Kavros pushes a configuration change to every MikroTik you own — with a diff you read before it lands, a rollback that fires by itself, and proof from each site that the service came back.
Self-hosted. Runs on your hardware, credentials never leave your network.
| Name | Model | RouterOS | Uptime | |
|---|---|---|---|---|
| border-tll-01 | CCR2004-16G | 7.20 | 171d | |
| core-tll-02 | CCR1009-7G | 7.22.2 | 84d | |
| pop-tbs-01 | RB5009UPr+S+ | 7.19 | — | |
| pop-mil-04 | hAP ac² | 7.23.3 | 12d | |
| pop-rix-07 | hEX S | 7.22.2 | 6d |
One view
A router that answers, a router that answers badly and a router that stopped answering are three different facts. Kavros keeps them apart, on a map you can open on a phone in a taxi, and it never asks a router a question to find out - the answer is already there.
The problem
You paste it into the first WinBox window and hope. Somewhere around the twelfth you have lost track of which ones took it, and the only way to find out is to open them one at a time.
That is how a Friday afternoon turns into an outage. It is also why most fleets still run a RouterOS from two years ago — the upgrade is a night of manual work with no way back.
Before it lands
No abstraction, no summary. The diff is the exact command list Kavros will send, and automatic checks refuse the whole batch if it would cut management access.
After it lands
Kavros probes the services your subscribers actually use, from each POP, and separates reachable from reachable but leaving through the wrong uplink — the failure nobody else reports, and the one that costs you the support call.
| Site | YouTube | Banking | Speedtest | ||
|---|---|---|---|---|---|
| Site 04 · West Europe | |||||
| Site 09 · South Caucasus | |||||
| Site 17 · South Europe | |||||
| Site 23 · South America | |||||
| Site 31 · Southeast Asia |
What the fleet is carrying
Every device is read against a hardening baseline - open management services, default SNMP strings, MAC access left on every interface, a firewall with nothing dropping on input. Each finding says what it found, quotes the line it found it on, and where it is safe, offers to fix it.
Fix it means: the router writes a backup of itself, the exact command for that finding is sent, and the setting is read back. If the device does not confirm the new value, nothing is recorded as fixed. What is safe to automate is a closed list in the code - never the API, Winbox or SSH services, never a firewall rule, never an account.
Anyone who reaches the port reads the configuration.
allowed-interface-list is unset, which means all.
A drifted clock breaks the log trail across the fleet.
How it hangs together
Neighbour discovery, routing adjacencies and the tunnels each device reports, drawn as one graph. When a link stops being reported, the graph shows the gap where it used to be - which is usually the first honest answer to why a site went quiet.
What Kavros does
Everything else in the product exists to make these three trustworthy.
Real RouterOS commands, blocking checks that refuse a dangerous batch outright, and a confirmation with a countdown before anything is sent.
Risky changes are armed before they are applied. If you do not confirm within the window, the router restores itself. Nothing to undo by hand at two in the morning.
Waves, automatic pause when the error rate climbs, failures grouped by cause, and a button that retries only what actually failed.
And the rest of it
Free for good. You pay only when Kavros starts changing the network for you.
How it is sold
Billed per site, not per device — growing your network does not quietly grow your bill. Runs on your own hardware, so credentials and configs never leave your premises.