Skip to main content

Changelog

All notable changes to ProxCenter are documented here. This changelog follows the Keep a Changelog format.

v1.4.10 -- 2026-09-16​

Site Recovery on ZFS with recovery per guest, the vDC tenant model, 53 Prometheus metric families with Grafana dashboards, and warm migrations that no longer wait on absent VMware Tools. Replication now runs on ZFS zvols next to Ceph RBD, with a test failover that clones instead of rolling back; Emergency DR acts on one guest at a time, with the replica state on its row and a start from a chosen restore point; a vDC carries fine-grained guest rights, a compute policy, read-only ISO libraries and its own VXLAN transport; and the public metrics endpoint answers with 53 families that five shipped Grafana dashboards read. Alongside them: guest disk latency from the inventory to the alert thresholds, a CVE scan that finally reads every installed package, DRS balanced inside each placement domain with a History tab saying why each guest moved, parallel disk downloads on cold vCenter exports, cross-cluster migration prerequisites cleared from the dialog, and a long tail of Site Recovery, Ceph, RBAC and white-label fixes.

Changed​

  • proxcenter_backup_age_seconds carries node, name and type labels -- The series identified a guest by its connection and its VMID alone, so every dashboard had to join it against another family to put a name or a node on a figure. It now carries the three labels itself. A query that aggregated over the bare metric sees one series per label set from here on and needs a max by (vmid) or an equivalent. See API Tokens.

Added​

  • Site Recovery on ZFS -- A replication job now picks its storage engine: Ceph RBD as before, or ZFS, which snapshots the zvols and pipes an incremental send over SSH into a receive on the target. A ZFS job replicates to a chosen target node rather than to a cluster-wide pool, its test failover clones the newest common snapshot instead of rolling the image back, and the cleanup destroys those clones from a manifest written before any mutation. Disks that resolve to no zvol, name collisions across pools and a volblocksize above 128 KiB are refused up front, and a cluster pair mixing both engines groups its jobs by engine. See Site Recovery. (Enterprise)
  • DR replicas named apart from production -- The wizard could only shift the target VMID, so a replica kept the production guest's name and the two were indistinguishable in the inventory. The create and edit dialogs now carry a prefix and a suffix for the replica name, previewed live on a guest actually picked, and validated in the browser against the same rule Proxmox applies, since the replica configuration is written straight into the target cluster's filesystem. Unlike the VMID prefix they stay editable, which is what lets an existing job name its replicas without being recreated. See Site Recovery. (Enterprise)
  • Emergency DR acts per guest -- The row gains a Replica column fed by the cluster inventory, a start that offers the restore points of that one guest, and a stop, which existed end to end in the API but no screen ever called, so an operator who started a replica had no way back. Starting one claims that guest alone instead of pausing its whole replication job, and rolling the disks back to the chosen point keeps the newer ones, because resuming replication rolls the image forward again. The chip says started and never running, Proxmox reporting a paused guest as running and nobody mid-incident being told a replica serves when it does not. The failback button leaves the guest row, where it ran a plan-wide destructive action, for the plan header. See Site Recovery. (Enterprise)
  • A replication network per connection -- The stream went to the management address of the destination, the same one the Proxmox API uses. A connection now carries a replication network as a CIDR, and the stream resolves the destination node's address inside it, the way a Proxmox datacenter uses its own migration network. The setting belongs to the connection whose nodes receive the stream, so a failback reverse sync reads the source connection's. A network matching no address on the node fails the run with the addresses that node does carry instead of falling back silently. See Connections. (Enterprise)
  • Interval schedule mode -- A job whose RPO target read 30 minutes replicated every ten, the scheduler taking a third of the target as margin, which made seven days of retention at that cadence impossible under the snapshot cap and said so nowhere. A schedule now states its cadence directly in minutes, restricted to regular ones, and the create and edit dialogs spell out the cadence the chosen schedule really produces and how far back the kept restore points reach. See Site Recovery. (Enterprise)
  • Fine-grained guest configuration rights -- vm.config splits into five sub-rights, media, NIC link, NIC, hardware and boot, with vm.config kept as a super-right implying them all, so the built-in roles are unchanged and a custom role can be cut finer. The configuration write classifies every key of the body into its sub-right and checks the union, a NIC change being diffed against the current configuration to tell a link toggle from a rewiring. The guest interface follows the same rights: Hardware, Options and Cloud-Init render read-only without them, and the create actions disappear without vm.create. See RBAC. (Enterprise)
  • A compute policy and ISO libraries per vDC -- A vDC now carries a CPU model mode, unrestricted, the cluster's custom models only or an explicit list, a default model for new guests, and a switch hiding the advanced CPU controls. Enforcement is server-side on the configuration, create and deploy routes, and a guest keeps a model that later leaves the allowed set so a provider template survives an edit. A provider can also hand ISO storages to a vDC as read-only libraries: the provider catalogue is visible to every vDC granted the storage, a tenant's own uploads stay visible to that tenant alone, and a library is never a write target for backups, disks, clones or restores. An optional switch lets the tenant upload into a namespaced area, with the upload button added to the CD/DVD dialogs since a tenant has no storage screen. See Virtual Datacenters. (Enterprise)
  • A VXLAN transport per vDC, and stretched tenant networks -- A tenant zone took its peers from the cluster status, so the overlay always rode the corosync addresses, frozen at creation, with no MTU and no way to change them afterwards. A vDC now chooses between the historical cluster mode, an explicit operator peer list that may name endpoints outside the cluster, and a dedicated transport segment whose per-node addresses ProxCenter provisions on an explicit action rather than on save. Two vDCs of one cluster may share an identical transport, a legitimate single operator fabric kept apart by the VNI, but a divergent one is refused by name because both would claim the same interface. A tenant-wide VNI reserves one L2 segment that several vDCs carry, and provider SDN VNets are accepted as shared uplinks with their allowed VLAN pool shown in the deploy wizard. See Virtual Datacenters. (Enterprise)
  • SSO groups map into tenants and vDCs -- The mapping was a flat object granting one role in the provider tenant, and its login re-sync owned a single assignment row hardcoded to the default tenant. An entry now carries a tenant and an optional vDC, a vDC resolving to a pool scope on its Proxmox pool, and a configuration written before this release reads back unchanged with no migration. The takeover rule became per tenant, an administrator owning a user in one tenant having otherwise frozen the identity provider out of every other one. Signing out also ends the provider session: the end-session endpoint is discovered from the issuer, the id_token is kept to serve as a hint, and a provider that advertises none keeps the local sign-out. See LDAP and OIDC.
  • 53 Prometheus metric families and five Grafana dashboards -- The public metrics endpoint exposed seven families. It now answers with 53, declared in one registry, covering cluster reachability and degradation, Ceph health, node memory, root filesystem, uptime and maintenance, guest memory, uptime and HA state, backup servers and their datastores, and the guests carrying no backup at all, which the old exposition could not count. Five dashboards ship with the image for the fleet, the nodes, the guests, the storage and backup compliance, built on core panels only so nothing has to be installed beside Grafana, and they are bound to the family registry by a test so a renamed metric cannot leave a panel blank. See API Tokens. (Enterprise)
  • Guest disk latency -- Derived from the QEMU block statistics: a Latency column in the guest table with a per-disk tooltip, one column per storage in the storage overview, one curve per disk on a second axis of the Disk I/O chart, a Storage Latency widget on the home dashboard, and a per-storage alert with its own warning, critical and sustained window. The metrics collection cadence, which lived only in the orchestrator's configuration file, now travels with the alert thresholds as a slider from 30 seconds to 10 minutes, the orchestrator rescheduling its collection when it changes. See Alerts. (Enterprise)
  • A DRS History tab -- DRS migrations were visible only in the Task Center, mixed with rolling updates and migration jobs, and without the reason DRS moved the guest. A History tab lists them newest first, grouped by day, with the reason, the duration and the outcome, plus cluster, status and name filters. The reason and the maintenance-evacuation flag are copied onto the migration row when it starts, the recommendation that carried them being pruned long before the row is; rows written before this release read as not recorded. See DRS.
  • A Guests per Node widget -- A dashboard widget listing every guest under its node and its cluster with its name, CPU and RAM visible at once, where the Guest Map shows one metric per tile and the name on hover only. Cluster rows carry the node count, the running and total guest counts and a load aggregated from their nodes, since the dashboard API exposes no per-cluster figures. The tree is collapsed by default and remembers what the user opened, and every level derives from the RBAC-filtered nodes and guests.
  • A backup server datastore attached from the inventory -- Adding a backup target no longer means leaving ProxCenter for the Proxmox web interface. The cluster Storage tab mounts a registered Proxmox Backup Server datastore as a storage, optionally scoped to a namespace and to given nodes, with a per-row detach. The credential the cluster receives is a sub-token minted for that datastore alone and never the admin token stored on the connection, its identifier derived from the cluster and the storage name so two identically named clusters never share one, and detaching revokes it unless another cluster still runs its backups through it. See Backups.
  • USB and PCI passthrough through resource mappings -- Proxmox only lets the root account, logged in with a password, attach a device given by its real hardware address, and an API token never satisfies that check, so the raw forms of the hardware dialogs could not succeed and failed with a root-only error. Devices are now attached through datacenter resource mappings, the dialogs listing the mappings the connection's token may use with the per-node checks Proxmox applies. The raw option stays visible but disabled with an explanation, an existing raw device opens read-only, and the Hardware tab labels a mapped device with its mapping name.
  • An LXC container features editor -- Containers reused the QEMU Options tab as it was, so VM-only rows showed up for them, features could only be set at creation time, and renaming wrote the key the configuration route refuses for a container whose display name is its hostname. The Options tab is now gated by guest type, a container renames through its hostname, and a Features row edits nesting, keyctl, FUSE, device nodes and NFS or CIFS mounts. On an unprivileged container only nesting is editable, Proxmox reserving the other flags to the root account itself, so they are shown locked with the reason.
  • Fullscreen and a detachable window for the node shell -- The shell tab is boxed into the node detail panel, which left around 380 pixels of terminal to read a log or edit a configuration file. Its status bar gains a fullscreen toggle and a pop-out control, and the tab's landing screen opens a window directly, so a shell per node costs one click. Windows are named per node, a second click raising the existing one, and each opens its own single-use session rather than stealing the tab's. The terminal is refitted on every resize and fullscreen transition, the remote pseudo-terminal keeping its old geometry otherwise.
  • A self-updating cloud image catalog -- The built-in catalog was a hardcoded list that went stale on its own: a pinned Fedora URL started answering 404 after an upstream respin, so deploying that image failed outright. The catalog is a validated document now, refreshed daily from a remote source and falling back to the built-in one, with per-distribution cards, real build dates, the source the entry came from and a manual check for updates. See Templates.
  • CSV and JSON exports -- The change tracking timeline exports what the filters select, every page of it and not the rows on screen, quoted per RFC 4180 because a configuration diff carries commas, quotes and newlines, and written with a byte order mark so a spreadsheet reads it as UTF-8 instead of the local codepage. Dashboards export and import as one JSON file, the import checking every connection, cluster and node selector against what the target install actually has, keeping what resolves, dropping what does not and saying how many widgets it touched. A report downloads its data as one CSV next to its PDF. See Change Tracking.
  • A Customization tab for the report PDF template -- Reports came out of a fixed layout, so a tenant could not put its own header, colours or fonts on the PDFs it sends to auditors. The tab edits a structured template plus a free-form stylesheet and renders a preview against fixed sample data before anything is saved. A stylesheet that could reach outside the document is refused, imports, non-data URLs and oversized payloads included, and the renderer serves data URIs only. See Reports. (Enterprise)
  • Cross-cluster migration prerequisites cleared from the dialog -- Proxmox refuses to remote-migrate a guest that is HA-managed, replicated or carries snapshots, and the dialog reported only the first of the three, so the other two surfaced as a raw Proxmox error once the migration had already started. All three are read from the source when the tab opens, cleared from the dialog itself, then re-applied on the target once the migration succeeds or put back on the source when it fails. A Site Recovery job stays a warning with no remediation button, since one job can cover several guests and clearing it would stop replicating the others. See Migration. (Enterprise)

Improved​

  • A source without guest tools is powered off hard at cutover -- A guest with no VMware Tools, or no XCP-ng guest tools, refuses the shutdown request on the spot, so the 30 minute operator wait could only ever end with a click on Force power off, once per guest on a bulk run. The warm pipelines recognise that refusal now, power the source off hard at once, confirm the powered-off state and move on to the final delta. The operator step and its button stay for every other refusal, and the job log warns at planning time when the source reports no running tools. See Migration. (Enterprise)
  • Parallel disk downloads, with honest thin-disk progress -- The cold vCenter path downloaded the disks one at a time while the transfer ceiling is per stream, so a 5 TB guest spent more than a day at 27 MB/s. The export now runs a bounded pool with a fresh lease per disk, sized by a 1 to 8 slider in the single and bulk dialogs, persisted on the job and replayed on retry. Progress no longer compares compressed bytes on the node with the provisioned capacity: the position is read from the markers inside the stream, so a thin disk reports a real percentage and the task bar gets a usable estimate. Stopping a download now kills the transfer itself rather than its wrapper, which used to leave the stream running and the lease open. See Migration. (Enterprise)
  • DRS balances inside each placement domain -- The homogenization pass computed its trigger, its average and its source and target classification over every node of the cluster. On a cluster cut into role-dedicated SDN zones that produced only cross-zone pairs, rejected one by one, while an imbalance confined to a single zone was never examined at all: with a busy zone at 80 percent and a quiet one at 20, every node of the first sits above the cluster average and every node of the second below it. Guests are grouped by the set of nodes they can really run on and each group is analysed with its own average and spread. They are also weighed by the memory their cgroup really holds on the node instead of the balloon figure, which counted a guest with drivers at 1.2 GiB where moving it frees 8. See DRS.
  • DRS says what constrains placement -- A cluster segmented by SDN or by a node-restricted storage showed a load spread that never comes down and no recommendation at all, which reads as a broken DRS. A card now lists, per cluster, the balancing domains with their nodes and their spread, and the guests no other node can run with the reason, while a chip in the cluster header names the cause, SDN or storage or both, read from what the orchestrator reports rather than guessed. The status payload is filtered per connection and through the RBAC infra scope, these being the first status fields to name guests. See DRS.
  • Every installed package is scanned for CVEs -- The scan read the Proxmox update endpoints, which expose the distribution's own packages plus whatever has an update pending: 62 of the 929 packages installed on a node, so a patched cluster reported zero vulnerabilities by construction. The inventory now comes from the package database over SSH, which also names the source package a tracker expresses its fixed version against, and findings are keyed on that source package instead of repeating across every binary it builds. The API path remains as a fallback for a connection without SSH, labelled partial rather than passed off as a full scan. See CVE Scanner. (Enterprise)
  • The CVE tab says what the scan covered -- It dropped every failed response on the floor, so a scan that could not reach the security tracker, or that the licence gate refused, rendered the same green no-vulnerabilities state as a healthy cluster. An error surfaces with its cause and a way to retry, the header carries how many packages were scanned and how many the tracker knows about, and the empty state says whether the node was read in full or only through the API, naming the reason. Findings with no published fix are counted on their own chip and kept out of the default view. See CVE Scanner. (Enterprise)
  • Ceph objects open their details, and the cluster flags are set from the page -- OSDs, pools and monitors were listed as bare names, every column the screen could not fit being simply lost, and nothing on the page could act on the cluster. A row now opens a detail dialog with what the API already returned, version, reweight, placement groups and latencies for an OSD, target placement groups, autoscale mode and CRUSH rule for a pool, rank and store size for a monitor, and the cluster OSD flags are set from the page. Two traps are handled rather than displayed raw: a down OSD reports zero latency, which would read as a perfect disk, and a pool's used ratio is a fraction where an OSD's is a percentage. See Ceph.
  • Site Recovery sessions open on a live cluster node -- The API client has failed over to another cluster member since v1.4.7, but the SSH sessions Site Recovery opens, and the destination of the transfer, still resolved from the configured base URL, so a replication or recovery run still stopped with the node the connection points at. Both dial the configured host first and, only on a network failure, the other members the inventory knows, each with a short timeout and the member the API layer has already failed over to tried first. A healthy cluster keeps every session on the configured node. See Site Recovery. (Enterprise)
  • An exclude pattern for stale snapshot alerts, and readable alert values -- Replicas kept as Proxmox snapshots by a third-party backup tool raised a stale-snapshot alert nobody can act on, and the exclude pattern of an event rule cannot reach them, these alerts being a threshold check and not events. The Stale Snapshots card gains an exclude expression matched against the guest and snapshot names, judged by the orchestrator alone because the syntax it accepts is not the one a browser accepts. Alert values were printed raw, a percentage to fifteen decimals and a percent sign glued to a figure measured in days; they round to one decimal and carry their own unit now, on the alerts page and in the dashboard dialogs. See Alerts.
  • The command palette finds guests by IP, MAC and notes -- It matched guest names and VMIDs only. It now also matches MAC addresses read from the guest configuration, so it needs no guest agent and works on a stopped guest, with the separators written any way; IP addresses, both the ones pinned in the configuration and the live ones, taken from a per-connection index refreshed in the background rather than from a probe per request, a stopped guest keeping its last known addresses flagged as such; the notes field, with the matching excerpt in the row; and node IP addresses. Rows carry the inventory's guest and node icons with their status badge.
  • Nested pools render as a tree -- Pool identifiers containing a separator, the nested pools Proxmox has supported since 8.1, were listed flat. They now render as an indented, collapsible tree like the Proxmox interface, intermediate pools without direct members being synthesized from the path, parent counters aggregating their descendants and the expand button covering every level. See Inventory.
  • Infra scope isolation for aggregate reads -- The RBAC infra scope introduced for the inventory tree now covers the aggregate endpoints too: the change feed, the Proxmox tasks and logs, the dashboard, the orchestrator alerts and the alert rules. A user scoped to a connection, a node or a guest sees only the rows attributable to their grants, a guest grant no longer opening its node, while administrators, global grants and tag or pool scopes are unchanged. The inventory tree also groups hosts under their cluster for every user holding an infra scope on a tenant that owns whole clusters, instead of for super administrators alone. See RBAC. (Enterprise)

Fixed​

  • A warm migration whose source the node cannot read is refused up front -- A warm run against an old ESXi reached the copy and died on the first block with an I/O error after zero bytes: the disk library opens the disk over SOAP and reports the right capacity, so the NBD stack comes up, and only the data channel refuses, each library release supporting its own vSphere release and the two before it. The source version was captured at login and then read nowhere, so the operator paid for the whole plan before finding out. The dialog and the engine compare it with the generation found on the node, refusing below vSphere 6.5, which nothing runnable on Proxmox VE 9 can read, and warning inside the band that is outside the matrix but may still work. The node probe resolves the library's versioned name rather than the unversioned symlink, which could only ever answer that something was installed, and a failed block apply now shows the real error instead of the wrapper that hid it. See Migration. (Enterprise)
  • Warm migrations no longer wedge NBD devices -- Guest LVM volumes activated on the host kept NBD devices pinned after a successful detach, exhausting the migration slots until a reboot. Holders are now released by walking the kernel holder tree of the owned device, partitions and leaves first, so identical guest and host volume group names cannot widen the cleanup, and node preparation excludes the transient NBD devices from the host LVM filter, with the edited configuration validated and its backup restored if it does not hold. See Migration. (Enterprise)
  • Cutover now takes effect -- Cutover did nothing on a warm run: the route filled a set held in module memory while the pipeline polled a different one, a route compiled after the pipeline started getting its own instance of the shared module, and the same gap opens with a second frontend replica since only one process owns the job. Cutover, hard power off and the multi-boot root pick are recorded on the job row now, where cancel already wrote its status, and every pipeline mirrors that row back into its own registry while the run lasts. The confirmation dialog also stays open and states the reason when a request is refused, instead of closing as if the action had gone through, which is what made a lost click indistinguishable from a successful one. See Migration. (Enterprise)
  • IDE and SATA disks keep their bus -- The hardware mapper put every disk on VirtIO SCSI under the q35 machine type whatever the source controller was, although the parser already knew it, and Proxmox hangs IDE disks off the AHCI controller on q35 where only two of them can exist, so a closed appliance with four IDE disks never found them. IDE disks now come back at their source position on IDE and switch the machine type, SATA disks stay on SATA, and the QEMU agent is left off when the source has no tools installed. See Migration. (Enterprise)
  • A cut off cleanup no longer reads as a finished one -- The dialog keyed its banner on an empty error list, so any payload without one read as a success: an aborted cleanup came back green with its retry button gone, while the DR guests were still up on the replica images and replication was about to resume onto them. It keys on the orchestrator's own verdict now, keeps the retry button until that verdict is true, and says what an unfinished cleanup means. The client budget was too short to begin with, 30 seconds against a cleanup measured at 20 for a single-disk guest and handling them one after another; it gets 55, under the read timeout of a packaged install so an abort comes back as our own error. Auto-HA also stops enrolling DR replicas, which reached their cluster as new guests, were handed to the resource manager as started and undid every stop the cleanup issued. See Site Recovery. (Enterprise)
  • A test failover suspends only the guests under test -- It paused every replication job covering the plan, so a job also carrying guests outside it stopped protecting them for the whole length of the test, which a tag-based job makes routine: one guest under test, a dozen left unprotected. A job the plan covers entirely is still paused outright, which keeps the cleanup's resume honest; a job with guests left over keeps running and skips the claimed ones, reported as suspended on the per-guest table rather than left looking stale. The claim is read off the plan, the only way to cover a tag-based job whose own guest list is written at the end of a run, and the pre-flight wait watches the plan's guests rather than the job status, so a test no longer queues behind an unrelated guest. See Site Recovery. (Enterprise)
  • A guest two jobs replicate is refused -- Snapshot housekeeping works per image and not per job, keeping the newest mirror snapshots of a source image whoever wrote them, so two jobs on one guest prune each other's base and the one left without a common snapshot cannot re-seed on its own. Creation refuses the overlap and names the job already holding the guest, and the create dialog greys those guests out while the operator chooses rather than refusing after submission. The check is on the source cluster alone, the same VMID on another cluster being a different disk. See Site Recovery. (Enterprise)
  • The initial sync streams a sparse diff -- The first sync of a disk piped an export into an import, and written to a pipe the export emits zeros for every unallocated extent, so a thin 500 GB disk holding 96 MiB of data cost 500 GB on the wire. It now runs as a diff without a base, which carries the allocated extents only and creates its end snapshot itself, the target image being created beforehand at the source size and stamped with the job identifier so only this job's own interrupted first sync is ever replaced. Bytes credited to a disk are what the transfer really measured, instead of the image size that used to credit a 60 GB disk to every twenty-second incremental. See Site Recovery. (Enterprise)
  • Failback across differently named Ceph pools -- Failback assumed the production disks lived in a pool carrying the DR pool's name, in the reverse pairing and again in the rollback, so a plan whose DR pool is named differently could never start its reverse sync: every guest failed the pre-check with a specification mixing the DR pool name and the production image name. The production pool is resolved per disk from the source guest's configuration on the production cluster, each DR disk paired by its rewritten image name, and a DR disk with no counterpart fails closed with both names rather than guessing. See Site Recovery. (Enterprise)
  • A Ceph cluster in HEALTH_ERR no longer blocks a replication job -- Ceph 20.2.4 added insecure-authentication checks, two of them at error severity, so a cluster still holding old keys reports HEALTH_ERR while serving I/O perfectly, and the preflight turned every status other than OK or WARN into an error, which made a job against such a target impossible to create. It blocks only on the conditions that actually refuse writes now, full OSDs or pool, inactive placement groups and the pause and full flags, and warns on the rest. The detail was also read from the first iteration of a map, so an operator got one of the eight checks at random and a different one on each reopen; every condition is named and sorted by code, in the preflight and in the connection diagnostics alike. See Ceph. (Enterprise)
  • Ceph charts read in the browser timezone -- The page mixed two clocks: the historical series received a label pre-formatted inside the API route, which carries the container's clock, while the live series formatted their own in the browser. The route returns the raw timestamp and every axis is built locally now, with seconds on the rolling live windows and a date beyond a day on the historical ones. Snapshot times had the same defect and are formatted the same way. See Ceph.
  • White label brands a tenant again, and only as a super administrator -- The branding row has been keyed by tenant since multi-tenancy landed, but the tenant boundary pass swept the tab into the provider-only group along with the tabs that really do configure the provider, which left no path to brand a tenant at all. It is gated on the super administrator alone now, whichever tenant they stand in, and the write routes carry the same check, which they needed, having only asked for the settings permission a tenant administrator already holds. See White Label. (Enterprise)
  • The white-label favicon and the browser tab title -- The application ships both an icon file and an SVG icon, so two icon links are rendered and the browser keeps the SVG; rewriting only the first match repointed the file nobody reads and left the stock icon in the tab. Every icon link follows the upload now, with its type recomputed. The tab title also joined every running task, and Proxmox keeps a shell task open for as long as its console is, so three open shells read as the same name three times: one job is named and the rest are counted, the shell task types that showed through raw are translated, and the base title is no longer captured before the white-label title reaches it, which used to restore the stock name over the tenant's own. See White Label. (Enterprise)
  • An SSO login no longer re-adds its own role -- The users dialog deletes every role row of a user, the provider-owned one included, and writes back its own, while the login re-sync only ever deleted the provider row, so finding none it created a fresh one. The user then carried two roles, the role picker opened empty because of it, and a demotion below the configured default was undone at every login. A provider row that is gone while an administrator-granted one stands now means the administrator owns the role and the re-sync leaves it alone; clearing the role in the dialog still hands the user back to the identity provider. See LDAP and OIDC.
  • DRS stops proposing migrations the target node cannot run -- Every eligible node was scored as a target without checking that the guest could run there, so a cluster segmented into SDN zones kept recommending moves that fail in the second phase, after the target guest has already been started, because the VNet does not reach the other zone. Proxmox does not help on the network side, its migration precondition reporting every node as allowed for a guest attached to a restricted zone, so the placement filter resolves each interface to its VNet and that VNet's zone, and each disk to its storage, then drops the nodes they do not reach. It is wired into every path that picks a target, reactive and proactive balancing, affinity enforcement, maintenance evacuation and the rolling update placer. See DRS.
  • A subscribed node is no longer refused its update -- The repository preflight flagged every enterprise repository enabled without a no-subscription counterpart as a blocking error, without ever reading the node's subscription, so a node with an active subscription running the production layout Proxmox recommends was refused every update. The preflight reads the repositories and the subscription together now and skips the enterprise rules when the subscription is active; an unreadable subscription counts as inactive, the strict side, and unparsable repository files stay blocking regardless. See Rolling Updates.
  • A user whose assignment keeps the default scope gets the whole inventory back -- An assignment left on Default carries an inherit sentinel that the server resolves everywhere, but the client hook still read the raw scope type, so inherit matched neither the infra bucket nor the tag and pool ones and the inventory fell back to its minimal profile: guests, favourites and templates, with no tree, hosts, pools or tags view. Setting an explicit global scope worked around it, which is how it was reported. The hook reads the aggregated scope types from the RBAC context now, which also covers a user whose only grant is a direct permission. See RBAC. (Enterprise)

Security​

  • Advisories closed on the frontend chain -- next 16.3.3 for a cache path traversal leaking a manifest encryption key, sharp 0.35.4, svgo 4.1.0 and the AI SDK provider utilities, which arrive through the embedded API reference viewer and pin an exact version, so an override is the only way to move them. fast-uri is bumped alongside.
  • The mysql2 pin inherited from the Prisma CLI is overridden -- The CLI pins mysql2 to an exact version carrying two advisories. ProxCenter only talks to PostgreSQL and the CLI imports that driver lazily for the MySQL provider alone, so the code never loads, but the package still sat in the lockfile and in the runtime image, and an exact transitive pin cannot be bumped automatically.

Upgrade notes​

  • Pull the images. Eight schema migrations ship with this release and are applied by the frontend entrypoint at first boot, and the orchestrator updates its own schema when it starts. Nothing has to be edited by hand, on a standalone install as on an HA cluster.
  • proxcenter_backup_age_seconds gains node, name and type labels. An aggregation over the bare metric needs a max by (vmid) or an equivalent. See API Tokens.
  • A guest can only belong to one replication job. Creating a job that covers a guest another job already replicates, or adding it to a job's guest list, is now refused; an existing overlap keeps running but leaves the two jobs pruning each other's snapshots.

v1.4.9 -- 2026-08-29​

The API reference inside the product, warm migration from XCP-ng, and rolling updates you can watch and approve. The public OpenAPI document is rendered under Settings with Try-it against your own instance, XCP-ng pools connect directly through XAPI and migrate warm with CBT over NBD, and a rolling update shows apt's own progress per node, waits for an explicit approval when asked to, and honours the parallel migrations setting it had been ignoring. Alongside them: PBS 4.x compatibility, an HA control plane that elects one leader and serves the DRS page from any node, DRS migrations that no longer stay stuck at running after an orchestrator restart, a replication job that continues past a failing VM, and a large batch of Hyper-V, console, and notification fixes.

Added​

  • API reference inside the product -- Settings gains an API reference page rendering the public OpenAPI 3.1 document, with Try-it targeting the logged-in instance. It is reached from the API tokens tab and from the command palette, gated like the API tokens tab, follows the white-label branding and the colour scheme, and ships with the embedded viewer's AI agent, developer toolbar, request proxy, telemetry and remote fonts all disabled. See API Tokens.
  • XCP-ng direct pool connections and warm migration -- An XCP-ng pool can be connected directly through XAPI, next to the Xen Orchestra mode, and a direct pool connection is the default for a new connection. A warm migration from XCP-ng takes a full copy of a live snapshot, then delta passes over NBD with TLS until the cutover, automatic or manual, with a checksum fallback when the storage repository lacks CBT. It needs a direct pool connection, a block storage target, NBD enabled on a pool network, and nbdkit, nbd-client and libnbd on the Proxmox node, all checked by the preflight. The Live mode is removed: it never worked, its snapshot call answered 422 on every pool. See Migration. (Enterprise)
  • Rolling updates: live progress and manual approval -- The progress bar advances with apt's own position, downloading, unpacking, configuring or waiting for the lock, and a collapsible apt output panel per node opens by itself on failure so the real cause is on screen. A run can require an explicit approval before each node, from the wizard or from the Task Center detail dialog, and cancel is honoured while paused. Finished runs stay in the Task Center with their full log, a cancelled run reads cancelled, and every wizard parameter carries a tooltip. See Rolling Updates.
  • Rolling updates: parallel evacuation with real placement -- The maximum parallel migrations setting was never read; guests are now evacuated through a worker pool and spread across targets by projected load, memory weighted over CPU, with a bonus for the preferred target and a refusal past 90 percent projected memory, honouring the DRS affinity rules. The preflight plan names the targets the run will really use, and a failure to enter HA maintenance is an error when the node hosts HA guests instead of a warning followed by a reboot under them. See Rolling Updates.
  • Partially synced replication jobs -- A replication job continues past a failing VM instead of stopping and leaving every later VM unprotected, and lands in a new Partially synced status with the failed VMs named. The Protection and Emergency DR tabs, the dashboard, the alert engine and the Site Recovery report all know the status, and a partial run notifies only the VMs newly failing. See Site Recovery. (Enterprise)
  • Consoles: fullscreen, scaling, power actions -- Both the noVNC and SPICE consoles gain fullscreen with an auto-hiding toolbar and a scaling selector, fit to window, resize the guest or 1:1, remembered per console kind. The SPICE toolbar gains start, shutdown, stop and pause with an automatic reconnect once the guest is up, plus reconnect, close and Ctrl+Alt+Del. noVNC gains a send-key menu and a send text to guest clipboard action.
  • Compact OS Windows guests convert -- The ntfs-3g system-compression plugin is built and installed by the migration preflight, shown as a required item in the dialog and installed on the fly when missing, so a Windows guest installed with Compact OS no longer fails its conversion. See Migration. (Enterprise)

Improved​

  • Cold migrations to file storage write the disk once -- On dir, NFS, CIFS, GlusterFS and Btrfs targets the converted image is adopted in place instead of being copied a second time by qm disk import, so the temporary space requirement drops from twice to once the disk size. Block targets and the warm pipeline are unchanged, and the legacy path remains as a fallback. Target nodes should run pve-qemu-kvm 11.0.3 or later: 11.0.0-1 and 11.0.0-2 carry a data-loss bug on sparse qcow2 images. See Migration.
  • Hyper-V inventory and migration -- The VM listing is a single PowerShell call with disk sizes read without opening every VHDX, so a freshly added connection no longer shows as unreachable; wrong credentials show an authentication error instead of a green Online; disk paths on SMB shares are resolved correctly; a failed migration is retried on the engine of its source type; a running source VM or one with checkpoints is refused with a message saying what to do; and Hyper-V and Nutanix guests keep their source CPU count and memory instead of the 1 vCPU and 2 GB placeholders. See Migration. (Enterprise)
  • Node update preflight reads every Proxmox field -- The repository check named undefined instead of the unreadable file, the enterprise-repository-without-free-alternative check had never fired since it shipped, and an empty repository list let the update start unchecked. All three read the right fields now, remediation text matches the problem found in six locales, and the compliance hardening check for repositories reads the right field too.
  • Rolling updates reach nodes on their management address -- The interface carrying the PVE URL host, then the default gateway, then vmbr0, instead of the first bridge, which could be a Corosync or Ceph network. The Ceph wait only holds on HEALTH_ERR and recovery checks, not on our own noout flag or unrelated warnings, and the disk preflight applies a 2 GB floor instead of failing a 14 GB root with 4.8 GB free. A non-root SSH user needs NOPASSWD: ALL; the sudoers page says so and its generated template ends with that line commented.
  • Install missing packages gets a 20 minute budget -- The 30 second budget left nodes half prepared, and a 401 from the enterprise repository no longer aborts the installation of packages that come from Debian.
  • Task Center -- Running DRS migrations show their real percentage instead of a constant 50 percent, an unreadable percentage shows an indeterminate bar, and rolling update runs are listed over the whole history with their log. See Task Center.
  • Tooltips stay reachable on disabled buttons -- Across the backups tabs, inventory tree, firewall panels, compliance, Site Recovery snapshots, HA node card, Ceph, connection settings, dashboard widgets and navbar, the reason a button is unavailable is readable, and icon-only buttons keep an accessible name.
  • The storage overview table fills the page and scrolls internally instead of sitting in a fixed 600 pixel box.

Fixed​

  • HA: one orchestrator leader at a time -- The leader lock was an advisory lock taken on whatever Postgres connection HAProxy handed out; on a hot standby the lock succeeded while every write failed with SQLSTATE 25006, so two orchestrators believed they led. The lock is now taken on the primary only, checked in the same round trip, and the pool pins target_session_attrs=primary so a connection routed to a standby is refused loudly and retried. A leader whose primary is demoted steps down within one heartbeat.
  • HA: the DRS page is populated from any node -- Metrics and recommendations live in the memory of the leader, and the frontend used to call the orchestrator local to the node holding the VIP, so the DRS page read No cluster connected whenever the VIP holder was not the leader. A new unauthenticated GET /api/v1/leader probe answers 200 on the leader only, the generated HAProxy configuration gains a leader frontend on 127.0.0.1:8081, and the frontend routes /metrics and /drs calls there through ORCHESTRATOR_LEADER_URL. See the upgrade notes for clusters deployed before this release.
  • HA: a long preflight returns its verdict -- The multi-cluster HA preflight could outlive the orchestrator's write timeout, so its response was cut and the UI reported a false Orchestrator unavailable while the port verdict was lost. The write deadline is cleared on every HA route, and a response cut mid-flight is now told apart from a dead orchestrator, with the orchestrator's own 400 and 409 payloads reaching the wizard verbatim.
  • DRS migrations no longer stay stuck at running -- A migration's status was advanced only by a goroutine living in the orchestrator process, so a container restart, upgrade, OOM or the ProxCenter guest being evacuated by the DRS itself left its rows at running forever, and the only self-heal looked the row up in memory and answered 404. Rows left running are now reconciled from the Proxmox task state, or the guest's placement, at boot and every five minutes, a migration genuinely still in flight is re-adopted with its remaining budget, and the sweep runs on the leader only. See DRS.
  • Site Recovery: a replicated VM carrying a Proxmox snapshot syncs again -- Disk discovery read the snapshot sections of the guest configuration and tried to create an RBD snapshot that already existed. Configuration parsing now stops at the first section header and deduplicates disks, and the replica configuration rewrite is no longer truncated by a blank line. The replication failure alert is held while a job runs, so a rerun longer than three minutes no longer flaps it.
  • PBS 4.x compatibility -- Refreshing the package database no longer fails with Expected boolean value, toggling a repository uses the right method and payload, API tokens are listed instead of always none, the S3 endpoints tab works instead of reporting unsupported, prune jobs appear in the job listing, and the sync, verify, prune and tape job configuration routes go through /config/* with the delete array to clear a field. Verified against PBS 4.2. See Backups.
  • sFlow configuration succeeds -- The ovs-vsctl target quoting was wrong, so every press of Configure sFlow wiped the existing configuration and put nothing back. The action now reports per-node results, a node without an OVS bridge is reported as nothing to configure, an audit entry is written, the configuration is re-applied every ten minutes on nodes whose bridges lost their collector, for instance after a reboot, and flows are attributed by guest MAC on SDN topologies where the guest interface is not an OVS port. See Network Flows.
  • Commas work in the default recipients field -- Typing a comma erased it, and the semicolon workaround stored one glued entry that silently cut every notification. Commas, semicolons and line breaks are all accepted, a glued list is re-split on load and repaired on save, invalid entries are flagged on blur without blocking save, and the orchestrator splits glued lists before sending. See Notifications.
  • XCP-ng offline downloads survive a slow SSH poll -- The poll misread a timeout as curl exiting 1 and deleted the partial file; the same fix applies to the nine equivalent loops of the direct ESXi pipeline, and the download is retried three times with curl's own error text.
  • Warm node preparation refuses Proxmox VE 8 with a clear message -- The nbdkit-plugin-vddk package only ships from Debian 13, so the Prepare the node action is hidden on a PVE 8 node and the script refuses before its first apt call instead of leaving a half-installed node behind a raw apt transcript.
  • Editing an external hypervisor connection no longer rewrites the stored user with the type default, and cancelling an offline XCP-ng job actually signals it.

Security​

  • noVNC no longer logs the keystrokes typed into a guest, passwords included, to the browser console.
  • XCP-ng warm migration pins the host certificate for NBD, passes credentials through a 0600 curl configuration file, and redacts the session id from logs.
  • Dependency batches -- Twenty-five updates, including undici 8 pinned to HTTP/1.1, cron-parser 5, dagre 3, react-resizable 4 and @types/node 26.

Upgrade notes​

  • Pull the images. One schema migration ships with this release and is applied by the frontend entrypoint at first boot: the XCP-ng connection sub-type, backfilled to Xen Orchestra for existing connections.
  • HA clusters deployed before v1.4.9 need two edits on each node to enable the DRS leader routing: the HAProxy leader frontend and the ORCHESTRATOR_LEADER_URL variable are written by the deployment templates and an image pull does not add them. Nothing breaks without them; the DRS page behaves as in v1.4.8. The procedure is in HA Prerequisites.
  • XCP-ng Live mode is removed; a job that used it must be recreated as Offline or Warm.
  • Rolling updates with a non-root SSH user need NOPASSWD: ALL; a per-command sudoers allowlist, including the one generated by the settings page, is not enough.
  • Cold migrations to file storage should target nodes running pve-qemu-kvm 11.0.3 or later.

v1.4.8 -- 2026-08-24​

vDC storage policies and tenant VLAN networks. A provider now governs tenant storage with QoS caps and per-tier quotas, and hands each vDC its own VLAN ranges to build networks in, self-service. Alongside them: a Task Center that finally shows every job, migrations included, warm migration nodes the product prepares itself, replication RPO and Ceph OSD latency alerts, and a large batch of Site Recovery, migration, and access control fixes.

Added​

  • vDC storage policies with QoS caps and per-tier quotas -- A provider declares a policy on a connection and one of its storages, sets read and write IOPS and bandwidth caps and a quota for that tier, then assigns policies to vDCs. The caps are stamped on the virtual machine disks a tenant creates, deploys, clones, restores, rolls back, imports, or moves, and per-tier usage is metered from the storage content listing rather than from the declared size, so an import-from allocation is counted for what Proxmox really allocates. Changing a policy's caps re-applies them to the disks already governed by it, with live progress, and the deploy wizard is gated on the tier quota instead of failing on its last step. The storage a policy governs has to be shared and to advertise disk images or container volumes. See Virtual Datacenters. (Enterprise)
  • Tenant VLAN networks with provider-managed pools -- A provider hands each vDC one or more VLAN pools, each a bridge paired with a tag range, and the tenant then creates its own networks inside them, self-service, with the tag allocated from its pool. ProxCenter derives and creates the SDN zone itself, one per connection and bridge, on the first tenant VLAN network. A pool also authorises the tags a tenant may set on a guest NIC attached directly to that shared bridge. VXLAN allocation is floored at VNI 10000 so a VLAN tag can never collide with it, and external addressing is offered on VLAN networks only. See Virtual Datacenters. (Enterprise)
  • Optional VMID ranges for vDC tenants -- The restriction to MSP tenants was purely application side. A vDC tenant on a shared provider cluster can now carry a range, with the used-VMID scan resolved through its vDCs so uniqueness and the next free id stay correct across tenants on the same cluster. The range is also a column of the tenants table, sorted on its lower bound. See Multi-Tenancy. (Enterprise)
  • Migrations in the Task Center -- The page aggregated four orchestrator sources and never the migration jobs table, so the Migration filter it offered could never match anything. Migration jobs join as a fifth source, scoped by target connection so a vDC tenant sees its own migrations even though it does not own the source hypervisor connection, and a migration can be cancelled from there. The ProxCenter tab of the tasks bar carries the same jobs over the whole history, and a double click on a row opens that job's details. See Task Center.
  • ProxCenter prepares a warm migration node -- Broadcom closed the public VDDK download in August 2026, so the portal URL the node-setup guide pointed at now returns 404 for everyone. The VDDK ships through a private registry package instead, and the migrate dialog gains a Prepare the node action that installs nbdkit, nbd-client, and the nbdkit VDDK plugin, enables the Debian non-free component, unpacks the VDDK, adds the symlink the nbdkit shipped with Proxmox 9 needs, and loads the nbd module. Every step is idempotent, and the manual guide stays as the fallback for a node without registry egress. See Migration. (Enterprise)
  • The operator chooses the warm cutover moment -- A warm migration used to switch over as soon as the projected downtime fitted its budget. In manual mode the run keeps issuing delta passes, paced at one per minute, with no expiry, until the operator asks for the switchover or cancels, and the downtime shown at the moment of the click is the real one. The downtime budget itself is settable from the migrate dialog, as a curated slider paired with an exact seconds field. See Migration. (Enterprise)
  • Replication RPO and Ceph OSD latency alerts -- Thresholds could only describe how full a resource was. Three types join them: a job whose last successful sync fell behind its own RPO target, a job that failed outright, and an OSD answering slower than the operator tolerates. The RPO grace is a percentage of each job's own target rather than a fixed delay, since ten minutes late is harmless against a 24 hour target and unacceptable against a 15 minute one. The OSD check ships disabled, because no latency threshold suits every disk and an upgrade must not start alerting on its own. See Alerts.
  • Recovery notifications when an alert clears -- The mail carries when the alert fired, when it cleared, how long it lasted, and the value it came back to, and it bypasses the minimum severity filter, since a recovery ranks below any threshold and would otherwise be dropped in silence. Resolution now waits for hysteresis, so a value oscillating around its threshold no longer mails once a minute, and both knobs, the margin and the number of confirmations, are exposed under Settings > Alert thresholds. See Alerts.
  • A configurable boot screenshot delay and non-isolated DR tests -- The stabilization wait before a console capture was a constant 45 seconds, so a guest that boots slower was photographed mid-boot; the delay is now a test failover option, from 5 to 600 seconds, persisted on the execution. A DR test can also leave the NICs connected instead of always isolating them: it is a switch, on by default, with a warning about colliding production addresses, and the mode the run used stays visible on a chip. See Site Recovery. (Enterprise)
  • Pool-based selection for backup jobs -- A provider can now point a job at a Proxmox resource pool instead of naming guests, fed by the pools endpoint so a scoped caller sees its own perimeter, and the inventory panel resolves the pool instead of showing a dash. A vDC tenant was already restricted to pool selection and is unaffected. See Backups.
  • Disk health, ZFS pool state, and node temperatures -- SMART attributes are shown when a disk row is expanded, including the NVMe text form Proxmox returns on real hardware, parsed into labelled rows whose direction is explicit so remaining life is never colored like consumed life. The node view gains ZFS pool state, scrub, and the vdev tree. Node temperatures are read from the kernel hwmon tree over SSH, since Proxmox exposes none and a stock node has neither lm-sensors nor ipmitool, aggregated per role with a threshold per role, and a node that reports nothing simply shows no temperature instead of an error. See Inventory.
  • A ZFS ARC dashboard widget -- ARC was only visible overlaid on memory available in the node summary, where three orders of magnitude flatten it onto the baseline. The widget gives ARC its own auto scaled axis plus a percentage view, excludes the nodes that report none, and names its requirement, Proxmox 9 with ZFS in use on the node, rather than showing an empty frame. See First Steps.
  • Free widget placement and a theme logo widget -- Dashboard widgets stay where they are dropped instead of being compacted upwards, and a new widget shows the branding logo, the ProxCenter logo, or the theme badge. See First Steps.
  • Appearance preferences are stored in the user account -- Color scheme, layout, density and typography, per tenant and per user, resolved server side so the restored palette is already in the first HTML. An existing cookie is imported once, carrying the id of the account that wrote it so a shared browser never copies one person's look into another's.

Improved​

  • Logs and actions are handled per job type in the Task Center -- Rolling updates and replication are read from the orchestrator, migrations from the shared task history, DRS from the Proxmox task log rebuilt out of the UPID, and Site Recovery is synthesized from the per-VM results. Actions are routed the same way, a migration cancellation is confirmed, action errors are surfaced, the buttons the orchestrator cannot honour are gone, deleted connections are named instead of printing a raw id, and a recovery plan execution is reported as Site Recovery instead of being filed under maintenance. See Task Center.
  • A refused guest shutdown is recoverable during a cutover -- The cutover asked the guest to shut down and then polled in silence for five minutes, so a guest that refused cost the whole transfer. The wait is now a step of its own, it restates the time left every minute, and it offers a hard power off, which stays the operator's decision because it makes the final delta crash-consistent. The budget grows to 30 minutes, a host that refuses the hard power off, as an ESXi licence restriction does, is logged instead of crashing the job, and vSphere SOAP faults carry the concrete fault type and message instead of the generic wrapper. See Migration. (Enterprise)
  • The Proxmox request budgets are settings -- PVE_TIMEOUT_MS covers a regular call and PVE_SLOW_READ_TIMEOUT_MS the reads that enumerate every storage, so a datacenter declaring many Proxmox Backup Server targets can be given the time it needs. A response timeout on a read no longer trips the failover circuit breaker like an unreachable host does. See Installation.
  • Virtual machine configuration writes follow the Proxmox task instead of racing the request budget, and the saved message follows the pending keys Proxmox reports rather than the power state, so a hotplugged change reads as applied and a pending one names the stop and start it needs. See Inventory.
  • The real disk format is reported. Proxmox deletes the optional format= property right after allocating a volume, so falling back to raw mislabelled every qcow2 and vmdk disk; the format is derived from the volume name instead. Which formats a storage accepts stopped being a function of its type in Proxmox 9, so both storage routes compute it from the cluster storage configuration and the disk dialogs follow that answer. The Cloud-Init drive is labelled as such rather than appearing as a CD-ROM, which also keeps the ISO editor from detaching its volume. See Inventory.
  • Text stays readable on a light branding color, and the tooltip hover band on bar charts follows the theme instead of painting a white block over the hovered bar in dark mode. See White Label.

Fixed​

  • A powered-off VM can be replicated -- Replication is pure Ceph RBD and the only power-dependent step is already guarded per VM, yet the create-job dialog and the API route both filtered on the running state. On a tag-based job, a guest that was powered off was also silently dropped from the protected set at the next re-resolution while the job kept reporting success. Tag resolution no longer looks at power state, every VM that leaves or joins the protected set is logged, and the per-VM rows that no longer belong are pruned. Templates stay excluded, since a replica of one could not start at failover. See Site Recovery. (Enterprise)
  • A tag-based job whose tags stop matching says so -- A job whose protected set empties at a later re-resolution lands in an explicit no match status instead of the error and retry path: no failure mail, the next sync stays scheduled, and the status is rendered on the protection chip and filter, the emergency DR chip, and the dashboard job distribution. RPO alerts deliberately keep firing, because a job protecting nothing must keep nagging. See Site Recovery. (Enterprise)
  • Community installs grant the super-admin role again -- Since v1.4.7, an account created from Security & Access > Users on a Community install received no RBAC grant at all: the auto-grant was gated on a resolved licence verdict, which a Community install running the frontend alone can never establish. Its owner saw an empty dashboard, and the operator could not repair it because the role picker is Enterprise gated. The gate now keys on the deployment shape, and a sign-in backfill repairs the accounts already created without one. See Users.
  • A pool or tag scoped user can create a guest -- A grant whose only scope is flat can never satisfy a connection-scoped check, so six of the routes the Create VM wizard calls refused it: the pool and storage pickers came back empty and the submit was denied. Such a caller now gets a perimeter derived from the guests they already see on one connection, nothing wider than what the inventory stream already sends them, and creation forces the accessible pool so a guest cannot be created invisible to its own creator. See RBAC.
  • An unparseable branding color no longer turns every page into a 500 -- A White Label primary color typed without its leading # was stored as is and handed to the theme, which throws on anything it cannot parse, in a provider that wraps the dashboard and the login page alike. The value is normalized on the way in and on the way out, the field explains the expected format and blocks Save, and both branding reads repair what is already stored, so an instance stuck on the 500 page recovers on its own after the update instead of needing a database edit. See White Label.
  • VMID availability is scoped to the target connection -- With two clusters connected, cloning a template was impossible: the dialogs were fed the merged inventory of every connection, so an id used on the second cluster was refused on the first. Proxmox only requires uniqueness inside a cluster. MSP and vDC tenants keep their cross-cluster range, which is an explicit contract enforced server side. See Inventory.
  • virt-v2v never prompts for the root filesystem -- The conversion is launched detached, so an interactive root prompt died on end of file after the whole transfer had completed. This is not limited to dual-boot guests: a btrfs guest with snapper snapshots inspects as one system per subvolume, and one reported guest listed sixteen candidates. Conversion now runs with stdin closed, drops snapshot subvolumes from the candidate list, retries once with an explicit root, and parks the job for an operator choice when several real systems remain. A root filesystem can also be pinned up front in the dialog. See Migration. (Enterprise)
  • A cancelled migration that was parked really stops. The virt-v2v cancel registry was never wired into the cancel route, so the row changed state while the pipeline kept waiting. (Enterprise)
  • A failed create no longer destroys a pre-existing VM -- The VMID is reserved before the guest exists, so a failure in between made the cleanup call DELETE on a VMID it had never created, and with a user-supplied id that was already taken it purged the guest holding that id. Destruction now happens only when the job actually created the VM. (Enterprise)
  • A slow storage listing no longer empties the migration Target Storage field. A datacenter declaring many Proxmox Backup Server storages needs 20 seconds or more to answer, well past the 8 second budget that was hardcoded in two literals. The dialog now surfaces the server reason with a retry instead of swallowing it. See Migration.
  • A slow RAM hotplug no longer reports a failed save. Removing memory unplugs one DIMM at a time and Proxmox sleeps 3 seconds per module, so dropping a running guest from 8G to 4G costs 24 seconds at best, well past the request budget: the write aborted on our side while Proxmox went on applying it. See Inventory.
  • Alert mails keep the severity the engine established. The notifier re-derived it from value against threshold, so an alert with no measured quantity, a failed replication job for instance, was always classed as a warning and never reached an operator whose minimum severity is critical. Stale snapshot alerts can also finally resolve: a deleted snapshot never comes back through the checker, so its alert stayed active for ever. See Alerts.
  • Presentation fixes. An unrecognised disk health string is no longer painted green, and a disk that reports no wearout says so instead of showing an empty bar. The tree context menus share one paper with theme-aware icons, the disk tables use the product typography instead of hardcoded monospace, and three list items no longer nest a block element under a paragraph.

Security​

  • API token offboarding, scope audit, and real deletion -- Disabling or deleting a user left the tokens they had minted behind with no way to see them. The user dialogs now list them and offer to delete them in the same gesture, unchecked by default, with the deletion running before the account write, and the creator is frozen on the token so provenance survives the account being deleted. Deleting a token now removes the row instead of stamping it revoked, which had left legacy revoked tokens stuck in the table. The compliance:read scope, which mapped to a write-capable permission and granted nothing today, is gone, and the scope test now fails on any scope mapping a dangerous or non-read permission. See API Tokens.
  • Two unguarded routes -- Creating an alert now requires alerts.manage, checked before the body is read, like the other writes on the resource. Upload progress is scoped to the user who opened the transfer, so the upload id is no longer the only thing standing between a signed-in user and someone else's counters.
  • The orchestrator no longer trusts X-Forwarded-For blindly on every request, where any caller could pick the IP it was recorded as (GO-2026-5777), and it builds on a Go toolchain that still receives patches.
  • CVE-2026-40345 -- A deepmerge-ts >= 8.0.2 floor, since the vulnerable version is pinned exactly by @prisma/config and no Prisma release ships the fix yet.
  • Dependency batches -- Eight updates batched, including Next 16.3 and MUI X Data Grid 9.12, plus concurrently 10, and the earlier batches of thirteen and five updates. Continuous integration runs on Node 26 and the package declares its Node floor.

Upgrade notes​

  • Pull the images. Four schema migrations ship with this release and are applied by the frontend entrypoint at first boot under an advisory lock: the user appearance preferences table, the API token creator provenance column, the vDC VLAN support tables, and the vDC storage policy tables.
  • Six optional settings are new, all empty by default, so an installation that sets none of them behaves exactly as before. PVE_TIMEOUT_MS and PVE_SLOW_READ_TIMEOUT_MS are the Proxmox request budgets and reach every edition. GHCR_TOKEN, PROXCENTER_VDDK_PACKAGE, PROXCENTER_VDDK_TAG, and V2V_ROOT_CHOICE_TIMEOUT_MS reach the Enterprise and high availability stacks, since migration is an Enterprise feature. See Installation.
  • Warm migration node preparation needs GHCR_TOKEN in the frontend container. The Enterprise installer already writes it to the stack environment file; on an installation upgraded by hand, add it there before using the Prepare the node action. See Migration.
  • The Ceph OSD latency alert ships disabled and no threshold is created for it, so an upgrade never starts alerting on latency by itself. Enable it and set the threshold that suits your disks. See Alerts.

v1.4.7 -- 2026-08-14​

Security release: two authentication fixes, revocable sessions, and disaster recovery failback. Two privately reported authentication issues are fixed, sessions are now tracked server side and can be revoked, Site Recovery gains a real failback flow along with boot screenshots on test failovers, and a large batch of migration, tenancy, and interface fixes lands. Upgrading is strongly recommended for every installation.

Added​

  • Revocable server-side sessions -- Sessions are tracked server side and can be revoked: from an Active sessions card on your profile for your own sessions, and from an All sessions tab on the Users page for everyone else's. Session cookies carry secure flags, and idle and absolute lifetimes are configurable through SESSION_IDLE_TIMEOUT and SESSION_ABSOLUTE_TIMEOUT. See Users.
  • Read-only API tokens -- pxc_ tokens grant read-only access to a set of aggregated endpoints, scoped and quota limited, for dashboards and external monitoring. See API Tokens. (Enterprise, API Access add-on)
  • Site Recovery failback -- A plan that has failed over can now fail back: a reverse incremental sync brings the source back up to date, then an operator-driven cutover switches back, with per-VM rollback and re-protect. Failed-over plans and their replication jobs stay locked until failback completes. See Site Recovery. (Enterprise)
  • Boot screenshots on a test failover -- Each recovered VM's console is captured while the test runs and kept with the execution, so you can see what a guest actually booted into instead of trusting a power state. The captures are listed and served from the execution view. See Site Recovery. (Enterprise)
  • Restore point selection and configurable snapshot retention -- A test or real failover can recover a VM from an older DR snapshot instead of the latest one, and retention is set per replication job for the source and the DR side separately. Per-VM failover steps are surfaced on the execution results. See Site Recovery. (Enterprise)
  • Several vDCs per tenant -- A tenant is no longer limited to a single virtual datacenter: it can hold one vDC per provider-pool cluster, and a global vDC context switches the interface between them. See Virtual Datacenters. (Enterprise)
  • Optional VMID ranges for MSP tenants, so guests created by a tenant stay inside a reserved numbering window. See Multi-Tenancy. (Enterprise)
  • Pre-migration check for HA affinity rules -- The node picker of the Proxmox migrate dialog flags a target that would break an affinity rule, and blocks it outright when the conflicting guest is running. See Migration.
  • Migrated disks can be converted to qcow2 after the move, an option offered on thick LVM targets so the guest gains Proxmox snapshots. See Migration.
  • vzdump archives are listed in a guest's Backups tab, alongside the Proxmox Backup Server snapshots, and can be restored from there. See Backups.
  • Security groups can be attached to several guests at once from the group view, with a corrected membership count. See Network. (Enterprise)
  • A CIS Controls v8.1 card joins the compliance Frameworks tab, next to NIST 800-53, NIST 800-171, CMMC Level 2, and ISO/IEC 27001. See Compliance. (Enterprise)
  • A provider-configurable broadcast banner announces planned maintenance to every tenant, or to selected tenants and roles, from one place. See Notifications.
  • A tenant filter on the storage overview, so a provider can read one tenant's storage without leaving the page. See Storage. (Enterprise)

Improved​

  • The orchestrator survives the loss of the node it was configured with -- its Proxmox API calls fail over to another node of the cluster instead of dying with that node, and guest commands are addressed to the node that actually owns the guest. The SSH and RBD data path still uses the configured address. See Site Recovery.
  • Warm migrations warn before falling back to CBT and report live progress during the pre-zero and copy phases instead of showing an indeterminate bar. See Migration.
  • Reports carry the tenant's white label, including the compliance PDF export, its logo, and its footer. See Reports.
  • AI prompts are answered in the language of the interface, whichever provider serves them. See AI.
  • The Proxmox rule log level is exposed in the firewall dialogs and rules tables. See Network.
  • The PVE node is shown in filtered flat VM lists, and console windows lead with the VM name instead of the connection identifier. See Inventory.

Fixed​

  • Tag and pool scoped users see their guests again -- a user whose only grant was a tag or a pool had an empty inventory since v1.4.6. The visible perimeter is now derived from the guests that remain after filtering. See RBAC.
  • A vSphere snapshot task is followed with per-phase budgets instead of failing at a fixed 120 second deadline, which blocked warm migrations of multi-terabyte guests. See Migration.
  • A fully copied warm target is kept instead of being freed when cleanup runs.
  • Migrated Windows and UEFI guests take their boot disk on SATA instead of LSI SCSI, so they boot without a driver injection.
  • The i440fx machine type is sent to Proxmox as pc, its real name, instead of the rejected i440fx, which unblocks guests pinned to that chipset. See Inventory.
  • Custom CPU models are handled in the CPU type selects and in the cross-cluster migration pre-check.
  • Migration jobs orphaned by a server restart fail cleanly instead of staying stuck in a running state.
  • The virt-v2v temporary storage requirement is hidden in warm mode, where it does not apply, and no longer reports a false lack of space. See Migration.
  • A real failover fences the source VMs before starting their replicas, so the same guest cannot run on both sides. The fencing is best effort and is skipped when the source cluster is unreachable. See Site Recovery. (Enterprise)
  • A failover no longer erases the recorded address of a node that stopped answering. (Enterprise)
  • Firewall data is read from and written directly to Proxmox when no orchestrator is reachable, instead of leaving the firewall views empty. See Network.
  • The infrastructure report includes every VM instead of stopping at an internal cap. See Reports.
  • Numeric fields can be cleared instead of snapping back to a default value while you type.
  • Snapshot rows follow the Proxmox task instead of claiming success before it finishes. See Inventory.
  • The tasks bar keeps the page content reachable when it expands, dashboard widget filters stay reachable when a filter empties the view, and batch actions stay available when alerts are selected from the header checkbox. See Task Center.

Security​

  • A dotted API path no longer skips authentication -- the middleware classified any request path containing a dot as a static asset and answered before the session check ran, so an API path carrying a dot reached its route handler unauthenticated. Proxmox node names accept dots and the guest routes carry the node name in their path, so a cluster with an FQDN node name exposed guest notes and task data to unauthenticated callers. Reported privately as GHSA-79j6-v2r5-5pw5.
  • Defense in depth on the guest routes -- notes, tasks, and features now carry their own permission checks, evaluated before the Proxmox connection is resolved, so a refused caller never causes the stored API token to be decrypted.
  • First-run setup is bounded -- the setup endpoint stays reachable while no account exists, which is how a self-hosted install bootstraps, but it now enforces a rate limit, accepts an optional PROXCENTER_SETUP_TOKEN shared secret, and decides that no account exists inside a serializable transaction, so two concurrent bootstraps can no longer both create an administrator. Reported privately as GHSA-qxgh-pw46-6pw6. See Installation.
  • Dependency batch -- seventeen updates consolidated into one pass: otplib 12 to 13 for TOTP, MUI X Data Grid raised to 9.9, the checkout, setup-node, and setup-go GitHub Actions raised to v7, and the fast-uri and brace-expansion advisories patched within their major branches.

Upgrade notes​

  • No manual migration step is required beyond the usual image pull: the schema migrations apply themselves when the container starts.
  • One of those migrations refuses to run if an installation somehow holds two vDCs sharing the same cluster, or two vDCs sharing the same slug, within one tenant. Only direct API calls could create such a pair, since the interface never allowed it. If the container stops on that message, remove the duplicate vDC and start it again.
  • Two optional settings are new and unset by default, which preserves the current behavior. PROXCENTER_SETUP_TOKEN guards the first-run setup endpoint, and SESSION_IDLE_TIMEOUT and SESSION_ABSOLUTE_TIMEOUT override the default session lifetimes of 12 hours idle and 7 days absolute. See Installation.
  • Setting PROXCENTER_SETUP_TOKEN means the browser setup wizard can no longer create the first account, since it does not send the header. Bootstrap that installation with a direct API call instead, as documented in Installation.

v1.4.6 -- 2026-07-27​

Control-plane HA, warm migration reliability, and license add-ons. ProxCenter can now convert a standalone installation into a three-node highly available control plane, warm migration gets a round of reliability fixes for block allocation and NBD device handling, and license add-ons let you stack extra paid capabilities on top of your edition license.

Added​

  • ProxCenter HA -- Turn a standalone installation into a three-node control plane with replicated PostgreSQL, etcd quorum, and a virtual IP that fails over. Operationally, this means the ProxCenter application itself keeps running if a node goes down: the virtual IP moves to a surviving node, etcd handles leader election so exactly one node is active, and PostgreSQL replication keeps application data consistent across all three nodes. (required license)
  • HA deployment wizard and cluster dashboard -- A guided wizard converts a standalone install into a three-node cluster, running prerequisite checks up front and showing live progress through each conversion step. Once converted, a cluster dashboard shows per-node status, a service grid, and an operations panel for day-to-day HA management. (required license)
  • Branding assets moved to PostgreSQL -- Logos and login backgrounds are stored in the database instead of on local disk, so they are identical on every node of an HA cluster instead of needing to be uploaded separately to each one. See White Label.
  • License add-ons -- Option licenses stack on top of your edition license to unlock a specific paid capability without replacing or regenerating your main license. Add-ons appear in the license table alongside the capabilities they unlock and are purchased and issued from the customer portal. See Licensing.
  • Interactive warm cutover -- Choose the exact moment a warm migration cuts over, with a live downtime estimate, instead of letting ProxCenter switch the guest over on its own once the delta sync is ready. See Migration. (Enterprise)
  • Delete all snapshots in one action -- Remove every snapshot of a VM in a single action instead of one at a time. A new guard also blocks a cross-cluster migration while snapshots still exist on the source VM, preventing a move that would silently leave orphaned snapshot data behind. See Migration.
  • Batch alert actions -- Select several alerts in the table and acknowledge or delete them in one action instead of one at a time. See Alerts.
  • Blueprints gain custom images and full deploy configuration -- Blueprints can now use custom uploaded images in addition to the catalog, and the deploy flow adds cloud-init configuration, hardware sliders (CPU, memory, disk), and IP and bridge selectors. See Templates & Cloud Images. (Enterprise)
  • Inventory, topology, and connections scoped to RBAC grants -- The inventory tree, the network topology view, and the connections list now filter down to the connections a user's role actually grants access to, instead of listing every connection in the tenant. See RBAC.
  • Korean and Spanish interface languages, plus KRW currency support for cost and billing displays.
  • VMs grouped by SDN VNet in the inventory -- Guests attached to an SDN VNet are grouped under that VNet in the inventory tree, with the VXLAN ID and zone shown alongside it. See Inventory.

Improved​

  • Cloning suggests the next available VMID instead of a random one, so sequential VMIDs stay predictable across a cluster.
  • The external hypervisor VM table can be sorted by column, making it practical to pick the right guest out of a large vCenter or ESXi inventory during migration. See Migration.
  • Users created on a Community installation are granted full super-admin rights, since Community has no RBAC roles to assign a more restricted permission set to.
  • Remaining hardcoded French strings in the alerting UI moved to translation keys, so the Alerts page is consistent in every supported language instead of showing French text regardless of the selected locale. See Alerts.

Fixed​

  • Warm migration allocates block volumes as raw instead of qcow2 -- this removes a large allocation delay on LVM and Fibre Channel targets, and a failed allocation no longer leaves an orphan volume behind that poisoned every subsequent retry. See Migration.
  • Warm migration allocates a free NBD device instead of assuming a fixed one, so a second concurrent warm migration on the same node no longer collides with the first.
  • Warm copy over SSH keeps the connection alive and applies an inactivity timeout, so a long-running copy can no longer hang indefinitely on a stalled connection.
  • A cross-cluster migration no longer fires two destroy tasks on the source VM, which could report a spurious failure even after the guest had already moved successfully. See Migration.
  • Node Local Time no longer applies the UTC offset twice in the inventory node detail panel. See Inventory.
  • Storage capacity in the Overview is aggregated per cluster, so shared storage (NFS, Ceph, etc.) is counted once per cluster instead of once per node, which previously inflated total capacity on multi-node clusters. See Storage.
  • The SSH-command and task-log copy buttons fall back gracefully when the browser blocks the Clipboard API outside a secure (HTTPS) context, instead of failing silently.
  • The migration log console keeps its last line visible above the tasks footer instead of it being hidden underneath. See Task Center.
  • A scheduled backup job runs on the guest's real node instead of always the first node of the cluster. See Backups.
  • Cloud-init IP settings are applied on bridges that have no IPAM configured, instead of silently being dropped when the target bridge has no IPAM pool behind it. See Virtual Datacenters.
  • VM names starting with a digit are accepted, instead of being rejected by a validation rule stricter than Proxmox itself requires.
  • Host VLANs with no attached VM are shown in the inventory Network view, instead of being hidden because the view previously only rendered VLANs that had a guest on them. See Inventory.
  • The generated PVE token setup script includes Sys.PowerMgmt, so node reboot and shutdown work out of the box instead of failing with a permissions error that required manually editing the token's ACL. See Connect Your Infrastructure.
  • Panel width is remembered across sessions, and status chips are readable in both light and dark themes instead of losing contrast in one of them.
  • Sorting external hypervisor VMs no longer crashes when the source inventory has incomplete data for some fields. See Migration.

Security​

  • Node, VMID, and storage identifiers are validated before being interpolated into SSH commands, closing an injection path where a crafted identifier could alter the command being run.
  • The license client no longer keeps the previous entitlement state when a license check fails, falling back to Community instead of continuing to honor a stale entitlement.

v1.4.5 -- 2026-06-27​

Compliance frameworks, DRS load balancing, and an OIDC role-sync fix. Assess a connection against major security compliance frameworks, DRS finally honors its Balance Types setting, and a login regression that could silently demote manually assigned administrators is fixed.

Added​

  • Security compliance frameworks -- Assess a connection against NIST 800-53, NIST 800-171, CMMC Level 2, and ISO/IEC 27001 from a new Frameworks tab, with a score donut, satisfied / partial / failed breakdown, per-node results, and a styled PDF report. See Compliance. (Enterprise)
  • Open in Proxmox -- A button next to the cluster or node name opens the native Proxmox web interface in a new tab, deep-linking a member node to its own management IP instead of always opening the cluster's primary node.
  • Migration target-network selector lists SDN VNets alongside classic bridges, so nodes whose guest networks are VNets rather than plain bridges no longer show an empty target list. See Migration.

Improved​

  • Inventory Network view shows host bridges and VLANs per node, so clusters with no VMs are no longer an empty page; bridges open a detail panel and SDN VNet IDs resolve to their friendly alias. See Inventory.
  • Node maintenance is simpler -- entering maintenance now triggers Proxmox's own node-maintenance mode (HA guests are evacuated by Proxmox itself), with a note that non-HA guests still need to be migrated or shut down manually.
  • DRS honors the Balance Types setting, previously a dead knob -- load-balancing candidates are now filtered by guest type for both reactive balancing and homogenization, with the guest-type gate also applied at execution time. See DRS.
  • DRS settings cleanup -- removed the dead balancing-method and balancing-mode knobs, guarded balance-types at a minimum of one, moved resource weights to a single row, and added status icons on exclusions and balance-types.
  • The inventory tree's expand/collapse state is now scoped per tenant, so switching tenant no longer carries over the previous tenant's expanded/collapsed state.
  • The cluster SSH test shows the per-node ok/error breakdown on failure too, not only on success.
  • The VM delete confirmation dialog spells out exactly what will be removed before you confirm.

Fixed​

  • OIDC role preserved on login -- v1.4.4's OIDC role re-sync demoted any user with no matching IdP group to Viewer on every sign-in, which could lock out a manually assigned administrator. The re-sync is now authoritative only when a group-to-role mapping is actually configured and groups are sent by the IdP.
  • OIDC accounts are labelled correctly and can no longer be given a local password, closing a path where a credentials-based login could bypass SSO and MFA entirely.
  • Warm and direct-ESXi migrations preserve the source NIC MAC address, so the migrated guest keeps its network identity instead of stranding its old IP on a ghost adapter.
  • Warm migration reliability -- a stale /dev/nbdN device is released before attaching, and the delta-apply step is chunked to stay under the SSH argument-size limit.
  • Migrating a running LXC container now uses restart mode instead of online=1, which Proxmox rejects for containers, so an online CT migration no longer fails outright.
  • Dropped the misleading "vSAN datastore detected" log line on the vCenter migration path.
  • The percent chart Y-axis is widened so the "100%" label is no longer clipped.
  • Old completed tasks are no longer re-alerted as new events roughly a week after they originally ran.

Security​

  • Patched Go orchestrator CVEs by bumping golang.org/x/crypto, x/net, and x/sys (SSH, HTML, and IDNA advisories).

v1.4.4 -- 2026-06-22​

Stability and security hardening, plus shared migration tasks. A patch-focused release: MSP gets a header tenant switcher, in-flight migrations become visible to the whole team, several data-integrity and error-surfacing fixes land across guests and RRD charts, and the runtime image gets a security cleanup.

Added​

  • Header tenant switcher -- MSP administrators can switch the active tenant directly from the navbar, with the dashboard and other pages re-scoping to show only that tenant's data. See Multi-Tenancy. (Enterprise)
  • Shared migration tasks -- In-flight migrations now appear in a shared footer panel visible to every user instead of only the one who started them, so the whole team can follow a long-running migration, with a link to the warm-migration node setup docs included. See Migration. (Enterprise)

Improved​

  • VM console screenshots are served as JPEG instead of raw PPM, producing lighter, faster-loading previews in the inventory tree and detail panel.

Fixed​

  • RRD performance charts show dates on multi-day timeframes -- charts previously showed only times, which made it impossible to tell which day a data point belonged to once the timeframe spanned more than 24 hours.
  • The Backups tab surfaces the real gateway error -- a reverse proxy returning an HTML error page used to fail silently with Unexpected token '<'; the actual gateway error is now shown. See Backups.
  • A failed migration block-device transfer is now reported as a failure instead of being masked as a successful migration.
  • Warm migration to a thick-provisioned target bounds its zero-fill pass, so it can no longer exit with a false out-of-space (ENOSPC) error.
  • Guest and node API routes no longer swallow real errors -- failures now surface to the UI instead of silently returning empty data.
  • OIDC users re-sync their role from IdP group membership on every login, so a group change in the identity provider takes effect immediately rather than waiting for the next manual sync.
  • RRD performance graphs are scoped to the resource rather than the whole connection, closing an RBAC scope leak where a user could see performance data for resources outside their granted scope.
  • The inventory NETWORK section stays stable when a connection briefly blips instead of collapsing and losing its expanded state. See Inventory.
  • Replication writes the DR config with cp -f on pmxcfs, avoiding a transient failure window during the write.

Security​

  • Removed the unused npm binary from the runtime image, patched dependency CVEs (undici, OpenSSL on the orchestrator), and refreshed front-end dependencies.

v1.4.3 -- 2026-06-15​

MSP mode, multi-license stacking, connection health diagnostics. MSP tenants can own whole Proxmox clusters, multiple licenses can be stacked on one install, and every connection gets a built-in health check.

Added​

  • MSP mode (whole-cluster tenant ownership) -- An MSP tenant can own entire Proxmox clusters with an unmasked full-cluster view, alongside the existing vDC / IaaS slicing. The provider / NOC keeps the fleet-wide view (dashboard, VMs, alerts, reports) for supervision and license aggregation, while each MSP tenant operates only its owned clusters. Includes provider provisioning (assign or release connections, a Tenant / vDC ownership column, and an owner selector when creating a connection) and scoped operations (inventory, dashboard, alerts, reports, backup jobs, and migration among owned connections). See Multi-Tenancy. (Enterprise)
  • License stacking -- Import additional licenses to grow fleet capacity without regenerating the primary license. Fleet-total node quota, per-tenant rollup, a "Licensed to" name per import, plus edit-mapping and remove, all from the License tab. A single-license install behaves exactly as before. See Licensing. (Enterprise)
  • Connection health diagnostics -- A per-connection Diagnostic column and modal run read-only checks: reachability, authentication and permissions, version, cluster health / quorum / Ceph, storage and SSH for PVE; version, auth and datastores for PBS; basic reachability for external migration sources. Works in Community mode with no orchestrator dependency.
  • Guest names in alerts and event emails -- VM and CT alerts and event notifications now show the guest name next to the vmid ("Name (vmid)") in the alerts table, the navbar dropdown and the email template.

Improved​

  • Nodes column on the connection lists collapses to the first node plus a count, with the full list on hover.
  • Deploy wizard exposes real bridges and an editable VLAN tag for provider and MSP modes (vDC tenants keep the VNet picker).
  • Green Score insight moves to its own row so longer suggestions stay fully readable.
  • The What's New panel no longer opens automatically on a new version; open it any time from the profile menu.

Fixed​

  • Orchestrator API authentication -- The orchestrator now reads the API key from PROXCENTER_API_API_KEY (the value docker-compose already injects, identical to the frontend's key), so authentication can be enabled and matches the frontend. An unset key keeps authentication disabled as a safe fallback, so installs without a shared key are unaffected.

v1.4.2 -- 2026-06-14​

Warm migration, SPICE consoles, Ceph topology, and a security sprint. No-data-loss VMware migration, in-browser SPICE, a read-only CRUSH topology view, role-level RBAC scopes, SSO-only and local 2FA policies, plus a security hardening sprint.

Added​

  • Warm migration for VMware (CBT) -- VMware VMs migrate with changed-block tracking and a final delta sync, so there is no data loss on large or busy disks. Covers ESXi-direct and vCenter (including vSAN), single and bulk, with a go/no-go preflight and SOAP-session keepalive. (Enterprise)
  • In-browser SPICE console for QEMU VMs, alongside noVNC.
  • Ceph CRUSH topology view -- Read-only CRUSH tree with details and pools in the cluster Ceph tab, plus full cluster config with working OSD flag toggles.
  • Role-level default RBAC scope, inherited by every assignment of that role. (Enterprise)
  • SSO-only login policy for OIDC, hiding the local form and forcing the SSO redirect, plus an issuer fix for manual endpoint overrides. (Enterprise)
  • Local TOTP two-factor with an admin enforcement policy.
  • Clone a VM from a snapshot restore point, choosing a snapshot as the clone source.

Improved​

  • Local migration from the cluster Guests tab (node-to-node) instead of forcing cross-cluster only.
  • Reports and notifications overhaul -- connection scoping, backup report polish, per-category severity, and an event-email rework (English copy, task-log details, one mail per event).
  • Guest VLANs resolved from host bond sub-interfaces so tagged guests group correctly.
  • Resume paused VMs, dots allowed in tags, and the guest icon dims when off for color-blind legibility.
  • Dashboard widgets honor the appearance settings (font-size, corner-rounding, shared gauge).
  • Tree sections stay open when clicking the PROXMOX VE / NETWORK headers.
  • Serial / headless VMs show a badge instead of looping on a failing screenshot.
  • VM User role gains the read access the Inventory needs to load.
  • Standalone hosts behind NAT connect to the public host for node management, not the private interface.
  • Pull-based threshold alert evaluation with silence sync; silences are respected in the home dashboard widget.

Fixed​

  • Partial-VM cleanup no longer leaks the target VMID after a failed conversion.
  • Empty guest Backups tab now explains why (no connected PBS vs no snapshots).
  • "Run now" works again (a missing route returned an HTML 404).
  • Real local backup time and Proxmox-style columns, and legacy maxfiles is translated to prune-backups.

Security​

  • Security hardening sprint -- critical findings closed plus follow-ups, TOFU host-key verification on the ssh2 path, per-connection ws-proxy TLS and Dependabot overrides, js-cookie bumped to clear a high-severity advisory, and Node 26 pipeline hardening for XCP-ng / Hyper-V / Nutanix.

v1.4.1 -- 2026-05-21​

DRS hardening, migration fixes, and security. Automatic-mode DRS is significantly safer, with several reliability fixes for vSphere migration and rolling updates.

Improved​

  • DRS automatic-mode hardening -- A per-cluster migration cap replaces the global cap as the throttle, an opt-in per-target inflow cap prevents ping-pong, and the post-migration snowball is fixed so the scheduled cron is the only periodic trigger (maintenance evacuations still self-loop). Backed by a hardening bundle: 64-bit recommendation IDs, post-migration singleflight, exclusive scheduler registration, a freshness gate, a storage gate scoped strictly to maintenance evacuation, and affinity preserved across a PVE flap.
  • DRS settings UI cleanup -- The advanced section is reorganized into migration limits, behavior and resource weights, slider help moved to tooltips, and misleading dead toggles removed. The rebalance interval now supports 15m and 30m.

Fixed​

  • Migrate-to-Proxmox no longer greys out on single-disk nodes (#331) -- /tmp is synthesized as a temporary-storage fallback when the root filesystem has free space.
  • Long-running config PUT timeouts on slow storage (#332) -- all migration-time /qemu/{vmid}/config PUTs now use a 120s timeout, fixing ZFS-over-iSCSI auto-attach and the false "all cluster nodes unreachable" masquerade.
  • Rolling update reliability -- respects reboot_timeout end-to-end with sustained-online polling and a verify retry, runs apt / ha-manager / ceph / reboot via sudo -n for non-root SSH users, and surfaces node version and API token permission errors (#318).
  • curl stderr surfaced and orphan LVM freed on stream failure (#316).
  • Test connection for Ollama fixed after the auth refactor (#314).

Security​

  • SSRF guard on the AI test and models endpoints (#335) -- cloud metadata endpoints (AWS, Alibaba, OCI, AWS IPv6 IMDS) are blocked, with a DNS lookup so aliases that resolve to blocked addresses are rejected; local Ollama setups are unaffected.
  • Dependency and hardening bumps -- ws 8.20.1, bundled npm 11.15.0, an ip-address fix, go-ntlmssp, Alpine 3.19 to 3.22, a tightened license URL spoofing check, and shell-arg validators on SSH-command routes.

Upgrade notes​

  • No schema changes since v1.4.0. The DRS settings now present max_concurrent_migrations_per_cluster instead of the global max_concurrent_migrations; existing configs are auto-migrated at runtime.

v1.4.0 -- 2026-05-11​

MSP / IaaS release. ProxCenter becomes a multi-tenant Proxmox cloud platform. Each customer gets a self-service virtual datacenter (vDC) with quotas, network and backup isolation, while the provider keeps a single pane of glass over the underlying clusters. The persistence layer also moves to PostgreSQL for production-grade reliability.

Breaking​

  • PostgreSQL is now required -- SQLite support has been removed entirely. Existing installations must plan a PostgreSQL cutover before upgrading, then re-bootstrap their configuration through the UI on first boot. The Docker image no longer ships better-sqlite3 or the legacy SQLite migrator. Full step-by-step instructions are documented in Upgrade to v1.4.

Added​

  • vDC tenant cockpit -- A dedicated "My vDC" workspace for each tenant with live consumption (host and VM metrics), quota donuts for CPU, RAM, storage, snapshots and backups, datacenter map and Green IT KPIs. Tenants self-serve their capacity without provider intervention. (Enterprise)
  • Self-service deployment wizard -- A guided flow for tenants to deploy VMs from templates, ISOs, clones or PBS restores. Every step is quota-enforced server-side, and foreign resources (storage, node, bridge outside the tenant's vDC) are refused with explicit errors instead of being silently swapped. (Enterprise)
  • Native IPAM at the vDC level -- Per-vDC SDN VNet and subnet management, with automatic IP and MAC reservation on deploy, clone, restore and config edit. A PVE pool scan reconciles externally created VMs back into the inventory. (Enterprise)
  • Per-vDC Proxmox Backup Server bindings -- Each vDC gets its own PBS namespace, sub-token, ACL and PVE storage. Auto-provisioning is the default (one-click), manual mode is supported for stricter operators. Backup data isolation by design. (Enterprise)
  • Tenant restore from PBS -- Tenants can overwrite a source VM or restore as a new VM into their vDC pool, through a simple-mode dialog that hides advanced PVE flags they don't need. (Enterprise)
  • Tenant-scoped backup jobs -- PVE backup jobs constrained to the tenant pool, with a structured schedule picker (frequency, time, weekdays) and Verify / Delete actions inline. Tenants can only target their own infrastructure. (Enterprise)
  • Datacenters and Green IT configuration -- Configure per-datacenter PUE, electricity price, CO² factor and server specs, then assign clusters, nodes or vDCs to them. Green metrics now reflect the real DC each VM runs on, not a global default.
  • Per-VM Green Score in the inventory header -- 30-day energy, cost and CO² aggregate shown inline next to each VM, with a hover breakdown (CPU average, PUE, score deltas) and one actionable insight (idle CPU, oversized RAM, mostly stopped, efficient DC). (Enterprise)
  • Tenant-scoped reports, alerts, tasks and events -- Every cross-cutting MSP feature now respects tenant boundaries on shared-node clusters. A new vDC-scoped report type is reserved to the super-admin. (Enterprise)
  • Cross-tenant users view -- Provider-side single page listing every user across tenants, with assignments overview and role propagation.
  • White-label login page -- The Login view is now a composable shell, fully covered by the white-label theme (logo, colors, copy, dark scheme). (Enterprise)
  • HA Failback per resource -- Toggle Failback on individual HA resources from the HA tab, with a refreshed UI.
  • LXC network edit -- Full edit dialog with IP, gateway and IPv6 fields. The CT template picker now lists templates from any node hosting the storage, not just the local one.
  • Cross-cluster migration progress -- Real progress reporting for offline cross-cluster moves. External migrations can target a specific VMID, and the VLAN tag is preserved on the migrated NIC.
  • WeasyPrint sidecar for PDFs -- Dedicated container for scheduled report PDF rendering, decoupled from the main app. (Enterprise)

Improved​

  • Settings tab visibility -- Enterprise-only tabs (alerts, LDAP, OIDC, white-label, notifications) are now hidden in Community rather than greyed out, and additionally hidden for vDC tenants since they do not manage tenant-wide infrastructure. Tabs are scrollable on narrow screens.
  • Tenant lifecycle clarity -- "Disabled" tenants are now "Locked" with explicit semantics: login blocked, data preserved.
  • Super-admin scope -- Super-admins are pinned to every tenant by design, removing the "I can no longer see this tenant" trap when leaving the provider tenant.
  • RBAC performance -- Tenant grants are preloaded once per request instead of being looked up N times across scoping helpers, removing a noticeable latency on large fleets.
  • Inventory polish for MSP -- Tenant and cluster icons in the inventory tree, plus bridge and interface labels no longer rendered in monospace.
  • Demo mode aligned with v1.4 -- The hosted demo now seeds the full MSP surface (vDCs, datacenters, PBS, users, RBAC) and locks mutating endpoints behind a 403.

Fixed​

  • Cross-tenant isolation -- Inventory, PBS backups and PVE backup jobs now enforce tenant scope consistently. A tenant with zero vDCs is no longer treated as the provider.
  • Tenant alert visibility -- The async visibility predicate is awaited on every callsite (regression test added).
  • Shared storage visibility -- Shared PVE storages are no longer hidden from tenants who need them.
  • Restored VM placement -- VMs and CTs restored from PBS now land in the tenant's vDC pool instead of the default pool.
  • Tags persistence -- Tag updates use parameterised queries and respect tenant scoping.
  • VxlanTag allocation -- The allocator queries live PVE state instead of trusting only the local database.
  • PBS metadata edge cases -- Millisecond timestamps are stripped before being sent to PVE, and backup IDs parse correctly when the namespace contains slashes.
  • Network inventory polish -- IP usage column, click-to-detail modal, no more flicker on refresh.
  • Provider role bypass closed -- PATCH /users/[id] enforces the provider-only role guard, and the role dropdown is cleared between edits to avoid stale state.

v1.3.5 -- 2026-04-22​

Added​

  • SSH Commands settings tab -- New Settings area showing the SSH command allowlist, connection status and sudoers security recommendations for operators who use SSH-backed orchestration.
  • PBS inventory tabs -- Proxmox Backup Server details now use horizontal tabs for a faster inventory workflow.
  • Advanced VM hardware editing -- USB, PCI, serial, audio and RNG devices can be edited or removed from the hardware view.
  • Alert exclusion patterns -- Alert rules now support an exclude-pattern field to suppress known noisy targets.
  • Improved ESXi Windows migration path -- Windows cold migrations from ESXi Direct can route through virt-v2v for driver injection, with additional guards for EFI, vSAN and custom temporary storage.

Improved​

  • Migration follow-up navigation -- After intra-cluster migrations, the inventory follows the VM on its new node instead of leaving the operator on stale node data.
  • Network flows diagnostics -- The collector-off state is clearer and agent probing is faster.
  • Locale-aware dates -- Date formatting now respects the user locale consistently across the product.

Fixed​

  • UEFI guest boot reliability -- UEFI migrations set pre-enrolled keys on efidisk0 where required.
  • Network flow commands -- OVS commands now route through the SSH execution layer, so sudo settings are applied correctly.
  • Inventory payload typing -- Details payloads now include the moved-to target used after VM relocation.

v1.3.4 -- 2026-04-22​

Added​

  • Site Recovery dashboard -- New pair-by-pair dashboard, protected VM list, per-VM status panel, bandwidth history and console access during failover.
  • Site Recovery scheduler -- RPO and scheduled modes, frequency tabs, timezone autocomplete, cron generation and preview of the next planned executions.
  • Safe Site Recovery job editing -- Protection jobs can be edited with clearer labels, validation and safer edit dialogs.
  • Disk lifecycle actions -- Regular disks are now detached instead of deleted directly, while unused disks can be attached or deleted inline.
  • Display hardware editing -- VGA memory and clipboard settings can be edited from the Display row.
  • NFR visibility -- Not For Resale licenses are shown in the license panel and top bar.
  • Configurable alert thresholds -- Dashboard alert thresholds moved to Settings and are available in Community edition.

Improved​

  • Dashboard thresholds -- Dashboard alerts now use configured thresholds instead of hardcoded 80/90 values.
  • Storage timeout feedback -- NFS content fetches fail faster and return a clearer timeout message.
  • Site Recovery polish -- Added job names, snapshot tabs, bandwidth windows, preflight details, auto-retry badge and delete confirmations.
  • Dependency and security maintenance -- Dependency updates and SonarCloud reliability fixes were included in the release.

Fixed​

  • Cross-cluster migration safety -- Source VM deletion is handled after migration, and CPU host mismatches are blocked before they can break a move.
  • Ceph target imports -- KRBD path formats returned by pvesm path are handled correctly on Ceph targets.
  • Metric server creation -- Metric servers are created through the correct Proxmox endpoint and schema.
  • Inventory and chart warnings -- Health alert drill-down, translated dashboard alerts and UI warnings were cleaned up.

v1.3.3 -- 2026-04-19​

Added​

  • vCenter live migration pipeline -- Live migrations use NFC on snapshot, include VMware Tools status checks and expose snapshot quiesce information.
  • Migration modal safeguards -- Power-state checks, VMware Tools guards and a temporary storage selector were added to the migration UI.
  • SDN cluster tab -- New SDN tab scaffolding with Zones, VNets, Options, IPAM, Firewall and Fabrics sub-tabs.
  • SDN apply workflow -- Pending banners and audit feedback were added to the SDN apply flow.
  • VM creation disk import -- VM creation can now attach an existing disk during the wizard.
  • Options pending-state UI -- VM option edits show pending change indicators and provide a revert action.
  • LDAP group restrictions -- LDAP access can be constrained by group membership.
  • Inventory tree controls -- Locked VMs display a lock icon, and the tree can show VM IDs.
  • Richer XLSX exports -- Inventory exports include vCPU plus allocated and used RAM/disk columns.

Improved​

  • Windows UEFI migration support -- Windows UEFI guests are handled through virt-v2v with OVMF, EFI disk and VirtIO fallback handling.
  • Bulk migration reliability -- Multi-disk and bulk vCenter migrations use a harder pipeline with sequential handling and adaptive UI.
  • VNC resiliency -- noVNC auto-reconnects with exponential backoff.
  • Hardware editing UX -- CPU, socket and memory inputs can be cleared, and the RAM slider supports smaller steps.

Fixed​

  • Cross-cluster VM unlock -- Source VMs are unlocked after successful cross-cluster migration.
  • Storage sharing detection -- Shared storage detection is now type-aware.
  • SSH diagnostics -- Non-zero SSH commands preserve stdout for troubleshooting and respect configured timeouts.
  • Production build issues -- Latent TypeScript errors that blocked builds were resolved.

v1.3.2 -- 2026-04-14​

Fixed​

  • ESXi vSAN migrations -- ESXi disk transfer now supports VMs stored on vSAN datastores, improving migrations from VMware environments where disk paths do not behave like classic datastores.

v1.3.1 -- 2026-04-11​

Added​

  • Alert silencing -- Alerts can be muted and unmuted with a duration, with translated UI labels and backend silence records.
  • Alert purge action -- Old alerts and silences can be purged from the orchestrator through the alert UI.
  • Rolling update timeout warning -- Rolling updates now warn more clearly about reboot timeouts and allow a longer maximum timeout.

Improved​

  • Alert state handling -- Muted alerts are separated from deleted alerts, hidden from active counts, and visible when using the silenced filter.
  • Dashboard tab order -- Dashboard tab drag-and-drop order persists across reloads.
  • Inventory maintainability -- Large inventory components were split into focused context menu, dialog, external hypervisor, storage and tree item modules.

Fixed​

  • Failover reliability -- Cluster failover is more robust when nodes are down, with lower thresholds and timeout-aware failure counting.
  • Cross-cluster migration cleanup -- Migrations track the Proxmox task ID, unlock the source VM and delete it when the delete-source option is enabled.
  • Alert deletion and deduplication -- Alert delete, resolve, silence and deduplication flows now target the correct endpoints and keep the expected visible state.
  • Cross-node VNC routing -- Console routing was restored after a node-IP routing regression.
  • Docker database migrations -- Missing alert and sort-order tables/columns were added to Docker migration scripts.

v1.3.0 -- 2026-04-08​

Added​

  • Failover node discovery -- Node IPs are discovered when a connection is created and refreshed every five minutes by the inventory poller.
  • Failover thresholds -- Failover logic now separates hard failures from timeouts and supports a configurable failure threshold.

Improved​

  • Migration storage selection -- Operators can choose storage for all migrated VMs, with a clearer migration UI.
  • XCP-ng migration handling -- XO downloads send the required accept header, keep snapshots when downloads fail and detect empty VHD downloads early.
  • Taskbar usability -- The target column is wider and supports the column menu.
  • Inventory state -- Expand-all state persists across page reloads.
  • Upload reliability -- Upload handling uses safer error boundaries and smaller chunks.

Fixed​

  • RBAC role display -- Custom role names display correctly in OIDC, LDAP and user screens, and global-scope assignments can be changed.
  • Console routing -- noVNC connects to the VM's actual node IP instead of the connection base URL.
  • Disk format choices -- Disk format options are filtered according to the selected target storage type.
  • Migration task responses -- XO task path responses and local disk flags are handled correctly.

v1.2.5 -- 2026-04-05​

Added​

  • Datacenter settings tab -- Datacenter-level settings now expose tag style, general options, replication settings and network interface selectors.
  • Metric Server and Notifications tabs -- These tabs are available for datacenters and standalone nodes.
  • Proxmox tag rendering -- Inventory tree items display Proxmox tag shapes and colors from datacenter.cfg.

Improved​

  • Settings modularity -- Datacenter settings were split into smaller components and completed with missing Proxmox fields.
  • Notification target resolution -- Notification APIs now return actual endpoints instead of only target types.
  • Toast system -- MUI Snackbar/Alert toasts were replaced with the product's custom notification implementation.

Fixed​

  • SSH node resolution -- SSH no longer falls back to the load balancer address when the app runs behind a proxy.
  • Inventory scrolling -- Removed an unwanted global scroll on the inventory page.
  • Tag edits -- Tag updates now sync correctly after edits.

v1.2.4 -- 2026-04-05​

Added​

  • LXC hardware editing -- LXC containers now support swap editing and clearer disk display.
  • AI settings disclosure -- The AI settings page includes a data-disclosure notice so operators understand what can be sent to an AI provider.
  • Automatic release publishing -- Version tags now create GitHub releases with generated changelog content.

Improved​

  • Rolling update polling -- Polling frequency is reduced while idle to lower background load.

Fixed​

  • LXC type coverage -- Swap and mountpoint fields were added to TypeScript types.
  • AI assistant toggle -- Disabled assistant state now persists correctly in Settings.

v1.2.3 -- 2026-04-03​

Fixed​

  • Managed host cleanup -- Settings now automatically remove stale managed host entries when nodes are removed from a Proxmox cluster.

v1.2.2 -- 2026-04-03​

Added​

  • Dashboard time range picker -- A global 1h / 6h / 24h / 7d / 30d range selector drives all chart widgets.
  • Collapsible dashboard sections -- Section headers now use Grafana-style separators and can collapse groups of widgets.
  • Free widget resizing -- Dashboard widgets can be resized freely instead of being constrained by fixed maximum sizes.

Improved​

  • Dashboard widgets -- PBS Overview, Ceph Status, DRS Status, Guest Heatmap, Infra Global Chart, Backup Calendar and KPI cards were refreshed.
  • Theme consistency -- Widget colors, tooltips and date displays now adapt better across light and dark themes.
  • Layout cleanup -- Deleted widget types are cleaned from saved layouts, and default layouts/presets were updated.
  • Internationalization -- Missing dashboard keys were added for English, French, German and Chinese.

Fixed​

  • Build stability -- A duplicate fontSize property that caused build failures was removed.
  • Static analysis issues -- SonarCloud findings around sort comparison and redundant ternaries were resolved.

v1.2.1 -- 2026-03-30​

Added​

  • Near-zero downtime migration mode -- ESXi and XCP-ng migrations gained SSHFS transfer and SSHFS Boot flows, with fallback to cold migration where needed.
  • Backup job dialog refresh -- Backup job creation was overhauled and integrated with HA resource management.
  • HA resource names -- HA resource tables now include a Name column.

Improved​

  • Migration hardware detection -- ESXi SOAP XML parsing now detects disk controller types such as SCSI, SATA and IDE.
  • vSAN handling -- VMware vSAN datastore support was improved for migration scenarios.
  • Inventory list scrolling -- VM, Pool, Tag and Node list views scroll correctly again.
  • Performance -- Polling, RRD field handling and inventory tree re-renders were optimized.

Fixed​

  • PBS restore modal -- Restoring from a PBS datastore view works correctly.
  • Disk wear display -- Storage details show disk wear percentage instead of remaining life.
  • Cluster selection typing -- TypeScript narrowing issues around cluster selection were fixed.
  • Backup schedule type errors -- Autocomplete typing for backup schedule options was corrected.

v1.1.0 -- 2026-03-19​

Added​

  • German language support -- Full German translation for the dashboard interface
  • Multi-Tenancy -- Tenant management in Settings with super_admin gating and per-tenant data isolation
  • Dashboard interactive widgets -- Clickable dashboard widgets for quick navigation
  • Template panel -- New template management panel in the inventory view
  • OS type labels -- Display OS type labels on VM inventory items

Improved​

  • Migration vSAN support -- Improved handling of VMs on VMware vSAN datastores
  • Migration SSH fixes -- Fixed SSH orchestrator silent failures and unreliable qm set commands replaced with PVE REST API
  • Migration NFS storage -- Fixed fallback volume naming for NFS/directory storage imports
  • Reports -- Fixed vCPU counts, percentage calculations, white-label branding in PDFs, and tenant scoping
  • Security -- Resolved CodeQL findings and improved code quality

Fixed​

  • Migration EFI VMs -- Correct handling of EFI disk allocation where data disk becomes disk-1
  • Migration disk volume parsing -- Fallback to reading VM config via PVE API when regex parsing fails
  • Report tenant scoping -- Reports now respect tenant boundaries for multi-tenant deployments

v1.0.0 -- 2025-06-01​

Initial release of ProxCenter.

Added​

  • Unified Inventory -- Centralized tree view of all Proxmox nodes, VMs, containers, and storage pools with split-pane layout and multiple view modes (Tree, Hosts, Pools, Tags)
  • Real-Time Monitoring -- Live dashboards with CPU, memory, storage, and network metrics for nodes and guests
  • Connection Management -- Support for Proxmox VE and Proxmox Backup Server connections with API token and username/password authentication
  • Backup Management -- Centralized view of backup jobs, schedules, and restore points across all connected PBS instances
  • Event Log -- Aggregated event stream from all connected Proxmox hosts with filtering and search
  • User Management -- Invite users via email, assign roles, manage accounts
  • System Roles -- Built-in Admin, Operator, and Viewer roles with predefined permissions
  • Audit Log -- Comprehensive action trail for all user activity with filtering, search, and export
  • DRS (Distributed Resource Scheduling) -- Automatic VM load balancing across cluster nodes (Enterprise)
  • Site Recovery -- Disaster recovery planning with automated failover configuration (Enterprise)
  • Network Security -- Firewall rule management and network security policies (Enterprise)
  • Custom RBAC -- Role creation with granular permissions and scoped access control (Enterprise)
  • Scheduled Jobs -- Recurring task automation for backups, snapshots, and maintenance (Enterprise)
  • Infrastructure Reports -- Scheduled reports with PDF/CSV export (Enterprise)
  • Alerts & Notifications -- Threshold-based alerting with email and webhook delivery (Enterprise)
  • LDAP Integration -- LDAP / Active Directory authentication support (Enterprise)
  • CVE Scanner -- Vulnerability detection for Proxmox hosts (Enterprise)
  • License Management -- License-based feature gating with Community and Enterprise editions
  • Multi-Tenancy -- Tenant isolation for multi-client and multi-team environments (Enterprise)
  • White-Label Branding -- Custom logo, colors, and branding for the ProxCenter interface (Enterprise)
  • Templates & Cloud Images -- VM template management and cloud image deployment (Enterprise)
  • Rolling Updates -- Orchestrated node updates with automatic VM evacuation (Enterprise)
  • VMware / XCP-ng Migration -- Automated migration pipelines from ESXi and XCP-ng to Proxmox (Enterprise)
  • AI Insights -- AI-powered infrastructure analysis and recommendations (Enterprise)
  • OIDC / SSO -- OpenID Connect and single sign-on authentication (Enterprise)
  • Compliance -- Security hardening compliance checks (Enterprise)
  • Change Tracking -- Configuration change detection and diff view (Enterprise)
  • Self-Hosted Deployment -- Docker-based deployment with SQLite backend