Proxmox VE
17 posts on Proxmox VE: design decisions and how-to guides from small infrastructure estates run on a very low budget.
- PBS: fix the fingerprint mismatch after a rename or reinstall
Rename or reinstall a PBS host and it presents a new self-signed certificate. Every PVE storage entry and every remote on the other PBS has the old fingerprint pinned and refuses to connect. Where the pins live, how to read the new fingerprint, and the order to update them in.
- Proxmox: move VMs between two clusters
qm remote-migrate exists and is fussy. The path that works every time is a Proxmox Backup Server backup, already replicated to the other site, restored on the other cluster from a read-only storage entry with a new guest ID.
- PBS: a restore drill for one file, one guest and one site
A backup you have not restored from is a hope. Three rehearsed restores, each with its commands and its evidence: one file from a pxar archive, one guest to a new VMID on the local PBS, and one guest on the other cluster from the replica namespace. What the first drill found, how often to run it, and what to write down.
- Proxmox: SDN VLAN zones with an external IPAM
Two VLAN zones on the VLAN-aware bridge, a VNet per VLAN, and NetBox as the IPAM behind the tenant zone so the subnet Proxmox knows about is the one the address plan allocated. SDN does the plumbing; the firewall still does policy and NAT.
- Proxmox: bind-mount CephFS into an unprivileged container
Create a CephFS subvolume with a quota, scope a cephx key to its path, mount it on every node with a systemd unit, and bind-mount it into an unprivileged container that holds no Ceph key. df inside the container shows the quota, not the cluster.
- Proxmox: fix "cannot migrate local bind mount point"
The error means Proxmox cannot promise the directory behind mp0 exists on the target node. Mount the same path on every node with a systemd unit, check it, and only then add shared=1.
CephFS subvolumes under LXC: snapshots your backups can seeGuests are disposable; the data is not in them. Put user files on a CephFS subvolume, bind-mount it into an unprivileged container, snapshot on a schedule, and back the snapshot up, because vzdump skips bind mounts.
- Proxmox: replace a failed OSD, or reinstall and rejoin a node
Two runbooks that share a shape. For a dead disk: identify, out, stop, destroy, swap, create, watch recovery. For a dead node: drain it, remove its Ceph roles, pvecm delnode, reinstall by PXE, pvecm add, recreate the roles, and keep HA fencing in mind throughout.
- Proxmox: a cluster API address that follows a healthy node
One address for the Proxmox API that moves to a node whose pveproxy actually answers, using keepalived VRRP with a track script. A node with a wedged API still answers ARP, so the check has to ask port 8006, not the kernel.
- Proxmox: a three-node Ceph cluster on used Dell servers
From three second-hand R630-class servers with IT-mode HBAs to a quorate cluster with one replicated RBD pool, HA on every guest and no local storage for guests. The commands, in order, and what to check after each.
Ex-lease Dell Servers, one Ceph pool, no local-zfsSecond-hand servers are cheap. What costs money later is a storage decision that blocks migration. Here is the cluster layout that keeps HA, migration and backup working.
- Proxmox: automated install with an answer file and PXE
Build a self-installing Proxmox VE ISO with proxmox-auto-install-assistant, serve the TOML answer from the jumphost, boot it through iDRAC virtual media or PXE, and avoid the two traps that cost me an afternoon each.
- Proxmox: intra-day snapshots from cron that actually run
A snapshot script that ran from cron three times a day, reported success for months, and never created a snapshot, because cron's PATH does not include /usr/sbin and the output went to /dev/null. The fixed script, and the checks that make it fail loudly.
Proxmox Backup Server that leaves the buildingA standalone PBS per site is the easy part. The part most setups skip is getting a copy to the other site, verified, with a token that cannot do damage.
- Catalyst 3850: port-channel is up but no traffic passes
LACP bundles, the MAC table has entries, and nothing gets through. The port is tagging the wrong way for its host class, and the switch has no reason to tell you.
- Catalyst 3850: cross-stack LACP to a Proxmox bond, both sides
One port on each stack member, a port-channel in LACP active mode, a trunk whose native VLAN does not exist, and an 802.3ad bond under a VLAN-aware bridge on the Proxmox node. Both halves, and how to check they agree.
- Proxmox: Ubuntu cloud-init templates with static addresses
Turn an Ubuntu cloud image into a Proxmox template, clone it, and give each clone a static address, gateway, nameserver, SSH key, VLAN tag and a MAC derived from the address. Every value comes from the host plan, so nothing is typed twice.