Sysadmin Automation and Workflow Tools: Configuration Management, DNS as Code and Runbooks

This page is for sysadmins, MSP technicians and small IT teams who still do too much by hand: logging on to servers one by one, editing DNS in a provider console, running the same fix every time an alert fires, or answering the same request five times a week. It covers configuration management, DNS as code, runbooks, self-service jobs and the everyday admin desktop.

The short answer: pick one configuration management tool (Salt, Ansible or Rudder) and stick to it, put DNS under Git with octoDNS, wrap repeatable fixes in Rundeck or StackStorm jobs so others can run them safely, and test every change on a throwaway VM first.

The short list

Tool Best for Licence Platforms Status
Salt Minion for Windows Remote execution and desired state on mixed fleets Free, open source, Apache-2.0 Minion on Windows 10/11, Server 2016–2025; master on Linux/Unix Active, 3008.3 (Sept 2026)
Rudder Continuous configuration compliance Free core, GPL-3.0; Windows agents paid Linux Active, 9.1.4 (Aug 2026)
StackStorm Event-driven auto-remediation, ChatOps Free, open source, Apache-2.0 Linux, Docker, Kubernetes Active, slow cadence, 3.9.0 (Oct 2025)
octoDNS DNS zones as YAML in Git Free, open source, MIT Any OS with Python 3.10+ Active, 1.22.0 (Aug 2026)
Checkmk Community Monitoring managed systems Free, open source, GPL-2.0 Linux server, Docker; agents for all major OSes Active, 2.5.0p14 (Sept 2026)
PA Server Monitor Free Event log, ping and web checks Free edition (1 server or 10 monitors) Windows Active, 10.2.0.246
Multipass Disposable Ubuntu test VMs Free, open source, GPL-3.0 Windows, macOS, Linux Active, 1.16.4 (Sept 2026)
UTM Test VMs on a Mac Free, open source, Apache-2.0 macOS, iOS, iPadOS Active, 4.7.5 (Jan 2026)
LiteManager Free Unattended remote control, up to 30 PCs Free, proprietary, commercial use allowed Windows; apps for other OSes Active, 5.2 (Aug 2025)
Terminals Tabbed RDP, VNC and SSH Free, MS-CL source licence Windows Dormant, 4.0.1 (2017)
Explorer++ Portable file manager for servers, WinPE Free, open source, GPL-3.0 Windows Last stable 1.4.0 (2024), dev builds ongoing
My Commander Dual-pane file manager with SFTP Free, closed source Windows Dormant, 4.0 (2017)
Iperius Backup Free Scheduled file backups Free edition, proprietary Windows, Windows Server Active, 8.8.9 (Sept 2026)
Areca Backup Incremental, encrypted backups Free, open source, GPL-2.0 Windows, Linux Maintained fork, 8.2.6 (June 2026)
ZBack Portable folder sync jobs Free (freeware) Windows Dormant, 2.90.0.a (2020)
Genie Timeline File versioning on desktops Shareware (conditionally free) Windows Free edition discontinued
Ansible Agentless configuration over SSH/WinRM Free, open source, GPL-3.0 Control node: Linux, macOS, WSL Active
Microsoft DSC Declarative Windows configuration Free; DSC v3 open source, MIT Windows; v3 also Linux, macOS Active
Rundeck Self-service runbook jobs Free, open source, Apache-2.0 Linux, Windows Server, Docker Active
n8n Visual workflows across SaaS and APIs Shareware (conditionally free) Self-hosted (Docker) or cloud Active

Keep servers in a known state with configuration management

Configuration management is the base layer of admin automation: describe the desired state once, let a tool apply it and report drift.

Salt runs a master on Linux and a minion service on each node. The Windows minion connects outbound to the master on TCP 4505 and 4506, so nothing opens inbound on the servers. Its strength is speed across hundreds of hosts, targeted by grains such as OS. Always dry-run first:

salt -G 'os:Windows' state.apply win.baseline test=True

Rudder is compliance-first: agents check configuration every few minutes and the web interface shows which rule failed on which node. Start each rule in audit mode, read the report, then switch to enforce. The free core covers current Linux; Windows agents need a paid plan.

Ansible is agentless: a control node on Linux, macOS or WSL connects over SSH, and to Windows over WinRM or SSH. It is the easiest to start with. Its dry run is ansible-playbook -i inventory.ini site.yml --check --diff.

Microsoft DSC is the native choice for Windows admins. Classic PowerShell DSC 1.1, built into Windows PowerShell 5.1, applies compiled configurations through the Local Configuration Manager. DSC v3 is a standalone dsc command that reads YAML or JSON, runs on Windows, Linux and macOS, does not run as a service and can reuse PowerShell DSC resources through adapters: dsc config test --file .baseline.dsc.config.yaml, then dsc config set.

Manage DNS as code

Many outages start with a record edited in a web console with no review and no history. octoDNS keeps zones as YAML in Git and syncs them to Route 53, Cloudflare, Azure DNS, PowerDNS, BIND and other providers through separate provider packages. Dump the live zone first, then every change becomes a pull request with a plan:

octodns-dump --config-file=./config/production.yaml --output-dir=./config example.com. route53
octodns-sync --config-file=./config/production.yaml          # plan only
octodns-sync --config-file=./config/production.yaml --doit   # apply after review

octoDNS assumes it owns every zone you point it at and removes records missing from your YAML, so never skip the dump. There is no official provider for Active Directory-integrated Windows DNS. Run the plan in CI on each pull request and let only the pipeline run --doit after merge.

Turn runbooks into self-service jobs

A runbook in a wiki still needs a senior admin to run it. Self-service IT means wrapping those steps in a job that the help desk or on-call staff can start themselves, with access control and a record of who ran what.

Rundeck is built for this. Jobs take input options (server, service, ticket number), select nodes and run scripts or commands over SSH, with per-project ACL policies deciding who may run what. The help desk gets a “Restart print spooler” button, never a shell. It needs Java 17, listens on port 4440 by default and should use PostgreSQL or MariaDB in production; the embedded H2 database is for testing.

n8n suits workflows that reach into SaaS: a form creates an access request, posts to chat, waits for approval and calls an API. It is fair-code: self-hosting is free under the Sustainable Use License, while enterprise features and the hosted service are paid. For onboarding and access requests see the identity and access management hub; for ticketing, the help desk and IT asset hub.

Design self-service jobs defensively: inputs from fixed lists rather than free text, a dedicated service account with minimal rights, and output written back to the ticket.

React to alerts automatically

When the same alert always leads to the same fix, automate the first response. StackStorm receives events (webhooks, monitoring, chat), matches them against rules and starts actions or Orquesta workflows, logging every execution with inputs and output. A rule can restart nginx when monitoring posts a critical status; st2 execution list shows what ran.

The server is Linux-only and brings MongoDB, RabbitMQ and Redis, so give it a dedicated VM; Windows hosts are reached over WinRM. Releases are slow (3.9.0 came almost two years after 3.8.1), so check the supported OS list first. A good pattern: StackStorm decides when to act and calls Salt or Ansible to make the change. Start with low-risk actions, such as attaching diagnostics to the ticket, before allowing automatic restarts.

Monitor what your automation touches

Automation without monitoring just breaks things faster. Checkmk Community (renamed from Raw Edition in 2.5) monitors Windows, Linux and network devices with auto-discovery and rule-based thresholds, and its REST API lets provisioning scripts add hosts. Evaluate it with the official checkmk/check-mk-community Docker image, and update any scripts that still use the old raw package names.

For one Windows server, PA Server Monitor Free can alert on event IDs (a failed backup job, or 6008 for an unexpected shutdown), ping a gateway or check an intranet page. Disk, CPU, service and SNMP monitors are paid. Prove the alert path with eventcreate /T ERROR /ID 999 /L APPLICATION /SO TestSource /D "test".

Test changes on disposable VMs

Every state, playbook and script should run on a clean machine before production. Multipass launches an Ubuntu VM from an official cloud image in one command on Windows, macOS or Linux, applies cloud-init and snapshots stopped instances:

multipass launch 24.04 --name lab --cpus 2 --memory 2G --cloud-init lab.yaml
multipass delete lab && multipass purge

On Windows, version 1.16 uses Hyper-V, which needs Pro, Enterprise or Education; Home users switch to VirtualBox. Mac admins can use UTM, a QEMU-based VM host that runs Linux and Windows 11 ARM guests. There is no UTM for Windows.

Schedule backups that run without you

Backups are the first thing admins automate and the first thing that silently stops. Iperius Backup Free schedules full, incremental and differential file backups to NAS, USB, RDX and shares, with email alerts; it cannot run as a service and has no VSS, so jobs need a logged-on session and open files may be skipped. Areca Backup adds delta backups and AES encryption on Windows and Linux, with releases from a maintained fork.

ZBack is a tiny portable sync tool, unchanged since 2020. Genie Timeline no longer has a free edition and is now a commercial legacy product. Whatever you use, monitor the age of the newest backup file, not just the job exit code, and test a restore every month.

Equip the admin desktop: remote sessions and file work

LiteManager Free gives unattended access to up to 30 computers, including in a business, by IP on TCP 5650 or by ID behind NAT, and its Server MSI deploys silently with msiexec /qn. Terminals keeps RDP, VNC and SSH sessions in tabs, but it is dormant, so do not make it a team standard.

Explorer++ runs portable from a USB stick or share, adds tabs and bookmarks, and works in Windows PE. My Commander is a sub-2 MB dual-pane manager with built-in SFTP and SCP, though its last stable release is from 2017. For cloud consoles, see the cloud and SaaS administration hub.

How to choose

  1. Count your Windows hosts. Mostly Windows: Salt, Ansible over WinRM, or Microsoft DSC. Mostly Linux with audit needs: Rudder.
  2. Agent or agentless. Ansible starts fastest; Salt and Rudder agents give continuous enforcement and speed at scale.
  3. One source of truth. Keep states, playbooks, DNS YAML and job definitions in Git, reviewed as pull requests.
  4. Separate “when” from “what”. Rundeck or StackStorm decide when a job runs and who may start it; configuration management makes the change.
  5. Prefer maintained tools for shared work. Terminals, My Commander and ZBack are fine personally, not as team dependencies.
  6. Test, then monitor. Try changes on Multipass or UTM, and make sure monitoring tells you when automation fails.

FAQ

What is the best free configuration management tool for Windows and Linux?

Salt (Apache-2.0) and Ansible (GPL-3.0) both manage Windows and Linux for free. Salt needs a Linux master and minions; Ansible needs only a Linux, macOS or WSL control node. Rudder’s free core is Linux-only.

Ansible vs Salt vs Rudder: which should I learn first?

Ansible has the gentlest start. Salt is faster for remote execution at scale. Rudder fits best when auditors want continuous compliance reports.

What does “DNS as code” mean?

DNS records live in version-controlled files, and a tool such as octoDNS compares them with the live provider, shows a plan and applies only reviewed changes.

What is a runbook automation tool?

It turns documented procedures into jobs run on demand, on schedule or by events, with access control and logs. Rundeck focuses on jobs people start; StackStorm on jobs events start.

How do I set up self-service IT for common requests?

Script the three most frequent requests and publish them as Rundeck jobs with fixed options and per-team ACLs, or as n8n workflows with an approval step. Log every run to the ticket.

Is StackStorm still maintained?

Yes, by its community under the Linux Foundation; 3.9.0 shipped in October 2025. Releases are infrequent, so check supported OS and Python versions before deploying.

Last updated: 1 October 2026 · AdminHub Plus editorial team. Licence, version and platform details are checked against each developer's official documentation.

Submit your application