ProxmoxMCP-Plus v0.6.0
This release adds guarded, opt-in SSH commands on Proxmox nodes and improves
startup memory usage, client-specific Code Mode discovery and publication retries.
Features
- Add
execute_node_command(node, command, approval_token?, target?)from PR #147.
It is disabled by default and requires per-targetssh.allow_node_commands=true.
Node inventory, command policy, operation approval, client grants and read-only
restrictions are checked before host execution. Host allow patterns use a full
match; guest tools retain their existing regex search behavior. - Reuse strict SSH host verification, bounded output and remote command watchdogs.
See node command configuration, including the
privilege implications of elevating an entire shell wrapper with sudo.
Optimizations
- Load cached job summaries at startup without materializing historical audit
events. Full history remains available fromget_job, legacy polling and paged
audit routes. Tests verify that subsequent polls preserve events without duplication. - Filter Code Mode search, schemas and callable tools by the current client's tool
grants and access to configured targets. Evaluate grants on each request so one
client's discovery results cannot leak into another client's catalog. - Verify existing PyPI artifact checksums and unpacked contents before accepting a
previous upload. Upload only missing files; identical complete uploads succeed
and allow Registry publication to proceed. Changed contents, yanked files and
unexpected download origins fail closed. Archive creation timestamps may differ.
A local synthetic startup benchmark used 50 jobs and 50,050 audit events, three
runs per variant, with allocation tracing enabled. Median startup time decreased
from 0.960 seconds to 0.0043 seconds; peak traced allocation decreased from
38,151,599 bytes to 68,376 bytes. These measurements describe that workload, not
production cluster throughput.
Validation and upgrade
Local Windows/Python 3.13 validation passed 902 tests, with 3 skips and zero
warnings. Runtime statement coverage is 100%: 5,808 statements across all 55
runtime modules, zero missing statements. Ruff, Mypy, dependency security audit,
build, Twine and clean installed-wheel/source parity checks passed.
The gate checks actual missing lines rather than a rounded percentage. Regression tests cover real MCP dispatch,
target/client boundaries, approval rejection, lazy audit persistence and safe
partial-publication recovery. Real PostgreSQL OAuth compatibility tests remain required.
CI, CodeQL and downstream publication must finish before the release is verified.
No live destructive Proxmox requests were made for this release.
Upgrade to proxmox-mcp-plus==0.6.0 or the matching container tag and restart workers.
Keep existing SQLite and PostgreSQL state, including legacy OAuth metadata.
No database migration is required. Existing deployments gain no host command
permission unless explicitly enabled; existing API defaults and audit history are retained.