Skip to main content
See All Integrations

Proxmox VE

Protect access to the Proxmox VE management interface as an upstream web application.

Standard protected service pattern

Categories
Private Infrastructure, Upstream Applications

Overview

Proxmox Virtual Environment is a virtualization management platform. Its web interface and API normally use HTTPS port 8006. Browser consoles use long-lived and WebSocket connections. Other cluster and host services use separate ports.

Proxmox VE can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.

Pomerium controls who can establish the selected route to Proxmox VE. Proxmox VE remains responsible for its application, protocol, data, and service-level permissions.

How it works

Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL, trusted proxy settings, WebSocket forwarding, and suitable timeouts.

Keep application authentication and granular authorization active. Test interactive terminals, streaming views, agents, and other long-lived connections separately.

Expose only the selected management interface and API endpoint. Test login, API, noVNC console, downloads, uploads, and long-running tasks.

Example

Virtualization administrators reach the private Proxmox VE management interface through Pomerium. Proxmox keeps node, pool, virtual machine, storage, and cluster permissions.

Considerations

  • A route to port 8006 does not cover SSH, migration, cluster, SPICE, or every Proxmox service.
  • Preserve WebSocket upgrades and long-lived console timeouts.
  • Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.

Sources and official resources

  • Protect the VMware vCenter Server web interface and API without claiming to cover every vSphere service.

  • Protect access to Portainer container administration as an upstream web application.

  • Protect access to internal administration panels as upstream web applications.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo