This release adds two in-dashboard improvements — a one-click Proxmox update trigger from the Health Monitor and a mobile PWA install prompt — extends the Backups restore flow with atomic pmxcfs (`config.db`) snapshots and automatic ZFS data-pool import, sharpens Log2RAM behaviour on hosts running Proxmox Backup Server as a service, hardens firewall bridge sysctl tuning across VM lifecycle events, narrows the ZFS ARC optimization to its own scope, makes persistent NIC naming idempotent across reruns, rebuilds DKMS drivers automatically when a new kernel is staged, keeps the Monitor terminal session intact when a ProxMenux update is available, and reinforces five notification templates plus three Health panel checks.
Two changes, both scoped to scripts/backup_restore/backup_scheduler.sh, worth
shipping to main ahead of the full v1.2.3 release PR:
1. Attached-mode PBS jobs never asked about encryption. `_create_job_attached`
ran `hb_select_pbs_repository` and jumped straight to writing the .env with
PBS_REPOSITORY / PBS_PASSWORD / PBS_BACKUP_ID — no `hb_ask_pbs_encryption`
call, no PBS_KEYFILE / PBS_ENCRYPTION_PASSWORD emitted. The runner then
invoked `proxmox-backup-client backup` without `--keyfile`, so every
attached-mode backup landed on PBS unencrypted regardless of what the
operator would have picked. Confirmed via `git show` on eight historical
commits back to 61ff665c (beta 1.2.2.2) — the encryption call has NEVER
been in the attached branch; the standalone `_create_job_new` branch had
it since day one, they just diverged silently.
Fix mirrors `_create_job_new` exactly (lines 413-443):
hb_ask_pbs_encryption || return 1 # abort on cancel
local pbs_kf_val=""
[[ -n "${HB_PBS_KEYFILE_OPT:-}" ]] && pbs_kf_val="$HB_STATE_DIR/pbs-key.conf"
lines+=(... "PBS_KEYFILE=${pbs_kf_val}" "PBS_ENCRYPTION_PASSWORD=${HB_PBS_ENC_PASS:-}")
The Monitor Web path (flask_server.py::api_host_backups_job_create)
already accepted pbs_encrypt_mode for both modes and passed it through
correctly, so the fix is confined to the CLI wizard.
2. Backend selection menu reordered from `local | borg | pbs` to
`pbs (recommended) | borg | local` so the recommended default sits at the
top of the list. PBS gets the "(recommended)" suffix in its label.
Deployed and verified on the four test hosts (.50, .55, .89, .1.10) —
attached-mode wizard now shows the encryption dialog immediately after the
PBS job picker, and the .env carries PBS_KEYFILE + PBS_ENCRYPTION_PASSWORD
when the operator opts in.