You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
VM/CT Firewall tab (T73): inner Rules / Aliases / IP Sets tabs. Aliases and IP sets are the
datacenter firewall's panels pointed at the guest (add, edit, rename and delete aliases; create,
rename and delete IP sets and add, edit and remove their entries, including the nomatch flag),
and the rule dialog's source and destination fields now suggest the guest's own aliases and IP sets
next to the inherited datacenter ones. Needs a signed-in session and VM.Config.Network on the
guest; changes forward PVE's digest. New routes under /api/actions/guest/{node}/{type}/{vmid}/firewall/{aliases,ipsets}.
VM Hardware tab: the BIOS, Machine, Display and SCSI Controller rows are now editable, and a VM
without an EFI disk or TPM state gets "Add EFI disk" / "Add TPM state". BIOS switches between
SeaBIOS and OVMF (and can add the EFI disk in the same save, since an OVMF guest without one loses
its UEFI settings on every stop); Machine picks i440fx or q35, a pinned version from the node's own
list or "Latest (default)", a virtual IOMMU on q35, or resets to PVE's default; Display sets the
adapter and video memory; SCSI Controller picks the model. Needs a signed-in session and VM.Config.HWType for the four rows, VM.Config.Disk plus Datastore.AllocateSpace on the
storage for the EFI disk and TPM state. New route PUT /api/actions/guest/:node/qemu/:vmid/firmware.
Node > System: a new System tab with inner tabs for DNS (search domain and up to three servers),
Time (time zone, with the node's local and UTC time), Options (description, start-all-on-boot
delay, wake-on-LAN MAC, ballooning target), Hosts (an /etc/hosts editor) and Certificates (every
certificate file with its validity, amber under 30 days and red once expired). A custom
certificate can be uploaded (certificate chain, private key, optional force and pveproxy restart)
behind a typed UPLOAD confirmation that warns the Proxmox web UI becomes unreachable if the
certificate or key is wrong and that a PVE_TLS_FINGERPRINT pin needs updating, or removed behind
a typed REMOVE confirmation. The private key is never logged or kept. Needs a signed-in session
and Sys.Modify on the node; edits forward PVE's digest where it accepts one. New routes under /api/actions/node/:node/system/*.