Skip to main content
Glama

Named for Proximo, the lanista of Gladiator. The story is the design, joint for joint.

He armed his fighter with exactly what he needed, never more. He answered for every move in the arena. A lanista, not a jailer.

The Spaniard doesn't get his name up front. He earns it, by conduct, on the record. The helmet comes off: truth said plainly, at cost. That's the "not yet proven, said plainly" section below, and AGENTS.md leading with Proximo's own sharp edges.

His last act opened the cages, holding the wooden sword of his own freedom. A tool should hope to end that well.

"Win the crowd and you will win your freedom."

The others make you choose. A read-only inspector that's safe because it can't touch anything. Or a loaded gun aimed at a cluster you care about.

Proximo refuses the trade. Every dangerous move is planned: see the blast radius first. Every move is proven: a tamper-evident record. And undoable wherever the platform can snapshot: it snapshots before it acts.

Trust built into the substrate, not bolted on after. Hand an AI agent the keys; keep the receipts.

Sovereign and agent-agnostic. Your metal, your token, a ledger you own. No cloud, no phone-home, no standing server unless you opt in.

Don't take our word for any of it. Verify it yourself.

# 1. The tool count is real — ask the server itself, cold (=> 904).
#    (in a clone of this repo, after `uv sync`)
uv run python -c "import asyncio; from proximo import server; \
print(len(asyncio.run(server.mcp.list_tools())))"

# 2. The container image is what the repo built — sigstore provenance (exit 0 = verified):
gh attestation verify oci://ghcr.io/john-broadway/proximo:latest --owner john-broadway

# 3. The security posture is graded by a third party, not by us:
#    https://scorecard.dev/viewer/?uri=github.com/john-broadway/proximo

The rest is in VERIFY.md: forge a ledger byte and watch verify() refuse, grep the outbound surface for phone-home (there is none). These checks work on any tool, from any vendor. Demand them everywhere.


What it does

Ask, in plain English: "why is ct 105 thrashing?" An AI agent pulls node and guest status, tails the logs, and runs a diagnostic inside the container to find out.

If there's a fix, it shows you the plan before it touches anything. Snapshots first. Applies. Hands you a signed receipt of exactly what changed.

That's the product: a hypervisor an AI can operate without being able to wreck it.

Read-only by default. No mutation runs on the first call: it returns its blast radius as a plan for you to see first. A tamper-evident receipt for every change.

The comparison isn't Proximo vs. the GUI. It's Proximo vs. handing an LLM your root token and hoping.

Related MCP server: ProxmoxMCP-Plus

Quickstart

// your MCP client config (Claude Desktop / Claude Code / Cursor / …)
{
  "mcpServers": {
    "proximo": {
      "command": "uvx",
      "args": ["proximo-proxmox"],
      "env": {
        "PROXIMO_API_BASE_URL": "https://your-pve:8006/api2/json",
        "PROXIMO_NODE": "your-node",
        "PROXIMO_TOKEN_PATH": "/path/to/token-file"   // USER@REALM!TOKENID=SECRET — by reference, never inlined
      }
    }
  }
}

Or install with one click:

Install in VS Code Install in Cursor

Both prompt for the token file path; the secret never lands in client config. No token yet? uvx proximo-proxmox mint prints the least-privilege runbook.

Then preflight what your token can actually do (read-only):

uvx proximo-proxmox doctor

Start with a read-only token. Proximo is useful long before you grant it write. Full token-first walkthrough: docs/SETUP.md · more install paths: Install & run.

Why Proximo exists

The Proxmox MCP landscape is split. API-based servers manage nodes and VMs but structurally cannot run a command inside an LXC: the REST API has no exec endpoint. SSH-based servers can, through broad shell access with little scoping.

Proximo builds the principled whole. Both halves, one audited surface, least-privilege. Trust by construction:

Read-only inspector

Full-access executor

Proximo

Can mutate

no — that's the safety

yes

yes — plan recorded first, then confirm=true

Preview before a change

n/a

rarely

default — blast radius + live state, every mutation

Record of what happened

no

app logs, editable

keyed hash-chained ledger, tamper-evident, on by default

Undo

n/a

rare

snapshot-first, wherever the platform can snapshot

Command inside an LXC

no

broad SSH

opt-in, fail-closed CTID allowlist

Products covered

usually PVE

usually PVE

PVE + PBS + PMG + PDM — one audited plane

Verify the artifact you run

varies

varies

signed image · PyPI provenance · SBOM · Scorecard

(The archetype columns describe the split above, not any specific project. There is no official Proxmox MCP; Proximo is a community project, standing on its own.)

The trust layer — what makes Proximo different

Four controls on by default:

Control

What it does

PLAN

Every mutation first returns a recorded preview — the exact change, live state, blast radius, an advisory risk rating. Nothing mutates without its plan recorded; one confirm=true call records and performs.

PROVE

Keyed (HMAC-SHA256), hash-chained audit ledger — audit_verify catches edits, reordering, insertion. Pin the head off-box (expected_head) to catch truncation too: that's the strong guarantee, and it's opt-in.

UNDO

Snapshot-first, fail-closed where the platform can snapshot: auto-snapshot before risky exec, config-revert, pve_rollback. Planes with no snapshot primitive (firewall/SDN/ACL) have no rollback — said plainly.

DIAGNOSE

Read-only evidence battery + node health → advisory flags that surface incompleteness too, so an empty list never reads as a false clean bill.

Six more ship off until you configure them — per-plan CONSENT, a CONTAIN kill-switch, an arm-LEASE, an arm-time SCOPE, a FORBID/RATE ENVELOPE, and TAINT (the prompt-injection mitigation). What each one actually defends against: SECURITY.md.

Honesty note (load-bearing): risk ratings are an advisory heuristic, not a sandbox — LOW means "no state change," not "safe," and the absence of a HIGH flag is not a safety signal. Review every change yourself. The floor beneath it all is the token you mint: Proxmox RBAC holds even if Proximo's process is fully compromised — a stronger guarantee than anything Proximo's own code provides. Scope it to exactly what you mean to grant: SECURITY.md.

Hold any tool to this, including this one: The Keys Test. Ten questions to ask before you hand an AI agent real infrastructure. Proximo's own scorecard published, partials included.

And watch the spine hold, live:

Demo

The record defends itself:

A second cut: doctor preflight, a destructive delete answered with a PLAN, the ledger verifying clean. Recorded live against real PVE 9.2 with a read-only token: docs/demo/demo.svg · scripts/demo/demo.py.

Surfaces & tools — one control plane

Surface

Backend

For

Proxmox VE

REST API + scoped token

node/guest lifecycle, storage, SDN, identity, HA, firewall

Proxmox Backup Server

REST API + scoped token

datastores, namespaces, snapshots, sync, GC, verify, tape

Proxmox Mail Gateway

Ticket auth

mail flow, quarantine, filtering rules, domains, services

Proxmox Datacenter Manager

API token

federated fleet — reads plus governed control (power/snapshot/migrate, dry-run-first)

Container exec

sshpct exec

run-command-in-container, psql, log tailing — what the API structurally can't do

Those backends are deliberately boring. Anyone can call them. The product is the trust layer over them.

904 tools is an estate, not a starting point — and you only carry the part you use. One env var sets your floor: PROXIMO_TOOLSETS=dynamic serves 3 search tools with every other one still callable (~555 tokens of context), one domain like pve.guests runs ~8,900, a whole plane ~97,000. The estate is 904. The doorway is yours to size. Coverage and context stopped being the same number.

Where an operator actually starts:

You want to…

Start with

Worth knowing

See the whole cluster at once

pve_cluster_resources, pve_list_guests

one call, every node

Find out why a container is sick

ct_diagnose, ct_logs, pve_guest_status

read-only evidence battery

Preflight a token / config

proximo doctor (CLI) or pve_doctor, pve_overbroad_grants

run this before wiring an agent

Power / lifecycle

pve_guest_power

returns a PLAN first — nothing moves without confirm=true

Snapshot before touching anything

pve_snapshot_create, pve_rollback

UNDO's foundation

Check backups are actually fresh

pve_backup_freshness, pbs_snapshots_list

walks real archives — "task OK" is never evidence

Run a command in a container

ct_exec

opt-in (PROXIMO_ENABLE_EXEC=1), fail-closed allowlist

Trace / release mail

pmg_tracker_list, pmg_quarantine_spam

full PMG plane behind it

Operate the federated fleet

pdm_resources_list, pdm_pve_lxc_list

governed control, dry-run-first

Prove the record wasn't touched

audit_verify

registered on every surface, always

Every tool with typed inputs: docs/TOOLS.md · sizing the surface to your model: docs/SETUP.md.

Install & run

📦 0.28.0 — on PyPI, GitHub, and GHCR (signed multi-arch image).

New in 0.28.0 — two honesty fixes. The RRD tools stopped letting a model call a rolling window "today": the schema never said those windows roll and end at now, so an agent asked for today answered from the last 24 hours. It wasn't hallucinating — the description told it that. Fixed at all five sites that shipped the wording, pinned by tests. And proximo reap gained opt-in cleanup (PROXIMO_REAP_UNLINK_DAYS) for dead sessions' token and lock files, which restoring the key never removed. Tool count unchanged at 904.

Recent: 0.27.1 — an unbounded mcp dependency met an SDK major that removed the module this server imports, so every fresh PyPI install broke while the suite stayed green. Capped and bounded: a lockfile protects the build, not the adopter.

Proximo runs on your machine, on demand. No daemon, no open port.

uvx proximo-proxmox            # zero-install run (PyPI package: proximo-proxmox; command stays `proximo`)
# or: pip install proximo-proxmox            the MCP core
# or: pip install "proximo-proxmox[a2a]"     + the optional A2A face
# or: pip install "proximo-proxmox[http]"    + the optional HTTP/OpenAPI face
# or: pip install "proximo-proxmox[mcp-http]" + the optional MCP-over-streamable-HTTP face
# or, from source:  git clone https://github.com/john-broadway/proximo.git && cd proximo && uv pip install -e .

Wire it into your MCP client as the command proximo, with the PROXIMO_* env vars — see packaging/proximo.env.example.

Docker (GHCR): docker run -i --rm … ghcr.io/john-broadway/proximo:latest. Multi-arch, SBOM, sigstore-signed provenance (gh attestation verify oci://ghcr.io/john-broadway/proximo --owner john-broadway). Mirrored to Docker Hub (docker.io/jebroadway/proximo, identical digest); GHCR stays the signed primary.

Safe by default: API-only out of the box. The two near-root edges are opt-in and say so loudly: LXC exec (PROXIMO_ENABLE_EXEC=1, near-root on the host) and the qemu-guest-agent edge (PROXIMO_ENABLE_AGENT=1, near-root in a guest). Each is scoped by its own fail-closed allowlist.

Smallest footprint by design: you don't have to load the whole estate — what a box serves is autoscoped to what it configures. A PBS-only box gets that plane's tools plus the always-on audit trail; PROXIMO_SURFACES=pve,exec registers just that pair (314 tools); a typo'd surface refuses startup rather than serving a surprise. The leanest doorway (PROXIMO_TOOLSETS=dynamic) keeps three search-and-call tools resident plus audit_verify — one more if estate memory is on — with the full catalog reachable by name. That narrowing is guarded at every entry point (0.27.0 closed a path where an opt-in flag could silently cut the registry to 5 tools), and the gates don't shrink with the doorway: PLAN and PROVE apply however small the visible surface gets.

The network faces (experimental, opt-in): proximo-a2a speaks Agent2Agent. proximo-http serves plain HTTP + generated /openapi.json for no-code clients. proximo-mcp-http serves MCP itself over Streamable HTTP (the SDK's native transport) for networked MCP clients: no third-party stdio→HTTP bridge, so the perimeter stays Proximo's.

All three serve the full surface through the same spine as MCP. No second code path; trust spine and token scope inherited. Fail-closed perimeter: loopback, bearer-token required off-localhost, DNS-rebind and CSRF defended. Details: SECURITY.md.

At scale

One container is the demo. A cluster is the point.

  • The whole cluster in one call. pve_cluster_resources: every VM, node, storage pool, SDN object.

  • One tamper-evident record across every node. "Show me every state-changing action this month, and prove the log wasn't touched" becomes a query you can actually answer. No human at the CLI walks away with that.

  • Where the time comes back. On one node a senior at the CLI is faster, and that's fine. Across a dozen nodes and hundreds of guests, a bounded, audited agent earns its keep.

Many boxes, one Proximo: register remotes in a TOML file (secrets by reference, never inlined), point PROXIMO_TARGETS at it, aim any tool with proximo_target="edge-pve". The target travels with the call. PLAN and EXECUTE hit the same box, the ledger records which, cross-plane calls error. Config shape: packaging/targets.example.toml.

Status — the arena record

  • 🩸 0.28.0a reviewer asked for "utilization charts for today" and got the last 24 hours, and he was right to call it: the RRD schema never said its windows roll and end at now, so the model picked one and called it today. The model wasn't hallucinating — our own tool description authored the claim. Every one of the five tools carrying that wording now states the limit, and what to report instead, pinned by tests. proximo reap also learned to clean up after dead sessions, since putting the key back never removed the files. A tool description is a prompt: whatever it omits, the model fills in.

Every release before it — every pillar, every redteam, every fix — lives in CHANGELOG.md.

The numbers, honestly: 904 MCP tools, proved in two deliberate layers. 11,000+ in-process tests (ruff + pyright clean) pin every tool's shape. A separate live-smoke harness drives real Proxmox hardware: a 3-node PVE 9.2 cluster, PBS 4.2, PMG 9.1, PDM 1.1.4, a real cross-datacenter move. The two are kept apart on purpose: passing shape tests never gets to masquerade as "works on a real host." And this workspace administers its own Proxmox estate through Proximo daily (dogfood). The blast-radius engine carries the destructive surface: across eleven op-classes it names the specific guests, nodes, principals, or disks at risk. Nothing falls back to a bare confirm.

Proven live (not mocks): the trust spine end-to-end; identity/storage/SDN/firewall/HA create→read→delete with the ledger verified throughout; offline + online live-migration and HA fencing (softdog) on a real 3-node cluster; full PBS/PMG/PDM planes including a real cross-datacenter move. Not yet proven — said plainly: hardware-watchdog fencing (needs physical iTCO/IPMI) and behavior at production scale. The unrecoverable ops (SDN apply, etc.) are deliberately never fired live: proven by plan, held back by design, not a gap. Per-surface detail: CHANGELOG.md.

Documentation

Document

What it answers

Setup

Token-first walkthrough: mint a least-privilege token, verify it, widen deliberately.

Verify

Every trust claim paired with the command that proves it — run them cold.

Security

The two-deployment trust model, all ten controls, what each honestly holds, reporting.

Threat model

What Proximo defends against, what it doesn't, where the boundaries sit.

Tools

All 904 tools, grouped by surface, typed inputs.

Agents

The page written for the agent itself — Proximo's sharp edges, stated first.

Known issues

What's broken or odd right now, said plainly.

Contributing

Dev setup, the CI gates, what a PR is expected to keep intact.

Changelog

Every release, every redteam, every fix — the full build history.

License

Apache-2.0 — chosen for the patent grant that suits infrastructure tooling. Full text in LICENSE.

Credits

Built by John Broadway with Claude and Maude — a human–AI partnership, and the first thing we made on this box to give away to the world. Claude Opus 4.8 built the trust pillars and the original tool surface and has carried the work since; Claude Fable 5 ran the 101-agent release audit and the first publish. Every commit carries its co-author trailer. And to meyergru, who put a real measurement on the table instead of an opinion — the context-cost work above exists because of that report.


"Are you not entertained?" — stars, issues, and sparring partners welcome. Strength and honor. ⚔️

Install Server
A
license - permissive license
A
quality
A
maintenance

Maintenance

Maintainers
15hResponse time
1dRelease cycle
43Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

View all related MCP servers

Related MCP Connectors

  • Let AI operate servers without SSH. Choose actions, approve risky changes, and audit every step.

  • Operate your own Linux servers from your LLM. Requires the SentinelX agent installed per host.

  • Issue, rotate and revoke scoped API-key passes for 25+ providers — the agent never sees a real key

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/john-broadway/proximo'

If you have feedback or need assistance with the MCP directory API, please join our Discord server