Praxis manages Linux servers from one place you run yourself. Patch Debian and RHEL family hosts on a schedule or behind an approval, catch hosts that drift from their baseline, and tell real security updates from the rest. SSH access uses short-lived certificates instead of static keys, so patch runs and admin sessions land in the same audit trail, keyed to the same host and the same user. Free up to 15 hosts. No license key, no call home, works air-gapped.
I've spent my career in cyber operations, and every environment I worked in had the same split. One tool patched the Linux boxes. A different one decided who could SSH in. At audit time somebody spent a week gluing logs together to prove a patch actually went out and who signed off on it. The tools that cover more of that are either locked to RHEL or they're SaaS, which is dead on arrival for anything air-gapped or security focused.
So Praxis does patching, drift detection, and SSH access on a box you run yourself. No call home, no license server, free up to 15 hosts.