github Corsinvest/cv4pve-diag v2.7.0
Release v2.7.0

4 hours ago

Critical codes for threshold checks

The first letter of a code is now always the severity of the finding. Checks with a warning and a critical threshold used to report both levels with their W code; the critical level now has its own C code, with the same number as the W code (WN0027 → CN0027). Breaking: ignore rules on the W codes no longer hide the critical findings — add the C code to them.

Check Warning Critical
VM/CT CPU, memory, network in, network out WG0025–WG0028 CG0025–CG0028
VM/CT PSI CPU, I/O, memory WG0029–WG0031 CG0029–CG0031
VM/CT health score WG0032 CG0032
Node CPU, memory, network in, network out WN0027, WN0038–WN0040 CN0027, CN0038–CN0040
Node I/O wait, root filesystem, swap WN0028–WN0030 CN0028–CN0030
Node PSI CPU, I/O, memory WN0031–WN0033 CN0031–CN0033
SSD wearout, ZFS pool usage WN0018, WN0044 CN0018, CN0044
Node health score WN0048 (was WG0032) CN0048
Storage usage WS0009 (was WS0001) CS0009

Changed codes:

  • The node health score gets node codes: it reported WG0032, a guest code.
  • Storage usage moves from WS0001 to WS0009, because CS0001 already means "storage not accessible".
  • The critical codes that already existed take the number of their warning code: disk temperature CN0007 → CN0019 (WN0019), LVM-thin metadata CN0013 → CN0026 (WN0026), CVE CN0015 → CN0042 (WN0042).

Retired codes, not reused: WS0001, CN0007, CN0013, CN0015.

One finding per problem

Several problems were reported twice, under two codes, often with two different severities. Each is now reported once.

Problem Before Now
Nodes on different Proxmox VE versions WC0011 Warning for the cluster + CN0001 Critical on every node + pve-manager in CN0002 WC0011 only, with the nodes on each version. CN0001 is retired
HA guest with disks on local storage and no replication CG0005 Critical + WG0043 Warning CG0005 only, and skipped when the replication jobs cannot be read. WG0043 is retired
Disk with backup disabled and cache=writeback CG0002 + WG0009 CG0002 only. WG0009 is retired
Shared storage not reachable on the other nodes CS0001 on each node + WS0005 CS0001 only. WS0005 is retired
Backup job storage not reachable on a node CS0001 + WS0007 CS0001. WS0007 now reports only a storage not enabled on a node the job runs on
SCSI disk on a non-VirtIO controller IG0001 + IG0002 for each disk IG0001. IG0002 reports only IDE and SATA disks
CPU type host/max on an HA VM WG0006 + CG0004 CG0004 only
Disabled user with Administrator on / WC0005 + WC0014 WC0014 only
Admin without TFA, with a direct ACL and via a group WC0007 + WC0013 WC0007 only
Faulted disk in a ZFS mirror or raidz CN0010 for the pool + CN0012 for the group and for the disk CN0010 for the pool + CN0012 for the disk only

Retired codes, not reused: CN0001, WG0009, WG0043, WS0005. Ignore rules on them can be removed.

Fixes

  • WN0019/CN0019 (disk temperature): with Critical set to 0 every disk was reported Critical. A level set to 0 is now off, and 0/0 turns the check off, as for the other thresholds.
  • WC0008 (permissive firewall rule): a rule with an empty source, which in Proxmox VE means any address, was not reported. Now every enabled inbound ACCEPT rule of the cluster firewall from any source is reported; the destination is no longer judged, because on an inbound rule an empty destination is the host itself.
  • WS0003 (orphaned backups): with Backup.Enabled off or the backup privileges missing, the backup files are not read, yet an Ok "No orphaned backup files" was reported. The check is now skipped, like the other backup checks.
  • CG0001 (leftover hibernation state) ran on containers too, which cannot hibernate: it only produced an Ok row labelled "VM State". VMs only now.
  • Excel report: rows are sorted by gravity, context and subcontext, as in the other formats.

Documentation


What's Changed

  • docs: documentation site on Astro Starlight, published to GitHub Pages by @franklupo in #60
  • docs: open external links in a new tab by @franklupo in #61
  • docs: use the shared cv4pve docs theme, add the product icon by @franklupo in #62
  • docs: repair the Ignore rules page by @franklupo in #63
  • docs: compliance pages per framework, settings as tables, terminal-style report by @franklupo in #64
  • feat: critical codes for threshold checks by @franklupo in #65
  • fix(checks): temperature thresholds, firewall empty source, WS0003, CG0001, Excel sort by @franklupo in #67
  • fix(checks): report each problem once by @franklupo in #68
  • docs: align check, settings and compliance pages with the code by @franklupo in #69
  • chore(release): bump to 2.7.0 by @franklupo in #66

Full Changelog: v2.6.0...v2.7.0

Don't miss a new cv4pve-diag release

NewReleases is sending notifications on new releases.