Skip to content
Prefer a web interface with scheduled runs? cv4pve-diag also runs inside cv4pve-admin →
# install (x64 — arm64 on the Releases page)
$ wget https://github.com/Corsinvest/\
cv4pve-diag/releases/latest/download/\
cv4pve-diag-linux-x64.zip
$ unzip cv4pve-diag-linux-x64.zip
$ chmod +x cv4pve-diag

# run against any node
$ ./cv4pve-diag --host=pve01 \
    --api-token='diag@pve!audit=…' \
    execute --full
2 critical  5 warning  2 info  4 ok

Find what is wrong in your Proxmox VE cluster

Runs outside the nodes, API only — 170+ health checks on cluster, nodes, storages, VMs and containers in a single run, with findings mapped to 18 compliance frameworks from ISO 27001 to NIS2 and DORA.
cv4pve-diag --host=pve01 --api-token='diag@pve!audit=…' execute --full
GravityCodeIdDescriptionContextSubContext
CriticalCC0004access/users/root@pamroot@pam has no TFA configured — full access protected only by passwordClusterAccess
CriticalCG0002nodes/pve02/qemu/203Disk 'scsi0' disabled for backupQemuBackup
WarningWN0013nodes/pve01Node requires reboot: running kernel '6.8.12-20-pve' but newer kernel '6.8.12-43-pve' is installedNodeReboot
WarningWS0002nodes/pve01/storage/datapoolImage Orphaned 51.54 GB file vm-106-disk-1StorageImage
WarningWS0009nodes/pve01/storage/pbs01Storage usage 80% - 2.58 TB of 3.22 TBStorageUsage
WarningWG0037nodes/pve01/qemu/1010CPU type 'kvm64' is missing security flags: +spec-ctrl, +ssbd, +pcid, +md-clear — add to cpu flags to mitigate Spectre/Meltdown/MDSQemuCPU
WarningWG0017nodes/pve02/qemu/999vzdump backup not configuredQemuBackup
InfoIC0002clusterNo HA resources configured — VMs will not automatically restart on node failureClusterHA
InfoIN0001nodes/pve026 Update availableNodeUpdate
OkWC0001cluster/backup3 backup job(s) configured at cluster levelClusterBackup
OkWC0003clusterCluster firewall is enabledClusterFirewall
OkWG0017nodes/pve01/qemu/100Guest is covered by at least one enabled backup jobQemuBackup
OkWG0017nodes/pve01/qemu/101Guest is covered by at least one enabled backup jobQemuBackup
One row per object: a check failing — or passing — on ten VMs gives ten rows, all the controls of a finding in the same row. Ok rows come from --full, or IncludeOkResult: true in the settings file.

A Proxmox VE cluster rarely breaks all at once: it drifts. A disk gets excluded from backup, a snapshot is forgotten for months, a node keeps running the old kernel after an update, root@pam has no second factor, an HA guest has no replica to fail over to. The web UI shows each object on its own page, so nothing tells you what is wrong across the cluster — you find out during a restore, a failover or an audit.

cv4pve-diag reads the whole cluster and lists those problems in one report, each with a stable code, a severity and the resource it concerns, so you can fix them before they matter.

The cv4pve suite follows the Unix philosophy: each tool does one thing and does it well. cv4pve-diag finds what is wrong. Its companion cv4pve-report is the RVTools for Proxmox VE: it exports everything the cluster contains, to read, share and keep. Two questions, two tools, used together.

cv4pve-diag cv4pve-report
Question What is wrong? What do I have?
Purpose Diagnostics and health checks Inventory and reporting
Result A list of problems, each with a code, a severity and the resource it concerns The full inventory: nodes, VMs, containers, storage, network, users…
Formats Text, HTML, JSON, Markdown, Excel Excel, static HTML site, multi-file JSON, plus an SVG network diagram
Compliance Findings tagged with the controls of 18 standards —
Access Proxmox VE API only, from outside the nodes Proxmox VE API only, from outside the nodes

Want both on a schedule, from a web interface? cv4pve-admin runs them as its Diagnostics and System Report modules.

cv4pve-diag runs outside the cluster — on your workstation, a management VM or a scheduled job — and talks only to the Proxmox VE REST API. Nothing is installed on the nodes and no SSH or root shell is needed: an API token with the privileges listed in Permissions is enough. Give it more than one node and it connects to the first one that answers, so it still runs while a node is down.

100+ findings are tagged with the controls they relate to. Run it with --compliance=Nis2 (or any of 18 frameworks) and the report keeps only the findings that matter for that standard, each with its control — root@pam without TFA becomes a gap against NIS2 Art. 21(j), a disk excluded from backup one against Art. 21(c). A report you can hand to an auditor, produced from the cluster itself.

ISO 27001 · NIS2 · NIS2 Implementing Regulation · ACN NIS2 Italy · DORA · PCI DSS · GDPR · AgID · ENS · BSI C5 · BSI IT-Grundschutz · ISO 22301 · SOC 2 · NIST 800-53 · ISO 27017 · ISO 27018 · CIS · NIST CSF

See the compliance mapping and an example report →

Part of the cv4pve suite →

Run your first diagnostic

Download the binary, point it at any node, read the report.

ProxmoxMade by Corsinvest,
official Proxmox partner