Proxmox Aiops
Governed Proxmox VE VM/container ops — 43 MCP tools with audit, budget, undo & risk-tier guards.
- Transport
- Not stated
- Package
- —
- Registry id
- io.github.AIops-tools/proxmox-aiops
No install snippet on purpose. A working MCP config is a command, its arguments and an environment block — the last two are where API keys live, so this catalogue never stores them and cannot publish them. Follow the link above for the authors' own instructions.
Disclaimer: Community-maintained open-source project. Not affiliated with, endorsed by, or sponsored by Proxmox Server Solutions GmbH. "Proxmox" is a trademark of its owner. MIT licensed.
AI-powered Proxmox VE VM and container lifecycle operations with a built-in
governance harness — unified audit log, token/runaway budget
guard, undo-token recording, and descriptive risk-tier labels. Self-contained:
no external dependencies beyond proxmoxer and the MCP SDK. Coverage is not
yet exhaustive across every Proxmox operation.
Verification status: live-verified against real Proxmox VE 8.4.19 across three rounds — read-only surfaces, the QEMU write surface, and a two-node cluster (quorum, live migration,
move-disk, a backup that actually succeeded). Rounds 2 and 3 each found a real bug the mocks could not see. See docs/VERIFICATION.md for exactly what was proven and what is still uncovered.
What works
- CLI (
proxmox-aiops ...):vm list/get/config/start/stop/shutdown/reboot/reconfigure/clone/delete/migrate,vm resize-disk/move-disk/agent-ping,vm snapshot-create/snapshot-delete/snapshot-list/snapshot-rollback,backup create/list/restore,ct list/start/stop,cluster nodes/status/task-status/resources/node-status/task-log/next-vmid,ha status/resources,pool list/members,firewall vm-rules/cluster-status,storage list/content,diagnose node-pressure/guest-health,undo list/apply,init,secret set/list/rm/migrate/rotate-password,doctor,mcp. - MCP server (
proxmox-aiops mcporproxmox-aiops-mcp): 43 tools, every one wrapped with the bundled@governed_toolharness. - Diagnostics / RCA (read-only):
diagnose node-pressureranks cluster nodes by CPU/memory/root-fs pressure;diagnose guest-healthscans VMs/containers for stopped guests, memory saturation, and disks near full. Every finding cites the measured number that tripped it and a concrete action — transparent heuristics, not a black-box verdict. - Credentials:
proxmox-aiops init(onboarding wizard) andproxmox-aiops secret ...manage an encrypted secret store — no plaintext passwords inconfig.yaml. - Reversibility: write ops with a clean inverse (start/stop/shutdown/reconfigure/clone/migrate/snapshot-create/move-disk, container start/stop, and restore-into-a-free-vmid) record an inverse undo descriptor; irreversible ops (delete, snapshot-rollback, forced restore) declare none and are tagged
highrisk. Disk resize is grow-only (shrink refused). - Async tasks: Proxmox writes return a task UPID — poll completion with
cluster task-status/ read lines withcluster task-log(the runaway budget guard prevents poll loops from running away).
What this tool does, and does not, decide
It delivers Proxmox VE operations — reads and writes — accurately and efficiently, and records every one of them. It does not decide whether a write is allowed to happen. That is the agent's judgement, or the permission of the account you connect it with: use a Proxmox VE user or API token granted only read privileges (no VM./Datastore. write roles), and the writes fail at the server — the place that actually owns the permission.
So there is no read-only switch, no policy file, no approval gate to configure. The one thing the
tool guarantees is that nothing is silent: every call, over MCP and over the CLI alike, lands an
audit row in ~/.proxmox-aiops/audit.db, and destructive writes still capture their before-state
and record an inverse where one exists.
Each tool declares a
risk_level, carried into the audit row as a descriptive tier (none/confirm/review) — so a reviewer can see at a glance that a row was a high-risk delete. It is a label, not a gate.
From the project's README.