LSUS — centralized update management

Manage software updates for Linux and Windows from one central console—at any scale, from data centers to fully air-gapped networks.

lsus.ru — management console
LSUS dashboard

Overview

Manage Linux and Windows updates from one console

LSUS is an update-management platform for all your endpoints: workstations and servers running Astra Linux, Red OS, ALT, Debian, Ubuntu, AlmaLinux, CentOS Stream, and Windows—across data centers, branches, and fully air-gapped environments. Track compliance from one dashboard, deploy updates immediately, schedule them for maintenance windows, or automate them during off-peak hours.

Explore all features

Monitor update compliance across every Linux and Windows machine, at headquarters and branches, from a single dashboard. Track each endpoint, deploy updates efficiently, and analyze results while keeping the environment secure and stable.

Agents connect to the server over HTTPS—without SSH or open inbound ports. Start managing updates as soon as the agent is installed: configurations and playbooks are signed with the server key (Ed25519) to prevent tampering.

Manage patches with granular access rights: 8 RBAC roles plus LDAP/LDAPS and Kerberos SSO integration. Assign owners for critical deployments, keep a complete audit trail, and export events to your SIEM.

Install updates immediately, schedule campaigns for a specific time, or automate them during off-peak hours. Testing → stable channels, hold lists for critical packages, and schedules by host group ensure updates are deployed when it is safe for the business.

Every update first passes through a pilot group and checklists, then moves to stable for rollout across the fleet. Versioned group policies and wave deployments (precheck → apply → verify) minimize the risk of widespread outages.

Features

Core update-management capabilities

Visibility and reporting

One dashboard for update compliance, reports, and unreachable-host notifications—across headquarters, branches, and isolated environments.

Update deployment

Deployment campaigns and package jobs for Linux and Windows: KB catalog, approvals, and MSU—on demand or on a schedule.

Learn more

Targeting

AD directory and collections: group endpoints by OS, domain, and criteria, then deploy updates to the right nodes at scale.

Scheduling and testing

Maintenance windows, testing → stable channels, pilot groups, and checklists ensure updates reach production only after validation.

Configuration management

Declarative Ansible configurations: Ed25519-signed playbooks, a compliance map, and an ADMX/GPO-style policy builder.

Learn more

AI assistant

Fleet health summaries, run analysis, and playbook drafts. Run locally with Ollama or in the cloud with GigaChat or Yandex AI Studio.

Learn more

Vulnerability analysis

Match packages against CVE databases (Debian, Red Hat, ALT, Ubuntu, SUSE, Oracle) and scan the fleet at scale.

Learn more

Integrations and SIEM

Export events to SIEM through Syslog RFC 5424 or webhooks; integrate with Directum RX, MaxPatrol VM, SecurITM, and X-Threat.

Learn more
Also included: USB control· hold lists· LVM snapshots· offline KB catalog· REST API· Kerberos SSO

Architecture

Master, Site, and Edge — roles in your environment

Clients communicate only with Master and Site. Edge connects only to Master: it is the perimeter for downloading and preparing updates, with no direct contact with workstation or server fleets.

Edge Master only Master Site
clients connect to Master and/or Site
Clients

When Site is unavailable, clients fail over to Master.

Central

Master

A single control point for policies, repository catalog, campaigns, OVAL, RBAC, reports, and API. Connects to Site, Edge, and clients.

  • Policies and schedules
  • Catalog and testing → stable channels
  • Serve clients directly
Site

Site

A branch proxy with local cache and smart replication from Master. Site clients connect to Site, and to Master when needed.

  • On-site package cache
  • Replication from Master
  • Serve branch clients
Perimeter

Edge

A DMZ edge server that works only with Master. It retrieves and prepares updates at the perimeter—without direct client access to Edge.

  • DMZ deployment
  • Connects only to Master
  • No direct client access

Resilience

If Site is unavailable, clients fail over to Master. Once the connection is restored, the update backlog catches up during an approved maintenance window.

Isolated environments

In an air-gapped scenario, packages are imported through ISO images and local repositories. If needed, Edge remains an external endpoint for Master only, never for clients.

Security

Built-in security and compliance

8

RBAC roles—from viewer to admin—with LDAP and Kerberos SSO integration.

Learn more
100%

of traffic over HTTPS (TLS 1.2/1.3). No binary protocols or inbound ports.

Learn more
6

OVAL data sources for vulnerability analysis: Debian, Red Hat, ALT, Ubuntu, SUSE, Oracle.

Learn more

LSUS software is registered with Rospatent—certificate No. 2026615730, issued 27 February 2026.

Platform protection

  • RBAC and single sign-on

    8 roles—from viewer to admin—with LDAP/LDAPS and Kerberos SSO integration.

  • Traffic encryption

    HTTPS at every layer (TLS 1.2/1.3), with no binary protocols or inbound ports.

  • Audit log

    A complete record of every administrator action, exportable to SIEM.

  • SIEM export

    Syslog RFC 5424 (UDP/TCP/TLS) and HTTP webhooks for MaxPatrol, KUMA, and Splunk.

  • Integrity control

    Playbooks and configurations are signed with the server key (Ed25519).

Pricing

LSUS pricing

Pricing combines the platform (Master, Site, Edge) with licenses for managed nodes. Choose Professional or Enterprise, annual subscription or perpetual licensing. The Early Access program offers a 30% discount.

View LSUS pricing

Resources

LSUS interface and documentation

Frequently asked questions

LSUS (Linux System Update Server) is an enterprise patch-management platform. It centralizes checking, testing, and installing updates across Linux and Windows fleets: instead of visiting servers and workstations manually, administrators define policies, repositories, and schedules from one web console.

Yes. It is a core use case: local repositories, package import from ISO images, and an offline Windows update catalog. Clients use Master and Site within the environment; when needed, an Edge server in the DMZ connects only to Master and never serves clients directly.

Astra Linux, Red OS, ALT, Debian, Ubuntu, Kubuntu, AlmaLinux, CentOS Stream, Windows 10/11, and Windows Server 2012 R2–2022. Linux uses APT, DNF/YUM, and APT-RPM; Windows uses an agent with the Windows Update API and offline KB catalog.

It is the process of applying updates to remediate vulnerabilities, fix defects, improve functionality, and maintain performance. LSUS automates the full cycle, from OVAL vulnerability analysis to testing and scheduled rollout.

Master is the control center and endpoint clients connect to. Site provides caching and replication for branches: site clients connect to Site and, when necessary, Master. Edge is the DMZ perimeter, connected only to Master and never serving clients. If Site is unavailable, clients fail over to Master.

Yes. LSUS (Linux System Update Server) is registered as software with Rospatent, certificate No. 2026615730, issued 27 February 2026.

Next steps

Start managing updates centrally

Choose what works for you: a live demo or a quote tailored to your fleet. Requests go to info@lsus.ru; we respond during business hours.

Demo

We will show the console, Linux/Windows workflows, and air-gapped scenarios in a demo environment.

Request a demo

Quote

Build an estimate in the calculator; your quote request will include the selected license parameters.

Open calculator

Or contact us directly: info@lsus.ru · +7 995 437-14-87