Checks on the cluster as a whole — they run once per analysis, whatever node you connect to. How to read the codes: Overview.
| Code |
SubContext |
Gravity |
Description |
WC0001 |
Backup |
Warning |
No automated backup job for any VM/CT |
IC0001 |
Backup |
Info |
Enabled backup job has no compression configured (jobs to Proxmox Backup Server excluded: it always compresses) |
WC0002 |
Backup |
Warning |
Neither the backup job nor its storage has a retention (prune-backups) — storage will fill up |
WC0017 |
Backup |
Warning |
Enabled backup job has no schedule — will never run |
IC0012 |
Backup |
Info |
Backup job is disabled |
WC0018 |
Backup |
Warning |
Recent vzdump task failed (a task ending with WARNINGS counts as completed) |
WC0019 |
Backup |
Warning |
Two or more enabled backup jobs run on the same storage at the same schedule (I/O contention) |
| Code |
SubContext |
Gravity |
Description |
CC0001 |
Quorum |
Critical |
Cluster has lost quorum — VM operations may be blocked |
CC0002 |
Quorum |
Critical |
Losing this single node would leave the cluster without quorum (skipped when a QDevice is configured) |
CC0003 |
HA |
Critical |
HA group references nodes that are currently offline (PVE 8 and earlier — HA groups became rules in PVE 9) |
CC0005 |
HA |
Critical |
HA service is in error state — manual recovery required |
IC0002 |
HA |
Info |
No VMs/CTs protected by HA — no automatic failover on node failure |
IC0003 |
Replication |
Info |
No storage replication configured — no redundant copy across nodes |
WC0009 |
Replication |
Warning |
Replication job is disabled — guest data is no longer replicated |
WC0010 |
Replication |
Warning |
Enabled replication job has no schedule — it will never run |
IC0017 |
Topology |
Info |
Cluster has a single node — HA / quorum / replication ineffective |
| Code |
SubContext |
Gravity |
Description |
IC0004 |
Pool |
Info |
Resource pool exists but has no VMs or storage assigned |
IC0020 |
Pool |
Info |
Pool has members but no ACL entry at /pool/<id> — not used as privilege boundary |
CC0004 |
Access |
Critical |
root@pam has no two-factor authentication configured |
WC0007 |
Access |
Warning |
User with Administrator role has no two-factor authentication |
WC0005 |
Access |
Warning |
Enabled user has Administrator role at root path / — prefer scoped permissions (disabled users: WC0014) |
WC0006 |
Access |
Warning |
Disabled user still has API tokens that should be revoked |
IC0005 |
Access |
Info |
Local user has no expiration date configured |
IC0006 |
Access |
Info |
API token of an enabled local (pam/pve) user has no expiration date |
IC0007 |
Access |
Info |
Enabled user has no email — will not receive notifications |
IC0008 |
Access |
Info |
Group has no members |
IC0009 |
Access |
Info |
Custom role is not assigned in any ACL |
WC0013 |
Access |
Warning |
User has Administrator role on / only via a group, and no TFA (direct Administrator: WC0007) |
WC0014 |
Access |
Warning |
Disabled user still has Administrator role on / |
IC0010 |
Access |
Info |
Administrator role on / with Propagate disabled |
IC0011 |
Access |
Info |
LDAP/AD/OpenID realm does not enforce TFA at realm level |
WC0015 |
Access |
Warning |
root@pam API token has no privilege separation |
WC0016 |
Access |
Warning |
User has expiration date in the past but is still enabled |
IC0021 |
Access |
Info |
API token has no comment — purpose / owner cannot be attributed at audit time |
WC0020 |
Permissions |
InfoWarning |
Account cannot see part of the cluster — Info for a reduced analysis scope, Warning when missing backup privileges would make other checks report the opposite of the truth |
| Code |
SubContext |
Gravity |
Description |
WC0003 |
Firewall |
Warning |
Cluster-level firewall is completely disabled |
WC0004 |
Firewall |
Warning |
Inbound policy is ACCEPT — unmatched incoming traffic is let through (outbound is not judged) |
WC0008 |
Firewall |
Warning |
Enabled inbound ACCEPT rule of the cluster firewall from any source (empty, 0.0.0.0/0 or ::/0) |
IC0013 |
Firewall |
Info |
Cluster firewall has enabled rules but none configure logging |
IC0014 |
Firewall |
Info |
Cluster firewall has 10+ disabled rules — stale configuration |
| Code |
SubContext |
Gravity |
Description |
IC0015 |
Log |
Info |
10+ error-level entries in the cluster journal |
IC0016 |
Tasks |
Info |
10%+ of recent cluster tasks failed |
IC0018 |
Metrics |
Info |
No external metric server configured — only volatile RRD data |
IC0019 |
Metrics |
Info |
Metric servers exist but every one of them is disabled |
| Code |
SubContext |
Gravity |
Description |
WC0011 |
Version |
Warning |
Online nodes run different Proxmox VE versions — lists the nodes on each version |
WC0012 |
Version |
Warning |
Online nodes run different kernel versions |
Any of these can be hidden with an ignore rule on its code.