You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A guest Options tab (VM and container), modelled on PVE's Options panel: start at boot,
start/shutdown order, protection (with a confirmation), tags, plus the VM's OS type, QEMU
guest agent, local-time RTC, tablet pointer, ACPI, KVM and hotplug, and the container's DNS
servers and search domain (unprivileged and architecture are shown read-only). Name/hostname
reuses the existing rename dialog. Backed by one new allow-listed PATCH /api/actions/guest/:node/:type/:vmid/options route that checks VM.Config.Options, VM.Config.HWType (VM tablet/ACPI/KVM/hotplug) or VM.Config.Network (container
hostname/DNS) per field; session sign-in only. Editing the guest agent keeps its type / freeze-fs-on-backup sub-options.
A Cloud-Init tab on VMs: view and edit user, password, DNS domain and servers, SSH public
keys, package upgrade, type and each network device's IP config (DHCP or static with gateway,
IPv4 and IPv6), see the changes PVE holds back as pending, and regenerate the cloud-init
image. Session sign-in only, gated on VM.Config.Cloudinit; the password is sent to Proxmox
to hash and is never logged or shown back. A VM without a Cloud-Init drive gets a hint to add
one on the Hardware tab.
Add, edit and remove a VM's USB devices, PCI passthrough devices and serial ports from its
Hardware tab ("Add device" menu in a new Devices row, plus a pencil and a remove button on each
device row; serial ports are add/remove only). USB: Spice port, host vendor:device ID, host
port or a mapped device, with USB 3; PCI: a host device (picked from the node's list grouped by
IOMMU group, or typed) or a mapped device, with All functions, PCI-Express, ROM-Bar, Primary
GPU and MDev type; serial: a socket. Session sign-in only, gated on VM.Config.HWType; raw
USB/PCI devices still need root@pam in Proxmox, whose error is shown as-is. The host and mapping
pickers fall back to typing when the account lacks Sys.Modify / Mapping.Audit. Options the
dialogs don't show (a PCI ROM file, vendor overrides, ...) are kept on edit. Containers are
unchanged.
A Firewall tab on VMs and containers: the guest's firewall options (enable, input/output
policy, DHCP, NDP, router advertisement, MAC and IP filter, log levels) and its rule list with
add, edit, delete, enable/disable and move up/down, including security-group rules. Enabling the
firewall with a DROP input policy asks first, and edits, deletes, moves and option changes
forward PVE's digest of the last read so a concurrent edit is refused. Session sign-in only, gated on VM.Config.Network.
Fixed
The Boot Order row of a VM with no boot order now reads "Default order (disks, then
CD/DVD, then network)" instead of "No boot device", since PVE still boots using its default.
Detaching a container bind mount no longer promises an unused volume: the confirmation says
a bind mount has no volume and the mount point is simply removed.
Editing a network device kept in the legacy <model>,macaddr=<MAC> form no longer duplicates
the MAC (PVE rejected the repeated key); the MAC is kept once as <model>=<MAC>.