About Portrait

Portrait is what Canonical Landscape would be if it had been built for Windows fleets, released free, and self-hosted on a single server you run yourself.

The name

Landscape manages Ubuntu; Portrait manages Windows. The pun signals the lineage immediately to anyone who knows Landscape, which is precisely the intended audience. The tagline is a claim of function, “fleet management for Windows,” never a claim of association.

What Portrait is not

  • Not an MDM. No mobile devices, no Apple, no enrollment profiles.
  • Not a software distribution point. No repository, mirror or package archive. It governs updates; it does not host the bits.
  • Not Active Directory aware. No LDAP auth, no GPO model, no domain-controller support.
  • Not an imaging / PXE server. It provisions the agent, not the OS.
  • Not an EDR. It reports Defender’s posture; it does not do threat detection or response.
  • Not a Linux manager. Landscape already does that, well. Portrait can hand off to it.
  • Not a SaaS. Self-hosted only. If it ships, it ships free.

The omissions are not gaps to be filled later. They are what keeps the project small enough to finish.

Governs, does not host

Portrait decides which updates and packages apply to which hosts and when, and orchestrates the reboots afterwards. It does not host, mirror, sign or deliver a single byte of update content; managed hosts keep drawing that from Microsoft Update, the public WinGet source, or whatever internal source they already use. Not running a software repository is the single largest piece of work Portrait deliberately declines, and it is what keeps the scope achievable.

Independent implementation: the clean room

Portrait is built from public Landscape documentation and observed behavior only. No Landscape Server source and no landscape-client source is read or used, and no model is ever asked for Landscape’s implementation. The permitted channels are public documentation, direct observation of a running Landscape instance, and a first-party Landscape API client. This is a firm policy, not a preference; it is what keeps Portrait legally clear and its agent’s permissive license clean.

Where Portrait diverges from Landscape it does so on purpose: TPM-bound identity instead of reactive duplicate cleanup; a PostgreSQL queue instead of RabbitMQ; one versioned REST API instead of a legacy HMAC API alongside it; a populated parent-activity aggregate with child filtering; first-class ad-hoc script execution. Plus Windows-native extensions with no Landscape analog: Defender posture, BitLocker key escrow, LAPS escrow.

Trademark position

A knockout trademark search found no live registration of the bare mark “Portrait” for IT-management, systems-administration or endpoint software; the closest historical marks in that space are dead, and the closest live ones (photo editing, display calibration) are in unrelated fields. That is a knockout search, not a clearance opinion; it measures the risk rather than removing it, and EU registrations and common-law use are not covered.

Every public artifact carries this disclaimer: Portrait is not affiliated with or endorsed by Canonical Ltd.; “Landscape” and “Ubuntu” are trademarks of Canonical Ltd. No part of Portrait’s visual identity derives from, or visually echoes, Canonical’s marks.

Licensing

Server, web UIAGPL-3.0-or-later
Agent, CLIApache-2.0
DocumentationCC-BY-4.0

Contributions are accepted by Developer Certificate of Origin sign-off, not a contributor license agreement.

Source

Portrait will be published at github.com/esowash/portrait at its public beta. Until then the repository is private and development is deliberately unpromoted; the release is meant to be quiet.

Success criteria

v1.0 is done when a Windows admin can, from a single server: enroll a fleet of standalone Windows hosts; see complete hardware, software and patch inventory; approve and schedule patches within maintenance windows; run PowerShell across a tag-targeted subset with full audit; define package profiles that self-enforce; escrow BitLocker keys; and drive all of it from a documented REST API, without paying anyone.

The project has succeeded when someone who was about to buy a commercial endpoint-management SaaS uses this instead.

Contact

Portrait is built by Eli Sowash. If you want to learn more, kick the tires, or tell me it is a bad idea: