An Open Source
Linux Platform
Based on OpenVox and designed to:
- Run any app on any server, cloud or on prem, in minutes
- Minimize operational cost
- Maximize security, reliability, digital sovereignty and autonomy
A fleet drifts one hotfix at a time.
Every server starts identical. A year of hand edits, hurried patches and forgotten firewall holes later, no two are alike, and nobody can say why.
Snowflake servers
Hand-edited configs turn a fleet into a collection of special cases nobody dares rebuild.
The patching backlog
Security updates wait for a quiet week that never comes.
The audit scramble
When someone asks who changed what and when, the honest answer is a shrug.
Compared, without the spin.
Ansible, Terraform, Chef and Salt are all capable tools, and the table says where they match or beat us. LinuxAid differs in one mechanical way. Agents pull a compiled catalog every hour and report what has drifted, then put it back wherever enforcement is switched on.
- Built in
- Needs extra tooling, a paid tier, or has known limits
- Not what the tool is for
| LinuxAid | Ansible | Terraform | Chef | Salt | |
|---|---|---|---|---|---|
| Change preview & drift control | Needs extra tooling, a paid tier, or has known limitsFleet-wide noop runs via OpenVoxDB | Needs extra tooling, a paid tier, or has known limitsCheck mode + AWX | Needs extra tooling, a paid tier, or has known limitsPlan per workspace | Needs extra tooling, a paid tier, or has known limitsWhy-run (limited accuracy) | Needs extra tooling, a paid tier, or has known limitsTest mode; diff coverage varies by state |
| Compliance frameworks & reporting | Needs extra tooling, a paid tier, or has known limitsGit-audited change history + OpenVoxDB reporting | Needs extra tooling, a paid tier, or has known limitsLockdown/AWX roles | Needs extra tooling, a paid tier, or has known limitsPolicy-as-code only | Built inInSpec + Automate | Needs extra tooling, a paid tier, or has known limitsRequires modules |
| Supply chain security & air-gap | Built inRepository server, GPG signing, snapshots | Needs extra tooling, a paid tier, or has known limitsManual hardening | Needs extra tooling, a paid tier, or has known limitsModule-by-module | Needs extra tooling, a paid tier, or has known limitsCustom pipeline | Needs extra tooling, a paid tier, or has known limitsCustom pipeline |
| Scale & performance track record | Needs extra tooling, a paid tier, or has known limitsCompile-master architecture, horizontal scale-out | Needs extra tooling, a paid tier, or has known limitsAWX scale tuning | Needs extra tooling, a paid tier, or has known limitsState file workflows | Built inEnterprises documented | Built inEnterprises documented (~20k per master) |
| Application catalog & monitoring | Built in110+ roles on 151 modules | Built inThousands of Galaxy roles; quality varies | Not what the tool is forBy design: provisioning, not app lifecycle | Needs extra tooling, a paid tier, or has known limitsCookbook marketplace | Needs extra tooling, a paid tier, or has known limitsCommunity states |
| Data ownership & GitOps | Built inGit repo you can host yourself | Needs extra tooling, a paid tier, or has known limitsPossible with AWX | Needs extra tooling, a paid tier, or has known limitsNeeds policy repos | Needs extra tooling, a paid tier, or has known limitsChef Automate workflows | Built inGitFS; RaaS in the commercial product |
| Operational maturity & anti-patterns | Built inPull-based, no prod SSH | Needs extra tooling, a paid tier, or has known limitsAd-hoc runs bypass playbooks | Needs extra tooling, a paid tier, or has known limitsState locking & per-env plans | Built inSimilar guardrails | Built inSimilar guardrails |
Change preview & drift control
- Needs extra tooling, a paid tier, or has known limitsLinuxAidFleet-wide noop runs via OpenVoxDB
- Needs extra tooling, a paid tier, or has known limitsAnsibleCheck mode + AWX
- Needs extra tooling, a paid tier, or has known limitsTerraformPlan per workspace
- Needs extra tooling, a paid tier, or has known limitsChefWhy-run (limited accuracy)
- Needs extra tooling, a paid tier, or has known limitsSaltTest mode; diff coverage varies by state
Compliance frameworks & reporting
- Needs extra tooling, a paid tier, or has known limitsLinuxAidGit-audited change history + OpenVoxDB reporting
- Needs extra tooling, a paid tier, or has known limitsAnsibleLockdown/AWX roles
- Needs extra tooling, a paid tier, or has known limitsTerraformPolicy-as-code only
- Built inChefInSpec + Automate
- Needs extra tooling, a paid tier, or has known limitsSaltRequires modules
Supply chain security & air-gap
- Built inLinuxAidRepository server, GPG signing, snapshots
- Needs extra tooling, a paid tier, or has known limitsAnsibleManual hardening
- Needs extra tooling, a paid tier, or has known limitsTerraformModule-by-module
- Needs extra tooling, a paid tier, or has known limitsChefCustom pipeline
- Needs extra tooling, a paid tier, or has known limitsSaltCustom pipeline
Scale & performance track record
- Needs extra tooling, a paid tier, or has known limitsLinuxAidCompile-master architecture, horizontal scale-out
- Needs extra tooling, a paid tier, or has known limitsAnsibleAWX scale tuning
- Needs extra tooling, a paid tier, or has known limitsTerraformState file workflows
- Built inChefEnterprises documented
- Built inSaltEnterprises documented (~20k per master)
Application catalog & monitoring
- Built inLinuxAid110+ roles on 151 modules
- Built inAnsibleThousands of Galaxy roles; quality varies
- Not what the tool is forTerraformBy design: provisioning, not app lifecycle
- Needs extra tooling, a paid tier, or has known limitsChefCookbook marketplace
- Needs extra tooling, a paid tier, or has known limitsSaltCommunity states
Data ownership & GitOps
- Built inLinuxAidGit repo you can host yourself
- Needs extra tooling, a paid tier, or has known limitsAnsiblePossible with AWX
- Needs extra tooling, a paid tier, or has known limitsTerraformNeeds policy repos
- Needs extra tooling, a paid tier, or has known limitsChefChef Automate workflows
- Built inSaltGitFS; RaaS in the commercial product
Operational maturity & anti-patterns
- Built inLinuxAidPull-based, no prod SSH
- Needs extra tooling, a paid tier, or has known limitsAnsibleAd-hoc runs bypass playbooks
- Needs extra tooling, a paid tier, or has known limitsTerraformState locking & per-env plans
- Built inChefSimilar guardrails
- Built inSaltSimilar guardrails
Enroll a node in one command.
linuxaid-install puts the openvox-agent on a server and signs it into your fleet. From then on the agent runs every hour and reports where the server differs from its role.
What that means in practice.
Run any app on any server, cloud or on prem
A server becomes a role in one line: 110+ ready-made roles built on 151 curated Puppet modules, from Nginx, PostgreSQL and GitLab to Mailcow, WordPress and Slurm HPC, installed and kept current from GPG-signed package repositories, on RHEL, Rocky, Alma, Ubuntu, Debian or SUSE.
110+ roles · 151 modules · GPG-signed repos
Minimize operational cost
OpenVox compiles a catalog per node from layered role, profile and hiera data. Agents pull every hour and compare every managed resource against it. You decide per class what happens next. Enforce, and a hand-edited config is put straight back. Alert only, and you are told a local change was detected and nothing is reverted. Either way nobody re-does the same fix. There is no per-node licensing, and the platform work is shared across customers as open source.
Enforce or alert, per class · no per-node licensing
Maximize security, reliability and sovereignty
Every node gets up to 24 Prometheus exporter integrations automatically, from node and RAID health to per-service metrics, wired to Grafana and Alertmanager. Every configuration change is a Git commit with an author and a diff. Everything is AGPL-3.0 and runs on your servers, cancel the subscription and it keeps converging.
24 exporter integrations · Git-audited changes · AGPL-3.0
Provable, not just patched.
Configuration lives in Git, packages are GPG-signed, and every change has an author and a timestamp. That is what GDPR, CIS and NIS2 conversations need, evidence, not assurances. The same hardened setups have carried customers through independent penetration tests and Cyber Essentials Plus recertification.
Run it yourself, or run it with us.
LinuxAid is AGPL-3.0 and free forever. Subscriptions add Obmondo operations per server. Cancel anytime, with expense ceilings so costs stay predictable. Maintenance is shared across customers running the same stack, so nobody pays for the same work twice.
- Full platform, nothing gated
- AGPL-3.0 licensed
- Community support on GitHub
| Basic | Bronze | Most popularSilver | Gold | Platinum | |
|---|---|---|---|---|---|
| Price | €29/server·mo | €129/server·mo | €165/server·mo | €199/server·mo | €265/server·mo |
| Response / SLA | Monitoring, alerts & live chat | 1-business-day response | 4-hour response, business hours | 2-hour response, 24×7 | 1-hour response, 24×7 |
| Service level |
Prices per server per month. Volume discounts, consultation hours and expense ceilings. See the full calculator.
Open the price calculatorSovereignty you can exit-test.
LinuxAid is AGPL-3.0 on top of OpenVox, the open-source Puppet-compatible configuration system, no per-node licensing, ever. Your setup runs on your servers and stays there: cancel the subscription and everything keeps converging. That is the exit test proprietary tooling fails. And because the platform work is shared across customers as open source, nobody builds compliance alone.
AGPL-3.0 · OpenVox foundation · the work shared as open source
FAQ
Yes. The full platform is AGPL-3.0 with nothing gated behind a paid edition. Subscriptions add operations, response times and support, not features.
Ansible pushes changes when someone runs a playbook. LinuxAid agents pull the desired state every hour and report what has drifted, then put it back wherever enforcement is switched on. Nobody has to run anything.
No. The role, profile and hiera layers are maintained for you. Your team describes what a server should be, in data. Teams that know Puppet can go as deep as they like.
RHEL, Rocky and Alma, Ubuntu 20.04–24.04, Debian and SUSE are covered with per-OS data out of the box, across cloud and on-prem.
The setup stays on your servers and keeps converging. You retain full control. Alert handling and consultation from the subscription stop; the platform does not.
Talk to the people who'll run it.
A 30-minute call with an Obmondo engineer who manages Linux fleets for a living, not a sales deck.