Hi all,
I'm Marcos Méndez, and I maintain Keel Linux, a community project that builds ready-to-use LXC appliances on Debian 13 (trixie) for Proxmox VE. It started from TurnKey Linux 19 and keeps what made TurnKey good for decades: a template you download, a first boot that asks a few questions, and a console menu to manage it.
Why we are building it
Many of us run two or three Proxmox hosts in different places and want the applications people have run from TurnKey for years (WordPress, Nextcloud, Odoo, Moodle, MediaWiki, Drupal, GitLab) to survive losing one of them. The usual answer is Kubernetes: powerful, but heavy for a sysadmin who just wants a site to stay up. Sometimes you just want to put the batteries in the toy and have it work.
We measured it on one host, idle, nothing else running (method at the end):
Keel runs as a normal unprivileged LXC. Each appliance is the container itself, so there are no containers inside containers. k3s only ran in our LXC test after we gave it /dev/kmsg and host kernel settings, and it loaded 19 modules on the host.
The goal: appliances on two or three Proxmox hosts in different sites, joined over an encrypted WireGuard mesh, then a small etcd registry, replicated data and failover, all managed with a template, a console menu and one YAML file per appliance. A design premise is poor networks: everything that spans sites is tested at 250 ms RTT with jitter and packet loss, because not everyone has 5 ms between sites.
Where we are (testing, not for production yet)
Getting the templates on Proxmox VE 9
Proxmox's template sources are fixed in pve-manager, so a small package fetches and verifies our signed index and drops the template in your storage. It changes no pve-manager file and pins the Keel archive so nothing else from it lands on your host.
Then Create CT as usual with the downloaded template (unprivileged; nesting is recommended for Debian 13's systemd, but Keel also runs without it).
What we'd love from you
Try Keel Web on your Proxmox and tell us what broke. There is a checklist issue for it: https://github.com/Keel-Linux/keel-web/issues/5
There are also small "good first issue" tasks across the repos, and the conversation lives in GitHub Discussions: https://github.com/orgs/Keel-Linux/discussions
Website: https://keellinux.org, code: https://github.com/Keel-Linux
Feedback is very welcome, especially from long-time TurnKey users.
Method for the numbers: one Debian 13 host with LXC, each system in its own fresh container, memory.current of the container's cgroup, median of 3 samples taken 5 minutes after start. Idle only, one host; full commands on request.
I'm Marcos Méndez, and I maintain Keel Linux, a community project that builds ready-to-use LXC appliances on Debian 13 (trixie) for Proxmox VE. It started from TurnKey Linux 19 and keeps what made TurnKey good for decades: a template you download, a first boot that asks a few questions, and a console menu to manage it.
Why we are building it
Many of us run two or three Proxmox hosts in different places and want the applications people have run from TurnKey for years (WordPress, Nextcloud, Odoo, Moodle, MediaWiki, Drupal, GitLab) to survive losing one of them. The usual answer is Kubernetes: powerful, but heavy for a sysadmin who just wants a site to stay up. Sometimes you just want to put the batteries in the toy and have it work.
We measured it on one host, idle, nothing else running (method at the end):
| Memory | Disk | First HTTPS answer | |
|---|---|---|---|
| Keel Web (nginx + HTTPS) | 89 MiB | 1.0 GiB | 2.7 s |
| k3s v1.36.5, defaults, empty | 647 MiB | 1.6 GiB | n/a |
| k3s + one nginx | 654 MiB | 1.7 GiB | 25.7 s |
Keel runs as a normal unprivileged LXC. Each appliance is the container itself, so there are no containers inside containers. k3s only ran in our LXC test after we gave it /dev/kmsg and host kernel settings, and it loaded 19 modules on the host.
The goal: appliances on two or three Proxmox hosts in different sites, joined over an encrypted WireGuard mesh, then a small etcd registry, replicated data and failover, all managed with a template, a console menu and one YAML file per appliance. A design premise is poor networks: everything that spans sites is tested at 250 ms RTT with jitter and packet loss, because not everyone has 5 ms between sites.
Where we are (testing, not for production yet)
- Keel Core and Keel Web templates. Keel Web serves HTTPS out of the box, with Let's Encrypt from the console menu and an optional Coraza WAF and Anubis bot challenge.
- Signed packages and images, built from Debian plus the signed Keel archive only. Every image is scanned so no SSH or TLS key ships in it; each machine generates its own at first boot.
- One YAML file per appliance:
keel diffshows drift,keel spec applyconverges. - TurnKey compatibility:
keel-transitionmoves an existing TurnKey 19 appliance onto the Keel archive, reversibly. - The mesh works across sites today, and a node joins with one command:
keel mesh inviteon a member prints one line; run it on the new node. Next: etcd at the third node, then replication and failover.
Getting the templates on Proxmox VE 9
Proxmox's template sources are fixed in pve-manager, so a small package fetches and verifies our signed index and drops the template in your storage. It changes no pve-manager file and pins the Keel archive so nothing else from it lands on your host.
Bash:
curl -fsSL https://archive.keellinux.org/keel-archive-keyring.asc -o /tmp/keel.asc
gpg --show-keys /tmp/keel.asc # AD09 64BE 3F09 DED4 69A3 B6B2 148E 9513 1470 3180
gpg --dearmor < /tmp/keel.asc > /usr/share/keyrings/keel-archive-keyring.gpg
cat > /etc/apt/sources.list.d/keel.sources <<'END'
Types: deb
URIs: https://archive.keellinux.org
Suites: trixie-testing
Components: main
Signed-By: /usr/share/keyrings/keel-archive-keyring.gpg
END
apt update && apt install keel-pve
keel-pve update
keel-pve download local keel-web
Then Create CT as usual with the downloaded template (unprivileged; nesting is recommended for Debian 13's systemd, but Keel also runs without it).
What we'd love from you
Try Keel Web on your Proxmox and tell us what broke. There is a checklist issue for it: https://github.com/Keel-Linux/keel-web/issues/5
There are also small "good first issue" tasks across the repos, and the conversation lives in GitHub Discussions: https://github.com/orgs/Keel-Linux/discussions
Website: https://keellinux.org, code: https://github.com/Keel-Linux
Feedback is very welcome, especially from long-time TurnKey users.
Method for the numbers: one Debian 13 host with LXC, each system in its own fresh container, memory.current of the container's cgroup, median of 3 samples taken 5 minutes after start. Idle only, one host; full commands on request.