Skip to content

Releases: C2Tech-sys/proxion

Proxion v0.13.0

Choose a tag to compare

@github-actions github-actions released this 08 Oct 23:18

Added

  • VM/CT Firewall tab (T73): inner Rules / Aliases / IP Sets tabs. Aliases and IP sets are the
    datacenter firewall's panels pointed at the guest (add, edit, rename and delete aliases; create,
    rename and delete IP sets and add, edit and remove their entries, including the nomatch flag),
    and the rule dialog's source and destination fields now suggest the guest's own aliases and IP sets
    next to the inherited datacenter ones. Needs a signed-in session and VM.Config.Network on the
    guest; changes forward PVE's digest. New routes under
    /api/actions/guest/{node}/{type}/{vmid}/firewall/{aliases,ipsets}.
  • VM Hardware tab: the BIOS, Machine, Display and SCSI Controller rows are now editable, and a VM
    without an EFI disk or TPM state gets "Add EFI disk" / "Add TPM state". BIOS switches between
    SeaBIOS and OVMF (and can add the EFI disk in the same save, since an OVMF guest without one loses
    its UEFI settings on every stop); Machine picks i440fx or q35, a pinned version from the node's own
    list or "Latest (default)", a virtual IOMMU on q35, or resets to PVE's default; Display sets the
    adapter and video memory; SCSI Controller picks the model. Needs a signed-in session and
    VM.Config.HWType for the four rows, VM.Config.Disk plus Datastore.AllocateSpace on the
    storage for the EFI disk and TPM state. New route
    PUT /api/actions/guest/:node/qemu/:vmid/firmware.
  • Node > System: a new System tab with inner tabs for DNS (search domain and up to three servers),
    Time (time zone, with the node's local and UTC time), Options (description, start-all-on-boot
    delay, wake-on-LAN MAC, ballooning target), Hosts (an /etc/hosts editor) and Certificates (every
    certificate file with its validity, amber under 30 days and red once expired). A custom
    certificate can be uploaded (certificate chain, private key, optional force and pveproxy restart)
    behind a typed UPLOAD confirmation that warns the Proxmox web UI becomes unreachable if the
    certificate or key is wrong and that a PVE_TLS_FINGERPRINT pin needs updating, or removed behind
    a typed REMOVE confirmation. The private key is never logged or kept. Needs a signed-in session
    and Sys.Modify on the node; edits forward PVE's digest where it accepts one. New routes under
    /api/actions/node/:node/system/*.

Proxion v0.12.0

Choose a tag to compare

@github-actions github-actions released this 08 Oct 19:45

Added

  • Datacenter > Firewall: the cluster-wide firewall in five inner tabs -- the datacenter's rules
    (add, edit, delete, enable or disable, reorder, reusing the guest firewall's rule dialog), the
    options (a master Enable switch that asks you to type ENABLE first because an inbound DROP
    policy can lock you out of every node, input and output policy, ebtables, the log rate limit),
    security groups and the rules inside them, aliases, and IP sets with their entries (including the
    nomatch exclusion flag). Needs a signed-in session and Sys.Modify on /; changes forward
    PVE's digest where it accepts one. New routes under /api/actions/datacenter/firewall/*.
  • Datacenter -> Backup Jobs: the Datacenter page's Backup Jobs tab manages the cluster's scheduled
    vzdump jobs like PVE's Datacenter -> Backup panel. The table shows each job's schedule, next run,
    storage, mode, which guests it covers, compression, retention and comment, with an inline
    Enabled switch; add and edit a job (schedule presets or a custom calendar event, all guests with
    an exclude list, a pool or chosen guests, keep-* retention, email notification, advanced
    options), "Run now", a "Show included guests" sheet with each guest's volumes (a drive with
    backup=0 is marked), and delete behind a typed-job-id confirmation. Needs a signed-in session
    and Sys.Modify on / (Run now: VM.Backup on each guest and Datastore.AllocateSpace on the
    storage).
  • Datacenter -> Users & Permissions (T68): manage users, groups, ACL entries and API tokens, view roles, and change passwords from
    the Datacenter page. Writes go through new /api/actions/datacenter/access/* routes (session sign-in only, one privilege checked per
    call, PVE's own refusals relayed); a password is never logged or echoed and a new API token's secret is shown once, never stored.
  • Datacenter -> Storage and Datacenter -> Pools. The Storage tab lists every storage definition with
    its usage and adds, edits and removes them (Directory, NFS, SMB/CIFS, LVM, LVM-Thin, ZFS and
    Proxmox Backup Server, with scan helpers, node selection and keep-* retention); removing one drops
    the definition only, never the data, and local cannot be removed. The Pools tab creates, comments
    and deletes pools and adds or removes guests and storages. New routes under
    /api/actions/datacenter/storage and /api/actions/datacenter/pools need a session sign-in and
    Datastore.Allocate / Pool.Allocate; CIFS and PBS passwords are sent to PVE once and are never
    logged, echoed or stored.
  • Node → Network: the node's Network tab now lists every interface and lets you create a Linux
    bridge, bond or VLAN, edit an interface (a physical one only its addressing, autostart, MTU and
    comment) and delete a bridge, bond or VLAN. Proxmox only stages these changes, so a pending
    banner shows the diff with Apply configuration (typed APPLY confirmation; applying can
    disconnect the node from the network if the configuration is wrong) and Revert. Needs a
    signed-in session and Sys.Modify on the node; deleting the interface that carries the address
    Proxion reaches Proxmox at is refused.

Proxion v0.11.1

Choose a tag to compare

@github-actions github-actions released this 08 Oct 15:54

Security

  • Notification webhooks never follow redirects, and "Send test notification" now reports a failed
    channel only as request failed (HTTP <status>), (timeout) or (network) (email: also
    authentication failed) instead of the upstream's error text, so the button cannot be used to
    probe hosts or ports reachable from the server. New optional PROXION_NOTIFY_ALLOWED_HOSTS
    restricts the webhook and SMTP hosts that settings (saved in the app or set in the environment)
    may use; unset keeps today's behaviour, and an unparseable value fails closed (nothing is sent
    or saved until it is fixed). The channel status shown in Preferences now reflects what was
    actually built, not just what is stored. Email sender and recipient addresses are validated as
    bare addresses, and a kept webhook token is only reused while the scheme, host and port are
    unchanged.

Added

  • Notification settings in the app: the Preferences page can now switch notifications on or off,
    snooze them (1 h, 8 h, 24 h, 7 days), mute individual alert kinds (backups, failed tasks, storage
    usage), and edit the delivery options and the webhook / email channel details, with no command
    line. Needs a signed-in session and Sys.Modify on /. The PROXION_NOTIFY_* variables stay the
    defaults; saving writes notify-settings.json (mode 0600) into the data directory, which then
    takes over and is applied immediately, without a restart. Secrets are never sent back to the
    browser. New routes: GET/PUT /api/notify/settings and POST /api/notify/mute.

Proxion v0.11.0

Choose a tag to compare

@github-actions github-actions released this 06 Oct 22:47

Added

  • Convert to template: a stopped VM or container can be turned into a template from the object
    header's "More" menu or the inventory tree's context menu, behind a typed-VMID confirmation
    (the change is permanent). POST /api/actions/guest/:node/:type/:vmid/template needs a signed-in
    session and VM.Allocate on the guest, and refuses a running/paused guest (guest-running) or one
    that is already a template (already-template).
  • Create container wizard: General, Template, Disks, CPU, Memory, Network, DNS and Confirm steps
    (opened from the node context menu or the top bar's Create menu), validated per step, ending in
    one new allow-listed POST /api/actions/guest/:node/lxc/create that follows the task and opens
    the new container. Needs a signed-in session, VM.Allocate on the new CT ID and
    Datastore.AllocateSpace on the root disk's storage (409 vmid-taken for an id in use). The root
    password is never logged, echoed or stored; SSH public keys travel newline-separated, as PVE's
    ssh-public-keys expects.
  • Create VM wizard: eight steps (General, OS, System, Disks, CPU, Memory, Network, Confirm) that
    mirror PVE's, opened from the top bar's Create menu or a node's context menu. One request to a
    new allow-listed route, POST /api/actions/guest/:node/qemu/create, composes the whole VM (ISO
    or no media, q35/OVMF with an EFI disk, optional TPM 2.0, one disk, CPU, memory, one NIC, boot
    order) from a strict typed body, then Proxion follows the task and opens the new VM. Needs a
    signed-in session, VM.Allocate on the new VMID and Datastore.AllocateSpace on every storage a
    new volume goes on (Datastore.Audit or Datastore.AllocateSpace on the ISO's storage); a VMID
    already in use is refused with 409 before PVE is called. The shared service token stays
    read-only.

Changed

  • An invalid PROXION_NOTIFY_* / PROXION_PUBLIC_URL value no longer crash-loops the server at
    boot: notifications are disabled with one startup warning (Notifications disabled: <key and allowed values>, never echoing webhook/SMTP URLs or tokens), GET /api/notify/status reports
    the error, and the Preferences page shows it and disables "Send test notification". Core
    settings (PVE URL, token, session secret, ports, TLS pin, agents) still fail hard.

Proxion v0.10.3

Choose a tag to compare

@github-actions github-actions released this 06 Oct 20:52

Fixed

  • Notification emails: the Outlook button label sat below the button edge (Word's engine
    pushes text down when a line-height is forced inside VML); the label now relies on
    v-text-anchor:middle alone.

Proxion v0.10.2

Choose a tag to compare

@github-actions github-actions released this 06 Oct 20:04

Fixed

  • Notification emails: the "Open in Proxion" button no longer clips its label in Outlook desktop
    (96-DPI Office block, VML namespaces, a wider fixed-height VML button with exact line height).

Proxion v0.10.1

Choose a tag to compare

@github-actions github-actions released this 06 Oct 16:41

Changed

  • Alert notifications are formatted per channel instead of plain text: email is an HTML message
    with a card per alert and an "Open in Proxion" button (plain-text alternative kept), Discord
    gets embeds, Slack gets blocks, ntfy and Gotify get Markdown with a click action, and the
    generic webhook gains headline, highestSeverity, sentAt and per-event
    guestName/guestType/label/color. Events now carry the guest's name and type, the email
    subject is [site] headline — first alert, and "Send test" sends two realistic sample alerts.
    No env variable, channel selection or route changes.

Fixed

  • Deploy kit: set-env.sh writes values single-quoted so Docker Compose never interpolates a
    $ inside a secret (an SMTP password containing $abc used to be silently truncated).

Proxion v0.10.0

Choose a tag to compare

@github-actions github-actions released this 05 Oct 22:35

Added

  • A guest Options tab (VM and container), modelled on PVE's Options panel: start at boot,
    start/shutdown order, protection (with a confirmation), tags, plus the VM's OS type, QEMU
    guest agent, local-time RTC, tablet pointer, ACPI, KVM and hotplug, and the container's DNS
    servers and search domain (unprivileged and architecture are shown read-only). Name/hostname
    reuses the existing rename dialog. Backed by one new allow-listed
    PATCH /api/actions/guest/:node/:type/:vmid/options route that checks VM.Config.Options,
    VM.Config.HWType (VM tablet/ACPI/KVM/hotplug) or VM.Config.Network (container
    hostname/DNS) per field; session sign-in only. Editing the guest agent keeps its
    type / freeze-fs-on-backup sub-options.
  • A Cloud-Init tab on VMs: view and edit user, password, DNS domain and servers, SSH public
    keys, package upgrade, type and each network device's IP config (DHCP or static with gateway,
    IPv4 and IPv6), see the changes PVE holds back as pending, and regenerate the cloud-init
    image. Session sign-in only, gated on VM.Config.Cloudinit; the password is sent to Proxmox
    to hash and is never logged or shown back. A VM without a Cloud-Init drive gets a hint to add
    one on the Hardware tab.
  • Add, edit and remove a VM's USB devices, PCI passthrough devices and serial ports from its
    Hardware tab ("Add device" menu in a new Devices row, plus a pencil and a remove button on each
    device row; serial ports are add/remove only). USB: Spice port, host vendor:device ID, host
    port or a mapped device, with USB 3; PCI: a host device (picked from the node's list grouped by
    IOMMU group, or typed) or a mapped device, with All functions, PCI-Express, ROM-Bar, Primary
    GPU and MDev type; serial: a socket. Session sign-in only, gated on VM.Config.HWType; raw
    USB/PCI devices still need root@pam in Proxmox, whose error is shown as-is. The host and mapping
    pickers fall back to typing when the account lacks Sys.Modify / Mapping.Audit. Options the
    dialogs don't show (a PCI ROM file, vendor overrides, ...) are kept on edit. Containers are
    unchanged.
  • A Firewall tab on VMs and containers: the guest's firewall options (enable, input/output
    policy, DHCP, NDP, router advertisement, MAC and IP filter, log levels) and its rule list with
    add, edit, delete, enable/disable and move up/down, including security-group rules. Enabling the
    firewall with a DROP input policy asks first, and edits, deletes, moves and option changes
    forward PVE's digest of the last read so a concurrent edit is refused. Session sign-in only, gated on VM.Config.Network.

Fixed

  • The Boot Order row of a VM with no boot order now reads "Default order (disks, then
    CD/DVD, then network)" instead of "No boot device", since PVE still boots using its default.
  • Detaching a container bind mount no longer promises an unused volume: the confirmation says
    a bind mount has no volume and the mount point is simply removed.
  • Editing a network device kept in the legacy <model>,macaddr=<MAC> form no longer duplicates
    the MAC (PVE rejected the repeated key); the MAC is kept once as <model>=<MAC>.

Proxion v0.9.0

Choose a tag to compare

@github-actions github-actions released this 01 Oct 00:27

Added

  • Edit a VM's boot order from its Hardware tab: the Boot Order row shows the order as
    chips (or "No boot device") and a pencil opens a dialog listing every bootable device
    (disks, CD/DVD drives, network devices) with an "enabled" checkbox and Up/Down buttons.
    Legacy boot: cdn + bootdisk configs are read and rewritten as order=.... Session
    sign-in only, gated on VM.Config.Options; containers have no boot order.
  • Add, detach and remove disks from a guest's Hardware tab. "Add disk" (VM) / "Add mount
    point" (container) creates a new volume on an image-capable storage of the node -- bus,
    size, a format limited to what the storage supports, cache / discard / SSD / IO thread and
    backup for a VM; path, backup, read-only and ACL for a container -- and shows each
    storage's free space. "Detach" keeps the volume as an unused disk; "Remove" on an unused
    disk destroys the volume and needs its slot name typed to confirm. Session sign-in only;
    adding needs VM.Config.Disk on the guest plus Datastore.AllocateSpace on the storage,
    detaching and removing need VM.Config.Disk.
  • Add, edit and remove network devices from a guest's Hardware tab: an "Add network
    device" button and an edit/remove action on each NIC row. A VM picks model, bridge
    (from the node's bridges), VLAN tag, firewall, rate limit, disconnect and MTU; a
    container picks its interface name, bridge, IPv4 (DHCP / static + gateway /
    manual), IPv6 (SLAAC / DHCP / static + gateway / manual), VLAN tag, firewall, rate
    limit and MTU (1 = the bridge MTU on a VM). A new device gets a Proxmox-generated MAC
    (or an override); editing never changes an existing MAC and keeps options the dialog
    doesn't show (queues, trunks, ...). Session sign-in only, gated on VM.Config.Network
    -- the shared service token stays read-only here too.

Changed

  • Web test suite: 30 s test/hook timeouts, 10 s element-wait budgets in the heavy
    route-level tests, and an opt-in PROXION_VITEST_WORKERS=<n> cap so parallel suites
    on a busy machine stop timing out.

Proxion v0.8.0

Choose a tag to compare

@github-actions github-actions released this 30 Sep 21:11

Added

  • Edit a guest's hardware from its Hardware tab (first cut): processors (sockets,
    cores, CPU type grouped by vendor; a container's cores), memory (MiB with a GiB
    helper, plus the balloon minimum for a VM and swap for a container), the ISO in
    each CD/DVD drive (or "No media"), and growing a disk (add N GiB -- never a
    shrink). Changes PVE holds back until the guest restarts are listed in a
    "Changes pending a restart" banner with the affected rows badged "pending".
    Session sign-in only, gated on VM.Config.CPU/VM.Config.Memory/
    VM.Config.CDROM/VM.Config.Disk -- the shared service token stays read-only
    here too.