netbox-proxbox 0.0.29 — security hardening
Supports NetBox 4.5.8 through 4.7.0. Pairs with proxbox-api 0.0.23.post3, proxmox-sdk 0.0.15, and netbox-sdk 0.0.13.
Security
- Sensitive data: credential export, SSH credential secret reads, and the settings runtime key require an active superuser or an explicit per-user sensitive-data grant. Change-log snapshots of credential-bearing objects are redacted.
- Connection-target approval: credentials are sent only to a Proxmox or NetBox endpoint whose exact connection target was approved; editing the target clears the approval.
- Scoped reads and actions: plugin settings reads require view permission; HA data covers only endpoints the caller may view; HA arm/disarm requires the grantable
run_proxmox_actionaction, skips endpoints with writes disabled, and reports per-cluster backend errors as failures. - WebSocket sync: the server-side sync route no longer starts work on GET; syncs require an authorized, CSRF-protected POST.
- Input validation: Proxmox node, storage, guest type, VM ID, and firewall identifiers are validated before they reach backend request paths.
- Secure defaults: new endpoints default to HTTPS and TLS verification, the process-wide certificate bundle override is removed, and new encryption keys must be canonical Fernet keys. System checks
netbox_proxbox.W100–W105report insecure existing configuration. - Dependencies: raised security floors for Django, oauthlib, PyJWT, social-auth-core, urllib3, and virtualenv.
Fixes
- The Proxbox home page and the NetBox endpoint list no longer fail with a server error on NetBox 4.7.
- Virtual-machine synchronization no longer stops with a duplicate node-device claim when paired with proxbox-api 0.0.23.post3.
- Cluster virtual-machine bulk deletion is limited to the active cluster and reports missing or mismatched records.
Upgrade notes
- Apply the single migration
0104_security_hardening. Existing endpoints keep their stored transport settings. - Approve each endpoint's connection target before synchronization resumes.
- Grant
run_proxmox_actionto operators who use HA arm/disarm. - Automation that creates plain-HTTP backend endpoints must send
use_https: false. - Rotate legacy raw encryption keys (
netbox_proxbox.W104).
Known limitation
Node device identity is not yet scoped by Proxmox endpoint. If two Proxmox endpoints use the same cluster name and node name, give them distinct names until a later release adds endpoint scoping.
Version note
Version 0.0.28 is not used: its only published candidate predates this release's schema change, and each release ships exactly one migration.
Full notes: docs/release-notes/version-0.0.29.md