aethercert
Virtualization

Automated certificates for Proxmox VE

The Proxmox package uploads the renewed certificate as the node's custom certificate through the Proxmox VE API and restarts the web proxy so it is served right away.

The deployment steps defined in this package's manifest.

At a glance

Package
proxmox-target 2.0.0
Compatibility
Proxmox VE >=6.0 <10.0
Runs from
Any Windows or Linux agent with network access to it
Mechanism
REST API
Authentication
API token
Capabilities
Import certificate and key
Deployment steps
uploadCustomCertificate
Rollback
None
Key usage
No requirement

What it does

An agent on your network calls the node's certificates endpoint with an API token, uploads the full chain and key, replaces the existing custom certificate and restarts the Proxmox web proxy.

Each node in a cluster is configured as its own deploy target.

How it runs

  1. 01

    uploadCustomCertificate

    Full chain and key are uploaded as the custom certificate, replacing the previous one, and the web proxy is restarted.

What you configure

  • API host and port (default 8006)
  • Node name
  • API token id (user@realm!tokenname) and secret (stored encrypted)

Prerequisites

  • An agent with network access to the node API
  • An API token with permission to manage node certificates

Limitations

  • One node per deploy target.

Doing it by hand

The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.

Manual replacement guide

Automate Proxmox VE

Enroll an agent, attach the package, and the next renewal installs itself.

Community plan, no card required. Open registration - your account is ready in a few minutes.