What's the point on having the decrypt key physically on the same place as the server itself? IMHO that's as secure as an unencrypted disk. What am I missing here?
You need vRack for such setup to work properly and seamlessly. Also vRack public IP range so you can "move" the IP with VMs among the servers in the cluster (i.e. whe you move that pfsense VM to another host in the cluster).
You really need 3...
Special device does not help with verify, as verify reads the whole data from your HDD to checksum each chunk again and make sure that it still has the same checksum it had when originally stored. I mean, it barely puts any load on the special...
I would bet that something isn't properly installed/updated and you should solve it before continuing deployment, as you may find similar behavior with other actions too.
The traditional backup (vzdump to a file) is just a bit copy of whatever is in the source. Three options come to my mind atm:
Encrypt the VM / CT if possible.
Use LUKS or ZFS encryption in the storage (disk, NFS, etc) used as destination of the...
Running PVE on SD card or USB drive is not supported nor recommended due to the use PVE/Debian does of the OS disk. Also, not having redundant OS disk is nonsense for me for anything except testing machines.
Having SSD also for the main storage...
I've installed literally hundreds of clusters with zero issues related to clustering. Yes, there's been bugs with corosync, qdevice, etc but they got sorted out eventually. There aren't too many questions about clustering issues in the forum, so...
Yes,
the patches restoring the catalog dump [0] and catalog shell [1] functionality for split pxar archives have been applied and packaged starting with proxmox-backup-client version 3.2.9.
[0]...
/etc/pve is populated by pve-cluster service based on the contents of the sqlite database at /var/lib/pve-cluster. If pve-cluster isn't running, /etc/pve should be empty... If it has contents someone/something has copied data there while the...
Is this host part of a cluster?
Looks like the cert and the privkey don't match for some reason or that they don't match the host name. Probably caused by that ACME plugin. I would try to move pveproxy-ssl.key and pveproxy-ssl.pem from...