# install (x64; arm64 on the Releases page) $ wget https://github.com/Corsinvest/\ cv4pve-node-protect/releases/latest/download/\ cv4pve-node-protect-linux-x64.zip $ unzip cv4pve-node-protect-linux-x64.zip $ chmod +x cv4pve-node-protect # run against any node $ ./cv4pve-node-protect --host=pve01,pve02,pve03 \ --username=root --private-key-file=id_ed25519 \ backup --paths='/etc/.;/etc/pve/.;/var/lib/pve-cluster/.' \ --directory-work=. --keep=7
# install $ brew install corsinvest/tap/cv4pve-node-protect # run against any node $ cv4pve-node-protect --host=pve01,pve02,pve03 \ --username=root --private-key-file=id_ed25519 \ backup --paths='/etc/.;/etc/pve/.;/var/lib/pve-cluster/.' \ --directory-work=. --keep=7
# install PS> winget install Corsinvest.cv4pve.nodeprotect # run against any node PS> cv4pve-node-protect --host=pve01,pve02,pve03 ` --username=root --private-key-file=id_ed25519 ` backup --paths='/etc/.;/etc/pve/.;/var/lib/pve-cluster/.' ` --directory-work=. --keep=7
Create config: 2026-09-29-03-00-01/pve01-config.tar.gzBack up the configuration of your Proxmox VE nodes
Proxmox VE backup jobs save your VMs and containers, not the node they run on. The node has its own
configuration: bridges, bonds and VLANs in /etc/network/interfaces, /etc/hosts, storage
definitions, the cluster configuration in /etc/pve, certificates, SSH keys, apt repositories,
kernel parameters, the cron jobs and scripts you added.
When a node’s boot disk dies, or someone breaks a file by mistake, that configuration has to come back. Rebuilding it by hand from memory and screenshots is slow and easy to get wrong: a bridge with a different name, a missing VLAN, and guests do not start on the reinstalled node.
cv4pve-node-protect copies those files from every node into a dated tar.gz, on a schedule, so you
can compare what changed and put back exactly what was there.
Where it fits
Section titled “Where it fits”The cv4pve suite follows the Unix philosophy: each tool does one thing and does it well. cv4pve-node-protect protects the node, the other tools the guests and the knowledge of the cluster.
| Tool | Protects | How |
|---|---|---|
| cv4pve-node-protect | Node configuration files | SSH, tar.gz per node |
| Proxmox VE backup / Proxmox Backup Server | VMs and containers | Built into Proxmox VE |
| cv4pve-autosnap | VM and container snapshots on a schedule | Proxmox VE API |
| cv4pve-report | A readable inventory of the cluster, to document it | Proxmox VE API |
Prefer a web interface with scheduled backups? cv4pve-admin runs the same engine as its Node Protect module.
Outside the nodes, over SSH
Section titled “Outside the nodes, over SSH”cv4pve-node-protect runs outside the cluster (on your workstation, a management VM or the machine
that keeps your backups) and connects to each node over SSH, not through the Proxmox VE API.
On every node it runs a single tar command and streams the archive back; nothing is installed and
nothing is written on the node.
Reading the whole configuration needs root, and the archives hold secrets such as /etc/shadow,
SSH keys and storage passwords. SSH access and security
explains the account, the host key and how to keep the archives safe: read it before the first run.
What an archive contains
Section titled “What an archive contains”One run with the recommended paths on a node of our test cluster, grouped (about 1 MB compressed):
| Part | Examples |
|---|---|
| Network | /etc/network/interfaces, /etc/hosts, /etc/hostname, /etc/resolv.conf |
| System | /etc/fstab, /etc/kernel/cmdline, /etc/modprobe.d/, /etc/apt/sources.list.d/, /etc/vzdump.conf, /etc/zfs/, /etc/lvm/ |
| Cluster | /etc/corosync/corosync.conf, and /var/lib/pve-cluster/config.db: the database behind /etc/pve |
/etc/pve as files |
storage.cfg, datacenter.cfg, user.cfg, jobs.cfg, firewall rules, guest configurations, node certificates pve-ssl.pem / pve-ssl.key, priv/ |
| Accounts and keys | /etc/shadow, SSH host keys, /root/.ssh/, /var/spool/cron/crontabs/ |
What it does for you
Section titled “What it does for you”The whole cluster in one run
Pass every node in --host: one archive per node, all in the same dated folder.
02You choose what goes in
/etc, the readable /etc/pve files, the cluster database, crontabs, root SSH keys, your own scripts.
03Nothing left on the nodes
tar writes to the SSH channel and the archive lands straight in your local file: no temporary files, no agent.
04Retention built in
--keep removes the oldest dated folders after each run, and never touches other folders.
05A restore you control
Plain tar.gz files: extract to a staging folder, compare, then put back only what you need.
06Scheduled and scriptable
cron or Task Scheduler, an options file for the connection, exit code 1 when a run fails.
Take your first node backup
Download the binary, point it at your nodes over SSH, open the archive.
official Proxmox partner