Development docs. You’re reading the docs for the next release (v0.9.0); some features here may not have shipped yet. The current stable release is v0.8.0 — see installation.

Running on Proxmox VE

Bewitch runs well on a Proxmox VE host: it's a Debian system underneath, and the packaged daemon stays unprivileged. This page covers what works out of the box, the few things to set up, and how to pull guest and storage stats from the Proxmox API.

Install on the host, not in a container🔗

Install bewitch on the Proxmox host itself (the Debian package or the install script, as on any Debian system). Inside an LXC container it can't see block devices or SMART, and lxcfs virtualizes /proc/meminfo and /proc/stat, so CPU and memory describe the container rather than the machine.

What works out of the box🔗

Things to know🔗

Guests, storage and quorum from the Proxmox API🔗

The Proxmox API already knows per-guest status, storage usage (including LVM-thin pool usage, which needs root to read directly) and cluster quorum. Bewitch's custom sources can poll it with no extra software. examples/sources.d/proxmox.toml is a ready-made starting point; the Debian package installs it as /usr/share/bewitch/examples/sources.d/proxmox.toml:

  1. Create a read-only API token (the PVEAuditor role is enough):

    pveum user add bewitch@pve
    pveum acl modify / --users bewitch@pve --roles PVEAuditor
    pveum user token add bewitch@pve monitor --privsep 0
  2. Install the example into your sources directory (it holds the token, so keep it 0640 root:bewitch), then paste the token secret into its header_value lines and set your node name in the node-status path.

  3. Pin the API's certificate. Proxmox serves :8006 with a self-signed certificate. Get its SHA-256 fingerprint from the web UI (Node → System → Certificates) or run openssl x509 -in /etc/pve/local/pve-ssl.pem -noout -fingerprint -sha256, and put it in each [custom_source.tls] fingerprint. See Self-signed HTTPS.

  4. Restart bewitchd. The sources appear under the TUI's Services tab:

    • pve-node: CPU, load, memory, KSM sharing, root filesystem, PVE and kernel versions.
    • pve-guests: running, stopped and locked guest counts (a lock means a backup, snapshot or migration is in flight). Per-guest CPU and memory can be added one block per guest.
    • pve-storage: LVM-thin pool usage.
    • pve-cluster: nodes online and quorum.

    The numbers are stored and chartable, and you can alert on them like any other metric.

Authenticate with type = "header" and header_name = "Authorization". Proxmox expects PVEAPIToken=… rather than Bearer …, so the bearer auth type won't work.