Skip to content

v1.2.5

Latest

Choose a tag to compare

@MacRimi MacRimi released this 01 Sep 17:10
· 136 commits to main since this release

ProxMenux logo ProxMenux v1.2.5

ProxMenux v1.2.5 introduces the complete Apps and Easy Updates experience for LXC: application detection and registration, a centralised web-link launcher, version tracking and independent or bulk updates for the operating system, applications, Docker Engine and Docker projects. This release also brings the Monitor in eight languages, customisable navigation, an Actions API for automation, native Pushover and wide-reaching improvements across backups, health, hardware, network and post-install.

🚀 Apps dashboard

  • New top-level Apps tab with a single grid for every web link registered in LXCs together with the user's custom links.
  • Each card opens the service directly and, when it is associated with a guest, offers a shortcut into the modal of the owning LXC or VM.
  • Search, category filter and sort by name, ID or category, with per-device preferences preserved between sessions.
  • Categories coming from Proxmox VE Helper-Scripts are shared across the application editor, the LXC App tab and the dashboard.
  • Custom links cover services running inside a VM, reverse proxies, external panels or any URL the user wants at hand.
  • Docker states resolve per image associated with the link, so the container update never gets confused with the engine update.

🔄 Easy Updates for LXC applications

  • The Updates tab presents independent blocks for OS packages, registered applications, Docker Engine and Docker images or projects.
  • Each block carries its own action. Green is reserved for a verified up-to-date state, purple flags an available update and a neutral state covers manual methods or version-less checks.
  • Compatible with current and historical Proxmox VE Helper-Scripts updaters, relying only on static wrappers that can be validated without executing dynamic values.
  • Official or manual installations can define their own version detector and a custom update command. That command replaces the automatic method so the user keeps explicit control.
  • An application that carries only web links can also declare an updater, even without version tracking configured.
  • New Bulk update section above Options. The OS is always part of the action and the user picks which applications, Docker Engine and additional Docker units go along with it.
  • Images that belong to the same Compose project are grouped internally and recreated in a single execution.
  • Scheduled automations can pick the same component set instead of being limited to the old "OS / application / both" model.
  • Completed actions regenerate the affected information and update counters and notifications with the real post-run state.

🐳 Docker Engine and images

  • Docker is treated as the parent application of the LXC; the services it runs stay as associated links and images rather than surfacing as independent native apps.
  • The inventory relies on the containers actually in use and on Compose projects, avoiding turning stale unused images into false pending updates.
  • Docker Engine has its own detection and action, separated from the general OS packages.
  • Images are compared by remote digest, show installed and available versions when they can be resolved, and let the user update the matching unit.
  • The inventory follows the 24-hour rolling cycle, can be refreshed with Check now and is forced after updates or guest lifecycle events.
  • Startup states distinguish between Docker not yet available and an inventory that is genuinely empty.

🎯 Application detection and catalog

  • .github/scripts/generate_app_tracking_catalog.py builds a reproducible catalog from a pinned commit of community-scripts/ProxmoxVE and analyses only LXC launchers.
  • 389 operational hints and 23 real-container overrides now cover more than 380 workloads.
  • Supported methods: file + regex, binary, dpkg package, apk package, Python distribution, Docker exec and compatible Docker metadata.
  • Detectors can use ordered alternatives and fallback paths so both modern, historical and official installations are recognised.
  • Registration data can include name, official website, port, category and theme-aware logos.
  • Detected suggestions are preloaded together with the guest and appear immediately; Find applications runs a full on-demand scan for a specific LXC.

⚡ Cache and VM/LXC lifecycle

  • Each modal's data is preloaded and reused across tabs, so opening App or Updates never triggers a full refetch nor replaces valid content with a loading placeholder.
  • Saving, editing, checking, hiding or removing an application writes the result directly into the shared caches.
  • Start, stop, restart and restore events reuse the Proxmox task watcher and regenerate only the affected guest.
  • VM/LXC backups return the task UPID and continue inside Proxmox without depending on an HTTP connection limited to 60 seconds.

🌍 Languages and navigation

  • The Monitor is available in English, Spanish, German, French, Italian, Portuguese, Slovak and Swedish.
  • Swedish was fully reviewed by a native speaker and the official product vocabulary is protected across every language.
  • New Navigation order card to move Overview, Apps, VM & LXC, Node, Backup, Terminal and Admin. Whatever slot the user drags to the first position becomes the tab the Monitor opens on.
  • The custom order works with mouse, touch, desktop and mobile menu, and is preserved in localStorage.
  • The documentation site gained a resumable incremental translation flow that preserves human wording, commands, paths, URLs, placeholders and rich-text tags.

🎯 Automation and notifications

  • New authenticated Actions API to reboot or shut down the host, run the safe Proxmox update, update ProxMenux itself and control or back up VM/LXC from external integrations.
  • Long operations run under transient systemd units and status endpoints so they survive even if the Monitor itself restarts.
  • Pushover joins as a native channel with encrypted credentials, event filters, quiet hours, daily digest, sound / device selectors and optional high priority for critical events.
  • PVE webhooks accept local host addresses over LAN, Tailscale, WireGuard and IPv6; the full vzdump body reaches the parser before being split across channels.
  • Backup destination, migration target node, snapshot name and the real reason behind system trouble now surface in the matching notifications.

🩺 Health and storage

  • Memory & Swap raises a critical alert only when both high swap usage and low available RAM hold at the same time during the configured window.
  • Kernel OOM blocks are correlated as a single event so host, cgroup, cpuset and NUMA pressure can be told apart, and the actually affected LXC and process are identified when the evidence is available.
  • VMs running the QEMU Guest Agent report real aggregated filesystem usage; pseudo filesystems, read-only media and duplicates are excluded.
  • The same numbers feed configurable low-space alerts for VMs.
  • Storages such as iSCSI with maxdisk=0 stay available when Proxmox reports status=available; the UI states that capacity has not been reported instead of assuming a fault.
  • USB disks behind SAT bridges can be queried with the correct smartctl mode when direct access works.

🌡 Sensors and physical identity

  • NVMe and drivetemp sensors are correlated with /sys/class/hwmon and /sys/block to show the Linux device, model and serial number.
  • HDD and SSD are classified by the block device's real rotational flag, not just by the sensor name.
  • Only the hwmon topology is cached for 60 seconds; temperatures continue to be live readings.

🟢 NVIDIA and hardware

  • The NVIDIA installer cross-references the running kernel, official branch and the GPU's PCI IDs before recommending a driver.
  • Passthrough and VM/LXC switching work by exact BDF, letting one NVIDIA GPU be assigned to a VM while another — even one with the same vendor:device pair — stays operational on the host or in an LXC.
  • Migrations from older VFIO configurations preserve effective ownership and never drop unrelated Intel or AMD IDs.
  • NVIDIA and Coral DKMS installers rebuild on a best-effort basis against a new kernel before the next boot.

🌐 Network and security

  • Network Flow recognises Linux bonds and represents both the bond topology and its active member without hiding the real physical link.
  • The view respects the user's Bits/Bytes preference.
  • Persistent NIC rules exclude bridges, migrate legacy ProxMenux formats and only remove files that carry their ownership marker.
  • Sysctl tuning for fwbr*, fwln*, fwpr* and tap* interfaces is applied even when Proxmox creates them during a VM's lifecycle.
  • Fail2Ban carries a global allowlist for IPv4, IPv6 and CIDR entries manageable from Security, honouring inherited values and protecting loopback.

🗄 Host backup and restore

  • /var/lib/proxmenux/backup-jobs is part of the default profile and job definitions travel with custom profiles as well.
  • After a restore, jobs are validated and rebuilt as their own timers or vzdump hooks, honouring the enabled state and preventing duplicates.
  • A custom path is always copied whole as an explicit user decision; the safety exclusions of the built-in profile are not extended to it.
  • Any real staging failure aborts the operation and is documented in metadata/failed_paths.txt.
  • pmxcfs's config.db is captured with sqlite3 .backup while pve-cluster stays running.
  • ZFS data pools can be imported after restore; incomplete pools are skipped and the outcome shows on the progress card.
  • /etc/systemd/network is included in the default paths so persistent interface names are preserved.

🛡 Post-install

  • Registered functions with precise rollback for rpcbind, MOTD, selected utilities, Ceph repositories, subscription banner and settings managed by ProxMenux.
  • Debian 13 compatibility and signed-by/deb822 repositories without relying on apt-key.
  • ZFS ARC uses a target of 10% of RAM capped at 16 GiB, reports the effective value and safely reconciles duplicate limits coming from other files.
  • The generic memory optimisation no longer imposes a global overcommit policy.
  • Bashrc lets the user pick between current directory name and full path, and explains how to reload the running session.
  • Log2RAM rotates PBS logs and avoids unsupported ACL operations on the backing filesystem.
  • The post-install update detector recognises heredoc-based functions, and modified functions publish their new version through the existing registry.

🩹 Fixes

  • Scheduled PBS jobs preserve the server fingerprint.
  • Scheduled SMART tests carry valid /dev/... paths.
  • Disks in standby are respected by the Monitor's checks.
  • Backup runner ships a safe .env parser compatible with legacy values that contain spaces.
  • Uninstall menu handles boolean entries inherited in installed_tools.json.
  • Safe update relies on HTTPS 443 instead of an ICMP probe that a firewall could block.
  • Proxmox/ACME certificate renewal on new TLS connections, preserving the last validated context while the certificate or key is still being written.
  • Authentication setup form recoverable after declining the initial configuration.
  • Long vzdump reports preserved to avoid false failures when a row is truncated.
  • Persistent NIC rules kept from accidentally renaming vmbr0.
  • Script terminal closed in the correct order at the end so no bogus WebSocket error is surfaced.

🙏 Acknowledgments

Special thanks — @Vaso73

@Vaso73 has been a driving force of the 1.2.4 beta cycle. He built the i18n scaffolding that turned the Monitor into a multilingual product, delivered the full Slovak translation reviewed page by page, and contributed a sustained series of hardening pull requests across authentication, Fail2Ban, LXC flows and vzdump webhook preservation (#273, #277, #278, #279, #281, #282, #283). This release would not have the shape it has without that ongoing hands-on collaboration.

Contributors