Critical codes for threshold checks
The first letter of a code is now always the severity of the finding. Checks with a warning and a critical threshold used to report both levels with their W code; the critical level now has its own C code, with the same number as the W code (WN0027 → CN0027). Breaking: ignore rules on the W codes no longer hide the critical findings — add the C code to them.
| Check | Warning | Critical |
|---|---|---|
| VM/CT CPU, memory, network in, network out | WG0025–WG0028
| CG0025–CG0028
|
| VM/CT PSI CPU, I/O, memory | WG0029–WG0031
| CG0029–CG0031
|
| VM/CT health score | WG0032
| CG0032
|
| Node CPU, memory, network in, network out | WN0027, WN0038–WN0040
| CN0027, CN0038–CN0040
|
| Node I/O wait, root filesystem, swap | WN0028–WN0030
| CN0028–CN0030
|
| Node PSI CPU, I/O, memory | WN0031–WN0033
| CN0031–CN0033
|
| SSD wearout, ZFS pool usage | WN0018, WN0044
| CN0018, CN0044
|
| Node health score | WN0048 (was WG0032)
| CN0048
|
| Storage usage | WS0009 (was WS0001)
| CS0009
|
Changed codes:
- The node health score gets node codes: it reported
WG0032, a guest code. - Storage usage moves from
WS0001toWS0009, becauseCS0001already means "storage not accessible". - The critical codes that already existed take the number of their warning code: disk temperature
CN0007→CN0019(WN0019), LVM-thin metadataCN0013→CN0026(WN0026), CVECN0015→CN0042(WN0042).
Retired codes, not reused: WS0001, CN0007, CN0013, CN0015.
One finding per problem
Several problems were reported twice, under two codes, often with two different severities. Each is now reported once.
| Problem | Before | Now |
|---|---|---|
| Nodes on different Proxmox VE versions | WC0011 Warning for the cluster + CN0001 Critical on every node + pve-manager in CN0002
| WC0011 only, with the nodes on each version. CN0001 is retired
|
| HA guest with disks on local storage and no replication | CG0005 Critical + WG0043 Warning
| CG0005 only, and skipped when the replication jobs cannot be read. WG0043 is retired
|
Disk with backup disabled and cache=writeback
| CG0002 + WG0009
| CG0002 only. WG0009 is retired
|
| Shared storage not reachable on the other nodes | CS0001 on each node + WS0005
| CS0001 only. WS0005 is retired
|
| Backup job storage not reachable on a node | CS0001 + WS0007
| CS0001. WS0007 now reports only a storage not enabled on a node the job runs on
|
| SCSI disk on a non-VirtIO controller | IG0001 + IG0002 for each disk
| IG0001. IG0002 reports only IDE and SATA disks
|
CPU type host/max on an HA VM
| WG0006 + CG0004
| CG0004 only
|
Disabled user with Administrator on /
| WC0005 + WC0014
| WC0014 only
|
| Admin without TFA, with a direct ACL and via a group | WC0007 + WC0013
| WC0007 only
|
| Faulted disk in a ZFS mirror or raidz | CN0010 for the pool + CN0012 for the group and for the disk
| CN0010 for the pool + CN0012 for the disk only
|
Retired codes, not reused: CN0001, WG0009, WG0043, WS0005. Ignore rules on them can be removed.
Fixes
WN0019/CN0019(disk temperature): withCriticalset to0every disk was reported Critical. A level set to0is now off, and0/0turns the check off, as for the other thresholds.WC0008(permissive firewall rule): a rule with an empty source, which in Proxmox VE means any address, was not reported. Now every enabled inboundACCEPTrule of the cluster firewall from any source is reported; the destination is no longer judged, because on an inbound rule an empty destination is the host itself.WS0003(orphaned backups): withBackup.Enabledoff or the backup privileges missing, the backup files are not read, yet an Ok "No orphaned backup files" was reported. The check is now skipped, like the other backup checks.CG0001(leftover hibernation state) ran on containers too, which cannot hibernate: it only produced an Ok row labelled "VM State". VMs only now.- Excel report: rows are sorted by gravity, context and subcontext, as in the other formats.
Documentation
- New documentation site: Documentation.
- New product icon.
What's Changed
- docs: documentation site on Astro Starlight, published to GitHub Pages by @franklupo in #60
- docs: open external links in a new tab by @franklupo in #61
- docs: use the shared cv4pve docs theme, add the product icon by @franklupo in #62
- docs: repair the Ignore rules page by @franklupo in #63
- docs: compliance pages per framework, settings as tables, terminal-style report by @franklupo in #64
- feat: critical codes for threshold checks by @franklupo in #65
- fix(checks): temperature thresholds, firewall empty source, WS0003, CG0001, Excel sort by @franklupo in #67
- fix(checks): report each problem once by @franklupo in #68
- docs: align check, settings and compliance pages with the code by @franklupo in #69
- chore(release): bump to 2.7.0 by @franklupo in #66
Full Changelog: v2.6.0...v2.7.0