ProxmoxMCP-Plus v0.5.26
This release repairs the project audit findings across destructive resource
selection, authorization, guest task handling, OAuth, asynchronous dispatch,
inventory reporting and deployment lifecycle.
Changes
- Validate resource path segments and fresh storage content before deletion;
enforce exact volume identity, content type and backup protection on retries too. - Enforce high-risk policy and current tool exposure consistently, including job
retry and reconciliation. Add optional client grants for tools and targets. - Offload blocking operations, bound target concurrency and record queue latency.
Bound SSH output, honor strict host keys and supervise owned tunnel processes. - Wait for successful stop completion before forced guest deletion. Track container
resize tasks and return structured submission metadata for asynchronous operations. - Preserve transactional job state and audit evidence across competing workers;
require reconciliation after uncertain submissions, interruptions or expired claims. - Add bounded job summaries, audit pagination, cache limits and persistent Compose
job storage. Optimize statistics with bounded prefetch and coalesced cached reads. - Use explicit guest shell argv across Windows and Linux servers, handle signals
and unknown exit status safely, and remove unsupported LXC RRD parameters. - Distinguish incomplete inventories, unknown storage capacity and inactive storage;
select storage from node capabilities and support LVM cloud-init disks. - Correct metric outcome classification, bound HTTP metric labels, sanitize bulk
errors and format petabyte/exabyte capacities correctly. - Reject malformed OAuth transactions and periodically clean bounded batches of
expired state while preserving legacy metadata compatibility. - Roll back partial startup resources, pin hashed runtime dependencies, pin CI
actions and publish dependency evidence plus container SBOM/provenance attestations.
Upgrade
Install proxmox-mcp-plus==0.5.26 or use the matching container tag. Preserve the job
database and existing OAuth tables during upgrades. Restart workers together when
rotating the consent API key. Native HTTP still requires authentication by default.
New options preserve existing clients: client grants are opt-in, Code Mode worker
reuse remains opt-in, and polling includes historical audit events unless
include_audit=false is requested. Secret-containing retry callbacks remain
in-process; redacted recipes cannot reconstruct secrets after restart or eviction.
See runtime safety and operations for approval
policy, principal identities, reconciliation, limits, persistence and health checks.
Validation scope
The full runtime statement coverage gate requires 100% coverage with zero missing
statements and verifies that every runtime module appears in the report. Regression
tests include real PostgreSQL, transactional SQLite concurrency, MCP schemas,
strict request contracts and platform-independent guest command encoding.
Live destructive guest operations require operator validation in a controlled
Proxmox cluster; mocked API and HTTP encoding tests do not establish that proof.
Local Windows/Python 3.13 verification passed 828 tests with 3 platform-specific
skips, covering all 5,736 statements across 55 runtime modules. Ruff, Mypy, dependency
audit, wheel/source build, Twine and release metadata checks passed. The built wheel
was installed into a fresh environment using the hashed runtime lock.