mkellermann97
5acd19887f
docs(nginx): route termwebsocket through the reverse-proxy example ( #541 )
...
- the example nginx.conf only matched shellws on the SSH-WS upstream, so the
VM/LXC terminal (termwebsocket) fell through to the default backend behind a
reverse proxy — the term console couldn't connect even after the #539 fix.
- widen the SSH-WS location to ^/api/clusters/.*/(shellws|termwebsocket); both
are served by the same port+2 server. Thanks markushergeth for the regex.
2026-06-12 16:50:35 +02:00
mkellermann97
f8c12d548e
v0.9.4 — Network View, Light Mode, Security Hardening
...
Features:
- Network View in Corporate Layout sidebar (bridges, SDN, per-node VM mapping)
- Custom bind address for reverse proxy on different host (#212 )
- OIDC JWT verification toggle for broken JWKS environments
- Corporate Layout light mode improvements
- Language picker dropdown for Corporate Layout (#236 )
- Community plugin: proxmox-ha (#226 )
- Spanish translations update (#234 )
Fixes:
- Cross-cluster replication storage mapping (#192 )
- Site recovery stuck plans + race conditions (#238 )
- Container/local disk migration with multiple storages
- Guest agent log spam when QEMU agent disabled (#237 )
- BG image upload behind reverse proxy (#210 )
- Topology diagram layout stability
- PBS cluster filtering (#142 )
- Datastore usage mismatch sidebar vs tab (#201 )
- Node shell letter-spacing in Corporate Layout
- Chevron icon rotation in Corporate node cards
Security:
- SQL injection whitelist for cluster field updates
- File upload path traversal + null byte hardening
- Cluster credentials endpoint access control
- Error message leak prevention (14 endpoints)
- Permission template fixes (5 undefined permissions)
2026-03-29 22:17:31 +02:00
hugo
a3ab4af227
grrr
2026-03-26 09:47:03 +01:00
hugo
363a6581a5
update http2 directive to new format
...
https://hg.nginx.org/nginx/rev/08ef02ad5c54
2026-03-26 09:43:33 +01:00
mkellermann97
67e7004271
v0.9.3: plugin system, balancing tolerance, 15 bug fixes, 8 features
...
Features:
- Plugin system: auto-discover, enable/disable at runtime, plugin API
- Pool exclusion from auto-balancing (like VM/node exclusion)
- Migration tolerance/hysteresis + 15min VM cooldown (anti-ping-pong)
- Storage cluster tolerance (per-storage deadband)
- CVE scanner PNG + PDF export
- Backup schedule editing (#207 )
- Custom role editing with name persistence (#167 )
- Reverse proxy WebSocket port reuse for VNC/SSH (PR #173 )
Bug Fixes:
- Cross-cluster replication: clone used target storage on source cluster (#192 )
- CVE scanner fails on failover node — wrong IP from _get_node_ip (#199 )
- SMBIOS status-all: skip offline nodes, bulk IP, retries=1 (#198 )
- PBS VM backups not showing — volid path format for linked PBS (#143 )
- Login background upload 403 behind reverse proxy — CSRF check (#210 )
- Rolling update log vanishes during node reboot (#179 )
- Rolling update confirmation wrong node count (#180 )
- Migration false failure on WARNINGS exit status (#184 )
- Ceph panel not rendering on PVE 9 + Ceph Squid (#191 )
- OIDC PKCE support for Authentik (#188 )
- Support bundle OOM on large log dirs — deque for tail
- Custom role name not persisted — name/ID conflation
- Cluster icon stays Database when offline
- Corporate overview Cluster Storage: sum shared + local datastores
- nginx.conf: correct WebSocket URL patterns for VNC/SSH
Other:
- @FernandoRD added to About credits (Portuguese)
- Site recovery: 8 missing audit log operations added
- VNC cert hints hidden when reverse proxy active
2026-03-22 21:38:41 +01:00
mkellermann97
1213c8abda
feat: XCP-ng Tech Preview integration, ACME auto-renewal, misc fixes
...
- XCP-ng/XAPI pool manager with full VM lifecycle (create, clone, migrate, snapshots)
- VM power actions, disk/network/CD-ROM management via XAPI XML-RPC
- VNC console, maintenance mode, node details, ISO upload
- RBAC with xapi.* permissions (16 new permissions)
- XCP-ng cluster type in frontend with Tech Preview badge
- ACME/Let's Encrypt auto-renewal support
- Datastore uploads, offline operation fixes
- SSH WebSocket auth hardening
- Example nginx reverse proxy config
2026-03-08 12:33:00 +01:00