuntu, Docker inventory and one Proxmox cluster. Exact OS releases and deployment requirements are confirmed when scoping an evaluation.

Vitrinode complements existing SSH and configuration-management workflows. Windows management, VMware integration and multi-tenancy are outside the current scope.

Assess where Vitrinode fits →

A defined trust boundary on each host

Agents initiate connections to the server. Each runs unprivileged and uses a separate local executor for permitted operations that require elevated rights.

Components, connections and trust boundaries →

Identity and constrained access

Device identityMutual TLS with revocation checks on authenticated agent requests.
Administrator accessWebAuthn sign-in; step-up for device revocation and attestation re-baselining.
Remote operationsTyped, signed jobs with expiry, replay protection and local privilege separation.

Device authentication and attestation are separate claims. TPM-backed evidence and software evidence are distinguished explicitly. No certification or third-party penetration-test claims are made.

Read the security model and its limits →

Current development status

Reviewed . Host enrolment, inventory collection, typed jobs and read-only Proxmox correlation are implemented.

Full inventory views, change intelligence and SSH certificate access remain planned. The separate HSM prototype is in development and is not integrated with the server.

Development history · Roadmap · Hardware prototype

Evaluate a defined use case

Start with a lab or isolated test environment and a clear question to assess. Scope, compatibility and access are agreed directly with Vitrinode Ltd.

See how a technical evaluation is arranged →