ProxCenter — self-hosted web panel for PVE 8/9 (VMs + LXC, cloud-init, RBAC, audit)

yjscloud

Member
Jan 18, 2022
1
0
21
30
Hi all,

I've been building a self-hosted web management panel for Proxmox VE 8.x / 9.x and would
like to share it. It started as a way to give my team a narrower, self-service view of our
cluster without handing out full PVE access.

Repo: https://github.com/yjscloud/ProxCenter (Apache-2.0)
Screenshots and full docs: https://github.com/yjscloud/ProxCenter#readme

What it covers:

- **VMs and LXC containers**: create (blank / template clone / cloud image import), power
operations with graceful shutdown + force-stop fallback, disk resize, disk and node
migration, snapshots, in-browser VNC (QEMU) and serial console (LXC).
- **cloud-init template pipeline**: build a template from a cloud image step by step
(download → import → configure → convert → seal), waiting on each PVE task.
- **Networking & firewall**: bridges, VLANs, static/DHCP per interface, IP pools with
automatic free-address allocation, and rule templates pushed to many guests at once.
- **Self-service controls**: reusable resource specs (cores/RAM/disk), per-user issuance
quotas, per-object ownership so non-admins only see their own guests.
- **Ops extras I have not seen in other panels**: SSH brute-force protection (fail2ban
integration, unknown-IP login alerts), a security baseline audit/hardening flow for the
panel host *and* managed hosts with automatic rollback, port & process anomaly detection
(reverse-shell signatures, unexpected listeners), and emergency response (one action to
isolate a VM and protect its backups).
- **Multi-user from the start**: roles and fine-grained permissions, two-factor auth,
self-registration with admin approval, login lockout and rate limiting, and an audit log
of every write operation.

Deployment is one command — it installs dependencies, creates the database, builds the
frontend and installs a systemd service:

sudo ./deploy.sh

Two notes I would rather state up front:

1. It talks to PVE over the REST API with an API token. Because Proxmox does not allow
tokens to open VNC/serial consoles, the console needs an additional PVE user/password —
everything else works with the token alone.
2. The panel's own UI is Chinese-first. There is an English README, and translation of the
interface is on the roadmap; I mention it so nobody is surprised.

Feedback, bug reports and feature requests are very welcome — especially from anyone
running a multi-node cluster or Ceph, which I can only test in a limited way here.