ProxMenux 1.2.6.2-beta: OCI containers in the Monitor, docs and fixes

OCI manager Apps
- App tab: containers installed from an OCI image are identified from their
  installation record; the application and image versions are shown and an
  update is detected by image digest; repository link; Refresh data.
- Updates tab for OCI containers: Update and Recreate run the same flow as the
  OCI menu in the Monitor terminal; the pre-update backup can be kept in a
  backup storage; scheduled image updates with an optional minimum age.
- Logs tab: console output of the application, kept on the host
  (lxc.console.logfile + logrotate) and followed live.
- The Proxmox console opens a shell (cmode: shell) when the image has one.
- A damaged image download is fetched again before failing.
- Multi-container applications open at their LAN address; volume mount
  points on block storage report their usage.

Monitor
- Proxmox notifications are delivered to a loopback-only HTTP listener when
  HTTPS is enabled, so they no longer fail certificate verification.
- Log persistence counts recurring patterns only; an ended burst is not
  reported as persistent and its warning clears on its own (#386).
- Proxmox notification config backups are deduplicated and capped at three.
- The update icon on the Apps page opens the container on its Updates tab.
- Version 1.2.6.2-beta and its release notes in every Monitor language.

Docs
- OCI manager Apps and Audit & Report rebuilt as per-page message files,
  with a new page for OCI containers in the Monitor.
- Seven pages fixed where rich-text tags were missing from t.rich.

Translations
- Spanish fixes across the OCI engine, the Monitor and the TUI menus.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
MacRimi
2026-09-25 21:51:12 +02:00
co-authored by Claude Opus 5.5
parent 386d33df6e
commit 4437a671d2
524 changed files with 14459 additions and 3841 deletions
@@ -157,12 +157,12 @@
{
"endpoint": "/api/vms/<vmid>/control",
"method": "POST",
"use": "Start / stop / shutdown / reboot a VM or LXC container (the same operations the Monitor's VM & LXC modal exposes). Body: {\"action\": \"start|stop|shutdown|reboot\"}. Synchronous — returns the outcome directly with no polling needed."
"use": "Start / stop / shutdown / reboot a VM or LXC container (the same operations the Monitor's VM & LXC modal exposes). The body carries <code>action</code>: <code>start</code>, <code>stop</code>, <code>shutdown</code> or <code>reboot</code>. Synchronous — returns the outcome directly with no polling needed."
},
{
"endpoint": "/api/vms/<vmid>/backup",
"method": "POST",
"use": "Create a vzdump backup of a VM or LXC. Body (all optional except when the defaults don't match your storage layout): {\"storage\": \"<pve-storage>\", \"mode\": \"snapshot|suspend|stop\", \"compress\": \"zstd|lzo|gz|none\", \"protected\": true, \"notes\": \"…\", \"notification\": \"auto|always|failure|never\", \"pbs_change_detection\": \"default|legacy|data\"}. Returns the PVE task UPID."
"use": "Create a vzdump backup of a VM or LXC. Body fields, all optional unless the defaults do not match the storage layout: <code>storage</code> (a PVE storage), <code>mode</code> (<code>snapshot</code>, <code>suspend</code> or <code>stop</code>), <code>compress</code> (<code>zstd</code>, <code>lzo</code>, <code>gz</code> or <code>none</code>), <code>protected</code> (<code>true</code> or <code>false</code>), <code>notes</code>, <code>notification</code> (<code>auto</code>, <code>always</code>, <code>failure</code> or <code>never</code>) and <code>pbs_change_detection</code> (<code>default</code>, <code>legacy</code> or <code>data</code>). Returns the PVE task UPID."
},
{
"endpoint": "/api/vms/<vmid>/backups",
@@ -0,0 +1,146 @@
{
"meta": {
"title": "Assessment and inventory | Audit & Report",
"description": "The Audit & Report assessment: report profiles, how results are classified, accepted risks, unreadable sources, Lynis and the inventory of the node."
},
"header": {
"title": "Assessment and inventory",
"description": "The assessment inspects the node, keeps its findings and answers different questions depending on the report profile.",
"section": "Audit & Report"
},
"sections": [
{
"id": "read-only",
"blocks": [
{
"calloutInfo": {
"title": "An assessment inspects; it does not change the configuration",
"body": "It reads the configuration and state of the host. It writes its results, reports and logs, and the boot checks can mount EFI system partitions for a moment. The configuration it assesses is not modified."
}
},
{
"p": "<strong>Run assessment</strong> starts a run with the profile selected in <strong>Report</strong>. The view shows the date of the last run and how long ago it was."
}
]
},
{
"id": "profiles",
"title": "Report profiles",
"intro": "Each profile answers a different question. The checks and sections are selected before the document is composed.",
"blocks": [
{
"table": {
"headers": ["Profile", "What it covers"],
"rows": [
["Full audit", "Every check and all the structure available."],
["Quick diagnosis", "Every check; the result opens with the critical findings, the warnings and the readings that could not be verified."],
["Inventory", "A description of the node, with no checks and no classification."],
["Security review", "Exposure, access, privileges, certificates, updates, repositories and Lynis."],
["Backup assurance", "Coverage, age, results, verification, retention and recovery of the backups."],
["Capacity and wear", "Growth margin, memory, space usage and the service life of the disks."]
]
}
},
{
"p": "The contents of each document are described in <reportsLink>Reports and comparisons</reportsLink>."
}
]
},
{
"id": "results",
"title": "How results are classified",
"blocks": [
{
"table": {
"headers": ["Classification", "Meaning"],
"rows": [
["Critical", "A failed condition that has priority."],
["Warning", "A condition that needs a review, given the evidence or the policy."],
["Observation", "Information about the node that is not reported as a failure."],
["Unverified", "The source the check needs could not be read. It does not mean the problem is absent."],
["Conformant", "The condition meets the criterion applied."],
["Not applicable", "Nothing within the scope of the check applies."],
["Accepted risk", "The finding exists and a decision about it has been recorded."],
["Excluded by policy", "The policy declares that the element is left out of the count."]
]
}
},
{
"p": "Findings can be filtered by area: System, Storage, Network, Security, Backup, Guests and Hardware. Each finding keeps its evidence, with the source it was read from."
}
]
},
{
"id": "unverified",
"title": "When a source cannot be read",
"blocks": [
{
"table": {
"headers": ["Case", "Behaviour"],
"rows": [
["Unverified", "The check keeps its identity, states in its evidence which source failed and does not turn missing data into a conformant result."],
["Incomplete evidence", "The report names the source and the time of collection, so a real problem can be told apart from an insufficient reading."],
["A new run", "Once the access, package or service is corrected, the same profile runs again and the comparison shows whether the result could be verified."]
]
}
}
]
},
{
"id": "lynis",
"title": "Lynis",
"blocks": [
{
"p": "The security review uses the Lynis report of the host. When Lynis has not been run yet, or its report is older than the threshold of the policy, a dialog offers <strong>Run with Lynis</strong>, which takes a few minutes longer, or <strong>Run without Lynis</strong>, which uses the existing report."
},
{
"figure": {
"src": "/monitor/audit/lynis-dialog.png",
"alt": "Dialog that offers to run the assessment with or without Lynis",
"caption": "The Lynis dialog before a security review."
}
}
]
},
{
"id": "accept",
"title": "Accepting a risk",
"blocks": [
{
"p": "<strong>Accept risk</strong> records a decision on a finding. The reason is required and is stored with the author and the date."
},
{
"table": {
"headers": ["Field", "Options"],
"rows": [
["Reason", "Free text, required."],
["Stops applying after", "90 days, 180 days, 1 year or does not expire. When the period ends the finding becomes active again."],
["Remind me to review", "A reminder that brings the decision back to attention while it stays in force."]
]
}
},
{
"p": "An accepted finding stays visible with its decision, and <strong>Return to active</strong> revokes it. An accepted risk is not a correction: the comparison reports it as accepted, not as resolved."
}
]
},
{
"id": "inventory",
"title": "Inventory",
"blocks": [
{
"list": {
"items": [
"Identity, Proxmox VE version, kernel, subscription and cluster.",
"CPU, memory, board, BIOS, controllers and IOMMU.",
"Disks, SMART, power-on hours and recorded events.",
"Adapters, bonds, bridges, latency and connections.",
"Storage, guests with their disks and interfaces, and backups.",
"PCI passthrough and the software ProxMenux manages."
]
}
}
]
}
]
}
@@ -0,0 +1,148 @@
{
"meta": {
"title": "Changes | Audit & Report",
"description": "The change journal of Audit & Report: what ProxMenux changed on the host, what was there before, the difference and whether it can be undone."
},
"header": {
"title": "Changes",
"description": "The journal of the operations ProxMenux performs on the host and, where it was captured, the state before and after each one.",
"section": "Audit & Report"
},
"sections": [
{
"id": "purpose",
"blocks": [
{
"calloutInfo": {
"title": "From the script that ran to the change it made",
"body": "A long function may change only two lines. The journal keeps each concrete operation with the script, function and version responsible, the resource affected, the difference and whether it can be undone."
}
},
{
"flow": {
"nodes": [
{ "label": "Script", "detail": "function + version" },
{ "label": "Capture", "detail": "content before" },
{ "label": "Operation", "detail": "file · package · service" },
{ "label": "Journal", "detail": "attribution + difference" }
],
"caption": "The capture is taken when the operation runs and is consolidated when the Monitor reads the journal."
}
},
{
"figure": {
"src": "/monitor/audit/changes-view.png",
"alt": "Changes view of Audit & Report with the entries grouped by post-install option and script",
"caption": "The Changes view, with the difference of a file edited by ProxMenux."
}
}
]
},
{
"id": "types",
"title": "Kinds of entry",
"intro": "The filter at the top separates the entries by kind.",
"blocks": [
{
"table": {
"headers": ["Kind", "What it records"],
"rows": [
["Configuration", "ProxMenux wrote, edited or removed a file, changed a setting or altered a service."],
["Installations", "ProxMenux added a package or component, and the packages that actually appeared are recorded."],
["Executions", "ProxMenux ran a command; what it changed is up to the command itself."],
["Applied", "A function was applied before the journal existed; the state before it was not captured."]
]
}
}
]
},
{
"id": "groups",
"title": "How the view is organised",
"blocks": [
{
"table": {
"headers": ["Section", "Contents"],
"rows": [
["Post-install optimizations", "Grouped by the post-install option the user selected."],
["ProxMenux scripts", "GPU, Coral, network, storage, security, utilities and the other instrumented scripts, including the ProxMenux installer and ProxMenux Monitor."],
["Installed packages and utilities", "Software ProxMenux installed on the host."]
]
}
},
{
"p": "Within each section, <strong>By function</strong> groups the entries under the function that made them."
}
]
},
{
"id": "entry",
"title": "What each entry shows",
"blocks": [
{
"list": {
"items": [
"The script, function and version responsible.",
"The date and the affected resource.",
"The known state before and after the change.",
"The lines added and removed.",
"The packages that were actually added.",
"The state transition of a service.",
"<strong>Undoing this</strong>: <em>Restores exactly what was there</em>, <em>Deletes the file (there was none before)</em>, <em>The package can be uninstalled</em>, a partial undo, or <em>Cannot be undone from the journal</em>."
]
}
}
]
},
{
"id": "before",
"title": "What the state before means",
"blocks": [
{
"p": "The state before can be captured content, a file created for the first time or an unknown state. Changes made before the journal existed cannot be reconstructed; running the function again captures first the state found at that moment."
}
]
},
{
"id": "limits",
"title": "Scope of the journal",
"blocks": [
{
"list": {
"items": [
"Manual changes and changes made by other software are not recorded.",
"Only operations that go through the ProxMenux audit primitives are covered.",
"Recording never blocks the operation it describes: if the entry cannot be written, the operation goes on.",
"Successive changes to one resource are shown as the known origin against the current state."
]
}
}
]
},
{
"id": "retention",
"title": "Stored evidence",
"blocks": [
{
"table": {
"headers": ["Element", "Behaviour"],
"rows": [
["Entries", "They are kept on the host; nothing is removed from the journal automatically."],
["Captured content", "A captured object is kept while an entry refers to it."],
["Size of a capture", "Content above 1 MiB is not stored whole; the entry records that the capture was skipped because of its size."],
["Reading", "The Monitor does not load stored objects above 2 MiB."],
["Difference", "At most 400 lines are shown, and a longer difference is marked as truncated."],
["Listing", "The API returns 200 entries per request by default and up to 1000."]
]
}
},
{
"calloutWarning": {
"title": "Kept content is not an automatic undo",
"body": "The content before a change can be inspected and restored by hand, but the Changes view does not revert operations. An execution entry records the command without knowing every effect of the tool it ran."
}
}
]
}
]
}
@@ -0,0 +1,83 @@
{
"meta": {
"title": "Audit & Report | ProxMenux Monitor",
"description": "Assess a Proxmox VE node, record what ProxMenux changed on it and declare what is expected from its guests and storage, with printable reports."
},
"header": {
"title": "Audit & Report",
"description": "An assessment of the node, the journal of what ProxMenux changed on it and the declaration of what is expected from it, with documents that can be printed or saved as PDF.",
"section": "ProxMenux Monitor"
},
"sections": [
{
"id": "views",
"blocks": [
{
"calloutInfo": {
"title": "Three views, three questions",
"body": "Audit & Report keeps apart the facts of the node, the interventions of ProxMenux and the expectations declared for it. A configuration the assessment cannot place against a declared purpose is described, not reported as a failure."
}
},
{
"cards": {
"items": [
{ "icon": "shield", "title": "Assessment — how is the node?", "body": "Runs the checks of the chosen profile, composes the inventory and classifies what needs attention, with the evidence of each result." },
{ "icon": "refresh", "title": "Changes — what did ProxMenux do?", "body": "Lists the files, packages, services and commands the instrumented ProxMenux scripts changed, with what was there before when it was captured." },
{ "icon": "fileText", "title": "Policy — what is expected?", "body": "Declares which guests need a backup or must start with the host, which storage is essential and the thresholds of the checks." }
]
}
},
{
"flow": {
"nodes": [
{ "label": "Assessment", "detail": "facts" },
{ "label": "Policy", "detail": "context" },
{ "label": "Changes", "detail": "interventions" }
],
"caption": "The assessment provides the facts, the policy gives them context and the journal records what ProxMenux did."
}
},
{
"figure": {
"src": "/monitor/audit/assessment-view.png",
"alt": "Audit & Report in ProxMenux Monitor with the Assessment, Changes and Policy views",
"caption": "Audit & Report, with the Assessment view open."
}
}
]
},
{
"id": "boundaries",
"title": "Three different functions",
"blocks": [
{
"table": {
"headers": ["Function", "What it does"],
"rows": [
["<healthLink>Health Monitor</healthLink>", "Observes metrics and events continuously and can raise notifications."],
["Audit & Report", "Runs an assessment when it is asked for, documents the node and compares runs with each other."],
["Change journal", "Records the operations ProxMenux performs through its audit primitives."]
]
}
}
]
},
{
"id": "pages",
"title": "Pages of this section",
"blocks": [
{
"next": {
"items": [
{ "label": "Assessment and inventory", "href": "/docs/monitor/audit-report/assessment", "tail": "profiles, results, accepted risks and inventory." },
{ "label": "Changes", "href": "/docs/monitor/audit-report/changes", "tail": "the journal of what ProxMenux changed on the host." },
{ "label": "Policy", "href": "/docs/monitor/audit-report/policy", "tail": "guests, storage and thresholds." },
{ "label": "Reports and comparisons", "href": "/docs/monitor/audit-report/reports", "tail": "the six documents and the reference run." },
{ "label": "Scope and guarantees", "href": "/docs/monitor/audit-report/scope", "tail": "sources, limits and stored data." }
]
}
}
]
}
]
}
@@ -0,0 +1,111 @@
{
"meta": {
"title": "Policy | Audit & Report",
"description": "The node policy of Audit & Report: backup, autostart and recovery objective of each guest, the role of each storage and the thresholds of the checks."
},
"header": {
"title": "Policy",
"description": "The policy declares what no inspection can deduce: what each guest and storage is for and the thresholds the checks apply.",
"section": "Audit & Report"
},
"sections": [
{
"id": "principle",
"blocks": [
{
"calloutInfo": {
"title": "With no declaration, the report describes; with one, it assesses",
"body": "An assessment sees what the host does, not what it is for. A guest without a backup whose purpose is not declared is reported as an observation. If its backup is declared required, the same absence is reported as a warning. Nothing has to be declared."
}
},
{
"figure": {
"src": "/monitor/audit/policy-view.png",
"alt": "Policy view with the guests, the storage and the thresholds of the node",
"caption": "The Policy view."
}
}
]
},
{
"id": "guests",
"title": "Guests",
"intro": "Each VM and LXC of the node has three fields. A value left as default takes the general value, shown next to it.",
"blocks": [
{
"table": {
"headers": [
"Field",
"Values",
"Effect on the assessment"
],
"rows": [
[
"Backup",
"Required, Not required, Not stated",
"A missing backup is a warning when it is required, an observation when it is not stated, and it is left out of the count when it is not required."
],
[
"Autostart",
"Required, Not required, Not stated",
"Whether the guest has to start with the host."
],
[
"Recovery objective",
"Hours",
"The maximum acceptable age of the last backup."
]
]
}
}
]
},
{
"id": "storage",
"title": "Storage",
"blocks": [
{
"p": "An unreachable storage is reported as critical when it is declared essential or serves a running guest, as a warning when its role is not stated, and as an observation when it is declared optional."
}
],
"intro": "Each storage of the node is declared Essential, Optional or Not stated."
},
{
"id": "thresholds",
"title": "Thresholds",
"intro": "An empty threshold uses the shipped value, shown as its placeholder.",
"blocks": [
{
"list": {
"items": [
"Storage capacity review (%) and thin pool fill review (%).",
"Thin overprovisioning ratio and memory overcommit ratio.",
"ZFS scrub interval (days).",
"Backup age fallback (days) and schedule grace (ratio).",
"Certificate expiry notice (days).",
"Disk service life (hours) and recent disk error window (days).",
"Lynis report age (days) and package index age (days).",
"Journal against its cap (%).",
"Filesystem space review (%) and filesystem inode review (%)."
]
}
}
]
},
{
"id": "save",
"title": "How the policy is saved",
"blocks": [
{
"p": "The declaration is validated and saved atomically in <code>/usr/local/share/proxmenux/audit_policy.json</code>. Each save carries a revision: if the declaration changed in another session, the draft is not saved and the view offers to reload the saved declaration."
},
{
"calloutWarning": {
"title": "The policy is never inferred",
"body": "ProxMenux adds no requirement on its own. An empty field keeps the shipped value or stays not stated, and a partial declaration only affects the elements it names."
}
}
]
}
]
}
@@ -0,0 +1,160 @@
{
"meta": {
"title": "Reports and comparisons | Audit & Report",
"description": "The six Audit & Report documents, how they are printed or saved as PDF, and how runs are compared with a reference run."
},
"header": {
"title": "Reports and comparisons",
"description": "Six documents, each composed for a different question, and the comparison of every run with a reference run.",
"section": "Audit & Report"
},
"sections": [
{
"id": "intro",
"blocks": [
{
"calloutInfo": {
"title": "Six documents, not six styles",
"body": "The engine selects checks and sections before composing the document. A quick diagnosis is not a full audit with fewer pages, and an inventory presents no assessment results. The sample documents below use fictitious data."
}
}
]
},
{
"id": "documents",
"title": "The six documents",
"blocks": [
{
"downloads": {
"items": [
{
"title": "Full audit",
"body": "Documents the node end to end as a technical record.",
"href": "/monitor/audit/sample-audit-full-report.pdf",
"facts": [
{ "label": "Checks", "value": "Every available check." },
{ "label": "Contents", "value": "Executive summary; identity and cluster; hardware; network and latency; storage; guests; passthrough; applications; findings with evidence; sources and scope." }
]
},
{
"title": "Quick diagnosis",
"body": "Shows what needs attention without the complete inventory.",
"href": "/monitor/audit/sample-audit-diagnostic-report.pdf",
"facts": [
{ "label": "Checks", "value": "The same checks as the full audit." },
{ "label": "Contents", "value": "Minimal identity; critical findings; warnings; relevant observations; unverified readings and priority actions. Diagrams, inventory and long annexes are left out." }
]
},
{
"title": "Inventory",
"body": "Describes what exists on the node without assessing it.",
"href": "/monitor/audit/sample-audit-inventory-report.pdf",
"facts": [
{ "label": "Checks", "value": "None; no finding is classified." },
{ "label": "Contents", "value": "Identity; cluster; CPU and memory; board, BIOS and controllers; network; storage; VMs and LXCs; passthrough; applications and elements managed by ProxMenux." }
]
},
{
"title": "Security review",
"body": "Covers exposure and the controls over access to the node.",
"href": "/monitor/audit/sample-audit-security-report.pdf",
"facts": [
{ "label": "Checks", "value": "The security area, plus container privileges, updates, repositories and the APT chain." },
{ "label": "Contents", "value": "Identity and cluster; network and latency; access; firewall; 2FA; certificates; privileges; updates; repositories; state and age of Lynis." }
]
},
{
"title": "Backup assurance",
"body": "Checks that the declared protection exists and that its backups are usable.",
"href": "/monitor/audit/sample-audit-backup-report.pdf",
"facts": [
{ "label": "Checks", "value": "The backup area, plus storage connectivity and notification delivery." },
{ "label": "Contents", "value": "Coverage per guest; declared recovery objective; age and result; destination; retention; verification; failed jobs; recovery and incomplete sources." }
]
},
{
"title": "Capacity and wear",
"body": "Measures growth margin and signs of exhaustion or ageing.",
"href": "/monitor/audit/sample-audit-capacity-report.pdf",
"facts": [
{ "label": "Checks", "value": "The storage and hardware areas, plus memory, swap, journal and the host filesystem." },
{ "label": "Contents", "value": "Usage and thresholds; thin pools; overprovisioning; memory; inodes; ZFS; temperatures; power-on hours; SMART errors and NVMe/SSD service life." }
]
}
]
}
},
{
"figure": {
"src": "/monitor/audit/audit-report-preview.png",
"alt": "First page of a full audit report",
"caption": "Every document shares the report identifier, numbered sections, date, node, profile and footer."
}
},
{
"p": "A document contains the identity of the node and the date of the assessment, the executive result, a summary by area, the structure of hardware, network and storage, the protection of the guests, the findings with their evidence, the sources that could not be read, and the scope and policy applied, in the measure each profile includes them."
}
]
},
{
"id": "print",
"title": "Printing or saving as PDF",
"blocks": [
{
"steps": {
"items": [
{ "title": "Run", "body": "An assessment runs with the profile selected in <strong>Report</strong>." },
{ "title": "Review", "body": "The finished run shows its findings, the sources it could not read and the policy it applied." },
{ "title": "Generate report", "body": "<strong>Generate report</strong> opens the view prepared as a document." },
{ "title": "Print", "body": "<strong>Print or save as PDF</strong> opens the print dialog of the browser, where a printer or <em>Save as PDF</em> is selected." }
]
}
},
{
"calloutTip": {
"title": "The printout is a document, not a screenshot",
"body": "The action bar is hidden, a table that continues on the next page repeats its header, blocks avoid unnecessary breaks and every page keeps the identification and numbering."
}
}
]
},
{
"id": "compare",
"title": "Comparing with a reference run",
"intro": "<strong>Use as reference</strong> marks a finished run as the reference. Later runs are compared with it and their findings are separated into:",
"blocks": [
{
"table": {
"headers": ["Group", "Meaning"],
"rows": [
["New", "Reported now and not before."],
["Worse", "Still reported, and graver or reaching further than before."],
["Better", "Still reported, but less grave or reaching less far than before."],
["Resolved", "No longer reported, and nobody accepted them."],
["Accepted", "No longer counted because a risk was accepted, not because the host changed."],
["No longer assessed", "Present before and absent from this run; nothing verified that they stopped."]
]
}
},
{
"table": {
"headers": ["Reference run", "Behaviour"],
"rows": [
["Setting it", "Any finished run can be marked; none is marked automatically."],
["Changing it", "Marking another run moves the reference without deleting the history."],
["Comparing", "When no two runs are selected, the comparison uses the reference and the selected or most recent run."],
["Keeping runs", "The 30 most recent runs are kept, and the reference run is never removed."],
["Without a reference", "The view states that no reference run has been chosen yet, so there is nothing to compare against."]
]
}
},
{
"calloutWarning": {
"title": "A report describes one moment",
"body": "An assessment does not certify a whole period. Older results stop describing the current state; the view shows the age of the last run and each source keeps the time it was collected."
}
}
]
}
]
}
@@ -0,0 +1,97 @@
{
"meta": {
"title": "Scope and guarantees | Audit & Report",
"description": "Where the data of Audit & Report comes from, what is outside its view, the guarantees of its design and where its data is stored."
},
"header": {
"title": "Scope and guarantees",
"description": "Where the data of an assessment comes from, what stays outside its view and where Audit & Report keeps its data.",
"section": "Audit & Report"
},
"sections": [
{
"id": "sees",
"title": "What it observes",
"blocks": [
{
"list": {
"items": [
"The configuration and state of the local node.",
"The declared configuration of the VMs and LXCs.",
"The state of the storage as Proxmox VE knows it.",
"The available history of backups and verifications.",
"SMART data and the events the Monitor has collected.",
"The state of services, cluster, HA and local sources."
]
}
}
]
},
{
"id": "outside",
"title": "What is outside its view",
"blocks": [
{
"list": {
"items": [
"The interior of the guests, beyond what they declare to Proxmox VE.",
"Network equipment outside the host.",
"Remote dependencies the node cannot observe.",
"Physical state the hardware does not expose.",
"Manual actions or actions of other software, in the change journal."
]
}
},
{
"calloutWarning": {
"title": "Missing evidence is not evidence of absence",
"body": "A source that cannot be read gives an unverified or incomplete result, never a conformant one. The report lists the sources that were not available."
}
}
]
},
{
"id": "guarantees",
"title": "Guarantees of the design",
"blocks": [
{
"list": {
"items": [
"Stable identifiers for the checks.",
"History of runs and findings.",
"A validated policy, saved atomically.",
"Accepted risks with a reason, visible.",
"Attribution of changes to script and function.",
"Capture before and after, where it is available.",
"An explicit result when something cannot be measured or captured."
]
}
}
]
},
{
"id": "storage",
"title": "Where the data is stored",
"blocks": [
{
"table": {
"headers": ["Data", "Location"],
"rows": [
["Policy", "<code>/usr/local/share/proxmenux/audit_policy.json</code>"],
["Assessments", "The audit database of the Monitor"],
["Captured objects", "<code>/usr/local/share/proxmenux/changes/objects/</code>"],
["Pending entries", "<code>/usr/local/share/proxmenux/changes/spool/</code>"],
["Consolidated journal", "<code>/usr/local/share/proxmenux/changes.db</code>"]
]
}
},
{
"calloutInfo": {
"title": "A tool to review, not a certification",
"body": "Audit & Report reviews, compares and documents the node. Its results are read together with the purpose of the system, the declared policy and the sources available."
}
}
]
}
]
}
@@ -96,7 +96,8 @@
{ "method": "docker label / docker exec", "use": "Reads an OCI version label or runs a version command inside a Docker container." },
{ "method": "python distribution", "use": "Uses importlib.metadata through the selected Python interpreter." },
{ "method": "command", "use": "Runs an advanced argv-style command without a shell and extracts the version from its output." },
{ "method": "manual", "use": "Stores a version entered manually; it must be changed after upgrading the app." }
{ "method": "manual", "use": "Stores a version entered manually; it must be changed after upgrading the app." },
{ "method": "OCI image", "use": "For containers installed by OCI manager Apps. Reads the application and image versions from the installation record and compares the installed digest with the one the registry publishes; it needs no configuration." }
],
"sourcesHeading": "Available-version sources",
"sources": [
@@ -52,7 +52,7 @@
},
"drillIn": {
"heading": "Per-guest drill-in modal",
"intro": "The modal opens with the guest name, VMID, type, state and uptime. Its navigation adapts to the guest: <strong>Status</strong>, <strong>App</strong> and <strong>Updates</strong> for LXC application management, <strong>Mounts</strong> when an LXC has mount points, plus <strong>Backups</strong> and <strong>Firewall</strong>. The fixed action bar keeps the lifecycle controls and the LXC terminal available from every tab.",
"intro": "The modal opens with the guest name, VMID, type, state and uptime. Its navigation adapts to the guest: <strong>Status</strong>, <strong>App</strong> and <strong>Updates</strong> for LXC application management, <strong>Mounts</strong> when an LXC has mount points, <strong>Logs</strong> for containers installed by OCI manager Apps, plus <strong>Backups</strong> and <strong>Firewall</strong>. The fixed action bar keeps the lifecycle controls and the LXC terminal available from every tab.",
"statusTitle": "Tab 1 — Status",
"statusImageAlt": "Per-guest drill-in modal — Status tab with CPU / Memory / Disk live cards, Disk and Network I/O totals, the OS distro logo, and the Resources / IP Addresses block",
"statusImageCaption": "Status tab — live CPU / Memory / Disk with progress bars at the top, accumulated I/O totals (disk read/write, network down/up) below, then the static Resources block with Notes and + Info expansions and the IP Addresses pill list.",
@@ -106,7 +106,9 @@
],
"mountsCalloutTitle": "What this gives you over the native UI",
"mountsCalloutBody": "A truthful, capacity-aware view of every place the container reads or writes. NFS or CIFS shares mounted from inside the CT — invisible to the Proxmox web UI — appear here with the same look and the same health probe as any configured mount point. Stale remote mounts and zombie binds are flagged before they bite during a backup.",
"backupsTitle": "Tab 5 — Backups",
"logsTitle": "Tab 5 — Logs (OCI containers only)",
"logsBody": "Appears only for containers installed by OCI manager Apps. It shows the console output of the main process of the image, kept on the host in <code>/var/log/proxmenux/oci/VMID.console.log</code>: the last 100, 500 or 1000 lines, followed live while the container runs, with a filter and a download. It reads the file on every open, so it also works with the container stopped. The details are in <ociLink>OCI containers in ProxMenux Monitor</ociLink>.",
"backupsTitle": "Tab 6 — Backups",
"backupsImageAlt": "Per-guest drill-in modal — Backups tab with the available backups list, destination tag, sizes and the Create Backup button",
"backupsImageCaption": "Backups tab — every backup stored on configured Proxmox storages for this guest, sorted newest first. The tab header carries the count badge.",
"backupsIntro": "Lists every backup stored across configured Proxmox storages for this guest, sorted newest first. The tab title carries a count badge so you see at a glance whether the guest is backed up. Per row:",
@@ -116,7 +118,7 @@
"<strong>Size</strong> — final on-disk size of the backup."
],
"backupsOutro": "The <strong>+ Create Backup</strong> button at the top right kicks off a new run on the storage marked as \"Backup target\" in the Proxmox storage config. Restore lives in the Proxmox web UI — the Monitor exposes the \"is this guest backed up recently?\" view, not the recovery flow.",
"firewallTitle": "Tab 6 — Firewall",
"firewallTitle": "Tab 7 — Firewall",
"firewallIntro": "Reads the per-guest Proxmox firewall log straight from the host (no extra service, no polling). The tab is always present in the navigation strip; the panel decides what to render depending on whether the firewall is enabled for that guest and whether any rule is actually logging:",
"firewallItems": [
"<strong>Firewall disabled</strong> — an amber notice explains exactly where to enable it in the Proxmox UI (<em>&lt;Container|VM&gt; → Firewall → Options</em>) and reminds you that at least one rule needs <code>log: info</code> (or higher) before packets show up.",