EasyLinuxLinux fleet management

New machines set themselves up

Ship a bare PC to any site. It boots from the network, installs your Linux distribution, joins your fleet, and appears on the dashboard in minutes — no engineer touches it. Ubuntu LTS by default, with other enterprise desktop distributions such as SUSE Linux Enterprise Desktop on request.

ZERO-TOUCH SETUP · UBUNTU 24.04 LTS · ACTIVE DIRECTORY SIGN-IN · CIS COMPLIANT

Site 014 · Anna's laptop
  • Network bootdone
  • Ubuntu LTS installdone · unattended
  • Agent installdone
  • Enrollmentdone · inventory match
  • Device profileapplied · v41
  • Status reporton dashboard

Setup complete

managed enterprise desktop · active directory sign-in

6 OF 6 STEPS COMPLETE · NO ENGINEER TOUCHED IT

The old way

No more hand-built Linux machines

Replacing a PC at a remote branch used to mean one of three slow options — and none of them produced the same machine twice.

Without EasyLinuxcost
  • Fly an engineer to the sitedays
  • Image the disk at HQ, then ship itdays
  • Talk someone on site through itan afternoon

Every machine ends up a little different from the last.

With EasyLinux

Plug it in. It builds itself.

The vendor ships a bare machine to the site. Anyone plugs it in, and it installs itself against the profile IT defined at headquarters.

SAME PROFILE · SAME RESULT · EVERY SITE

Zero-touch setup

From the loading dock to the dashboard

Four automated steps. A person is involved exactly once — to press the power button.

  1. 01

    Plug in and power on

    Someone connects the machine and presses power. The only manual step.

  2. 02

    It installs itself

    Boots from the network and installs a hardened Ubuntu LTS at local-network speed.

  3. 03

    It joins the fleet

    Enrolls against the site inventory, then applies its device profile and software.

  4. 04

    It reports ready

    Appears on the HQ dashboard, configured. People sign in with Active Directory.

The desktop

An enterprise desktop, tailored to every role

We design the enterprise desktop to your requirements. Every enterprise desktop starts with exactly the applications its role needs — kiosk, service desk, office, lab, or developer — arranged and ready to use. People sign in and see everything at a glance, with no hunting and no setup.

TAILORED · PER ROLE · APPLICATIONS AT A GLANCE

Architecture

Every machine has exactly one upstream

Three tiers. A control center at your headquarters, one small distribution point per site, and the enterprise desktops themselves. Profiles and software flow out; health and status flow back. If the link drops, the site keeps running on its local cache.

Headquarter
Managed Linux Server
EasyLinux Distribution Point
vCenter Managed VM
Site Clients
config & configuration templatesagent status callbacksPXE bootapt packagesconfiguration templatesstatus reportsapt upstream
Central Management Site · HQ Linux Server
EasyLinux Platform
Web UI · Engine · EasyLinux API
Managed VMDocker / K8s HA
EasyLinux API config & status endpoint for every distribution point
Stats & Monitoring live dashboard with per-device status & health
Data tier
Database
PostgreSQL — templates, inventories, jobs, status.
Master APT
Single egress proxy → Ubuntu mirrors.
Ubuntu Mirrors
archive.ubuntu.com
Edge Site · one per Market
EasyLinux Distribution Point
Sole entry point for the site's clients
Managed VMconfig syncagent proxyapt cachePXE
Pulls this site's bundle from HQ, runs the services below, and proxies every client request to the EasyLinux API (and status callbacks back).
Services on the distribution point
Local APT Cache
apt-cacher-ng
Serves .deb packages to clients on the LAN.
Upstream proxy points at the Master APT, which fetches from Ubuntu mirrors.
LAN-speedchained
PXE Boot Server
mde-ubuntu24
DHCPTFTPHTTPSNFS
Unattended Ubuntu 24.04 install via subiquity / cloud-init.
Bakes in the EasyLinux Agent so the client enrols on first boot.
client-01
PXE → install → enrol
client-02
applying templates
client-03
reporting status
client-N
running · steady state
Installed Agents
Ubuntu Pro
CrowdStrike
CyberArk
Intune Agent
SSSD (AD)
EasyLinux Agent
Workflow

Client lifecycle — from first power-on to steady-state

1
Power on · PXE boot
Fresh client boots with no OS. NIC requests DHCP; the distribution point answers and chain-loads iPXE over TFTP.
2
Unattended Ubuntu install
PXE serves the kernel, initrd and autoinstall config over HTTPS. Subiquity installs Ubuntu 24.04 LTS with zero prompts.
3
Agent installed
A late-command in the autoinstall installs the EasyLinux agent package, pulled from the distribution point's Local APT.
4
First-boot enrol
On first boot the agent registers with the distribution point, which forwards it to HQ and returns an auth token + host-group binding.
5
Pull & apply templates
Agent fetches its configuration templates via the distribution point and runs them locally. Packages come from the Local APT.
6
Report status
Per-task results, exit codes and logs are posted to the distribution point, which proxies them back to HQ.

Rollout steps

Define it once, then power on

01

Define the installation profile

Choose your enterprise desktop distribution version, disk layout, CIS hardening level, base packages, and first-boot settings every new machine should receive.

02

Add the site inventory

List the machines allowed to enroll at each site: serial number, MAC address, hostname, location, and the profile they should receive.

03

Assign roles and software

Group machines by job: kiosk, service desk, office, lab, developer, or admin. Attach the packages, policies, and scripts each role needs.

04

Register the site VM

Add one distribution point VM per site. It receives profiles from headquarters and serves boot files, packages, and configuration locally.

05

Power on the machines

Ship bare PCs to the site. When someone plugs them in, they PXE boot, match against inventory, install, enroll, and apply their role.

06

Watch the rollout

Use the dashboard to see progress, failed steps, last check-in, applied profile version, and logs for every machine and site.

Trust model

Built for the security review

Your reviewers get a short, checkable list — not a whitepaper.

  • self-hosted: the control center runs at your headquarters
  • mutual TLS between headquarters and every site
  • per-machine auth tokens, issued at enrollment
  • enrollment gate: machines not in the site inventory are refused
  • Ubuntu 24.04 LTS with CIS Level 1 hardening applied at install time
  • Ubuntu Pro extended security maintenance on every machine
  • one controlled internet connection for all OS packages — one audit point, predictable bandwidth

Pricing

Pricing that scales with your fleet

Pricing is based on managed enterprise desktops. Plans start at 250 machines, include zero-touch setup and the HQ dashboard, and scale across sites — talk to sales for a quote.

Monthly price

Custom

Zero-touch setup, enrolment, and the HQ dashboard are included. Migration and on-site rollout are billed time and materials.

Contact sales

Starter

For 250+ enterprise desktops on a single site, with zero-touch setup and the HQ dashboard included.

Growth

Multi-site fleets, with automatic volume discounts as your fleet grows.

Enterprise

Air-gapped and on-prem deployments, plus SLA, Ubuntu Pro, and rollout planning.

FAQ

What IT leads ask first

What happens when a site loses its connection to headquarters?

Nothing dramatic. Machines talk only to the site’s distribution point, which caches configuration and software locally — so booting, installs, and configuration continue, and status reports queue until the link returns. The one limit: a package the site hasn’t cached yet waits for the link.

What if setup fails partway?

It shows up. The dashboard reports the failed step within seconds of the machine reporting — per task, with exit codes and logs — so you see exactly which machine stopped where. Re-running the job is safe: runs are idempotent, so it changes only what is wrong and leaves correct machines untouched. Scheduled checks catch and correct drift the same way.

Which operating systems does EasyLinux manage?

Ubuntu 24.04 LTS by default — other enterprise distributions such as SUSE Linux Enterprise Desktop on request. EasyLinux owns each machine’s setup and state and brings your Linux fleet to one consistent, managed standard.

Does it replace Active Directory, Intune, or our security tooling?

No. Users sign in with their existing Active Directory credentials, and managed machines run alongside CrowdStrike, CyberArk, and Intune. EasyLinux owns the machine’s setup and state; your identity and security stack stays where it is.

How do you stop an unknown machine from joining the fleet?

Enrollment is gated against the site inventory: a machine that isn’t expected is refused. Every enrolled machine gets its own auth token, and all traffic between headquarters and sites runs over mutual TLS.

What does it take to add a new site?

One small VM at the site, registered with headquarters. It pulls the site’s configuration and software cache down on its own, and the enterprise-desktop fleet can roll out the same week. The VM holds nothing precious: a site’s full configuration can be reconstructed from headquarters at any time.

How fast do configuration changes reach machines?

Agents check in with their site’s distribution point on a schedule and apply the profile version assigned to them. Changes land on each machine’s next check-in — a short, predictable delay by design rather than an instant push. Every job pins to a specific profile version, never “latest”, so any run is reproducible after the fact.

Watch a machine set itself up

Book a demo: a bare PC, one power button, and a few minutes later a managed enterprise desktop on your dashboard.

ZERO-TOUCH SETUP · UBUNTU 24.04 LTS · ACTIVE DIRECTORY SIGN-IN