Reference¶
Context
Look-up facts: current versions, release history, support lifecycle, subscription pricing, system requirements, network ports, repository definitions, the storage capability matrix, CRS modes, and hard limits.
Current Versions (September 2026)¶
| Product | Version | Released | Base / notes |
|---|---|---|---|
| Proxmox VE | 9.2 (x86-64) | 2026-05-21 | Debian 13.5 Trixie, kernel 7.0 (default), QEMU 11.0, LXC 7.0, ZFS 2.4; pve-manager 9.2.21 as of 2026-09-24 |
| Proxmox VE | 9.2 (arm64) | 2026-08-05 | First officially supported arm64 build; same feature set |
| Proxmox Backup Server | 4.2 | 2026-04-29 | Debian 13.4, kernel 7.0, ZFS 2.4; S3-compatible datastores now officially supported |
| Proxmox Datacenter Manager | 1.1 | 2026-05-28 | Debian 13.5, kernel 7.0; 1.0 shipped 2025-12-04 |
| Ceph (integrated) | Tentacle 20.2 / Squid 19.2 | with PVE 9.2 | Tentacle is the default for new installs since 9.2; existing clusters keep their release |
PVE 8 is end-of-life
Proxmox VE 8 (Debian 12 Bookworm) reached Proxmox EOL in 2026-08. Nodes still on 8.x no longer receive updates; upgrade to 9.x (see How-to guides).
Release History (recent)¶
| Release | Date | Base | Notable |
|---|---|---|---|
| PVE 9.0 | 2025-08-05 | Debian 13.0, kernel 6.14, QEMU 10.0, ZFS 2.3, Ceph Squid 19.2 | Snapshots-as-volume-chain (tech preview, incl. thick LVM); HA affinity rules replace HA groups; SDN fabrics; Rust/Yew mobile UI |
| PVE 9.1 | 2025-11-19 | Debian 13.2, kernel 6.17, QEMU 10.1, LXC 6.0.5, ZFS 2.3.4, Ceph Squid 19.2.3 | LXC from OCI images (tech preview); vTPM state in qcow2 (snapshots with TPM); granular nested virtualization |
| PVE 9.2 | 2026-05-21 | Debian 13.5, kernel 7.0, QEMU 11.0, LXC 7.0, ZFS 2.4, Ceph Tentacle 20.2 | Dynamic-load CRS + automatic HA rebalancing; WireGuard and BGP SDN fabrics; custom CPU models in GUI; cluster-wide disarm-ha / arm-ha |
| PVE 9.2 arm64 | 2026-08-05 | same userspace | First arm64 release; NVIDIA Grace Hopper / Vera supported from launch |
Support Lifecycle¶
| PVE major | Debian base | First release | Debian EOL | Proxmox EOL |
|---|---|---|---|---|
| 9 | 13 Trixie | 2025-08 | tba | tba |
| 8 | 12 Bookworm | 2023-06 | 2026-07 | 2026-08 |
| 7 | 11 Bullseye | 2021-07 | 2024-07 | 2024-07 |
| 6 | 10 Buster | 2019-07 | 2022-09 | 2022-09 |
PVE follows a rolling model: each major lives as long as its Debian base, roughly 3 years plus a short overlap after the next major ships. Ceph repositories carry their own EOL: Squid 19.2 — 2026-09, Tentacle 20.2 — 2027-11 (per the PVE package-repository docs). Squid clusters should plan the move to Tentacle now.
Subscription Pricing (per occupied CPU socket / year, net EUR)¶
| Tier | Price | Support |
|---|---|---|
| Premium | EUR 1,100 | Unlimited tickets, 2h response for critical issues, remote SSH support, offline updates; global 24/7 support from 2026-10-19 |
| Standard | EUR 550 | 10 tickets/yr, 4h response; to be added to 24/7 support in a Q4 2026 onboarding window |
| Basic | EUR 370 | 3 tickets/yr, 1 business-day response (SLA unchanged) |
| Community | EUR 120 | Enterprise repo access, no ticket support (forum only) |
| No-subscription repo | free | Same packages, less tested; not recommended for production |
Rules: a subscription covers every occupied socket (core count irrelevant); every cluster node must be covered and all nodes in a cluster must use the same level. All PVE features exist at every level — tiers differ only in support and repo access. Subscription keys are bound to CPU architecture: arm64 hosts need arm64 keys (sold via sales contact), and an x86 key is rejected on arm64. Proxmox North America Inc. (Kingston, Ontario) adds North American business-hours support alongside the 24/7 rollout.
Datacenter Manager licensing: PDM has no subscription of its own. A PDM instance gets enterprise-repo access and support when at least 80% of its configured remote nodes hold Basic or higher subscriptions.
System Requirements¶
| Evaluation (min) | Recommended production | |
|---|---|---|
| CPU | 64-bit x86 (Intel 64/AMD64) with VT-x/AMD-V, or arm64 (ARMv8-A) | Same on x86; ARMv9-A or newer on arm64 |
| RAM | 1 GB + guest RAM | 2 GB for OS/services + guests; ~1 GB per TB used storage for ZFS/Ceph |
| Disk | Hard drive | SSDs with power-loss protection; HW RAID with BBU or non-RAID for ZFS/Ceph (neither works on HW RAID) |
| Network | 1 NIC | Redundant multi-Gbit NICs; dedicated NIC for corosync |
| Passthrough | — | IOMMU: Intel VT-d / AMD-Vi (SMMU on arm64), enabled in firmware |
arm64 specifics¶
- Officially supported on NVIDIA Grace Hopper and NVIDIA Vera; other UEFI-based ARMv9-A hardware is best-effort. Device-tree-only boards (e.g. Raspberry Pi) are not supported; hosts must boot UEFI + ACPI.
- VMs always boot via UEFI (AAVMF); no SeaBIOS. AMD SEV and Intel GVT-g are x86-only; no OS-level microcode package.
- Mixed x86 + arm64 clusters are allowed, but live migration only works between same-architecture nodes; a guest only runs on a node of its own architecture.
Benchmark a node with pveperf (CPU + fsync throughput).
Network Ports¶
| Port | Protocol | Service |
|---|---|---|
| 8006 | TCP | Web UI + REST API (pveproxy) |
| 22 | TCP | SSH (cluster actions, node joins) |
| 5405-5412 | UDP | corosync cluster traffic |
| 5900-5999 | TCP | VNC web console (WebSocket) |
| 3128 | TCP | SPICE proxy |
| 60000-60050 | TCP | Live migration (VM memory and local-disk data) |
| 111 | UDP | rpcbind |
| 25 | TCP (outgoing) | sendmail (notifications) |
Package Repositories (9.x, deb822 format)¶
| Repo | URI | Component | Access |
|---|---|---|---|
| Enterprise (default after install) | https://enterprise.proxmox.com/debian/pve |
pve-enterprise |
Any subscription level; most tested |
| No-subscription | http://download.proxmox.com/debian/pve |
pve-no-subscription |
Free; testing / non-production |
| Test | http://download.proxmox.com/debian/pve |
pve-test |
Developers / early testing only |
| Ceph enterprise | https://enterprise.proxmox.com/debian/ceph-<release> |
enterprise |
Subscription |
| Ceph no-subscription | http://download.proxmox.com/debian/ceph-<release> |
no-subscription |
Free |
Suite: trixie for PVE 9.x; Signed-By: /usr/share/keyrings/proxmox-archive-keyring.gpg. Files live in /etc/apt/sources.list.d/*.sources (pve-enterprise.sources, proxmox.sources, ceph.sources). Disable an entry by adding Enabled: no. Legacy one-line .list files still work but apt on Trixie warns; apt modernize-sources converts them. The Debian non-free-firmware component is enabled by default on 9.x installs.
Storage Type Matrix¶
| Type | Plugin | Shared | Snapshots | Notes |
|---|---|---|---|---|
| ZFS (local) | zfspool |
no | yes | zvols; PVE replication (pvesr) source/target |
| Directory | dir |
no | yes (qcow2 / volume chain) | any filesystem |
| BTRFS | btrfs |
no | yes | tech preview |
| NFS / CIFS | nfs/cifs |
yes | yes (qcow2 / volume chain) | file-based internal snapshots can block large VMs |
| LVM | lvm |
no (yes on a shared LUN) | via volume chain (9.0+, tech preview) | thick provisioning |
| LVM-thin | lvmthin |
no | yes | thin provisioning |
| iSCSI (kernel / libiscsi) | iscsi/iscsidirect |
yes | no | raw LUNs; usually put LVM on top; multipath recommended |
| FC / SAS LUN | (no dedicated plugin) | yes | via lvm on the LUN |
shared thick LVM is the classic SAN pattern |
| Ceph RBD | rbd |
yes | yes | hyperconverged or external (monhost list) |
| CephFS | cephfs |
yes | yes | file storage on Ceph |
| ZFS over iSCSI | zfs |
yes | yes | remote ZFS appliance |
| Proxmox Backup | pbs |
yes | n/a (backup target) | dedup, encryption, live restore |
Storage Config Examples (/etc/pve/storage.cfg)¶
zfspool: vmdata
pool tank/vmdata
content rootdir,images
sparse
rbd: ceph-external
monhost 192.0.2.20 192.0.2.21 192.0.2.22
pool ceph-external
content images
username pve-rbd
pbs: pbs-main
datastore main
server pbs.example.com
username backup@pbs!pve
fingerprint <sha256 fingerprint>
prune-backups keep-daily=7,keep-weekly=4
content backup
Backup Modes (vzdump)¶
| Mode | Downtime | Consistency | Use |
|---|---|---|---|
stop |
full (VM restarted after backup starts; CT stopped for duration) | highest | small guests, maintenance windows |
suspend |
short (CT: rsync then suspend + second rsync) | good | containers on storage without snapshots |
snapshot |
none | crash-consistent; guest-agent fsfreeze for VMs |
default for modern setups; fleecing optional |
Fleecing: vzdump <vmid> --fleecing enabled=1,storage=<fast-local-storage> (or the backup job's Advanced tab). Live restore: qmrestore ... --live-restore 1 or the GUI checkbox (PBS sources only).
CRS Scheduling Modes (HA)¶
| Mode | Uses | Since |
|---|---|---|
basic (default) |
Number of active guests per node | 7.x |
static |
Configured CPU/memory of active guests | 7.3 |
dynamic |
Average real CPU/memory usage plus configured quotas | 9.2 |
Opt-in scheduling points: ha-rebalance-on-start (place a starting HA resource on the best node) and automatic rebalancing (9.2; per-resource opt-out via the auto-rebalance property). Always-active points: recovery after fencing and HA rule changes. Set in Datacenter -> Options -> Cluster Resource Scheduling.
Limits and Gotchas¶
- pmxcfs config database: 128 MiB cap (thousands of VM configs fit).
- Cluster size: no explicit node limit; production clusters of 50+ nodes reported (pvecm docs, 2021 statement).
- corosync: up to 8 links (kronosnet); a single bond-backed link can mask partitions — use physically separate links.
- Live migration: same CPU vendor recommended (cross-vendor "might work", untested), same architecture required; target node needs equal or newer PVE packages. Passed-through PCI/USB devices block live migration unless marked
live-migration-capable(experimental, NVIDIA only). - Storage content types are per storage (
content images,rootdir,...); a missing content type is a common "cannot allocate disk" cause. pvecm expected Noverrides quorum — break-glass only.- QDevice: supported for even node counts; not recommended for odd counts.
- All nodes should run the same PVE version; mixed versions only during rolling upgrades.
Hardening Pointers (checklist form)¶
- Management on a dedicated VLAN; 8006 + 22 reachable only from admin networks
- 2FA (TOTP/WebAuthn) enforced on all admin realms; root login via PAM restricted
- API tokens for automation; per-path RBAC instead of Administrator@pam everywhere
- corosync on isolated NIC/VLAN (traffic is encrypted/authenticated with
/etc/corosync/authkey) - PBS client-side encryption enabled for off-site copies; key custody documented and tested
- Unprivileged LXC by default; nesting only where required
- Enterprise (or Community) repo + timely updates; offline-update procedure for air-gapped sites
- No nodes left on EOL majors (PVE 8 EOL 2026-08)
- Regular restore tests (PBS live restore makes this cheap)
Sources¶
- PVE Roadmap — release history, component versions
- PVE 9.2 press release — 2026-05-21, Debian 13.5, kernel 7.0, QEMU 11.0, LXC 7.0, ZFS 2.4, Ceph Tentacle
- PVE 9.1 press release — 2025-11-19, OCI images, vTPM in qcow2
- PVE arm64 press release — 2026-08-05, arm64 subscriptions via sales
- PBS 4.2 press release — 2026-04-29, S3 support
- PDM 1.1 press release — 2026-05-28
- PDM FAQ — 80% remote-subscription rule
- 24/7 support and Proxmox North America — Premium 24/7 from 2026-10-19
- Proxmox VE pricing — tiers, socket rules
- pve-docs: FAQ (support table), system requirements, package repos, firewall ports, ha-manager (CRS)
- PVE Package Repositories — repo URIs and formats
- PVE Storage — capability matrix, config examples
- PVE Backup and Restore — vzdump modes, fleecing, live restore
- Cluster Manager — corosync links, QDevice
- PBS Roadmap — 4.x releases