Skip to main content

Manage Proxmox VE from your Mac

A shell on every node, a VM console without the browser, ISOs dropped straight into storage, and the web interface kept behind SSH.

By Lucas Russo, developer of SSHive · Updated

Proxmox VE is a Debian-based hypervisor for KVM virtual machines and LXC containers, with a web interface on port 8006. The web interface remains the place to create and configure guests. The rest of the day happens around it: maintenance on the nodes over SSH, a console for a VM that has no network yet, an ISO to upload, the same check run on every node of a cluster. SSHive handles those from one window, with a profile per node filed in a Proxmox folder. One thing to know up front: the console built into the web interface is noVNC, which runs in the browser. SSHive's VNC viewer connects to a VM once you give that VM a VNC display of its own, as described below.

SSH on each node

Proxmox logs you in as root by default. Install your key first (Settings > SSH Keys > Install on host does it through an open session), then create one profile per node, pve1, pve2, pve3, in the Proxmox folder. To check a cluster, broadcast pvecm status or pveversion to all three: each node answers in its own tab, and a node that has lost quorum stands out. For a shell inside an LXC container, pct enter 101 in the node's session is enough; the container needs no SSH server of its own.

A VM console over VNC

The Proxmox wiki documents how to give a VM a VNC display of its own: add an args: line to /etc/pve/local/qemu-server/<VMID>.conf, then stop and start the VM. The wiki's example listens on 0.0.0.0, every interface of the node. With args: -vnc 127.0.0.1:77 instead, the display listens on port 5977 (5900 + 77) on the node's loopback only, so the only way in is through SSH. In the node's profile, add a local tunnel from port 5977 to localhost:5977, then point a VNC profile at localhost:5977. To require a password, add ,password=on to that line (args: -vnc 127.0.0.1:77,password=on), start the VM, then run set_password vnc <password> -d vnc2 in its Monitor panel. The wiki notes that this needs QEMU 6.1 or later and that a VNC password is limited to 8 characters. The password also does not survive a restart of the VM: set it again each time the VM starts. This is how you reach an installer or a rescue boot before the VM has an SSH server.

Uploading ISOs

Drag an .iso from Finder into /var/lib/vz/template/iso/ on a node, the directory behind the default local storage, and it shows up in the web interface's ISO list for new VMs. Container templates go in /var/lib/vz/template/cache/. An ISO is far larger than the free version's upload cap, so this part needs Pro.

What is free here, and what needs Pro

SSH to the nodes, SFTP for configs and scripts, and one local tunnel per profile, enough for the web interface on 8006, are free. The rest of this page is Pro: the VM console needs VNC, cluster checks need broadcast, and an ISO is well past the free upload cap of 10 MB per file. SSHive Pro is a one-time purchase of $12.99.

Frequently asked questions

Can SSHive replace the Proxmox web interface?+
No, and it does not try to. Creating, configuring and migrating guests, storage and backups belong in the web interface. SSHive covers what sits around it: the node's shell, files on the node, a VM's VNC display and the tunnel that keeps the web interface off the internet.
How do I reach the web interface safely from outside?+
Do not forward port 8006 on your router. Add a local tunnel to the node's profile, local port 8006 to localhost:8006, connect over SSH and open https://localhost:8006 in Safari or Chrome. The web interface traffic then travels inside the SSH connection, and that single tunnel works in the free version.

Try SSHive Free for macOS

Get the all-in-one SSH, SFTP, RDP and VNC client for Mac. Free download, no signup required.