-
-
Notifications
You must be signed in to change notification settings - Fork 27
Proxmox VE
Since 3.1.0 Β· Contributed by Andrew Turbay (@turbay-a) in PR #167 Β· How it works underneath: Proxmox and Cloud Director β Developer Guide
FreeITSM reads the virtual machines, LXC containers, nodes, IP addresses and MAC addresses from one or more Proxmox VE servers and lists them under Asset Management β Servers, next to vCenter. It only reads: nothing is ever changed in Proxmox.
You can add several servers. Each syncs on its own schedule, and its VMs are kept apart from every other server's.
Cloud Director too? See VMware Cloud Director. Both work the same way.
- A Proxmox user who can manage permissions (for example
root@pam), once, for the setup. - The address of a Proxmox node, normally
https://<host>:8006. - The FreeITSM server able to reach port 8006 on that node.
- Proxmox web UI β Datacenter β Permissions β Users β Add.
-
User name
freeitsm, Realm Proxmox VE authentication server (pve). Usepve, notpam, so it isn't a Linux login. - A password is optional: FreeITSM will use an API token, not the password.
- Add.
Datacenter β Permissions β Roles β Create, name it FreeITSMSync, and tick:
| Privilege | Why |
|---|---|
Sys.Audit |
the cluster and the node list |
VM.Audit |
each VM's and container's configuration |
Datastore.Audit |
storage, for disk sizes |
VM.GuestAgent.Audit (Proxmox VE 9) or VM.Monitor (Proxmox VE 8) |
a VM's IP addresses, through the QEMU guest agent |
Proxmox VE 9 removed VM.Monitor and split its job into the VM.GuestAgent.* privileges; VM.GuestAgent.Audit is the read-only one. Without either, every VM and container is still found, with its MAC addresses, but not a VM's IP addresses.
Give the role no write privilege. FreeITSM never needs one.
Datacenter β Permissions β Add β User Permission: path /, user freeitsm@pve, role FreeITSMSync, Propagate on.
A token has its own secret and can be revoked without touching the user.
-
Datacenter β Permissions β API Tokens β Add, user
freeitsm@pve, Token IDitsm. -
Privilege Separation: untick it and the token has the user's permissions (simplest). Leave it ticked and you must also give the role to the token: Permissions β Add β API Token Permission, path
/, tokenfreeitsm@pve!itsm, roleFreeITSMSync. - Add. Proxmox shows the secret, a UUID, once. Copy it now; if it's lost, delete the token and make another.
That gives you two values: the Token ID freeitsm@pve!itsm and the secret.
Asset Management β Settings β Proxmox VE servers β Add server:
| Field | Value |
|---|---|
| Name | anything, e.g. pve-lab
|
| Server address |
https://<host>:8006. https only: the secret travels with every request, so FreeITSM won't send it over plain http |
| User or API token |
freeitsm@pve!itsm (or a user such as freeitsm@pve, with its password) |
| Password | the token secret (or the user's password). Stored encrypted, never shown again; leave it empty when editing to keep it |
| Sync every (minutes) | 5 to 10080 |
| Verify certificate | ticked for a certificate from a trusted authority. Proxmox installs with its own self-signed certificate: untick it for that, or better, give Proxmox a trusted certificate |
| Active | ticked |
Save, then Test. It says how many nodes it can see. Then Sync now, and Show VMs.
-
VMs: Proxmox only knows a VM's address through the QEMU guest agent. Turn it on in the VM's Options β QEMU Guest Agent, install
qemu-guest-agentinside it (apt install qemu-guest-agenton Debian or Ubuntu), and restart the VM. Only addresses on the VM's own network cards are kept, sodocker0,vethβ¦and bridge interfaces inside the guest are skipped. - Containers: no agent needed; the address comes from the container's configuration. A container on DHCP shows no address, because Proxmox doesn't know its lease.
- Sync hypervisors on the Servers page syncs vCenter, then every active Proxmox and Cloud Director server, with one result line for each. Anyone who can use Asset Management can press it, as for vCenter. Adding, changing and testing servers needs the Proxmox VE servers settings permission.
-
On a schedule,
cron/proxmox_sync.phpsyncs every active server whose interval has passed. Run it every few minutes:
*/5 * * * * php /var/www/html/cron/proxmox_sync.php >> /var/log/freeitsm-proxmox.log 2>&1
In Docker: docker exec <app container> php /var/www/html/cron/proxmox_sync.php, from the host's cron. On Windows, a Task Scheduler task running php.exe with the full path. It runs from the command line only; it can't be started from a browser.
FreeITSM removes a VM only when a list it read successfully no longer has it:
- A node that's offline keeps all its VMs.
- A node that's online but whose list of VMs (or of containers) couldn't be read keeps those VMs.
- The safety guard: if fewer than half of the VMs FreeITSM knows were seen in one sync, nothing is removed until a healthy sync confirms it. The usual cause is a permission or an offline node, not a real mass deletion.
A VM keeps its identity (server + VMID), so renaming it in Proxmox updates it rather than adding a second one.
| What you see | Likely cause |
|---|---|
| "Use an https:// address" | The address starts http://. Proxmox serves its API on https, port 8006. |
| "Proxmox refused this request (HTTP 401)" | Wrong token ID or secret, or the wrong realm: pve, not pam. |
| "Proxmox refused this request (HTTP 403)" | The user or token has no permissions. Check step 3, and step 4 if Privilege Separation is ticked. |
| "Could not reach the Proxmox server: β¦" | The address or port is wrong, or a firewall is in the way. The text after the colon says which. |
| "β¦SSL certificate problemβ¦" | Verify certificate is ticked and Proxmox has its self-signed certificate. Untick it, or install a trusted certificate. |
| "Connected, but the node list could not be read" | The user lacks Sys.Audit on /. |
| A VM has no IP address | The guest agent isn't running, or the role lacks VM.GuestAgent.Audit / VM.Monitor. For a container: it uses DHCP. |
| "Not reachable this cycle: pve2" or "pve2/qemu" | That node, or that list on it, didn't answer. Its VMs are kept. |
| "SAFETY GUARD: only 3 of 40 known VMs were seen" | Nothing was deleted. Check the nodes and the permissions, then sync again. |
Related: VMware Cloud Director Β· Proxmox and Cloud Director β Developer Guide Β· Assets
FreeITSM β an open-source IT Service Management platform Β· github.com/edmozley/freeitsm Β· MIT licence
- Installation
- β° Scheduled tasks (cron jobs)
- Architecture
- π§ͺ Developer tests
- AI Providers
- Internationalisation (i18n)
- Timezones & Time Handling
- π Date & Time Formats
- Theming & Dark Mode
- ποΈ Recent β getting back to what you were doing
- β¨οΈ Command palette (βK)
- π Searching inside tickets
- π Attached documents
-
MobileβFriendly
- β³ π« Mobile: Tickets
- β³ π» Mobile: Assets
- β³ π Mobile: Calendar
- β³ π Mobile: Knowledge
- β³ π¦ Mobile: Service Status
- β³ πΌ Mobile: Watchtower
- β³ π§© Mobile: Problem Management
- β³ π Mobile: Change Management
- β³ πΏ Mobile: Software
- β³ β Mobile: Tasks
- β³ π Mobile: Forms
- β³ π Mobile: Contracts
- β³ π Mobile: Domains
- β³ π Mobile: People
- β³ π Mobile: LMS
- β³ πΊοΈ Mobile: CMDB
- β³ πΊοΈ Mobile: Network Mapper
- β³ π§ Mobile: Process Mapper
- β³ βοΈ Mobile: Workflow
- β³ π₯οΈ Mobile: System
- β³ π Mobile: Reporting
- β³ π Mobile: System Wiki
- β³ π Mobile: Self-Service Portal
- β³ π§° Mobile: Techniques & Tricks
-
Security
- Layer 1 β which modules you can enter
- β³ π§© Module Access Control
- β³ π οΈ Module Access β Developer Guide
- Layer 2 β what you can administer
- β³ π Roles & Permissions
- β³ π οΈ Roles β Developer Guide
- β³ π€ Why capabilities are constants
- Layer 3 β the System module
- β³ π Admin Access Control
- Hardening
- β³ π Security review response 2026-08
- β³ π‘οΈ Security hardening 2026-08
- β³ π οΈ Security hardening 2026-08 β Developer Guide
- β³ π‘οΈ Round three β plain English
- β³ π οΈ Round three β Developer Guide
- β³ π‘οΈ CSRF protection (S4) β Developer Guide
- Single Sign-On (SSO)
- ποΈ LDAP & Active Directory
- π CardDAV contact sync
- Browser Extension
- API Reference
-
π REST API β how it works
- β³ π« REST API: Tickets
- β³ π» REST API: Assets
- β³ π΄ REST API: Problems
- β³ π REST API: Changes
- β³ π REST API: Knowledge
- β³ β REST API: Tasks
- β³ ποΈ REST API: CMDB
- β³ π REST API: Contracts
- β³ ποΈ REST API: Calendar
- β³ πΏ REST API: Software
- β³ π REST API: Domains
- β³ π¦ REST API: Service Status
- β³ βοΈ REST API: Morning Checks
- β³ π REST API: Forms
- β³ βοΈ REST API: Workflow
- β³ π·οΈ REST API: Cost centres
- β³ πΊοΈ REST API: Network Mapper
- β³ π§ Using the API docs page
- β³ π OpenAPI specification
- β³ β OpenAPI: kept correct
- β³ π οΈ Maintaining the catalogue
- Watchtower
-
Tickets
- β³ π Rota copy and paste β Developer Deep Dive
- β³ β Checklists & SOPs
- β³ βοΈ Mandatory fields
- β³ π·οΈ Ticket categories
- β³ π₯ Assigning tickets to a team, and escalation
- β³ π’ One board across every company
- β³ Mailbox Authentication
- β³ π€ Email send log
- β³ Basic IMAP mailboxes
- β³ Email rendering & images
- β³ SLA Management
- β³ WhatsApp channel
-
β³
βοΈ Telegram channel - β³ β CSAT company scope and filters β Developer Guide
- β³ π₯ Microsoft Teams channel
- β³ π¨οΈ Mattermost channel
- β³ π¬ Web chat channel
- β³ π£ Slack channel
- β³ π Linking tickets
- β³ β Record previews
- β³ π Ticket notes: internal or shared
- β³ ποΈ Canned responses
- β³ βοΈ Limiting replies to particular senders
- β³ π¨ Telling the analyst a ticket is theirs
- β³ βοΈ Email signatures
- β³ π The public web address
- β³ π’ Ticket numbering
- β³ π Raising a ticket for someone else
- β³ π Merging tickets
- β³ π Confidential tickets
- β³ π₯ Portal managers
- β³ π Who has seen a ticket
- β³ π Reading long tickets
- β³ β Splitting tickets
- β³ β Selecting several tickets
- β³ ποΈ The folder pane
- β³ π½ Just my tickets, or no closed ones
- β³ π οΈ Snoozing tickets β Developer Guide
- β³ π₯ Collision detection
- β³ β±οΈ Time tracking
- β³ π Scheduled work in your own calendar
- Problem Management
- Tasks
-
Assets
- β³ π’ Moving an asset between companies
- β³ π Shared asset locations
- β³ π§βπΌ Assigning assets to analysts
- β³ π Warranty and lease alerts
- β³ π Saved table views
- β³ π¨οΈ Recording anything, and importing it
- β³ π·οΈ QR asset labels
- β³ π Who holds what, and handover documents
- β³ π₯οΈ The inventory agent (PowerShell)
- β³ ποΈ Proxmox VE servers
- β³ βοΈ VMware Cloud Director servers
- β³ π Linking equipment to tickets
- β³ βοΈ Follow-up tasks on a ticket
- Knowledge
- Change Management
- Calendar
- Morning Checks
- Reporting
- Software
-
Forms
- β³ π¨ The form designer β Developer Guide
- β³ π Layout & the grid β Developer Guide
- β³ ποΈ Collections β grouping submissions
- β³ π Submissions as PDFs
- β³ β‘ What happens next β a form's own actions
- β³ π οΈ Sections & conditional logic β Developer Guide
- β³ π οΈ Lookup fields β Developer Guide
- β³ π‘οΈ Catalogue request approvals
- People
- Domains
- Contracts
- Service Status
- π Notifications
- π¨ War Room
- Self-Service Portal
- LMS
- Process Mapper
- CMDB
- Network Mapper
- Workflows
- Issue trackers (Jira, Azure DevOps)
- System
-
Overview
- β³ π Progress tracker
- β³ Concepts & vocabulary
- β³ Email routing & mailboxes
- β³ Settings: global vs per-company
- β³ Users & self-service
- β³ Staff cross-company access
- β³ π’ One board across every company
- β³ Worked examples
- β³ Pitfalls & gotchas
- β³ Scope: what it's for
- β³ π οΈ Developer Guide (make a module multi-company)
- β³ ποΈ Case study: CMDB (a linked graph)
- β³ π§ͺ Test harness (prove it's isolated)
- What this is
-
π Bugs resolved
- β³ π’ Chat tickets ignored your ticket numbering
- β³ π Dates shown as a dash, or in server time
- β³ π Assets β Users showed people from other companies
- β³ π Restricted analysts could read other modules' data
- β³ πΌοΈ Replies with a picture in the thread failed to send
- β³ π Reply attachments never reached the customer
- β³ π οΈ Outbound email attachments β Developer Guide
- β³ π A global SSO provider was missing from the portal
- β³ π Behind a proxy, the SSO redirect said http
- β³ βοΈ The portal tagline moved when you saved it
- β³ π¨ The portal settings screen forgot what you saved
- β³ π‘οΈ The approvals inbox said "Error" and nothing else
- β³ π A table's answers were missing from the PDF
- β³ β A single-select column let you tick every option
- β³ π The portal ignored a form's field widths
- β³ π The tasks board stopped taking clicks
- β³ ποΈ #121 The index list is out of date after upgrading
- β³ π #133 The calendar subscription was empty
- β³ π #131 Tasks always reopened on the board
- β³ π₯ #129 Every page returned HTTP 500 after upgrading
- β³ π³ #127 A PHP warning above the System page
- β³ π #126 Notes stamped with the server's clock
- β³ π Storing every date in UTC
- β³ πͺ The portal was down for everyone signed in
- β³ βοΈ #120 Workflow notes could never be written
- β³ βοΈ #123 Three errors when running Database Verification
- β³ π #122 The description box was a stub in the corner
- β³ π£ Demo data deleted real accounts
- β³ π #117 Sign-in redirected to the wrong address
- β³ π¨ #108 The priority dot was invisible
- β³ β±οΈ #116 Time logged from the right-click menu
- β³ π #114 API keys refused by our own guard
- β³ ποΈ #110 Assigning a task told nobody
- β³ πͺ #107 Signed out while still working
- β³ π #103 "Share with Requester" reached nobody
- β³ π #102 Search found nothing for hyphens
- β³ πͺ #101 Source code editor opened behind
- β³ βοΈ #88 Subtasks could not be ticked off
- β³ π» #84 Asset deep link selected nothing
- β³ π« #79 A new ticket arrived with no status
- β³ π§ #79 A ticket from email did not say so
- β³ π #78 Bell opened to nothing
- β³ π¬ #77 Mail only collected from Inbox
- β³ π #74 The default password could not be changed
- β³ π¦ #70 Renaming an impact level
- β³ π€ #67 App-only mailboxes could not send
- β³ π #45 Verify only ever worked for Microsoft
- β³ π #45 IMAP reported as not authenticated
- β³ βοΈ An email template stopped escaping itself
- β³ π The portal dashboard showed the wrong time
- β³ π’ The folder said 99 and the list showed 96