cv4pve-node-protect
______ _ __
/ ____/___ __________(_)___ _ _____ _____/ /_
/ / / __ \/ ___/ ___/ / __ \ | / / _ \/ ___/ __/
/ /___/ /_/ / / (__ ) / / / / |/ / __(__ ) /_
\____/\____/_/ /____/_/_/ /_/|___/\___/____/\__/
Node Protect for Proxmox VE (Made in Italy)

> Configuration backup for Proxmox VE nodes: connects to each node over SSH and saves the files you choose, from /etc/network/interfaces to the cluster database, in one tar.gz per node with automatic retention.
>
> Documentation
>
> Prefer a web interface with scheduled backups? cv4pve-node-protect also runs inside cv4pve-admin, as its Node Protect module.
Why
Proxmox VE backup jobs save your VMs and containers, not the node they run on. Bridges, bonds and VLANs, /etc/hosts, storage definitions, the cluster configuration in /etc/pve, certificates, SSH keys, cron jobs and scripts live on the node. When its boot disk dies, rebuilding them by hand is slow and easy to get wrong.
cv4pve-node-protect copies those files from every node into a dated archive, on a schedule, so you can see what changed and put back exactly what was there. It runs outside the nodes and connects over SSH, not through the Proxmox VE API. Nothing is installed or written on the nodes. It needs root, and the archives contain secrets: read SSH access and security first.
Features
- The whole cluster in one run: every node in
--host, one archive per node in the same dated folder.
- You choose what goes in:
/etc, the readable /etc/pve files, the cluster database, crontabs, SSH keys, your scripts.
- Nothing left on the nodes:
tar streams over SSH straight into your local file, with no temporary files and no agent.
- Retention:
--keep removes the oldest dated folders, never other folders.
- Plain
tar.gz: restore with standard tools, step by step.
- Password or SSH key, custom port per host, IPv4, IPv6 and host names.
- .NET library: the engine is on NuGet as
Corsinvest.ProxmoxVE.NodeProtect.Api.
Quick start
# Windows
winget install Corsinvest.cv4pve.nodeprotect
# Linux (other platforms and packages: see the documentation)
wget https://github.com/Corsinvest/cv4pve-node-protect/releases/latest/download/cv4pve-node-protect-linux-x64.zip
unzip cv4pve-node-protect-linux-x64.zip && chmod +x cv4pve-node-protect
# Back up three nodes, keep a week
mkdir -p /srv/node-protect && chmod 700 /srv/node-protect
./cv4pve-node-protect --host=pve01,pve02,pve03 --username=root --private-key-file=/root/.ssh/id_ed25519 \
backup --paths='/etc/.;/etc/pve/.;/var/lib/pve-cluster/.' --directory-work=/srv/node-protect --keep=7
/etc/. alone does not include /etc/pve: what to back up explains why and which paths to add.
Documentation
| |
|---|
| Getting started | Install, first backup, the options of backup |
| SSH access and security | The account it needs, host keys, protecting the archives |
| Connection | What runs on each node, hosts and ports, authentication, options in a file |
| What to back up | Recommended paths, /etc/pve and the cluster database |
| Archives and retention | Layout, format, --keep, what happens when a run fails |
| Scheduling | cron and Task Scheduler |
| Restore | A single file, a reinstalled node, a lost node |
| .NET library | The engine in your own application |
| AI assistants | Claude Code, Codex, the cv4pve-node-protect skill |
| Troubleshooting | Diagnostic options and common errors |
Related tools
cv4pve-node-protect protects the node; cv4pve-autosnap takes scheduled snapshots of the guests, cv4pve-report documents the whole cluster. The whole suite: corsinvest.it/cv4pve.
Support
Professional support and consulting available through Corsinvest.
Part of cv4pve suite | Made with ❤️ in Italy by Corsinvest
Copyright © Corsinvest Srl