[PROJECT] AnPreD InfraShield — Self-hosted fleet security, SSH key rotation, & JIT access for Proxmox

Dheeraj Kumar

New Member
Aug 15, 2026
6
0
1
Hi Proxmox Community,
I wanted to share a self-hosted project I’ve been working on that hooks right into Proxmox VE to solve a few pain points around fleet management, automation, and secure access: AnPreD InfraShield.
 
How it connects to Proxmox VE:
  • One-Click Provisioning: Connects via a restricted API token (PVEAuditor role). It can clone a cloud-init template, automatically inject fresh SSH keys, boot the VM, and pull it into your managed inventory seamlessly.
  • Existing VM Discovery: Features a 'Register as Server' option that pulls existing virtual machines and containers directly from your Proxmox nodes into the tool's core dash using the QEMU guest agent data.
  • Automated NFS Orchestration: Walks through attaching NFS storage interfaces directly from Proxmox to target servers end-to-end.
  • Other Main Pillars:
    1. Automated SSH Rotation: Periodically handles full key life-cycles with automated fallback protections.
    2. Just-In-Time (JIT) Bastion Access: Grants time-limited server terminal access via an ephemeral proxy path without ever exposing raw private keys—fully logged with visual playback.
    3. Vulnerability Remediation: Parses Tenable/Nessus scans to generate local package repositories via an internal Nginx sidecar for safe, dry-run patching.
    4. Compliance Checking: Performs native OpenSCAP benchmarking directly on targets.
    • How do you currently manage SSH keys and patching workflows across your Proxmox VMs?
    • Are there any specific integration features you'd like to see added to the roadmap next?
 
Why a Hypervisor Alone Isn't Enough for Infrastructure Security
If you run Proxmox VE, native hypervisors leave critical operational and security gaps:
❌ No native daemons for automated SSH key rotations or Just-In-Time (JIT) access.
❌ No built-in way to spin up multiple VMs simultaneously via the UI.
❌ No native mechanism to automatically deploy and configure monitoring agents (Zabbix, Alloy).
❌ Absolute permission models—no authorization steps before an operator accidentally triggers a Stop, Restart, or Delete command.
❌ No centralized command auditing or recorded terminal playback.
That is exactly why we built AnPreD InfraShield.
Here is how AnPreD transforms your standard Proxmox infrastructure into a secure, fully auditable environment:

Enterprise SSH Key & Access Controls
  • Just-In-Time (JIT) Access: Grant temporary, time-limited server access on demand.


  • Mandatory Bastion Recording: Users log in using ephemeral bastion keys into a fully recorded SSH proxy. Real server credentials never leave the backend, and an automated key rotation fires the millisecond the grant expires.
  • Visual Terminal Playback: Every proxy session is recorded as a genuine terminal playback with accurate timing, allowing you to replay exactly what an operator did.
  • Automated Key Rotation: Stop letting static SSH keys live forever. AnPreD continuously generates, deploys, and verifies fresh keys.

Centralised Auditing & Visibility
  • Immutable Audit Logs: Every meaningful action is logged with absolute precision—tracking who did what, when, and whether it succeeded or failed.
  • Searchable Command Logs: Don't waste time hunting through hours of video. AnPreD parses typed history into a searchable text log, allowing you to search for specific commands and jump straight to that exact timestamp in the session playback.

️ Advanced VM Management
  • Bulk Provisioning: Deploy multiple VMs in a single coordinated action, straight from the UI.
  • Cloud-Init Integration: Seamlessly deploy VMs using your existing cloud-init.img templates or raw image files.
  • Pre-Configured Agent Mappings: Automatically install and configure Zabbix agents, Alloy, and logging pipelines during provisioning according to your corporate templates.
  • Lifecycle Guardrails & Approvals: Protect production nodes. Destructive actions like Stop, Restart, or Delete generate an immediate authorization request to a designated Approval Group via secure links. No rogue modifications, no accidents.
  • Security Banners: Inject custom login warning banners straight into your VMs automatically upon creation using our Custom Compliance engine.


Stop relying on absolute hypervisor permissions and static, unaudited credentials. Move to a closed-loop platform designed for secure, transparent, and unattended infrastructure operations.

#Proxmox #Cybersecurity #SysAdmin #DevOps #CloudSecurity #InfrastructureAutomation #ZeroTrust #AnPreD #AuditLog #PrivilegedAccess
 
It's definitely a real project, not an AI exercise! The text templates were generated to prep our product documentation and announcement copy, which is why it might have looked overly formatted.
The platform is AnPreD InfraShield, a self-hosted security and lifecycle automation layer built specifically to sit on top of Proxmox VE API structures. We are wrapping up the final integration tests right now and are about 7 to 10 days away from our public MVP release.
What the MVP actually does under the hood:
  • Agentless Proxmox Hooking: Connects via a restricted PVE API token to pull live cluster telemetry and node states into a single dashboard.
  • Just-In-Time (JIT) Bastion Proxy: Instead of giving operators permanent SSH access to guest VMs, it creates ephemeral bastion connections with full terminal playback recording and auto-rotates the VM keys immediately on expiry.
  • Multi-Sig VM Power Actions: Intercepts disruptive VM actions (stop, restart, delete) and routes them through a strict, out-of-band email Approval Group verification loop.
  • Local Patch Repositories: Parses standard vulnerability scan PDFs to recursively pull packages and host a localized, air-gapped apt repo via an internal Nginx sidecar.
As soon as the repo is public and the installer script is ready next week, I will drop the link right here in this thread. If you run large multi-node clusters and want to beta-test or audit our Proxmox firewall automation logic, I'd love to get your feedback on it.
 
Yikes. So right now you don't have anything worth showing off except your posts meant to generate hype. These posts, suspiciously enough, read like they were generated by AI. If this any indicator on the project itself it's propably also generated by the slop machine. I will pass then
 
Last edited:
"That is a completely fair perspective, Johannes, and I appreciate the candid feedback. To clarify: AnPreD InfraShield is a commercial enterprise product, which is why the codebase is proprietary and won't be living in a public repository.
You are 100% right that security tools require strict validation. Because I used AI templates to help format my initial announcement copy, it came across as marketing hype rather than an enterprise introduction. That's on me.
We are launching a closed, compliant sandbox environment next week for enterprise teams who want to audit the platform and test the Proxmox API integrations securely without deploying anything in their own labs. If you or your team manage infrastructure at that scale, I'd be glad to set up access for you then."
 
Last edited:
"You are completely right to point to the rules, Johannes, and I apologize for the terrible first impression. Using AI templates to format the announcement made this look like a sketchy, closed-source commercial pitch, which is entirely my fault.
To clarify my purpose: the core security framework of AnPreD InfraShield—specifically the automated SSH key rotation and the Just-In-Time (JIT) Bastion proxy—is completely free to use for the community. We plan to monetize only advanced, multi-tenant compliance scaling for large enterprise teams later on.
My goal in posting here was to get brutal, technical feedback from experienced Proxmox admins on this free core logic before the MVP drops. I wanted to see if a JIT proxy built specifically around Proxmox guest APIs is something the community actually finds practical for securing VM access.
I respect the forum rules completely and will not post any paid or promotional links. I am just looking for architectural critique from fellow sysadmins. If you are willing to look past the AI-formatted rough start, I’d still value your take on the actual workflow."

1789410941207.png
 
Last edited: