Professional IT Solutions

Running Tactical RMM for 1,000 Agents on a Single VPS (And What It Really Takes)

RMM

If you manage more than a handful of computers, you already know the story. The RMM tool is the one piece of software you can't work without, and it is also the one invoice that grows every single time you add a client. A few years ago I got tired of that and started deploying Tactical RMM on my own servers. One of those installs now looks after about 1,000 agents. Here is what that actually looks like in practice.

The Problem: Paying Per Agent Forever

Most commercial RMM platforms are priced per agent or per technician, per month. That sounds fair when you have 50 endpoints. It feels very different at 500, and at 1,000 it becomes one of the biggest fixed costs in the whole operation.

And the cost is only half of it. Your monitoring data, your scripts, and the remote access to every machine you manage all live on somebody else's platform. If they change the pricing, get acquired, or have a bad day, you are along for the ride. For a tool that has admin access to every endpoint you look after, that's a lot of trust to hand over.

What Tactical RMM Actually Is

Tactical RMM is an open-source remote monitoring and management platform that you host yourself. It is built with Django, Vue and Go, the agent itself is written in Go, and remote control is handled through its MeshCentral integration.

It's not the prettiest tool on the market and it doesn't try to be a PSA, a ticketing system and a billing platform all in one. It does the RMM part, and it does it well. Honestly, that is exactly why I like it.

Key Features at a Glance

If you have never seen it, here is a short list of what you get out of the box, based on the official documentation (opens in a new tab):

  • Remote desktop control, similar to what you know from TeamViewer
  • Real-time remote shell and a remote file browser for uploading and downloading files
  • Script and command execution in PowerShell, batch, bash, Python, Nushell and Deno
  • Automated checks for CPU, disk, memory, services, event logs and your own scripts, with alerts by email, SMS or webhooks
  • Automated task runner for running scripts on a schedule
  • Windows patch management, services management, event log viewer and a registry editor
  • Software installation through Chocolatey
  • Software and hardware inventory for every agent

On the Windows side it supports everything from Windows 7 to 11 and Server 2008 R2 up to Server 2025. One thing to know before you plan: the Linux and macOS agents, code signed Windows agents, the reporting module and single sign-on are sponsorship features, so you get them by sponsoring the project. In my opinion that is a very fair deal for what you get back.

My Setup: 1,000 Agents, One Modest Server

I have done two Tactical RMM deployments so far. The bigger one has been in production for a couple of years and currently has around 1,000 agents installed. People usually expect some serious hardware behind that number. This is what it really runs on:

  • A single VPS with 4 vCPU
  • 8 GB of RAM and 1 GB of swap
  • 100 GB of disk
  • Debian 12 as the operating system

That's it. No cluster, no separate database server, nothing exotic. It has been stable and reliable the whole time, and I think that is the most important thing I can tell you about Tactical RMM: it doesn't need much to do its job.

What We Actually Use It For

Specs are nice, but the real question is what the tool does for you on a normal Tuesday. For this client, five things matter the most.

Remote access, with or without the screen. We use it a lot for remote access, and in two different ways. Sometimes you need the full desktop, to see what the user sees and click through a problem together. But very often the background shell is the more important one. You open a shell on the machine, fix what needs fixing, and the person sitting at that computer just keeps working. No popup, no "please don't touch the mouse for ten minutes". For a busy office that makes a huge difference.

Scripts, scripts, scripts. This is where Tactical RMM really shines. Anything you can write as a script, you can run on one machine or on hundreds of them, and see the output come back in one place. Over time you build your own library, and a lot of "can you quickly check..." requests turn into a two minute job.

Checks on Windows and Linux machines. Disk space, services, memory, or a custom script check that looks at whatever is specific to your environment. When something goes out of range you get an alert, instead of a phone call from an annoyed user.

Updating custom software. For my client this one is critical. They run their own software that no standard patching tool knows anything about. With Tactical RMM the update is just a script and a task, so a new version gets rolled out to every machine in a controlled way, without anybody walking from desk to desk.

Bulk changes per client or per site. Agents are organized by client and by site, and you can run a script against a whole client or just one location. Need to change a setting in one branch office only? Pick the site, run the script, done. For mass changes this is honestly a great solution.

What Keeps It Stable

There is no secret here, just boring discipline. Two things matter more than anything else: a careful configuration at the start, and regular maintenance after that.

Careful configuration from day one. Clients, sites, policies, alert rules, who gets access to what. It is worth taking the time to think this through before the first agent goes in, because with 1,000 agents every shortcut you took in the beginning gets multiplied by a thousand.

Regular Tactical RMM updates. The project moves fast and new versions come out often. I don't let the server fall many versions behind. Small, regular updates are much less scary than one big jump after a year of ignoring it.

Regular OS updates. Debian 12 gets patched on a schedule, like any other production server I manage. An RMM server that is itself unpatched is a bit of a bad joke.

Backups before anything risky. Tactical ships with its own backup and restore scripts, and a VPS snapshot before an update costs almost nothing. If you take one thing from this article, take this one.

Treat it like the high-value target it is. This server can run scripts on every machine you manage. Keep the firewall tight, keep the two-factor authentication that Tactical requires, and don't hand out logins casually.

What Nobody Tells You Upfront

Self-hosting is not free, it just moves the cost. You stop paying per agent and start paying with a bit of your own attention. Somebody has to own this server: watch the updates, check that backups really restore, and notice when the disk starts filling up.

The initial setup also has a few things that catch people out. You need a domain with a couple of DNS records set up correctly, and the standard install uses a wildcard Let's Encrypt certificate that has to be renewed. None of it is hard, but if you skip a step at the start you will meet it again later, usually at a bad moment.

For me it comes down to a small amount of maintenance time, on a server that otherwise just runs. Compared to a per-agent bill for 1,000 endpoints, that is a trade I'm very happy with.

When It Makes Sense (And When It Doesn't)

It makes sense if you are an MSP or an internal IT team with a lot of Windows machines, you have (or can hire) somebody comfortable with Linux, and you want control over your own tooling and data.

It probably doesn't if nobody on the team wants to own a server, or if you need one vendor to call when something breaks at 2 AM. In that case a commercial RMM is a perfectly reasonable thing to pay for. Just do the math for your own agent count first.

The Bottom Line

A lot of people assume that an RMM for a thousand endpoints must be expensive or complicated. My experience says otherwise. One 4 vCPU server with 8 GB of RAM, Debian 12, and a habit of updating things on time has been enough for years.

The software is the easy part. The discipline around it is what makes it reliable, and that is true for pretty much every piece of infrastructure I have ever worked on.

How much are you paying per agent right now, and what would that number look like on a server you control?

  • Tactical RMM
  • Self-Hosting
  • MSP
  • Linux
  • Infrastructure