Change everything.
Break nothing.

Kavros pushes a configuration change to every MikroTik you own — with a diff you read before it lands, a rollback that fires by itself, and proof from each site that the service came back.

Self-hosted. Runs on your hardware, credentials never leave your network.

AVROS
all124
up121
down2
drift1
NameModelRouterOSUptime
border-tll-01CCR2004-16G7.20171d
core-tll-02CCR1009-7G7.22.284d
pop-tbs-01RB5009UPr+S+7.19
pop-mil-04hAP ac²7.23.312d
pop-rix-07hEX S7.22.26d

The problem

Forty routers, four cities, one rule.

You paste it into the first WinBox window and hope. Somewhere around the twelfth you have lost track of which ones took it, and the only way to find out is to open them one at a time.

That is how a Friday afternoon turns into an outage. It is also why most fleets still run a RouterOS from two years ago — the upgrade is a night of manual work with no way back.

Before it lands

You read the change in the language the router speaks.

No abstraction, no summary. The diff is the exact command list Kavros will send, and automatic checks refuse the whole batch if it would cut management access.

border-tll-01 · 10.10.0.118 commands · 3 devices in this wave
/ip firewall mangle
- set [find comment="kv:policy:030"] dst-address-list=EU-CORE
+ add chain=prerouting action=mark-routing new-routing-mark=EU-CORE \
    dst-address-list=PARTNER-NETS passthrough=no comment="kv:policy:031"
/system scheduler
+ add name="kv-confirm" start-time=startup on-event="/system script run kv-rollback"
Blocking check passed — the management subnet 10.10.0.0/24 is still accepted by rule kv:policy:000 after this change.

After it lands

Proof from the site, not a green tick from the panel.

Kavros probes the services your subscribers actually use, from each POP, and separates reachable from reachable but leaving through the wrong uplink — the failure nobody else reports, and the one that costs you the support call.

SiteWhatsAppInstagramYouTubeBankingSpeedtest
Tallinn, EE
Tbilisi, GE
Milan, IT
Rome, IT
Riga, LV
reachable reachable, wrong path down

What Kavros does

Three things, done properly.

Everything else in the product exists to make these three trustworthy.

01

You see it first

Real RouterOS commands, blocking checks that refuse a dangerous batch outright, and a confirmation with a countdown before anything is sent.

02

It comes back on its own

Risky changes are armed before they are applied. If you do not confirm within the window, the router restores itself. Nothing to undo by hand at two in the morning.

03

Partial success is a first-class result

Waves, automatic pause when the error rate climbs, failures grouped by cause, and a button that retries only what actually failed.

And the rest of it

The work you do by hand today.

Free for good. You pay only when Kavros starts changing the network for you.

InventoryModel, RouterOS version, uptime, CPU and memory, on a schedule.
BackupsExports with a readable diff between any two points, and restore.
UpgradesInstalled versus available, rolled out in canary waves.
CredentialsEncrypted at rest. One click opens WinBox already connected.
AuditWho changed what, where, when, and the exact commands sent.
LogsSyslog from the whole fleet, with alerts that survive rotation.

How it is sold

Looking is free. Changing the whole network safely is not.

Billed per site, not per device — growing your network does not quietly grow your bill. Runs on your own hardware, so credentials and configs never leave your premises.