{"resources":{"proxmox":{"id":"proxmox","name":"proxmox","fields":{"about":{"name":"about","type":"\n","title":"Version and system information","desc":"Raw `/version` API response. Keys include `version` (the PVE manager version, e.g. `8.2.2`), `release` (the point release), and `repoid` (the package repository commit the build was produced from).","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"acl":{"name":"acl","type":"\u0019\u001bproxmox.acl","title":"Access-control list entries assigning roles to users, groups, and tokens on cluster paths","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"acme":{"name":"acme","type":"\u001bproxmox.acme","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"acmeAccounts":{"name":"acmeAccounts","type":"\u0019\u001bproxmox.acme.account","title":"ACME accounts registered for automatic certificate issuance","min_provider_version":"0.3.6","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"acmePlugins":{"name":"acmePlugins","type":"\u0019\u001bproxmox.acme.plugin","title":"ACME DNS challenge plugins configured on the cluster","min_provider_version":"0.3.6","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"backup":{"name":"backup","type":"\u001bproxmox.backup","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"backupJobs":{"name":"backupJobs","type":"\u0019\u001bproxmox.backup.job","title":"Scheduled cluster-wide vzdump backup jobs","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"ceph":{"name":"ceph","type":"\u001bproxmox.ceph","title":"Ceph storage cluster managed by this Proxmox deployment","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"certificate":{"name":"certificate","type":"\u001bproxmox.certificate","title":"Proxmox VE node TLS certificate","desc":"TLS/SSL certificate installed on a Proxmox node, used to secure the web interface and API. Auditing these certificates surfaces weak keys, mismatched or missing Subject Alternative Names, untrusted issuers, and certificates that are expired or nearing expiry. The `filename` field identifies which certificate file on the node the entry represents.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"cluster":{"name":"cluster","type":"\u001bproxmox.cluster","title":"Cluster-level information (HA, quorum, corosync)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"container":{"name":"container","type":"\u001bproxmox.container","title":"Proxmox VE LXC container","desc":"LXC container in the cluster, identified by numeric `id` and display `name`. Live `status` (running, stopped), the `node` it runs on, and resource usage (`cpu`, `mem`, `disk`, `netin`, `netout`) come from the cluster status API, while the per-container configuration exposes whether the container runs `unprivileged`, its `ostype`, `hostname`, enabled `features`, and boot options. Network interfaces, mount points, snapshots, and the container-level firewall (rules, options, ipsets, aliases) are reachable through their own fields, letting audits check isolation, host-device exposure, and firewall posture in a single query.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"containers":{"name":"containers","type":"\u0019\u001bproxmox.container","title":"All LXC containers across the cluster","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"corosync":{"name":"corosync","type":"\u001bproxmox.corosync","title":"Corosync cluster membership and transport configuration","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"dns":{"name":"dns","type":"\u001bproxmox.dns","title":"Proxmox VE node DNS configuration","desc":"DNS resolver configuration on a Proxmox node: the `search` domain and up to three nameservers (`dns1`, `dns2`, `dns3`). Useful for confirming a node resolves names through the expected servers and domain.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"firewall":{"name":"firewall","type":"\u001bproxmox.firewall","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"gotifyEndpoints":{"name":"gotifyEndpoints","type":"\u0019\u001bproxmox.notification.gotifyEndpoint","title":"Notification targets that post to a Gotify server","min_provider_version":"0.3.6","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"group":{"name":"group","type":"\u001bproxmox.group","title":"Proxmox VE access control group","desc":"Group defined in the Proxmox cluster, identified by `id`, for example `proxmox.group(id: \"admins\")`. Groups bundle users so a single access-control entry can grant a role to many accounts at once, which makes them the natural unit for auditing who holds privileges at a given path. The `memberIds` field lists the user IDs in the group; `members` resolves those IDs to `proxmox.user` records for traversal into each account.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"groups":{"name":"groups","type":"\u0019\u001bproxmox.group","title":"Groups configured in the cluster","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"lvm":{"name":"lvm","type":"\u001bproxmox.lvm","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"mapping":{"name":"mapping","type":"\u001bproxmox.mapping","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"metricServer":{"name":"metricServer","type":"\u001bproxmox.metricServer","title":"External metric server","desc":"External InfluxDB or Graphite server the cluster ships metrics to, selected by `id`. Guest names, node names, and resource figures leave the cluster continuously through these, so `server`, `port`, and `type` describe where that stream goes. The Graphite and InfluxDB-UDP transports carry no authentication or encryption at all. The API token for the HTTP transports is not returned by the API.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"metricServers":{"name":"metricServers","type":"\u0019\u001bproxmox.metricServer","title":"External servers the cluster ships metrics to","min_provider_version":"0.3.6","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"network":{"name":"network","type":"\u001bproxmox.network","title":"Proxmox VE node network interface","desc":"Network interface configured on a Proxmox node, selected by `iface` (e.g. `proxmox.network(iface: \"vmbr0\")`). Interfaces determine how a node reaches management, cluster, and guest networks, so their addressing and reachability are central to auditing host isolation and exposure. The `type` field distinguishes bridges, bonds, physical eth ports, VLANs, and Open vSwitch interfaces, and `bridgePorts` names the member ports carried by a bridge.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"node":{"name":"node","type":"\u001bproxmox.node","title":"Proxmox VE node","desc":"Physical or virtual host in the Proxmox cluster, identified by `name`. Reports hardware details including CPU model, socket and core counts, memory and swap totals, as well as current utilization via `cpuUsage`, `memUsed`, and `memFree`. System information covers the running `kernelVersion`, `pveVersion`, and `uptime`. Network interfaces are available through `networks`, DNS configuration through `dns`, and systemd service states through `services`. Security-relevant data includes TLS `certificates`, APT `repositories`, available `updates`, and node-level `firewallRules`. VMs running on the node are listed via `vms`, and subscription status is available through `subscription`.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"nodes":{"name":"nodes","type":"\u0019\u001bproxmox.node","title":"All cluster nodes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"notification":{"name":"notification","type":"\u001bproxmox.notification","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"notificationMatchers":{"name":"notificationMatchers","type":"\u0019\u001bproxmox.notification.matcher","title":"Rules deciding which notifications reach which targets","min_provider_version":"0.3.6","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"notificationTargets":{"name":"notificationTargets","type":"\u0019\u001bproxmox.notification.target","title":"Every configured notification target, of every type","min_provider_version":"0.3.6","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"pciMappings":{"name":"pciMappings","type":"\u0019\u001bproxmox.mapping.pci","title":"Cluster-wide PCI device mappings guests can be granted by name","min_provider_version":"0.3.6","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"pool":{"name":"pool","type":"\u001bproxmox.pool","title":"Proxmox VE resource pool","desc":"Resource pool in the cluster, selected by `id` (for example `proxmox.pool(id: \"prod\")`). Pools group virtual machines and storage into a single unit that permissions can be granted against, so auditing them shows how access to those resources is delegated. The `comment` field holds the pool description.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"pools":{"name":"pools","type":"\u0019\u001bproxmox.pool","title":"Resource pools","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"realm":{"name":"realm","type":"\u001bproxmox.realm","title":"Proxmox VE authentication realm","desc":"Authentication realm configured in the Proxmox cluster, identified by `realm`. Reports the realm `type` (pam, pve, ldap, ad, openid), whether it is the `default` realm, the realm-enforced TFA challenge in `tfaType` (empty when no realm-wide TFA is required), and full configuration via `config`, including LDAP servers, sync settings, OpenID issuer URLs, and `autocreate` flags.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"realms":{"name":"realms","type":"\u0019\u001bproxmox.realm","title":"Authentication realms (pam, pve, ldap, ad, openid)","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"replication":{"name":"replication","type":"\u001bproxmox.replication","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"replicationJobs":{"name":"replicationJobs","type":"\u0019\u001bproxmox.replication.job","title":"Guest-storage replication jobs configured on the cluster","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"repository":{"name":"repository","type":"\u001bproxmox.repository","title":"Proxmox VE node APT repository","desc":"APT package repository configured on a Proxmox node, covering both the legacy `sources.list` format and modern deb822 `.sources` entries. The `enabled` flag reflects whether the entry is active, and `signedBy` records the keyring that verifies package signatures. Useful for confirming that only official, correctly signed Proxmox repositories are configured and that no untrusted or disabled entries remain.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"role":{"name":"role","type":"\u001bproxmox.role","title":"Proxmox VE access control role","desc":"Role defined in the Proxmox cluster, identified by `id`. The `privs` list holds the privileges granted by the role, and `special` indicates whether it is a built-in role. Roles are assigned to users and groups on paths to implement Proxmox's path-based access-control model.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"roles":{"name":"roles","type":"\u0019\u001bproxmox.role","title":"Roles defined in the cluster","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"sdn":{"name":"sdn","type":"\u001bproxmox.sdn","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"sdnControllers":{"name":"sdnControllers","type":"\u0019\u001bproxmox.sdn.controller","title":"SDN controllers driving the routing protocols behind EVPN and BGP zones","min_provider_version":"0.3.6","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"sdnDnsServers":{"name":"sdnDnsServers","type":"\u0019\u001bproxmox.sdn.dns","title":"DNS backends the SDN registers guest records in","min_provider_version":"0.3.6","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"sdnIpams":{"name":"sdnIpams","type":"\u0019\u001bproxmox.sdn.ipam","title":"IP address management backends the SDN allocates guest addresses from","min_provider_version":"0.3.6","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"sdnVnets":{"name":"sdnVnets","type":"\u0019\u001bproxmox.sdn.vnet","title":"SDN virtual networks defined on the cluster","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"sdnZones":{"name":"sdnZones","type":"\u0019\u001bproxmox.sdn.zone","title":"SDN zones defined on the cluster","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"sendmailEndpoints":{"name":"sendmailEndpoints","type":"\u0019\u001bproxmox.notification.sendmailEndpoint","title":"Notification targets that mail through the local sendmail binary","min_provider_version":"0.3.6","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"service":{"name":"service","type":"\u001bproxmox.service","title":"Proxmox VE node systemd service","desc":"Systemd service on a Proxmox node, selected by `name` (for example `proxmox.service(name: \"pveproxy\")`). The `state` field reports the current runtime status (running, dead, etc.) and `unitFileState` reports the boot-time enablement (enabled, disabled, static, masked). Use it to audit whether critical Proxmox services such as `pve-cluster`, `pveproxy`, or `corosync` are active and enabled.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"smtpEndpoints":{"name":"smtpEndpoints","type":"\u0019\u001bproxmox.notification.smtpEndpoint","title":"Notification targets that mail through an SMTP server","min_provider_version":"0.3.6","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"storage":{"name":"storage","type":"\u001bproxmox.storage","title":"Proxmox VE storage pool","desc":"Storage pool configured in the cluster, identified by `id` (for example `proxmox.storage(id: \"local-lvm\")`). Reports the storage `type` (dir, lvm, lvmthin, nfs, cifs, zfspool, ceph, etc.), allowed `content` types, filesystem `path` for local types, and whether the pool is `enabled` and `shared` across nodes. Capacity is reported through `total`, `used`, `available`, and `usagePercent`, and `encrypted` flags PBS-encrypted datastores.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"storages":{"name":"storages","type":"\u0019\u001bproxmox.storage","title":"Storage pools configured in the cluster","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"subscription":{"name":"subscription","type":"\u001bproxmox.subscription","title":"Proxmox VE subscription","desc":"Support subscription attached to a Proxmox node, covering its entitlement `status` (active, notfound, invalid), support `level` (basic, standard, premium), registration and renewal dates, and the server identifier the key is bound to. Use it in compliance checks that require nodes to carry an active, appropriately tiered subscription and to flag entitlements approaching their renewal.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"token":{"name":"token","type":"\u001bproxmox.token","title":"Proxmox VE API token","desc":"API token belonging to a Proxmox user, identified by `id` in the form `user@realm!tokenid`. Reports the token `comment`, `expire` time (Unix timestamp, 0 = never), and whether privilege separation is active via `privsep`. When `privsep` is true the token's permissions are limited to a subset of the owner's privileges, which makes tokens a useful audit surface for least-privilege review of non-interactive access.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"usbMappings":{"name":"usbMappings","type":"\u0019\u001bproxmox.mapping.usb","title":"Cluster-wide USB device mappings guests can be granted by name","min_provider_version":"0.3.6","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"user":{"name":"user","type":"\u001bproxmox.user","title":"Proxmox VE user","desc":"User account in the Proxmox cluster, identified by `id` in the form `user@realm`. Auditing accounts surfaces whether each is `enable`d, its `email`, `firstname`, `lastname`, `realm` (pam, pve, ldap, ad), `groups` membership, and `expire` time (Unix timestamp, 0 = never). Multi-factor enrollment is available through `tfaFactors` and `tfaLockedUntil`, the realm authentication type through `realmType`, and API tokens belonging to the user through `tokens`.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"users":{"name":"users","type":"\u0019\u001bproxmox.user","title":"Users configured in the cluster","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"vm":{"name":"vm","type":"\u001bproxmox.vm","title":"Proxmox VE virtual machine","desc":"QEMU virtual machine in the cluster, identified by numeric `id` and display `name`. Current `status` (running, stopped, paused), the `node` it runs on, and live resource usage (`cpu`, `mem`, `disk`, `netin`, `netout`) come from the cluster resource list, while configuration details (OS type, machine type, BIOS, boot order, guest agent state, protection, hookscript, and passthrough devices) are read from the per-VM config. Attached `networks`, `disks`, and point-in-time `snapshots` model the VM's devices; `firewallRules`, `firewallOptions`, `ipsets`, and `aliases` cover the VM-level firewall; and `updates` lists installed packages with available upgrades (requires the QEMU guest agent).","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"vms":{"name":"vms","type":"\u0019\u001bproxmox.vm","title":"All QEMU virtual machines across the cluster","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"webhookEndpoints":{"name":"webhookEndpoints","type":"\u0019\u001bproxmox.notification.webhookEndpoint","title":"Notification targets that post to an arbitrary URL","min_provider_version":"0.3.6","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"zfs":{"name":"zfs","type":"\u001bproxmox.zfs","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true}},"title":"Proxmox VE","desc":"Root of a Proxmox Virtual Environment cluster and the entry point for auditing everything it runs. Version and system information is available via `about`, the QEMU virtual machines and LXC containers it hosts through `vms` and `containers`, and the physical `nodes`, `storages`, and `pools` backing them. The access-control model is exposed through `users`, `groups`, `roles`, `acl`, and `realms`; cluster-wide HA, quorum, and firewall configuration through `cluster`; scheduled vzdump backups through `backupJobs`; guest replication through `replicationJobs`; software-defined networking through `sdnZones` and `sdnVnets`; and the Ceph storage cluster, when one is configured, through `ceph`.","min_provider_version":"0.1.1","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.acl":{"id":"proxmox.acl","name":"proxmox.acl","fields":{"group":{"name":"group","type":"\u001bproxmox.group","title":"Group this entry refers to when `type` is `group`; null otherwise","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"path":{"name":"path","type":"\u0007","is_mandatory":true,"title":"Path the entry applies to (e.g. /, /vms/100, /storage/local)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"propagate":{"name":"propagate","type":"\u0004","is_mandatory":true,"title":"Whether the grant propagates to child paths","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"role":{"name":"role","type":"\u001bproxmox.role","title":"Resolved role","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"roleId":{"name":"roleId","type":"\u0007","is_mandatory":true,"title":"Role ID granted at this path","desc":"Deprecated in favor of `role`, which resolves the same role as a role resource carrying its privilege list.","provider":"go.mondoo.com/mql/v13/providers/proxmox","maturity":"deprecated"},"token":{"name":"token","type":"\u001bproxmox.token","title":"Token this entry refers to when `type` is `token`; null otherwise","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Entry type: user, group, or token","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"ugid":{"name":"ugid","type":"\u0007","is_mandatory":true,"title":"Identifier of the user, group, or token the grant applies to","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"user":{"name":"user","type":"\u001bproxmox.user","title":"User this entry refers to when `type` is `user`; null otherwise","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE access control list entry","desc":"Access control list assignment in the Proxmox cluster. An entry grants a `role` to a user, group, or API token (identified by `ugid`) at a specific `path` such as `/`, `/vms/100`, or `/storage/local`. The `type` field discriminates between user, group, and token entries and selects which of `user`, `group`, and `token` resolves to a resource (the other two are null); `role` always resolves the granted role. `propagate` reports whether the grant extends to child paths. Auditing these entries reveals who holds which privileges and where in the cluster hierarchy those privileges apply.","min_provider_version":"0.1.9","defaults":"path type ugid roleId propagate","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.acme":{"id":"proxmox.acme","fields":{"account":{"name":"account","type":"\u001bproxmox.acme.account","title":"ACME account","desc":"ACME account registered for automatic certificate issuance, selected by `name`. Nodes issue their API certificates through one of these, so the presence of an account is what separates automatically renewed certificates from manually managed ones.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"plugin":{"name":"plugin","type":"\u001bproxmox.acme.plugin","title":"ACME challenge plugin","desc":"DNS-01 challenge plugin used to prove domain control during certificate issuance, selected by `plugin`. Each plugin holds credentials for a DNS provider that can create records on the cluster's domain, so `api` names which provider that is and `nodes` which nodes may use it. The credential data itself is not exposed here.  Reading plugin configuration requires Sys.Modify, which no audit role carries. A read-only token sees an empty list.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true}},"is_extension":true},"proxmox.acme.account":{"id":"proxmox.acme.account","name":"proxmox.acme.account","fields":{"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Account name","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"ACME account","desc":"ACME account registered for automatic certificate issuance, selected by `name`. Nodes issue their API certificates through one of these, so the presence of an account is what separates automatically renewed certificates from manually managed ones.","min_provider_version":"0.3.6","defaults":"name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.acme.plugin":{"id":"proxmox.acme.plugin","name":"proxmox.acme.plugin","fields":{"api":{"name":"api","type":"\u0007","is_mandatory":true,"title":"DNS provider plugin name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"disabled":{"name":"disabled","type":"\u0004","is_mandatory":true,"title":"Whether the plugin is disabled","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"nodes":{"name":"nodes","type":"\u0007","is_mandatory":true,"title":"Node restriction, comma-separated; empty when unrestricted","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"plugin":{"name":"plugin","type":"\u0007","is_mandatory":true,"title":"Plugin instance identifier","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"ACME challenge type (`dns` or `standalone`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"validationDelay":{"name":"validationDelay","type":"\u0005","is_mandatory":true,"title":"Extra seconds to wait before requesting validation","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"ACME challenge plugin","desc":"DNS-01 challenge plugin used to prove domain control during certificate issuance, selected by `plugin`. Each plugin holds credentials for a DNS provider that can create records on the cluster's domain, so `api` names which provider that is and `nodes` which nodes may use it. The credential data itself is not exposed here.  Reading plugin configuration requires Sys.Modify, which no audit role carries. A read-only token sees an empty list.","min_provider_version":"0.3.6","defaults":"plugin type api","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.backup":{"id":"proxmox.backup","fields":{"job":{"name":"job","type":"\u001bproxmox.backup.job","title":"Proxmox VE scheduled backup job","desc":"Cluster-wide vzdump backup job, identified by `id`. The job selects guests by explicit `vmids`, by `pool`, or by `all`, and writes to `storage` on the optional `schedule`. Reports the dump `mode` (snapshot, suspend, stop), `compress` algorithm, notification configuration via `mailto` and `notificationMode`, retention via `prune`, and the `fleecing` setting. `targetStorage` resolves `storage` to a `proxmox.storage` reference so audits can check the storage pool's encryption or sharing semantics in the same query. The full raw job definition is available through `config`.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true}},"is_extension":true},"proxmox.backup.job":{"id":"proxmox.backup.job","name":"proxmox.backup.job","fields":{"all":{"name":"all","type":"\u0004","is_mandatory":true,"title":"Whether the job targets every guest","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"comment":{"name":"comment","type":"\u0007","is_mandatory":true,"title":"Job comment","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"compress":{"name":"compress","type":"\u0007","is_mandatory":true,"title":"Compression algorithm (0, 1, gzip, lzo, zstd)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"config":{"name":"config","type":"\n","title":"Full raw job configuration as returned by /cluster/backup/\u003cid\u003e","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether the job is enabled","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"exclude":{"name":"exclude","type":"\u0007","is_mandatory":true,"title":"Comma-separated VMIDs to exclude","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"fleecing":{"name":"fleecing","type":"\u0007","is_mandatory":true,"title":"Fleecing configuration (e.g. enabled=1,storage=pbs)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Job identifier","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"mailto":{"name":"mailto","type":"\u0007","is_mandatory":true,"title":"Comma-separated email recipients","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"mode":{"name":"mode","type":"\u0007","is_mandatory":true,"title":"Dump mode (snapshot, suspend, stop)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"nextRun":{"name":"nextRun","type":"\u0005","is_mandatory":true,"title":"Next scheduled run as a Unix timestamp; 0 if not scheduled","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"node":{"name":"node","type":"\u0007","is_mandatory":true,"title":"Node the job is restricted to; empty when cluster-wide","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"notesTemplate":{"name":"notesTemplate","type":"\u0007","is_mandatory":true,"title":"Template for backup notes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"notificationMode":{"name":"notificationMode","type":"\u0007","is_mandatory":true,"title":"Notification routing mode (auto, legacy-sendmail, notification-system)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"pool":{"name":"pool","type":"\u0007","is_mandatory":true,"title":"Pool the job targets (alternative to vmids)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"protected":{"name":"protected","type":"\u0004","is_mandatory":true,"title":"Whether resulting backups are marked protected","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"prune":{"name":"prune","type":"\u0007","is_mandatory":true,"title":"Retention specification (e.g. keep-last=7,keep-daily=14)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"schedule":{"name":"schedule","type":"\u0007","is_mandatory":true,"title":"Schedule (systemd-calendar expression, e.g. `mon..fri 03:00`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"storage":{"name":"storage","type":"\u0007","is_mandatory":true,"title":"Storage name backups are written to","desc":"Deprecated in favor of `targetStorage`, which resolves the same pool as a storage resource.","provider":"go.mondoo.com/mql/v13/providers/proxmox","maturity":"deprecated"},"targetContainers":{"name":"targetContainers","type":"\u0019\u001bproxmox.container","title":"Containers this job targets, resolved the same way as `targetVms`","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"targetStorage":{"name":"targetStorage","type":"\u001bproxmox.storage","title":"Resolved target storage pool","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"targetVms":{"name":"targetVms","type":"\u0019\u001bproxmox.vm","title":"VMs this job targets","desc":"Resolved from `vmids` and `all` against the current cluster inventory. When `all` is true this returns every VM and `vmids` is ignored. Pool-scoped jobs (`pool` set, `vmids` empty) return an empty list. Query `pool` for those instead.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"vmids":{"name":"vmids","type":"\u0007","is_mandatory":true,"title":"Comma-separated VMIDs the job targets","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE scheduled backup job","desc":"Cluster-wide vzdump backup job, identified by `id`. The job selects guests by explicit `vmids`, by `pool`, or by `all`, and writes to `storage` on the optional `schedule`. Reports the dump `mode` (snapshot, suspend, stop), `compress` algorithm, notification configuration via `mailto` and `notificationMode`, retention via `prune`, and the `fleecing` setting. `targetStorage` resolves `storage` to a `proxmox.storage` reference so audits can check the storage pool's encryption or sharing semantics in the same query. The full raw job definition is available through `config`.","min_provider_version":"0.1.9","defaults":"id schedule storage enabled","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.ceph":{"id":"proxmox.ceph","name":"proxmox.ceph","fields":{"available":{"name":"available","type":"\u0004","title":"Whether Ceph is configured on this cluster","desc":"False when `pveceph` was never initialized. All other fields are empty in that case.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"config":{"name":"config","type":"\u0019\u001bproxmox.ceph.configEntry","title":"Cluster-wide configuration entries from the Ceph config database","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"configEntry":{"name":"configEntry","type":"\u001bproxmox.ceph.configEntry","title":"Ceph configuration database entry","desc":"Setting stored in the Ceph configuration database rather than in ceph.conf, selected by its `name` within a `section`. Entries here are what Ceph actually runs with, so this is where authentication and wire-protocol settings such as `auth_cluster_required`, `auth_service_required`, and `ms_bind_msgr2` can be confirmed. The `section` field scopes the entry to `global`, a daemon type, or a single daemon, and `mask` narrows it further to a CRUSH location or device class.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"crushRules":{"name":"crushRules","type":"\u0019\u0007","title":"Names of the CRUSH rules defined on the cluster","desc":"Rules decide which OSDs a pool places its replicas on. Pools reference them by name through `crushRuleName`.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"fileSystems":{"name":"fileSystems","type":"\u0019\u001bproxmox.ceph.filesystem","title":"CephFS file systems defined on the cluster","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"filesystem":{"name":"filesystem","type":"\u001bproxmox.ceph.filesystem","title":"CephFS file system","desc":"CephFS file system and the pools that store it, selected by `name`. The `metadataPool` holds the namespace and `dataPools` the file contents, so the durability of a CephFS is the durability of those pools. Proxmox mounts these through a `cephfs` storage entry.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"healthChecks":{"name":"healthChecks","type":"\n","title":"Health check summaries currently raised by Ceph","desc":"Keyed by the Ceph check name (for example `POOL_NO_REDUNDANCY`, `MON_CLOCK_SKEW`, `OSD_NEARFULL`), with the severity and message Ceph reports for each. Empty when health is HEALTH_OK.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"healthStatus":{"name":"healthStatus","type":"\u0007","title":"Overall Ceph health","desc":"One of HEALTH_OK, HEALTH_WARN, or HEALTH_ERR. Empty when Ceph is not configured on the cluster.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"manager":{"name":"manager","type":"\u001bproxmox.ceph.manager","title":"Ceph manager daemon","desc":"Manager daemon serving cluster metrics and hosted modules such as the dashboard and the placement-group autoscaler, selected by `name`. A cluster with no active manager keeps serving I/O but stops reporting usable statistics, so `state` is the field to check. The `host` field names the node the daemon runs on.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"managers":{"name":"managers","type":"\u0019\u001bproxmox.ceph.manager","title":"Managers that serve cluster metrics and hosted modules","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"metadataServer":{"name":"metadataServer","type":"\u001bproxmox.ceph.metadataServer","title":"Ceph metadata server daemon","desc":"Metadata server backing a CephFS file system, selected by `name`. Each file system needs an active MDS to serve its namespace, so `state` and `rank` show whether one is bound and standbys are available. The `fileSystem` field resolves the CephFS this daemon serves, and `standbyReplay` reports whether a standby is tracking the active daemon for faster failover.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"metadataServers":{"name":"metadataServers","type":"\u0019\u001bproxmox.ceph.metadataServer","title":"Metadata servers backing CephFS file systems","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"monitor":{"name":"monitor","type":"\u001bproxmox.ceph.monitor","title":"Ceph monitor daemon","desc":"Monitor daemon holding the authoritative copy of the cluster map, selected by `name`. Monitors must hold quorum for the cluster to accept I/O, so `quorum` and `state` are the fields that say whether the cluster is actually serving. The `host` field names the node the daemon runs on and `addr` its advertised bind address.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"monitors":{"name":"monitors","type":"\u0019\u001bproxmox.ceph.monitor","title":"Monitors that maintain the cluster map and quorum","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"nodeVersions":{"name":"nodeVersions","type":"\n","title":"Ceph version installed on each node, keyed by node name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"osd":{"name":"osd","type":"\u001bproxmox.ceph.osd","title":"Ceph object storage daemon","desc":"Object storage daemon holding one backing device worth of cluster data, selected by its numeric `id`. An OSD contributes capacity only while it is both `up` (running) and `inCluster` (accepting data), so those two fields together say whether the cluster is degraded. The `deviceClass` field (`hdd`, `ssd`, `nvme`) is what CRUSH rules select on, `crushWeight` sets the share of data it receives, and `devices` names the underlying block devices.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"osds":{"name":"osds","type":"\u0019\u001bproxmox.ceph.osd","title":"Object storage daemons holding the cluster data","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"pool":{"name":"pool","type":"\u001bproxmox.ceph.pool","title":"Ceph storage pool","desc":"Storage pool and the replication settings that decide how much hardware loss its data survives, selected by `name`. The `size` field is the number of replicas Ceph keeps and `minSize` the number it needs before it will still accept writes; a replicated pool at size 2 or minSize 1 can lose data to a single failure. The `crushRuleName` field names the placement rule and `pgAutoscaleMode` whether Ceph manages the placement-group count.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"pools":{"name":"pools","type":"\u0019\u001bproxmox.ceph.pool","title":"Storage pools and their replication settings","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"status":{"name":"status","type":"\n","title":"Complete Ceph status report","desc":"Raw `/cluster/ceph/status` response, holding the full fsid, mon map, osd map, pg map, and service map. The escape hatch for values not surfaced as their own fields.","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Ceph cluster backing a Proxmox VE deployment","desc":"Ceph storage cluster managed alongside Proxmox VE, covering the daemons that keep it running and the data-placement settings that decide how durable it is. Monitors, managers, metadata servers, and OSDs are listed through `monitors`, `managers`, `metadataServers`, and `osds`; the data layout through `pools`, `fileSystems`, and `crushRules`; and the cluster-wide tunables Ceph itself stores through `config`. Overall health is reported by `healthStatus`, with the complete unparsed report in `status`.  Many Proxmox clusters run no Ceph at all. On those, `available` is false and every list is empty, which is a real answer rather than a failed one. A token that cannot read Ceph reports an error instead, so missing permissions are never reported as a cluster without Ceph. Reading these fields requires Sys.Audit or Datastore.Audit on `/`.","min_provider_version":"0.3.6","defaults":"available healthStatus","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.ceph.configEntry":{"id":"proxmox.ceph.configEntry","name":"proxmox.ceph.configEntry","fields":{"canUpdateAtRuntime":{"name":"canUpdateAtRuntime","type":"\u0004","is_mandatory":true,"title":"Whether the value can change without restarting the affected daemons","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"level":{"name":"level","type":"\u0007","is_mandatory":true,"title":"Visibility level of the setting (`basic`, `advanced`, or `dev`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"mask":{"name":"mask","type":"\u0007","is_mandatory":true,"title":"Match expression narrowing the entry's scope; empty when unmasked","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Configuration key name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"section":{"name":"section","type":"\u0007","is_mandatory":true,"title":"Scope the entry applies to","desc":"`global`, a daemon type (`mon`, `osd`, `mds`, `mgr`, `client`), or a single daemon such as `osd.3`.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"value":{"name":"value","type":"\u0007","is_mandatory":true,"title":"Configured value, always serialized as a string by Ceph","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Ceph configuration database entry","desc":"Setting stored in the Ceph configuration database rather than in ceph.conf, selected by its `name` within a `section`. Entries here are what Ceph actually runs with, so this is where authentication and wire-protocol settings such as `auth_cluster_required`, `auth_service_required`, and `ms_bind_msgr2` can be confirmed. The `section` field scopes the entry to `global`, a daemon type, or a single daemon, and `mask` narrows it further to a CRUSH location or device class.","min_provider_version":"0.3.6","defaults":"section name value","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.ceph.filesystem":{"id":"proxmox.ceph.filesystem","name":"proxmox.ceph.filesystem","fields":{"dataPools":{"name":"dataPools","type":"\u0019\u0007","is_mandatory":true,"title":"Names of every data pool assigned to the file system","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"metadataPool":{"name":"metadataPool","type":"\u0007","is_mandatory":true,"title":"Name of the pool holding file-system metadata","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"File system name","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"CephFS file system","desc":"CephFS file system and the pools that store it, selected by `name`. The `metadataPool` holds the namespace and `dataPools` the file contents, so the durability of a CephFS is the durability of those pools. Proxmox mounts these through a `cephfs` storage entry.","min_provider_version":"0.3.6","defaults":"name metadataPool","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.ceph.manager":{"id":"proxmox.ceph.manager","name":"proxmox.ceph.manager","fields":{"addr":{"name":"addr","type":"\u0007","is_mandatory":true,"title":"Address the manager advertises, in Ceph format","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"cephVersion":{"name":"cephVersion","type":"\u0007","is_mandatory":true,"title":"Full Ceph version string of the daemon","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"cephVersionShort":{"name":"cephVersionShort","type":"\u0007","is_mandatory":true,"title":"Short numeric Ceph version of the daemon (e.g. `19.2.0`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"directoryExists":{"name":"directoryExists","type":"\u0004","is_mandatory":true,"title":"Whether the manager data directory exists on the hosting node","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"host":{"name":"host","type":"\u0007","is_mandatory":true,"title":"Node the manager runs on","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Manager id","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"node":{"name":"node","type":"\u001bproxmox.node","title":"Host the manager runs on","desc":"Resolves `host` against the cluster, so a stopped manager can be checked against the state of the node running it. Null when the named host is no longer in the cluster.","min_provider_version":"0.4.2","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"service":{"name":"service","type":"\u0004","is_mandatory":true,"title":"Whether a ceph-mgr systemd unit is enabled on the hosting node","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"Manager state","desc":"`active` or `standby` for daemons visible to the manager cluster, `stopped` when the systemd unit is configured but inactive, or `unknown`.","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Ceph manager daemon","desc":"Manager daemon serving cluster metrics and hosted modules such as the dashboard and the placement-group autoscaler, selected by `name`. A cluster with no active manager keeps serving I/O but stops reporting usable statistics, so `state` is the field to check. The `host` field names the node the daemon runs on.","min_provider_version":"0.3.6","defaults":"name host state","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.ceph.metadataServer":{"id":"proxmox.ceph.metadataServer","name":"proxmox.ceph.metadataServer","fields":{"addr":{"name":"addr","type":"\u0007","is_mandatory":true,"title":"Address the metadata server advertises, in Ceph format","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"cephVersion":{"name":"cephVersion","type":"\u0007","is_mandatory":true,"title":"Full Ceph version string of the daemon","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"cephVersionShort":{"name":"cephVersionShort","type":"\u0007","is_mandatory":true,"title":"Short numeric Ceph version of the daemon (e.g. `19.2.0`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"directoryExists":{"name":"directoryExists","type":"\u0004","is_mandatory":true,"title":"Whether the metadata server data directory exists on the hosting node","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"fileSystem":{"name":"fileSystem","type":"\u001bproxmox.ceph.filesystem","title":"CephFS this daemon serves; null for unbound standbys","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"fsName":{"name":"fsName","type":"\u0007","is_mandatory":true,"title":"Name of the CephFS this daemon is bound to; empty for unbound standbys","desc":"Deprecated in favor of `fileSystem`, which resolves the same file system as a CephFS resource.","provider":"go.mondoo.com/mql/v13/providers/proxmox","maturity":"deprecated"},"host":{"name":"host","type":"\u0007","is_mandatory":true,"title":"Node the metadata server runs on","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Metadata server id","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"node":{"name":"node","type":"\u001bproxmox.node","title":"Host the metadata server runs on","desc":"Resolves `host` against the cluster, so a file system left without an active daemon can be traced to the node running it. Null when the named host is no longer in the cluster.","min_provider_version":"0.4.2","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"rank":{"name":"rank","type":"\u0005","is_mandatory":true,"title":"Rank within the file system; -1 for standby daemons not bound to a rank","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"service":{"name":"service","type":"\u0004","is_mandatory":true,"title":"Whether a ceph-mds systemd unit is enabled on the hosting node","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"standbyReplay":{"name":"standbyReplay","type":"\u0004","is_mandatory":true,"title":"Whether the standby is polling the active daemon for faster recovery","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"Ceph-reported run state (e.g. `up:active`, `up:standby`, `up:standby-replay`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Ceph metadata server daemon","desc":"Metadata server backing a CephFS file system, selected by `name`. Each file system needs an active MDS to serve its namespace, so `state` and `rank` show whether one is bound and standbys are available. The `fileSystem` field resolves the CephFS this daemon serves, and `standbyReplay` reports whether a standby is tracking the active daemon for faster failover.","min_provider_version":"0.3.6","defaults":"name host state fsName","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.ceph.monitor":{"id":"proxmox.ceph.monitor","name":"proxmox.ceph.monitor","fields":{"addr":{"name":"addr","type":"\u0007","is_mandatory":true,"title":"Address the monitor advertises, in Ceph format (usually `IP:PORT/NONCE`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"cephVersion":{"name":"cephVersion","type":"\u0007","is_mandatory":true,"title":"Full Ceph version string of the daemon","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"cephVersionShort":{"name":"cephVersionShort","type":"\u0007","is_mandatory":true,"title":"Short numeric Ceph version of the daemon (e.g. `19.2.0`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"directoryExists":{"name":"directoryExists","type":"\u0004","is_mandatory":true,"title":"Whether the monitor data directory exists on the hosting node","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"host":{"name":"host","type":"\u0007","is_mandatory":true,"title":"Node the monitor runs on","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Monitor id, typically the hostname","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"node":{"name":"node","type":"\u001bproxmox.node","title":"Host the monitor runs on","desc":"Resolves `host` against the cluster, so a monitor out of quorum can be checked against the state of the node running it. Null when the named host is no longer in the cluster.","min_provider_version":"0.4.2","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"quorum":{"name":"quorum","type":"\u0004","is_mandatory":true,"title":"Whether the monitor is part of the current quorum","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"rank":{"name":"rank","type":"\u0005","is_mandatory":true,"title":"Rank of the monitor within the mon map; null when not reported","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"service":{"name":"service","type":"\u0004","is_mandatory":true,"title":"Whether a ceph-mon systemd unit is enabled on the hosting node","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"Run state of the monitor","desc":"`running` when in quorum, `stopped` when the systemd unit is configured but inactive, or `unknown`.","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Ceph monitor daemon","desc":"Monitor daemon holding the authoritative copy of the cluster map, selected by `name`. Monitors must hold quorum for the cluster to accept I/O, so `quorum` and `state` are the fields that say whether the cluster is actually serving. The `host` field names the node the daemon runs on and `addr` its advertised bind address.","min_provider_version":"0.3.6","defaults":"name host quorum state","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.ceph.osd":{"id":"proxmox.ceph.osd","name":"proxmox.ceph.osd","fields":{"backAddress":{"name":"backAddress","type":"\u0007","is_mandatory":true,"title":"Bind addresses for inter-OSD replication traffic","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"bytesUsed":{"name":"bytesUsed","type":"\u0005","is_mandatory":true,"title":"Used capacity in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"cephRelease":{"name":"cephRelease","type":"\u0007","is_mandatory":true,"title":"Ceph release codename the daemon runs","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"cephVersion":{"name":"cephVersion","type":"\u0007","is_mandatory":true,"title":"Full Ceph version string of the daemon","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"cephVersionShort":{"name":"cephVersionShort","type":"\u0007","is_mandatory":true,"title":"Short numeric Ceph version of the daemon (e.g. `19.2.0`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"crushWeight":{"name":"crushWeight","type":"\u0006","is_mandatory":true,"title":"Share of data this OSD receives in the CRUSH map","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"dataPath":{"name":"dataPath","type":"\u0007","is_mandatory":true,"title":"Path to the OSD data directory","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"deviceClass":{"name":"deviceClass","type":"\u0007","is_mandatory":true,"title":"Storage class CRUSH rules select on (`hdd`, `ssd`, `nvme`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"deviceIds":{"name":"deviceIds","type":"\u0007","is_mandatory":true,"title":"Underlying device serial identifiers, comma-joined","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"devicePaths":{"name":"devicePaths","type":"\u0007","is_mandatory":true,"title":"Underlying /dev/disk/by-path entries, comma-joined","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"devices":{"name":"devices","type":"\u0007","is_mandatory":true,"title":"Underlying block device names, comma-joined (e.g. `sdb,sdc`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"frontAddress":{"name":"frontAddress","type":"\u0007","is_mandatory":true,"title":"Bind addresses for client-facing traffic","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"host":{"name":"host","type":"\u0007","is_mandatory":true,"title":"Node the daemon runs on","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"id":{"name":"id","type":"\u0005","is_mandatory":true,"title":"Numeric OSD id","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"inCluster":{"name":"inCluster","type":"\u0004","is_mandatory":true,"title":"Whether the OSD is accepting data placement","desc":"An OSD that is up but marked out holds no data. Null when the CRUSH tree reports no membership state.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"OSD name as it appears in the CRUSH map (e.g. `osd.3`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"node":{"name":"node","type":"\u001bproxmox.node","title":"Host the daemon runs on","desc":"Resolves `host` against the cluster, so a down or out OSD can be checked against the state of the node holding its backing device. Null when the named host is no longer in the cluster.","min_provider_version":"0.4.2","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"objectStore":{"name":"objectStore","type":"\u0007","is_mandatory":true,"title":"Backing object store (`bluestore` or the legacy `filestore`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"percentUsed":{"name":"percentUsed","type":"\u0006","is_mandatory":true,"title":"Percentage of capacity in use","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"reweight":{"name":"reweight","type":"\u0006","is_mandatory":true,"title":"Manual override applied on top of the CRUSH weight; 1 when untouched","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Ceph-reported status string (`up` or `down`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"totalSpace":{"name":"totalSpace","type":"\u0005","is_mandatory":true,"title":"Total capacity in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"up":{"name":"up","type":"\u0004","is_mandatory":true,"title":"Whether the daemon is running","desc":"Null when the CRUSH tree reports no status for this OSD.","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Ceph object storage daemon","desc":"Object storage daemon holding one backing device worth of cluster data, selected by its numeric `id`. An OSD contributes capacity only while it is both `up` (running) and `inCluster` (accepting data), so those two fields together say whether the cluster is degraded. The `deviceClass` field (`hdd`, `ssd`, `nvme`) is what CRUSH rules select on, `crushWeight` sets the share of data it receives, and `devices` names the underlying block devices.","min_provider_version":"0.3.6","defaults":"id host up inCluster deviceClass","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.ceph.pool":{"id":"proxmox.ceph.pool","name":"proxmox.ceph.pool","fields":{"applications":{"name":"applications","type":"\n","is_mandatory":true,"title":"Applications tagged on the pool, keyed by application name","desc":"Proxmox tags pools it creates with `rbd` for guest disks or `cephfs` for file-system pools.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"bytesUsed":{"name":"bytesUsed","type":"\u0005","is_mandatory":true,"title":"Bytes currently stored in the pool","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"crushRuleId":{"name":"crushRuleId","type":"\u0005","is_mandatory":true,"title":"Numeric id of the CRUSH rule governing placement","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"crushRuleName":{"name":"crushRuleName","type":"\u0007","is_mandatory":true,"title":"Name of the CRUSH rule governing placement","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"minSize":{"name":"minSize","type":"\u0005","is_mandatory":true,"title":"Replicas required before the pool accepts writes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Operator-visible pool name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"percentUsed":{"name":"percentUsed","type":"\u0006","is_mandatory":true,"title":"Percentage of pool capacity in use","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"pgAutoscaleMode":{"name":"pgAutoscaleMode","type":"\u0007","is_mandatory":true,"title":"Placement-group autoscaler mode (`on`, `warn`, or `off`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"pgNum":{"name":"pgNum","type":"\u0005","is_mandatory":true,"title":"Current placement-group count","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"pgNumFinal":{"name":"pgNumFinal","type":"\u0005","is_mandatory":true,"title":"Optimal placement-group count computed by the autoscaler","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"pgNumMin":{"name":"pgNumMin","type":"\u0005","is_mandatory":true,"title":"Lowest placement-group count the autoscaler may choose","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"poolId":{"name":"poolId","type":"\u0005","is_mandatory":true,"title":"Numeric pool id assigned by Ceph","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"size":{"name":"size","type":"\u0005","is_mandatory":true,"title":"Number of object replicas Ceph keeps","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Pool type","desc":"`replicated` for n-way replication or `erasure` for an erasure-coded pool.","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Ceph storage pool","desc":"Storage pool and the replication settings that decide how much hardware loss its data survives, selected by `name`. The `size` field is the number of replicas Ceph keeps and `minSize` the number it needs before it will still accept writes; a replicated pool at size 2 or minSize 1 can lose data to a single failure. The `crushRuleName` field names the placement rule and `pgAutoscaleMode` whether Ceph manages the placement-group count.","min_provider_version":"0.3.6","defaults":"name type size minSize percentUsed","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.certificate":{"id":"proxmox.certificate","name":"proxmox.certificate","fields":{"daysUntilExpiry":{"name":"daysUntilExpiry","type":"\u0005","title":"Days remaining until `notAfter`","desc":"Computed as `notAfter` minus the time the value is read. Negative when the certificate has already expired, which makes `daysUntilExpiry \u003c 30` / `\u003c 0` a natural way to write expiry policies.","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"filename":{"name":"filename","type":"\u0007","is_mandatory":true,"title":"Certificate filename","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"fingerprint":{"name":"fingerprint","type":"\u0007","is_mandatory":true,"title":"Certificate fingerprint","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"issuer":{"name":"issuer","type":"\u0007","is_mandatory":true,"title":"Certificate issuer","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"notAfter":{"name":"notAfter","type":"\t","is_mandatory":true,"title":"Expiration date","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"notBefore":{"name":"notBefore","type":"\t","is_mandatory":true,"title":"Valid from date","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"publicKeyBits":{"name":"publicKeyBits","type":"\u0005","is_mandatory":true,"title":"Public key size in bits","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"publicKeyType":{"name":"publicKeyType","type":"\u0007","is_mandatory":true,"title":"Public key type (rsa, ec)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"san":{"name":"san","type":"\u0019\u0007","is_mandatory":true,"title":"Subject Alternative Names","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"subject":{"name":"subject","type":"\u0007","is_mandatory":true,"title":"Certificate subject","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE node TLS certificate","desc":"TLS/SSL certificate installed on a Proxmox node, used to secure the web interface and API. Auditing these certificates surfaces weak keys, mismatched or missing Subject Alternative Names, untrusted issuers, and certificates that are expired or nearing expiry. The `filename` field identifies which certificate file on the node the entry represents.","min_provider_version":"0.1.1","defaults":"subject notAfter","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.cluster":{"id":"proxmox.cluster","name":"proxmox.cluster","fields":{"aliases":{"name":"aliases","type":"\u0019\u001bproxmox.firewall.alias","title":"Cluster-level firewall aliases","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"bandwidthLimits":{"name":"bandwidthLimits","type":"\n","title":"Default cluster-wide bandwidth limits","desc":"Limits cover restore, migration, clone, and move operations. Keys mirror /cluster/options (`default`, `restore`, `migration`, etc.). Empty when no limits are set.","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"consoleViewer":{"name":"consoleViewer","type":"\u0007","title":"Default VNC/SPICE console viewer","desc":"One of `html5`, `vv`, or empty for the PVE default.","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"firewallGroups":{"name":"firewallGroups","type":"\u0019\u001bproxmox.firewall.group","title":"Cluster-level firewall security groups","desc":"Each group is a named rule set that other rules reference with `type=group`. Auditing the group definitions lets policies verify that the referenced rules match their stated intent.","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"firewallOptions":{"name":"firewallOptions","type":"\u001bproxmox.firewall.options","title":"Cluster-level firewall options (enable, policy_in, policy_out, log_*)","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"firewallRules":{"name":"firewallRules","type":"\u0019\u001bproxmox.firewall.rule","title":"Cluster-level firewall rules","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"haGroup":{"name":"haGroup","type":"\u001bproxmox.cluster.haGroup","title":"Proxmox VE HA group","desc":"High-availability group defined on the cluster that constrains where HA-managed guests are allowed to run. Reports the group `id`, comma-separated `nodes` membership (entries may include priorities like `pve1:2`), whether the group is `restricted` (HA will refuse to fail over outside group members), and `noFailback` (HA will not automatically move guests back to higher-priority nodes once they recover).","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"haGroups":{"name":"haGroups","type":"\u0019\u001bproxmox.cluster.haGroup","title":"High-availability groups","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"haResource":{"name":"haResource","type":"\u001bproxmox.cluster.haResource","title":"Proxmox VE cluster HA resource","desc":"High-availability resource managed by the cluster, identified by `id` (e.g. `vm:100`) and `type` (vm or ct). Reports its current `status`, assigned `node`, desired `state` (started, stopped, disabled), HA `group`, and the maximum number of restart and relocate attempts via `maxRestart` and `maxRelocate`.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"haResources":{"name":"haResources","type":"\u0019\u001bproxmox.cluster.haResource","title":"High-availability resources","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"ipsets":{"name":"ipsets","type":"\u0019\u001bproxmox.firewall.ipset","title":"Cluster-level IPsets","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"migrationNetwork":{"name":"migrationNetwork","type":"\u0007","title":"CIDR of the dedicated migration network","desc":"Empty when migrations use the management network.","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"migrationPolicy":{"name":"migrationPolicy","type":"\u0007","title":"Migration network policy","desc":"`secure` tunnels through SSH; `insecure` exposes the storage stream on the chosen migration network. Empty when not configured; Proxmox defaults to `secure`.","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Cluster name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"nodeCount":{"name":"nodeCount","type":"\u0005","is_mandatory":true,"title":"Number of nodes in the cluster","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"options":{"name":"options","type":"\n","title":"Cluster-wide options from /cluster/options","desc":"Raw key/value settings that apply across the whole cluster, mirroring the Proxmox /cluster/options API. Common keys include `keyboard`, `language`, `console`, `migration`, `bwlimit`, `mac_prefix`, `max_workers`, `email_from`, and `crs`. The most commonly audited values are also surfaced as dedicated fields: `migrationPolicy`, `migrationNetwork`, `consoleViewer`, and `bandwidthLimits`.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"quorate":{"name":"quorate","type":"\u0004","is_mandatory":true,"title":"Whether the cluster has quorum","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"version":{"name":"version","type":"\u0005","is_mandatory":true,"title":"Cluster config version","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE cluster","desc":"Cluster-level configuration and health for a Proxmox VE deployment. Reports the cluster `name`, config `version`, quorum status via `quorate`, and `nodeCount`. High-availability resources are listed through `haResources`, cluster-wide firewall rules through `firewallRules`, and global cluster options through `options`.","min_provider_version":"0.1.1","defaults":"name quorate","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.cluster.haGroup":{"id":"proxmox.cluster.haGroup","name":"proxmox.cluster.haGroup","fields":{"comment":{"name":"comment","type":"\u0007","is_mandatory":true,"title":"Group comment","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Group ID","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"noFailback":{"name":"noFailback","type":"\u0004","is_mandatory":true,"title":"Whether HA suppresses automatic failback to higher-priority members","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"nodes":{"name":"nodes","type":"\u0007","is_mandatory":true,"title":"Member nodes (comma-separated; entries may carry `node:priority`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"restricted":{"name":"restricted","type":"\u0004","is_mandatory":true,"title":"Whether HA refuses to fail over outside group members","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE HA group","desc":"High-availability group defined on the cluster that constrains where HA-managed guests are allowed to run. Reports the group `id`, comma-separated `nodes` membership (entries may include priorities like `pve1:2`), whether the group is `restricted` (HA will refuse to fail over outside group members), and `noFailback` (HA will not automatically move guests back to higher-priority nodes once they recover).","min_provider_version":"0.1.9","defaults":"id restricted noFailback","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.cluster.haResource":{"id":"proxmox.cluster.haResource","name":"proxmox.cluster.haResource","fields":{"container":{"name":"container","type":"\u001bproxmox.container","title":"Container this resource refers to when `type` is `ct`; null otherwise","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"group":{"name":"group","type":"\u0007","is_mandatory":true,"title":"HA group","desc":"Deprecated in favor of `groupRef`, which resolves the same group as an HA group resource.","provider":"go.mondoo.com/mql/v13/providers/proxmox","maturity":"deprecated"},"groupRef":{"name":"groupRef","type":"\u001bproxmox.cluster.haGroup","title":"Resolved HA group","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Resource ID (e.g. vm:100)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"maxRelocate":{"name":"maxRelocate","type":"\u0005","is_mandatory":true,"title":"Maximum relocate attempts","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"maxRestart":{"name":"maxRestart","type":"\u0005","is_mandatory":true,"title":"Maximum restart attempts","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"node":{"name":"node","type":"\u0007","is_mandatory":true,"title":"Node the resource is assigned to","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"Desired state (started, stopped, disabled)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Current HA status","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Resource type (vm, ct)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"vm":{"name":"vm","type":"\u001bproxmox.vm","title":"VM this resource refers to when `type` is `vm`; null otherwise","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE cluster HA resource","desc":"High-availability resource managed by the cluster, identified by `id` (e.g. `vm:100`) and `type` (vm or ct). Reports its current `status`, assigned `node`, desired `state` (started, stopped, disabled), HA `group`, and the maximum number of restart and relocate attempts via `maxRestart` and `maxRelocate`.","min_provider_version":"0.1.1","defaults":"id type status","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.container":{"id":"proxmox.container","name":"proxmox.container","fields":{"aliases":{"name":"aliases","type":"\u0019\u001bproxmox.firewall.alias","title":"Container-level firewall aliases","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"backups":{"name":"backups","type":"\u0019\u001bproxmox.storage.volume","title":"Backup archives held for this container","desc":"Every backup volume across all storages that owns this VMID, newest first. Reports what was actually captured, which scheduled backup jobs alone cannot confirm. Empty when the container has never been backed up to a storage this token can read.","min_provider_version":"0.3.6","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"cmode":{"name":"cmode","type":"\u0007","title":"Console mode","desc":"One of `tty` (per-tty consoles, default), `console` (single console on /dev/console), or `shell` (drop into a shell). `shell` disables the login prompt and is unusual in production.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"config":{"name":"config","type":"\n","title":"Full container configuration as dictionary","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"cpu":{"name":"cpu","type":"\u0006","is_mandatory":true,"title":"Current CPU usage (fraction)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"cpuLimit":{"name":"cpuLimit","type":"\u0006","title":"CPU limit in cores; 0 means no per-container limit (CFS bandwidth throttling disabled)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"cpuUnits":{"name":"cpuUnits","type":"\u0005","title":"CPU weight relative to other containers; PVE default is 1024","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"description":{"name":"description","type":"\u0007","title":"Container description/notes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"disk":{"name":"disk","type":"\u0005","is_mandatory":true,"title":"Current disk usage in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"diskread":{"name":"diskread","type":"\u0005","is_mandatory":true,"title":"Total bytes read from disk","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"diskwrite":{"name":"diskwrite","type":"\u0005","is_mandatory":true,"title":"Total bytes written to disk","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"features":{"name":"features","type":"\u0019\u0007","title":"Enabled features parsed from the `features` config line","desc":"Each entry is the name of an enabled extra capability, one of `nesting`, `fuse`, `mount=\u003ctypes\u003e`, or `keyctl`. An empty list means the container runs with the default capability set.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"firewallOptions":{"name":"firewallOptions","type":"\u001bproxmox.firewall.options","title":"Container-level firewall options","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"firewallRules":{"name":"firewallRules","type":"\u0019\u001bproxmox.firewall.rule","title":"Container-level firewall rules","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"hostname":{"name":"hostname","type":"\u0007","title":"Container hostname","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"id":{"name":"id","type":"\u0005","is_mandatory":true,"title":"VMID","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"ipsets":{"name":"ipsets","type":"\u0019\u001bproxmox.firewall.ipset","title":"Container-level IPsets","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"lastBackupAt":{"name":"lastBackupAt","type":"\t","title":"When this container was last backed up","desc":"Creation time of the newest backup archive owned by this container. Null when no backup exists.","min_provider_version":"0.3.6","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"maxcpu":{"name":"maxcpu","type":"\u0005","is_mandatory":true,"title":"Number of configured vCPUs","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"maxdisk":{"name":"maxdisk","type":"\u0005","is_mandatory":true,"title":"Configured maximum disk size in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"maxmem":{"name":"maxmem","type":"\u0005","is_mandatory":true,"title":"Configured maximum memory in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"mem":{"name":"mem","type":"\u0005","is_mandatory":true,"title":"Current memory usage in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"mountPoint":{"name":"mountPoint","type":"\u001bproxmox.container.mountPoint","title":"Proxmox VE container mount point","desc":"Mount point attached to an LXC container. The `id` field selects the slot (`rootfs`, `mp0`–`mp254`). Reports the backing `storage`, `size` in bytes, in-container `mountPath`, whether the mount is `backup`-included, `replicate`-included, and `readonly`, and whether POSIX ACLs are enabled via `aclEnabled`.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"mountPoints":{"name":"mountPoints","type":"\u0019\u001bproxmox.container.mountPoint","title":"Mount points (rootfs + mp0..mp254) attached to the container","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Container display name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"nameserver":{"name":"nameserver","type":"\u0007","title":"DNS nameservers configured for the container; empty inherits the host's resolver","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"netin":{"name":"netin","type":"\u0005","is_mandatory":true,"title":"Total incoming network bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"netout":{"name":"netout","type":"\u0005","is_mandatory":true,"title":"Total outgoing network bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"network":{"name":"network","type":"\u001bproxmox.container.network","title":"Proxmox VE container network interface","desc":"Network interface attached to an LXC container. The `id` field selects the slot (e.g. `net0`, `net1`). Reports the guest-visible interface `name`, `macAddress`, connected `bridge`, VLAN `tag`, whether the per-NIC `firewall` is enabled, and IPv4/IPv6 addressing (`ip`, `gw`, `ip6`, `gw6`).","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"networks":{"name":"networks","type":"\u0019\u001bproxmox.container.network","title":"Network interfaces attached to the container","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"node":{"name":"node","type":"\u0007","is_mandatory":true,"title":"Node this container is running on","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"nodeRef":{"name":"nodeRef","type":"\u001bproxmox.node","title":"Host the container runs on","desc":"Resolves `node` against the cluster, giving access to the host's status, address, kernel, subscription level, and firewall from the container itself. Null when the named node is no longer in the cluster.","min_provider_version":"0.4.2","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"onboot":{"name":"onboot","type":"\u0004","title":"Whether the container starts on boot","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"osType":{"name":"osType","type":"\u0007","title":"OS type (debian, ubuntu, centos, alpine, ...)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"passthroughDevice":{"name":"passthroughDevice","type":"\u001bproxmox.container.passthroughDevice","title":"Proxmox VE container host-device passthrough entry","desc":"Host-device passthrough entry from a `dev\u003cn\u003e` configuration line on an LXC container. PVE 7+ uses this format to expose a host `/dev` node into the guest; the optional `uid=`, `gid=`, and `mode=` overrides control the in-container permissions. A `mode=` of 0666 effectively grants the device to every UID in the container.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"passthroughDevices":{"name":"passthroughDevices","type":"\u0019\u001bproxmox.container.passthroughDevice","title":"Host devices passed through to the container","desc":"Parsed from `dev0`..`dev255`. Each entry grants the container direct access to a host `/dev` node and is a host-pivot surface. A permissive `mode=` (e.g. `0666`) effectively shares the device with everyone inside the guest.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"pool":{"name":"pool","type":"\u001bproxmox.pool","title":"Resource pool this container belongs to; null when unassigned","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"protection":{"name":"protection","type":"\u0004","title":"Whether the container is protected from removal","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"rawLxc":{"name":"rawLxc","type":"\u0019\u0007","title":"Raw `lxc.*` config lines applied verbatim to the container","desc":"Each entry is one `lxc.\u003ckey\u003e: \u003cvalue\u003e` line, typically used for AppArmor profiles (`lxc.apparmor.profile`), capability adjustments (`lxc.cap.drop` / `lxc.cap.keep`), or mount tweaks. Anything in here is an explicit override of the PVE defaults and warrants an audit review.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"searchDomain":{"name":"searchDomain","type":"\u0007","title":"DNS search domain configured for the container; empty inherits the host's resolver","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"snapshots":{"name":"snapshots","type":"\u0019\u001bproxmox.vm.snapshot","title":"Container snapshots","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Current status (running, stopped)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"swap":{"name":"swap","type":"\u0005","title":"Swap size in bytes; 0 means swap is disabled","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"tags":{"name":"tags","type":"\u0019\u0007","title":"Tags assigned to the container","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"template":{"name":"template","type":"\u0004","is_mandatory":true,"title":"Whether this container is a template","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"unprivileged":{"name":"unprivileged","type":"\u0004","title":"Whether the container runs unprivileged","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"uptime":{"name":"uptime","type":"\u0005","is_mandatory":true,"title":"Uptime in seconds","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE LXC container","desc":"LXC container in the cluster, identified by numeric `id` and display `name`. Live `status` (running, stopped), the `node` it runs on, and resource usage (`cpu`, `mem`, `disk`, `netin`, `netout`) come from the cluster status API, while the per-container configuration exposes whether the container runs `unprivileged`, its `ostype`, `hostname`, enabled `features`, and boot options. Network interfaces, mount points, snapshots, and the container-level firewall (rules, options, ipsets, aliases) are reachable through their own fields, letting audits check isolation, host-device exposure, and firewall posture in a single query.","min_provider_version":"0.1.9","defaults":"id name status unprivileged","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.container.mountPoint":{"id":"proxmox.container.mountPoint","name":"proxmox.container.mountPoint","fields":{"aclEnabled":{"name":"aclEnabled","type":"\u0004","is_mandatory":true,"title":"Whether POSIX ACLs are enabled on the mount","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"backup":{"name":"backup","type":"\u0004","is_mandatory":true,"title":"Whether this mount point is included in backups","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Mount point ID (rootfs, mp0, mp1, ...)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"mountPath":{"name":"mountPath","type":"\u0007","is_mandatory":true,"title":"Path inside the container","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"readonly":{"name":"readonly","type":"\u0004","is_mandatory":true,"title":"Whether the mount point is read-only","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"replicate":{"name":"replicate","type":"\u0004","is_mandatory":true,"title":"Whether this mount point is included in replication","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"size":{"name":"size","type":"\u0005","is_mandatory":true,"title":"Size in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"storage":{"name":"storage","type":"\u0007","is_mandatory":true,"title":"Backing storage name","desc":"Deprecated in favor of `storageRef`, which resolves the same pool as a storage resource.","provider":"go.mondoo.com/mql/v13/providers/proxmox","maturity":"deprecated"},"storageRef":{"name":"storageRef","type":"\u001bproxmox.storage","title":"Resolved backing storage pool","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE container mount point","desc":"Mount point attached to an LXC container. The `id` field selects the slot (`rootfs`, `mp0`–`mp254`). Reports the backing `storage`, `size` in bytes, in-container `mountPath`, whether the mount is `backup`-included, `replicate`-included, and `readonly`, and whether POSIX ACLs are enabled via `aclEnabled`.","min_provider_version":"0.1.9","defaults":"id storage mountPath size","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.container.network":{"id":"proxmox.container.network","name":"proxmox.container.network","fields":{"bridge":{"name":"bridge","type":"\u0007","is_mandatory":true,"title":"Bridge this NIC is connected to","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"firewall":{"name":"firewall","type":"\u0004","is_mandatory":true,"title":"Whether the firewall is enabled for this NIC","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"gw":{"name":"gw","type":"\u0007","is_mandatory":true,"title":"IPv4 gateway","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"gw6":{"name":"gw6","type":"\u0007","is_mandatory":true,"title":"IPv6 gateway","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Interface ID (net0, net1, ...)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"ip":{"name":"ip","type":"\u0007","is_mandatory":true,"title":"IPv4 address (CIDR notation, dhcp, or empty)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"ip6":{"name":"ip6","type":"\u0007","is_mandatory":true,"title":"IPv6 address (CIDR notation, auto, dhcp, or empty)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"macAddress":{"name":"macAddress","type":"\u0007","is_mandatory":true,"title":"MAC address","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Interface name inside the container (e.g. eth0)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"tag":{"name":"tag","type":"\u0005","is_mandatory":true,"title":"VLAN tag (0 = none)","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE container network interface","desc":"Network interface attached to an LXC container. The `id` field selects the slot (e.g. `net0`, `net1`). Reports the guest-visible interface `name`, `macAddress`, connected `bridge`, VLAN `tag`, whether the per-NIC `firewall` is enabled, and IPv4/IPv6 addressing (`ip`, `gw`, `ip6`, `gw6`).","min_provider_version":"0.1.9","defaults":"id name bridge","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.container.passthroughDevice":{"id":"proxmox.container.passthroughDevice","name":"proxmox.container.passthroughDevice","fields":{"gid":{"name":"gid","type":"\u0005","is_mandatory":true,"title":"GID owner inside the container; 0 when not overridden","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"mode":{"name":"mode","type":"\u0007","is_mandatory":true,"title":"Mode (octal) applied to the in-container device node; empty when not set","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"path":{"name":"path","type":"\u0007","is_mandatory":true,"title":"Host path being exposed (e.g. `/dev/kvm`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"slot":{"name":"slot","type":"\u0007","is_mandatory":true,"title":"Config slot (`dev0` through `dev255`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"uid":{"name":"uid","type":"\u0005","is_mandatory":true,"title":"UID owner inside the container; 0 when not overridden","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE container host-device passthrough entry","desc":"Host-device passthrough entry from a `dev\u003cn\u003e` configuration line on an LXC container. PVE 7+ uses this format to expose a host `/dev` node into the guest; the optional `uid=`, `gid=`, and `mode=` overrides control the in-container permissions. A `mode=` of 0666 effectively grants the device to every UID in the container.","min_provider_version":"0.1.9","defaults":"slot path mode","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.corosync":{"id":"proxmox.corosync","name":"proxmox.corosync","fields":{"configDigest":{"name":"configDigest","type":"\u0007","title":"Digest of the corosync configuration","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"node":{"name":"node","type":"\u001bproxmox.corosync.node","title":"Corosync cluster member","desc":"Single member of the corosync cluster, selected by `name`. The `quorumVotes` field is what the member contributes toward quorum, and `ring0Address` and `ring1Address` are the links it communicates over. A member with only ring 0 configured loses cluster membership if that network fails.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"nodes":{"name":"nodes","type":"\u0019\u001bproxmox.corosync.node","title":"Cluster members and their corosync links","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"preferredNode":{"name":"preferredNode","type":"\u0007","title":"Node the API suggests joining through","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"qdevice":{"name":"qdevice","type":"\n","title":"External quorum device configuration","desc":"A QDevice provides a tie-breaking vote so a two-node cluster can keep quorum when one node fails. Empty when none is configured.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"totem":{"name":"totem","type":"\n","title":"Raw corosync totem transport settings","desc":"Keys mirror the corosync totem section, including `cluster_name`, `config_version`, `transport`, `secauth`, `crypto_cipher`, and `crypto_hash`.","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Corosync cluster configuration","desc":"Corosync membership and transport configuration underpinning the cluster. Quorum is decided here: `nodes` lists every member with its vote count and ring addresses, so a cluster whose members all reach each other over a single link has no redundancy against that link failing. The `qdevice` field reports an external tie-breaker when one is configured, and `totem` holds the raw transport settings.  A standalone node has no corosync configuration; `nodes` is empty there.","min_provider_version":"0.3.6","defaults":"preferredNode","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.corosync.node":{"id":"proxmox.corosync.node","name":"proxmox.corosync.node","fields":{"apiAddress":{"name":"apiAddress","type":"\u0007","is_mandatory":true,"title":"Address the Proxmox API is reached on","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"certificateFingerprint":{"name":"certificateFingerprint","type":"\u0007","is_mandatory":true,"title":"SHA-256 fingerprint of the node's API certificate","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Cluster node name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"nodeId":{"name":"nodeId","type":"\u0005","is_mandatory":true,"title":"Corosync node id","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"quorumVotes":{"name":"quorumVotes","type":"\u0005","is_mandatory":true,"title":"Votes this member contributes toward quorum","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"ring0Address":{"name":"ring0Address","type":"\u0007","is_mandatory":true,"title":"Address of the primary corosync link","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"ring1Address":{"name":"ring1Address","type":"\u0007","is_mandatory":true,"title":"Address of the redundant corosync link; empty when only one link is configured","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Corosync cluster member","desc":"Single member of the corosync cluster, selected by `name`. The `quorumVotes` field is what the member contributes toward quorum, and `ring0Address` and `ring1Address` are the links it communicates over. A member with only ring 0 configured loses cluster membership if that network fails.","min_provider_version":"0.3.6","defaults":"name nodeId ring0Address quorumVotes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.dns":{"id":"proxmox.dns","name":"proxmox.dns","fields":{"dns1":{"name":"dns1","type":"\u0007","is_mandatory":true,"title":"Primary DNS server","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"dns2":{"name":"dns2","type":"\u0007","is_mandatory":true,"title":"Secondary DNS server","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"dns3":{"name":"dns3","type":"\u0007","is_mandatory":true,"title":"Tertiary DNS server","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"search":{"name":"search","type":"\u0007","is_mandatory":true,"title":"DNS search domain","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE node DNS configuration","desc":"DNS resolver configuration on a Proxmox node: the `search` domain and up to three nameservers (`dns1`, `dns2`, `dns3`). Useful for confirming a node resolves names through the expected servers and domain.","min_provider_version":"0.1.1","defaults":"search dns1","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.firewall":{"id":"proxmox.firewall","fields":{"alias":{"name":"alias","type":"\u001bproxmox.firewall.alias","title":"Proxmox VE firewall alias","desc":"Named alias for a CIDR at the cluster or guest level, identified by `name`. Aliases let firewall rules reference networks by symbolic name. The `scope` field identifies the owner (cluster, vm/\u003cid\u003e, ct/\u003cid\u003e) and `ipVersion` is 4 or 6.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"group":{"name":"group","type":"\u001bproxmox.firewall.group","title":"Proxmox VE firewall security group","desc":"Named rule set defined under `/cluster/firewall/groups`. Other firewall rules reference the group through `type=group, action=\u003cgroupName\u003e`; the rules inside the group then apply in place. Auditing both the references and the group's own `rules` is how policies confirm a `type=group` rule is actually doing what it claims to.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"ipset":{"name":"ipset","type":"\u001bproxmox.firewall.ipset","title":"Proxmox VE firewall IPset","desc":"IP set defined at the cluster or guest level, identified by `name`. IPsets group CIDR ranges that firewall rules can reference by name through the `+\u003cname\u003e` syntax. The `scope` field identifies the owner (cluster, vm/\u003cid\u003e, ct/\u003cid\u003e) and `entries` lists the contained CIDRs.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"options":{"name":"options","type":"\u001bproxmox.firewall.options","title":"Proxmox VE firewall options","desc":"Firewall options configured at the cluster, node, VM, or container level. The available keys differ by scope: cluster-level options include `policy_in`, `policy_out`, and `log_ratelimit`; node options include `nf_conntrack_*` tuning; guest-level options include `dhcp`, `ndp`, `macfilter`, `ipfilter`, and `radv`. The `config` dict holds the raw response so audits can target keys that vary by Proxmox version.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"rule":{"name":"rule","type":"\u001bproxmox.firewall.rule","title":"Proxmox VE firewall rule","desc":"Firewall rule applied at the cluster, node, or VM level. Rules are ordered by `pos` and specify a `type` (in, out, group), `action` (ACCEPT, DROP, REJECT), `proto`, source (`source`, `sport`), and destination (`dest`, `dport`). The `group` reference resolves the named rule set that applies when `type` is group, and `allowsPublicIngress` flags an enabled inbound ACCEPT rule whose source is unrestricted.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true}},"is_extension":true},"proxmox.firewall.alias":{"id":"proxmox.firewall.alias","name":"proxmox.firewall.alias","fields":{"cidr":{"name":"cidr","type":"\u0007","is_mandatory":true,"title":"CIDR the alias resolves to","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"comment":{"name":"comment","type":"\u0007","is_mandatory":true,"title":"Alias comment","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"ipVersion":{"name":"ipVersion","type":"\u0005","is_mandatory":true,"title":"IP version (4 or 6)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Alias name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"scope":{"name":"scope","type":"\u0007","is_mandatory":true,"title":"Scope of this alias (cluster, vm/\u003cid\u003e, ct/\u003cid\u003e)","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE firewall alias","desc":"Named alias for a CIDR at the cluster or guest level, identified by `name`. Aliases let firewall rules reference networks by symbolic name. The `scope` field identifies the owner (cluster, vm/\u003cid\u003e, ct/\u003cid\u003e) and `ipVersion` is 4 or 6.","min_provider_version":"0.1.9","defaults":"scope name cidr","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.firewall.group":{"id":"proxmox.firewall.group","name":"proxmox.firewall.group","fields":{"comment":{"name":"comment","type":"\u0007","is_mandatory":true,"title":"Group comment","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Group name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"rules":{"name":"rules","type":"\u0019\u001bproxmox.firewall.rule","title":"Rules contained in this group","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE firewall security group","desc":"Named rule set defined under `/cluster/firewall/groups`. Other firewall rules reference the group through `type=group, action=\u003cgroupName\u003e`; the rules inside the group then apply in place. Auditing both the references and the group's own `rules` is how policies confirm a `type=group` rule is actually doing what it claims to.","min_provider_version":"0.1.9","defaults":"name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.firewall.ipset":{"id":"proxmox.firewall.ipset","name":"proxmox.firewall.ipset","fields":{"comment":{"name":"comment","type":"\u0007","is_mandatory":true,"title":"IPset comment","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"entries":{"name":"entries","type":"\u0019\u001bproxmox.firewall.ipset.entry","title":"CIDR entries that belong to this set","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"entry":{"name":"entry","type":"\u001bproxmox.firewall.ipset.entry","title":"Proxmox VE firewall IPset entry","desc":"Single CIDR entry inside a Proxmox firewall IPset. The `cidr` is the network or host (e.g. `10.0.0.0/24`), `comment` holds any descriptive text, and `nomatch` inverts the membership semantics so the entry excludes rather than includes its CIDR.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"IPset name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"scope":{"name":"scope","type":"\u0007","is_mandatory":true,"title":"Scope of this ipset (cluster, vm/\u003cid\u003e, ct/\u003cid\u003e)","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE firewall IPset","desc":"IP set defined at the cluster or guest level, identified by `name`. IPsets group CIDR ranges that firewall rules can reference by name through the `+\u003cname\u003e` syntax. The `scope` field identifies the owner (cluster, vm/\u003cid\u003e, ct/\u003cid\u003e) and `entries` lists the contained CIDRs.","min_provider_version":"0.1.9","defaults":"scope name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.firewall.ipset.entry":{"id":"proxmox.firewall.ipset.entry","name":"proxmox.firewall.ipset.entry","fields":{"cidr":{"name":"cidr","type":"\u0007","is_mandatory":true,"title":"CIDR entry (e.g. 10.0.0.0/24)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"comment":{"name":"comment","type":"\u0007","is_mandatory":true,"title":"Entry comment","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"nomatch":{"name":"nomatch","type":"\u0004","is_mandatory":true,"title":"Whether the entry is a negative match (excludes the CIDR)","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE firewall IPset entry","desc":"Single CIDR entry inside a Proxmox firewall IPset. The `cidr` is the network or host (e.g. `10.0.0.0/24`), `comment` holds any descriptive text, and `nomatch` inverts the membership semantics so the entry excludes rather than includes its CIDR.","min_provider_version":"0.1.9","defaults":"cidr nomatch","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.firewall.options":{"id":"proxmox.firewall.options","name":"proxmox.firewall.options","fields":{"config":{"name":"config","type":"\n","is_mandatory":true,"title":"Raw firewall options keyed as the API returns them","desc":"Every option for this scope under its native API key. `enable`, `policy_in`, `policy_out`, `log_level_in`, `log_level_out`, `dhcp`, `ndp`, `macfilter`, `ipfilter`, and `radv` are also surfaced as typed fields on this resource; scope-specific keys such as `log_ratelimit` (cluster) and `nf_conntrack_*` tuning (node) are available only here.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"dhcp":{"name":"dhcp","type":"\u0004","is_mandatory":true,"title":"Whether DHCP is permitted (guest scope)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"enable":{"name":"enable","type":"\u0004","is_mandatory":true,"title":"Whether the firewall is enabled at this scope","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"ipfilter":{"name":"ipfilter","type":"\u0004","is_mandatory":true,"title":"Whether IP-address spoofing is filtered (guest scope)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"logLevelIn":{"name":"logLevelIn","type":"\u0007","is_mandatory":true,"title":"Log level for inbound traffic (nolog, emerg, alert, crit, err, warning, notice, info, debug)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"logLevelOut":{"name":"logLevelOut","type":"\u0007","is_mandatory":true,"title":"Log level for outbound traffic","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"macfilter":{"name":"macfilter","type":"\u0004","is_mandatory":true,"title":"Whether the firewall enforces matching MAC addresses (guest scope)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"ndp":{"name":"ndp","type":"\u0004","is_mandatory":true,"title":"Whether NDP is permitted (guest scope)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"policyIn":{"name":"policyIn","type":"\u0007","is_mandatory":true,"title":"Default inbound policy (ACCEPT, DROP, REJECT)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"policyOut":{"name":"policyOut","type":"\u0007","is_mandatory":true,"title":"Default outbound policy (ACCEPT, DROP, REJECT)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"radv":{"name":"radv","type":"\u0004","is_mandatory":true,"title":"Whether router advertisements are permitted (guest scope)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"scope":{"name":"scope","type":"\u0007","is_mandatory":true,"title":"Scope of these options (cluster, node/\u003cname\u003e, vm/\u003cid\u003e, ct/\u003cid\u003e)","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE firewall options","desc":"Firewall options configured at the cluster, node, VM, or container level. The available keys differ by scope: cluster-level options include `policy_in`, `policy_out`, and `log_ratelimit`; node options include `nf_conntrack_*` tuning; guest-level options include `dhcp`, `ndp`, `macfilter`, `ipfilter`, and `radv`. The `config` dict holds the raw response so audits can target keys that vary by Proxmox version.","min_provider_version":"0.1.9","defaults":"scope enable","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.firewall.rule":{"id":"proxmox.firewall.rule","name":"proxmox.firewall.rule","fields":{"action":{"name":"action","type":"\u0007","is_mandatory":true,"title":"Rule action (ACCEPT, DROP, REJECT)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"allowsPublicIngress":{"name":"allowsPublicIngress","type":"\u0004","title":"Whether this rule permits inbound traffic from any source","desc":"True when the rule is enabled, an inbound (`type == \"in\"`) ACCEPT rule, and its `source` is unrestricted: empty (Proxmox treats an empty source as \"any\"), `0.0.0.0/0`, `::/0`, or an equivalent all-addresses match. Such a rule opens the guarded VM, container, node, or cluster to every network the host can reach, including the internet when the bridge is routed publicly. False for outbound rules, DROP/REJECT rules, disabled rules, and rules restricted to a specific CIDR, IP, alias, or IPset reference.","min_provider_version":"0.1.13","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"comment":{"name":"comment","type":"\u0007","is_mandatory":true,"title":"Rule comment","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"dest":{"name":"dest","type":"\u0007","is_mandatory":true,"title":"Destination address","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"dport":{"name":"dport","type":"\u0007","is_mandatory":true,"title":"Destination port","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"enable":{"name":"enable","type":"\u0004","is_mandatory":true,"title":"Whether the rule is enabled","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"group":{"name":"group","type":"\u001bproxmox.firewall.group","title":"Security group referenced by this rule when `type == \"group\"`","desc":"PVE rules of type `group` carry the group name in `action` rather than a verb like ACCEPT/DROP, and apply that named rule set in place. This resolves the reference; null for non-group rules.","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"iface":{"name":"iface","type":"\u0007","is_mandatory":true,"title":"Network interface","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"log":{"name":"log","type":"\u0007","is_mandatory":true,"title":"Log level","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"macro":{"name":"macro","type":"\u0007","is_mandatory":true,"title":"Security macro name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"pos":{"name":"pos","type":"\u0005","is_mandatory":true,"title":"Rule position","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proto":{"name":"proto","type":"\u0007","is_mandatory":true,"title":"Protocol (tcp, udp, icmp, etc.)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"source":{"name":"source","type":"\u0007","is_mandatory":true,"title":"Source address","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"sport":{"name":"sport","type":"\u0007","is_mandatory":true,"title":"Source port","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Rule type (in, out, group)","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE firewall rule","desc":"Firewall rule applied at the cluster, node, or VM level. Rules are ordered by `pos` and specify a `type` (in, out, group), `action` (ACCEPT, DROP, REJECT), `proto`, source (`source`, `sport`), and destination (`dest`, `dport`). The `group` reference resolves the named rule set that applies when `type` is group, and `allowsPublicIngress` flags an enabled inbound ACCEPT rule whose source is unrestricted.","min_provider_version":"0.1.1","defaults":"pos action","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.group":{"id":"proxmox.group","name":"proxmox.group","fields":{"comment":{"name":"comment","type":"\u0007","is_mandatory":true,"title":"Group comment/description","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Group ID","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"memberIds":{"name":"memberIds","type":"\u0019\u0007","is_mandatory":true,"title":"User IDs that belong to this group","desc":"Deprecated in favor of `members`, which resolves the same accounts as user resources.","provider":"go.mondoo.com/mql/v13/providers/proxmox","maturity":"deprecated"},"members":{"name":"members","type":"\u0019\u001bproxmox.user","title":"Members of this group resolved as user resources","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE access control group","desc":"Group defined in the Proxmox cluster, identified by `id`, for example `proxmox.group(id: \"admins\")`. Groups bundle users so a single access-control entry can grant a role to many accounts at once, which makes them the natural unit for auditing who holds privileges at a given path. The `memberIds` field lists the user IDs in the group; `members` resolves those IDs to `proxmox.user` records for traversal into each account.","min_provider_version":"0.1.9","defaults":"id comment","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.lvm":{"id":"proxmox.lvm","fields":{"thinPool":{"name":"thinPool","type":"\u001bproxmox.lvm.thinPool","title":"Proxmox VE LVM-thin pool","desc":"LVM-thin pool on a Proxmox node, a thinly provisioned pool that overcommits storage across many logical volumes. The pool logical volume `name` selects it, for example `proxmox.lvm.thinPool(name: \"data\")`, within its parent `volumeGroup`. The data `size` and `used` bytes track allocation against the pool, while `metadataSize` and `metadataUsed` track the separate metadata pool: metadata exhaustion renders the entire thin pool read-only, so it is the failure mode that matters most.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"volumeGroup":{"name":"volumeGroup","type":"\u001bproxmox.lvm.volumeGroup","title":"Proxmox VE LVM volume group","desc":"LVM volume group on a Proxmox node, the pool of physical storage from which logical volumes are carved. The `name` selects the group, for example `proxmox.lvm.volumeGroup(name: \"pve\")`. The `size` and `free` bytes together reveal how much headroom remains before the group can no longer allocate new volumes, and `lvCount` reports how many logical volumes it currently backs.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true}},"is_extension":true},"proxmox.lvm.thinPool":{"id":"proxmox.lvm.thinPool","name":"proxmox.lvm.thinPool","fields":{"metadataSize":{"name":"metadataSize","type":"\u0005","is_mandatory":true,"title":"Metadata pool size in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"metadataUsed":{"name":"metadataUsed","type":"\u0005","is_mandatory":true,"title":"Metadata pool usage in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Thin-pool LV name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"size":{"name":"size","type":"\u0005","is_mandatory":true,"title":"Total data size in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"used":{"name":"used","type":"\u0005","is_mandatory":true,"title":"Allocated data bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"volumeGroup":{"name":"volumeGroup","type":"\u0007","is_mandatory":true,"title":"Parent volume group","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE LVM-thin pool","desc":"LVM-thin pool on a Proxmox node, a thinly provisioned pool that overcommits storage across many logical volumes. The pool logical volume `name` selects it, for example `proxmox.lvm.thinPool(name: \"data\")`, within its parent `volumeGroup`. The data `size` and `used` bytes track allocation against the pool, while `metadataSize` and `metadataUsed` track the separate metadata pool: metadata exhaustion renders the entire thin pool read-only, so it is the failure mode that matters most.","min_provider_version":"0.1.9","defaults":"name volumeGroup size used","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.lvm.volumeGroup":{"id":"proxmox.lvm.volumeGroup","name":"proxmox.lvm.volumeGroup","fields":{"free":{"name":"free","type":"\u0005","is_mandatory":true,"title":"Free space in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"lvCount":{"name":"lvCount","type":"\u0005","is_mandatory":true,"title":"Number of logical volumes in the VG","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Volume group name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"size":{"name":"size","type":"\u0005","is_mandatory":true,"title":"VG size in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE LVM volume group","desc":"LVM volume group on a Proxmox node, the pool of physical storage from which logical volumes are carved. The `name` selects the group, for example `proxmox.lvm.volumeGroup(name: \"pve\")`. The `size` and `free` bytes together reveal how much headroom remains before the group can no longer allocate new volumes, and `lvCount` reports how many logical volumes it currently backs.","min_provider_version":"0.1.9","defaults":"name size free lvCount","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.mapping":{"id":"proxmox.mapping","fields":{"pci":{"name":"pci","type":"\u001bproxmox.mapping.pci","title":"Cluster-wide PCI device mapping","desc":"Named alias for a physical PCI device, selected by `id`. A mapping grants a guest direct hardware access by name instead of by host address, which lets the guest migrate between nodes and keep the passthrough. Each mapping bypasses the virtualization boundary for the mapped device on every node it covers, so `entries` lists the per-node device addresses and IOMMU groups it resolves to.  Reading mappings requires Mapping.Audit on `/mapping/pci`. A token without it sees an empty list.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"usb":{"name":"usb","type":"\u001bproxmox.mapping.usb","title":"Cluster-wide USB device mapping","desc":"Named alias for a physical USB device, selected by `id`. A mapping grants a guest direct access to host USB hardware by name rather than by bus path, so the passthrough survives migration. Each mapping exposes the device to whatever the guest runs, so `entries` lists the per-node paths and vendor identifiers it resolves to.  Reading mappings requires Mapping.Audit on `/mapping/usb`. A token without it sees an empty list.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true}},"is_extension":true},"proxmox.mapping.pci":{"id":"proxmox.mapping.pci","name":"proxmox.mapping.pci","fields":{"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Operator description of the mapping","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"entries":{"name":"entries","type":"\u0019\n","is_mandatory":true,"title":"Per-node device entries the mapping resolves to","desc":"Each entry holds the `node` it applies to, the `path` of the PCI address, the `id` of the vendor and device, and optionally `iommugroup` and `subsystem-id`.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Logical mapping id, used in guest configuration","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Cluster-wide PCI device mapping","desc":"Named alias for a physical PCI device, selected by `id`. A mapping grants a guest direct hardware access by name instead of by host address, which lets the guest migrate between nodes and keep the passthrough. Each mapping bypasses the virtualization boundary for the mapped device on every node it covers, so `entries` lists the per-node device addresses and IOMMU groups it resolves to.  Reading mappings requires Mapping.Audit on `/mapping/pci`. A token without it sees an empty list.","min_provider_version":"0.3.6","defaults":"id description","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.mapping.usb":{"id":"proxmox.mapping.usb","name":"proxmox.mapping.usb","fields":{"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Operator description of the mapping","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"entries":{"name":"entries","type":"\u0019\n","is_mandatory":true,"title":"Per-node device entries the mapping resolves to","desc":"Each entry holds the `node` it applies to, the `id` of the vendor and product, and either a `path` naming a specific port or no path at all, which matches the device on any port.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Logical mapping id, used in guest configuration","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Cluster-wide USB device mapping","desc":"Named alias for a physical USB device, selected by `id`. A mapping grants a guest direct access to host USB hardware by name rather than by bus path, so the passthrough survives migration. Each mapping exposes the device to whatever the guest runs, so `entries` lists the per-node paths and vendor identifiers it resolves to.  Reading mappings requires Mapping.Audit on `/mapping/usb`. A token without it sees an empty list.","min_provider_version":"0.3.6","defaults":"id description","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.metricServer":{"id":"proxmox.metricServer","name":"proxmox.metricServer","fields":{"disabled":{"name":"disabled","type":"\u0004","is_mandatory":true,"title":"Whether the metric server is disabled and receives nothing","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Metric server entry id","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"port":{"name":"port","type":"\u0005","is_mandatory":true,"title":"Server network port","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"server":{"name":"server","type":"\u0007","is_mandatory":true,"title":"Server DNS name or IP address","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Plugin type (`influxdb` or `graphite`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"External metric server","desc":"External InfluxDB or Graphite server the cluster ships metrics to, selected by `id`. Guest names, node names, and resource figures leave the cluster continuously through these, so `server`, `port`, and `type` describe where that stream goes. The Graphite and InfluxDB-UDP transports carry no authentication or encryption at all. The API token for the HTTP transports is not returned by the API.","min_provider_version":"0.3.6","defaults":"id type server port","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.network":{"id":"proxmox.network","name":"proxmox.network","fields":{"active":{"name":"active","type":"\u0004","is_mandatory":true,"title":"Whether the interface is active","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"address":{"name":"address","type":"\u0007","is_mandatory":true,"title":"IP address","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"autostart":{"name":"autostart","type":"\u0004","is_mandatory":true,"title":"Whether the interface starts on boot","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"bridgePorts":{"name":"bridgePorts","type":"\u0007","is_mandatory":true,"title":"Bridge ports (for bridge interfaces)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"cidr":{"name":"cidr","type":"\u0007","is_mandatory":true,"title":"CIDR notation","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"comments":{"name":"comments","type":"\u0007","is_mandatory":true,"title":"Interface comments","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"gateway":{"name":"gateway","type":"\u0007","is_mandatory":true,"title":"Default gateway","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"iface":{"name":"iface","type":"\u0007","is_mandatory":true,"title":"Interface name (e.g. vmbr0, eth0)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"method":{"name":"method","type":"\u0007","is_mandatory":true,"title":"Address assignment method (static, dhcp, manual)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"netmask":{"name":"netmask","type":"\u0007","is_mandatory":true,"title":"Network mask","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Interface type (bridge, bond, eth, vlan, OVSBridge, etc.)","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE node network interface","desc":"Network interface configured on a Proxmox node, selected by `iface` (e.g. `proxmox.network(iface: \"vmbr0\")`). Interfaces determine how a node reaches management, cluster, and guest networks, so their addressing and reachability are central to auditing host isolation and exposure. The `type` field distinguishes bridges, bonds, physical eth ports, VLANs, and Open vSwitch interfaces, and `bridgePorts` names the member ports carried by a bridge.","min_provider_version":"0.1.1","defaults":"iface type active","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.node":{"id":"proxmox.node","name":"proxmox.node","fields":{"bootKernel":{"name":"bootKernel","type":"\u0007","title":"Kernel image that would boot on next reboot","desc":"When this differs from `kernelVersion` a kernel package has been installed but the host hasn't been rebooted to pick it up. Empty on older PVE versions that don't report `boot-info`.","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"certificates":{"name":"certificates","type":"\u0019\u001bproxmox.certificate","title":"TLS/SSL certificates","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"containers":{"name":"containers","type":"\u0019\u001bproxmox.container","title":"LXC containers running on this node","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"cpuCores":{"name":"cpuCores","type":"\u0005","is_mandatory":true,"title":"Number of CPU cores","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"cpuFlags":{"name":"cpuFlags","type":"\u0007","title":"CPU feature flags reported by /proc/cpuinfo","desc":"Space-separated when set, empty on older PVE versions that don't expose `cpuinfo.flags`. Use a `cpuFlags.contains(...)` query to detect microcode/vulnerability mitigations like `ibpb`, `ssbd`, `md_clear`, `pti`, etc.","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"cpuModel":{"name":"cpuModel","type":"\u0007","is_mandatory":true,"title":"CPU model name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"cpuSockets":{"name":"cpuSockets","type":"\u0005","is_mandatory":true,"title":"Number of CPU sockets","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"cpuUsage":{"name":"cpuUsage","type":"\u0006","is_mandatory":true,"title":"Current CPU usage (fraction 0.0-1.0)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"disk":{"name":"disk","type":"\u001bproxmox.node.disk","title":"Proxmox VE physical disk","desc":"Physical disk attached to a Proxmox node, identified by `devPath` (e.g. `/dev/sda`, `/dev/nvme0n1`). Reports the disk `model`, `vendor`, `serial`, `wwn`, capacity (`size` in bytes), rotational speed (`rpm`; 0 for SSDs/NVMe), `type` (hdd, ssd, nvme, usb), and current `health` from SMART. The `used` field reports which volume manager owns the disk (ZFS, LVM, partitions, or empty for unallocated). SMART attributes are available through `smart` when the device exposes them.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"disks":{"name":"disks","type":"\u0019\u001bproxmox.node.disk","title":"Physical disks attached to this node","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"dns":{"name":"dns","type":"\u001bproxmox.dns","title":"DNS configuration","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"firewallOptions":{"name":"firewallOptions","type":"\u001bproxmox.firewall.options","title":"Node-level firewall options (enable, log_nf_conntrack, nf_conntrack_*)","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"firewallRules":{"name":"firewallRules","type":"\u0019\u001bproxmox.firewall.rule","title":"Node-level firewall rules","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"ip":{"name":"ip","type":"\u0007","is_mandatory":true,"title":"Node IP address","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"kernelVersion":{"name":"kernelVersion","type":"\u0007","is_mandatory":true,"title":"Running kernel version","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"memFree":{"name":"memFree","type":"\u0005","is_mandatory":true,"title":"Free memory in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"memTotal":{"name":"memTotal","type":"\u0005","is_mandatory":true,"title":"Total memory in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"memUsed":{"name":"memUsed","type":"\u0005","is_mandatory":true,"title":"Used memory in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Node hostname","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"networks":{"name":"networks","type":"\u0019\u001bproxmox.network","title":"Network interfaces (bridges, bonds, physical)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"pciDevice":{"name":"pciDevice","type":"\u001bproxmox.node.pciDevice","title":"Proxmox VE node PCI device","desc":"PCI device visible to a Proxmox node, identified by its `id` (`\u003cseg\u003e:\u003cbus\u003e:\u003cslot\u003e.\u003cfunc\u003e`). Reports vendor and device IDs alongside their human-readable names, the PCI `class` (eg `0x0300` for VGA), the secondary vendor/device IDs (`subVendor`, `subDevice`) used to distinguish OEM variants, `iommuGroup` (passthrough granularity, devices in the same group must be passed through together), and whether the device advertises mediated-device support via `mdevSupported`.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"pciDevices":{"name":"pciDevices","type":"\u0019\u001bproxmox.node.pciDevice","title":"PCI devices visible to the host","desc":"Lists everything `/nodes/\u003cn\u003e/hardware/pci` reports, regardless of whether the device is currently assigned to a guest. Pair with `proxmox.vm.pciDevices` to confirm what's actually passed through.","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"pendingReboot":{"name":"pendingReboot","type":"\u0004","title":"Whether a kernel upgrade is pending a reboot","desc":"True when `kernelVersion` and `bootKernel` disagree. False when either value is empty so older PVE versions don't false-positive.","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"pveVersion":{"name":"pveVersion","type":"\u0007","is_mandatory":true,"title":"PVE manager version","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"repositories":{"name":"repositories","type":"\u0019\u001bproxmox.repository","title":"APT repositories configured on this node","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"secureBoot":{"name":"secureBoot","type":"\u0004","title":"UEFI Secure Boot status: true when enforcing, false when disabled or on BIOS-only platforms","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"services":{"name":"services","type":"\u0019\u001bproxmox.service","title":"systemd services","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Connectivity status of the node (online or offline)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"storages":{"name":"storages","type":"\u0019\u001bproxmox.storage","title":"Storage pools available on this node","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"subscription":{"name":"subscription","type":"\u001bproxmox.subscription","title":"Proxmox subscription status","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"swapTotal":{"name":"swapTotal","type":"\u0005","is_mandatory":true,"title":"Total swap in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"swapUsed":{"name":"swapUsed","type":"\u0005","is_mandatory":true,"title":"Used swap in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"thinPools":{"name":"thinPools","type":"\u0019\u001bproxmox.lvm.thinPool","title":"LVM-thin pools on this node","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"timezone":{"name":"timezone","type":"\u0007","is_mandatory":true,"title":"Configured timezone","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"update":{"name":"update","type":"\u001bproxmox.node.update","title":"Proxmox VE node package update","desc":"Available package update on a Proxmox node. Reports the `package` name, `installedVersion`, and available `newVersion`. The `severity` field indicates urgency (important, recommended, optional), enabling audits for outstanding security patches.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"updates":{"name":"updates","type":"\u0019\u001bproxmox.node.update","title":"Available package updates","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"uptime":{"name":"uptime","type":"\u0005","is_mandatory":true,"title":"Uptime in seconds","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"usbDevice":{"name":"usbDevice","type":"\u001bproxmox.node.usbDevice","title":"Proxmox VE node USB device","desc":"USB device plugged into a Proxmox node. Reports the `vendorId`/`productId` pair, manufacturer/product/serial strings (when the device exposes them), the bus and device numbers (`busNum`, `devNum`), the topology `port` / `level`, and the negotiated `speed` and `usbPath` Proxmox uses when assigning the device to a guest.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"usbDevices":{"name":"usbDevices","type":"\u0019\u001bproxmox.node.usbDevice","title":"USB devices visible to the host (pair with `proxmox.vm.usbDevices`)","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"vms":{"name":"vms","type":"\u0019\u001bproxmox.vm","title":"VMs running on this node","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"volumeGroups":{"name":"volumeGroups","type":"\u0019\u001bproxmox.lvm.volumeGroup","title":"LVM volume groups on this node","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"zfsPools":{"name":"zfsPools","type":"\u0019\u001bproxmox.zfs.pool","title":"ZFS storage pools managed by this node","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE node","desc":"Physical or virtual host in the Proxmox cluster, identified by `name`. Reports hardware details including CPU model, socket and core counts, memory and swap totals, as well as current utilization via `cpuUsage`, `memUsed`, and `memFree`. System information covers the running `kernelVersion`, `pveVersion`, and `uptime`. Network interfaces are available through `networks`, DNS configuration through `dns`, and systemd service states through `services`. Security-relevant data includes TLS `certificates`, APT `repositories`, available `updates`, and node-level `firewallRules`. VMs running on the node are listed via `vms`, and subscription status is available through `subscription`.","min_provider_version":"0.1.1","defaults":"name status","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.node.disk":{"id":"proxmox.node.disk","name":"proxmox.node.disk","fields":{"byIdLink":{"name":"byIdLink","type":"\u0007","is_mandatory":true,"title":"Stable /dev/disk/by-id symlink","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"devPath":{"name":"devPath","type":"\u0007","is_mandatory":true,"title":"Device path (e.g. /dev/sda)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"gpt":{"name":"gpt","type":"\u0004","is_mandatory":true,"title":"Whether the disk is partitioned with a GPT","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"health":{"name":"health","type":"\u0007","is_mandatory":true,"title":"Overall SMART health (PASSED, FAILED, UNKNOWN)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"model":{"name":"model","type":"\u0007","is_mandatory":true,"title":"Disk model","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"rpm":{"name":"rpm","type":"\u0005","is_mandatory":true,"title":"Rotational speed in RPM (0 for SSD/NVMe)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"serial":{"name":"serial","type":"\u0007","is_mandatory":true,"title":"Disk serial number","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"size":{"name":"size","type":"\u0005","is_mandatory":true,"title":"Capacity in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"smart":{"name":"smart","type":"\u001bproxmox.node.disk.smart","title":"SMART report including the per-attribute table","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Disk type (hdd, ssd, nvme, usb)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"usedBy":{"name":"usedBy","type":"\u0007","is_mandatory":true,"title":"Subsystem currently using the disk (ZFS, LVM, partitions, or empty)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"vendor":{"name":"vendor","type":"\u0007","is_mandatory":true,"title":"Disk vendor","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"wwn":{"name":"wwn","type":"\u0007","is_mandatory":true,"title":"World Wide Name identifier","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE physical disk","desc":"Physical disk attached to a Proxmox node, identified by `devPath` (e.g. `/dev/sda`, `/dev/nvme0n1`). Reports the disk `model`, `vendor`, `serial`, `wwn`, capacity (`size` in bytes), rotational speed (`rpm`; 0 for SSDs/NVMe), `type` (hdd, ssd, nvme, usb), and current `health` from SMART. The `used` field reports which volume manager owns the disk (ZFS, LVM, partitions, or empty for unallocated). SMART attributes are available through `smart` when the device exposes them.","min_provider_version":"0.1.9","defaults":"devPath model size health","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.node.disk.smart":{"id":"proxmox.node.disk.smart","name":"proxmox.node.disk.smart","fields":{"attributes":{"name":"attributes","type":"\u0019\n","is_mandatory":true,"title":"Per-attribute SMART entries","desc":"Empty for text-only reports. Each entry is a dict with `id` (numeric attribute number), `name` (attribute label), the normalized `value`, `worst`, and `threshold` ints, `raw` (raw attribute reading as a string), `flags` (SMART flag characters), and `fail` (populated when the attribute is failing, otherwise empty).","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"health":{"name":"health","type":"\u0007","is_mandatory":true,"title":"Overall device health verdict","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"text":{"name":"text","type":"\u0007","is_mandatory":true,"title":"Unstructured SMART output (populated when type=text)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"SMART report flavor (ata, nvme, sas, text)","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE disk SMART report","desc":"SMART self-assessment for a Proxmox-managed disk. The `health` field carries the device's overall PASSED/FAILED verdict. `type` is the SMART report flavor (`ata`, `nvme`, `sas`, `text`); when it is `text` the device only returns unstructured output via the `text` field. Structured `attributes` are available for ATA and SAS drives.","min_provider_version":"0.1.9","defaults":"health type","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.node.pciDevice":{"id":"proxmox.node.pciDevice","name":"proxmox.node.pciDevice","fields":{"class":{"name":"class","type":"\u0007","is_mandatory":true,"title":"PCI class code (hex string, e.g. `0x0300` for VGA)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"className":{"name":"className","type":"\u0007","is_mandatory":true,"title":"Human-readable PCI class name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"device":{"name":"device","type":"\u0007","is_mandatory":true,"title":"Device ID (4-digit hex string)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"deviceName":{"name":"deviceName","type":"\u0007","is_mandatory":true,"title":"Human-readable device name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"PCI address (e.g. 0000:01:00.0)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"iommuGroup":{"name":"iommuGroup","type":"\u0005","is_mandatory":true,"title":"IOMMU group; devices that share a group must be passed through together","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"mdevSupported":{"name":"mdevSupported","type":"\u0004","is_mandatory":true,"title":"Whether the device advertises mediated-device (vGPU) support","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"subDevice":{"name":"subDevice","type":"\u0007","is_mandatory":true,"title":"Secondary device ID","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"subDeviceName":{"name":"subDeviceName","type":"\u0007","is_mandatory":true,"title":"Human-readable secondary device name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"subVendor":{"name":"subVendor","type":"\u0007","is_mandatory":true,"title":"Secondary vendor ID","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"subVendorName":{"name":"subVendorName","type":"\u0007","is_mandatory":true,"title":"Human-readable secondary vendor name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"vendor":{"name":"vendor","type":"\u0007","is_mandatory":true,"title":"Vendor ID (4-digit hex string)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"vendorName":{"name":"vendorName","type":"\u0007","is_mandatory":true,"title":"Human-readable vendor name","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE node PCI device","desc":"PCI device visible to a Proxmox node, identified by its `id` (`\u003cseg\u003e:\u003cbus\u003e:\u003cslot\u003e.\u003cfunc\u003e`). Reports vendor and device IDs alongside their human-readable names, the PCI `class` (eg `0x0300` for VGA), the secondary vendor/device IDs (`subVendor`, `subDevice`) used to distinguish OEM variants, `iommuGroup` (passthrough granularity, devices in the same group must be passed through together), and whether the device advertises mediated-device support via `mdevSupported`.","min_provider_version":"0.1.9","defaults":"id deviceName iommuGroup","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.node.update":{"id":"proxmox.node.update","name":"proxmox.node.update","fields":{"installedVersion":{"name":"installedVersion","type":"\u0007","is_mandatory":true,"title":"Currently installed version","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"newVersion":{"name":"newVersion","type":"\u0007","is_mandatory":true,"title":"Available new version","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"package":{"name":"package","type":"\u0007","is_mandatory":true,"title":"Package name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"severity":{"name":"severity","type":"\u0007","is_mandatory":true,"title":"Update severity (important, recommended, optional)","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE node package update","desc":"Available package update on a Proxmox node. Reports the `package` name, `installedVersion`, and available `newVersion`. The `severity` field indicates urgency (important, recommended, optional), enabling audits for outstanding security patches.","min_provider_version":"0.1.1","defaults":"package newVersion severity","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.node.usbDevice":{"id":"proxmox.node.usbDevice","name":"proxmox.node.usbDevice","fields":{"busNum":{"name":"busNum","type":"\u0007","is_mandatory":true,"title":"Bus number","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"class":{"name":"class","type":"\u0007","is_mandatory":true,"title":"USB class string (e.g. `Hub`, `Mass Storage`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"devNum":{"name":"devNum","type":"\u0007","is_mandatory":true,"title":"Device number on the bus","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"level":{"name":"level","type":"\u0007","is_mandatory":true,"title":"Hub depth (0 = root port)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"manufacturer":{"name":"manufacturer","type":"\u0007","is_mandatory":true,"title":"Manufacturer string reported by the device","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"port":{"name":"port","type":"\u0007","is_mandatory":true,"title":"USB topology port","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"product":{"name":"product","type":"\u0007","is_mandatory":true,"title":"Product name reported by the device","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"productId":{"name":"productId","type":"\u0007","is_mandatory":true,"title":"Product ID (4-digit hex string)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"serial":{"name":"serial","type":"\u0007","is_mandatory":true,"title":"Serial number reported by the device; empty when not provided","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"speed":{"name":"speed","type":"\u0007","is_mandatory":true,"title":"Negotiated speed (e.g. `12`, `480`, `5000` Mbit/s)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"usbPath":{"name":"usbPath","type":"\u0007","is_mandatory":true,"title":"USB path Proxmox uses to assign the device to a guest","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"vendorId":{"name":"vendorId","type":"\u0007","is_mandatory":true,"title":"Vendor ID (4-digit hex string)","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE node USB device","desc":"USB device plugged into a Proxmox node. Reports the `vendorId`/`productId` pair, manufacturer/product/serial strings (when the device exposes them), the bus and device numbers (`busNum`, `devNum`), the topology `port` / `level`, and the negotiated `speed` and `usbPath` Proxmox uses when assigning the device to a guest.","min_provider_version":"0.1.9","defaults":"vendorId productId product","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.notification":{"id":"proxmox.notification","fields":{"gotifyEndpoint":{"name":"gotifyEndpoint","type":"\u001bproxmox.notification.gotifyEndpoint","title":"Gotify notification endpoint","desc":"Notification target that posts to a Gotify server, selected by `name`. The `server` URL carries the scheme, so it shows whether notifications, which are authenticated with a bearer token, travel over HTTPS or plain HTTP. The token itself is never returned by the API and is not exposed here.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"matcher":{"name":"matcher","type":"\u001bproxmox.notification.matcher","title":"Proxmox VE notification matcher","desc":"Rule deciding which notifications reach which targets, selected by `name`. A matcher that reaches no target, or one disabled matcher where an operator expected coverage, silently drops the events it governs. The `matchSeverity`, `matchField`, and `matchCalendar` fields hold the conditions, `mode` says whether all or any of them must hold, `invertMatch` flips the result, and `targets` names the destinations notified on a match.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"sendmailEndpoint":{"name":"sendmailEndpoint","type":"\u001bproxmox.notification.sendmailEndpoint","title":"Sendmail notification endpoint","desc":"Notification target that hands mail to the local sendmail binary, selected by `name`. Delivery depends entirely on the host mail transfer agent, so `mailto` and `mailtoUser` say who is meant to be reached but not whether anything actually leaves the node.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"smtpEndpoint":{"name":"smtpEndpoint","type":"\u001bproxmox.notification.smtpEndpoint","title":"SMTP notification endpoint","desc":"Notification target that mails through an SMTP server, selected by `name`. The `mode` field is the security-relevant one: it decides whether the connection is encrypted (`tls`, `starttls`) or sent in the clear (`insecure`), which matters because `username` authenticates with a password on the same connection. That password is never returned by the API and is not exposed here.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"target":{"name":"target","type":"\u001bproxmox.notification.target","title":"Proxmox VE notification target","desc":"Configured destination for cluster notifications, selected by `name`. This is the type-independent view of every target: backup failures, replication errors, fencing events, and package updates all reach an operator only through one of these, so a cluster with none is running unobserved. The `type` field says which transport carries it (`smtp`, `sendmail`, `gotify`, `webhook`), and the matching endpoint list holds the transport-specific settings. The `origin` field distinguishes operator-created targets from the built-in default.  Reading notification configuration requires Mapping.Audit on `/mapping/notifications`, which the PVEAuditor role does not include. A token without it sees an empty list.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"webhookEndpoint":{"name":"webhookEndpoint","type":"\u001bproxmox.notification.webhookEndpoint","title":"Webhook notification endpoint","desc":"Notification target that posts to an arbitrary URL, selected by `name`. The `url` scheme shows whether the payload, which can carry cluster names and failure detail, travels encrypted. The `headerNames` and `secretNames` fields list which headers and secrets are configured without their values, since a header value can itself carry an API token.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true}},"is_extension":true},"proxmox.notification.gotifyEndpoint":{"id":"proxmox.notification.gotifyEndpoint","name":"proxmox.notification.gotifyEndpoint","fields":{"comment":{"name":"comment","type":"\u0007","is_mandatory":true,"title":"Operator comment on the endpoint","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"disabled":{"name":"disabled","type":"\u0004","is_mandatory":true,"title":"Whether the endpoint is disabled","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Endpoint name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"origin":{"name":"origin","type":"\u0007","is_mandatory":true,"title":"Whether the endpoint is created by an operator or built in","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"server":{"name":"server","type":"\u0007","is_mandatory":true,"title":"Gotify server URL","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Gotify notification endpoint","desc":"Notification target that posts to a Gotify server, selected by `name`. The `server` URL carries the scheme, so it shows whether notifications, which are authenticated with a bearer token, travel over HTTPS or plain HTTP. The token itself is never returned by the API and is not exposed here.","min_provider_version":"0.3.6","defaults":"name server disabled","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.notification.matcher":{"id":"proxmox.notification.matcher","name":"proxmox.notification.matcher","fields":{"comment":{"name":"comment","type":"\u0007","is_mandatory":true,"title":"Operator comment on the matcher","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"disabled":{"name":"disabled","type":"\u0004","is_mandatory":true,"title":"Whether the matcher is disabled","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"invertMatch":{"name":"invertMatch","type":"\u0004","is_mandatory":true,"title":"Whether the overall match result is inverted","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"matchCalendar":{"name":"matchCalendar","type":"\u0019\u0007","is_mandatory":true,"title":"Timestamp conditions matched, as systemd calendar events","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"matchField":{"name":"matchField","type":"\u0019\u0007","is_mandatory":true,"title":"Metadata field conditions matched, as `(regex|exact):field=value`","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"matchSeverity":{"name":"matchSeverity","type":"\u0019\u0007","is_mandatory":true,"title":"Notification severities matched","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"mode":{"name":"mode","type":"\u0007","is_mandatory":true,"title":"Whether all or any of the configured conditions must hold (`all` or `any`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Matcher name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"origin":{"name":"origin","type":"\u0007","is_mandatory":true,"title":"Whether the matcher is created by an operator or built in","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"targets":{"name":"targets","type":"\u0019\u0007","is_mandatory":true,"title":"Names of the targets notified when the matcher fires","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE notification matcher","desc":"Rule deciding which notifications reach which targets, selected by `name`. A matcher that reaches no target, or one disabled matcher where an operator expected coverage, silently drops the events it governs. The `matchSeverity`, `matchField`, and `matchCalendar` fields hold the conditions, `mode` says whether all or any of them must hold, `invertMatch` flips the result, and `targets` names the destinations notified on a match.","min_provider_version":"0.3.6","defaults":"name mode disabled","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.notification.sendmailEndpoint":{"id":"proxmox.notification.sendmailEndpoint","name":"proxmox.notification.sendmailEndpoint","fields":{"author":{"name":"author","type":"\u0007","is_mandatory":true,"title":"Author name on the mail","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"comment":{"name":"comment","type":"\u0007","is_mandatory":true,"title":"Operator comment on the endpoint","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"disabled":{"name":"disabled","type":"\u0004","is_mandatory":true,"title":"Whether the endpoint is disabled","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"fromAddress":{"name":"fromAddress","type":"\u0007","is_mandatory":true,"title":"From address on the mail","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"mailto":{"name":"mailto","type":"\u0019\u0007","is_mandatory":true,"title":"Recipient email addresses","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"mailtoUser":{"name":"mailtoUser","type":"\u0019\u0007","is_mandatory":true,"title":"Recipient Proxmox users, notified at their configured address","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Endpoint name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"origin":{"name":"origin","type":"\u0007","is_mandatory":true,"title":"Whether the endpoint is created by an operator or built in","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Sendmail notification endpoint","desc":"Notification target that hands mail to the local sendmail binary, selected by `name`. Delivery depends entirely on the host mail transfer agent, so `mailto` and `mailtoUser` say who is meant to be reached but not whether anything actually leaves the node.","min_provider_version":"0.3.6","defaults":"name disabled","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.notification.smtpEndpoint":{"id":"proxmox.notification.smtpEndpoint","name":"proxmox.notification.smtpEndpoint","fields":{"author":{"name":"author","type":"\u0007","is_mandatory":true,"title":"Author name on the mail","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"comment":{"name":"comment","type":"\u0007","is_mandatory":true,"title":"Operator comment on the endpoint","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"disabled":{"name":"disabled","type":"\u0004","is_mandatory":true,"title":"Whether the endpoint is disabled","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"fromAddress":{"name":"fromAddress","type":"\u0007","is_mandatory":true,"title":"From address on the mail","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"mailto":{"name":"mailto","type":"\u0019\u0007","is_mandatory":true,"title":"Recipient email addresses","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"mailtoUser":{"name":"mailtoUser","type":"\u0019\u0007","is_mandatory":true,"title":"Recipient Proxmox users, notified at their configured address","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"mode":{"name":"mode","type":"\u0007","is_mandatory":true,"title":"Encryption method used for the connection","desc":"One of `tls`, `starttls`, or `insecure`. An empty value takes the Proxmox default of `tls`.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Endpoint name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"origin":{"name":"origin","type":"\u0007","is_mandatory":true,"title":"Whether the endpoint is created by an operator or built in","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"port":{"name":"port","type":"\u0005","is_mandatory":true,"title":"Port used for the connection; 0 when the default applies","desc":"Proxmox defaults to 465 for TLS and 587 for STARTTLS.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"server":{"name":"server","type":"\u0007","is_mandatory":true,"title":"Address of the SMTP server","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"username":{"name":"username","type":"\u0007","is_mandatory":true,"title":"Username authenticating to the SMTP server; empty when unauthenticated","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"SMTP notification endpoint","desc":"Notification target that mails through an SMTP server, selected by `name`. The `mode` field is the security-relevant one: it decides whether the connection is encrypted (`tls`, `starttls`) or sent in the clear (`insecure`), which matters because `username` authenticates with a password on the same connection. That password is never returned by the API and is not exposed here.","min_provider_version":"0.3.6","defaults":"name server port mode","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.notification.target":{"id":"proxmox.notification.target","name":"proxmox.notification.target","fields":{"comment":{"name":"comment","type":"\u0007","is_mandatory":true,"title":"Operator comment on the target","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"disabled":{"name":"disabled","type":"\u0004","is_mandatory":true,"title":"Whether the target is disabled and will not be notified","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Target name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"origin":{"name":"origin","type":"\u0007","is_mandatory":true,"title":"Whether the target is created by an operator or built in","desc":"One of `user-created`, `builtin`, or `modified-builtin`.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Transport type (`smtp`, `sendmail`, `gotify`, `webhook`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE notification target","desc":"Configured destination for cluster notifications, selected by `name`. This is the type-independent view of every target: backup failures, replication errors, fencing events, and package updates all reach an operator only through one of these, so a cluster with none is running unobserved. The `type` field says which transport carries it (`smtp`, `sendmail`, `gotify`, `webhook`), and the matching endpoint list holds the transport-specific settings. The `origin` field distinguishes operator-created targets from the built-in default.  Reading notification configuration requires Mapping.Audit on `/mapping/notifications`, which the PVEAuditor role does not include. A token without it sees an empty list.","min_provider_version":"0.3.6","defaults":"name type disabled","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.notification.webhookEndpoint":{"id":"proxmox.notification.webhookEndpoint","name":"proxmox.notification.webhookEndpoint","fields":{"comment":{"name":"comment","type":"\u0007","is_mandatory":true,"title":"Operator comment on the endpoint","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"disabled":{"name":"disabled","type":"\u0004","is_mandatory":true,"title":"Whether the endpoint is disabled","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"headerNames":{"name":"headerNames","type":"\u0019\u0007","is_mandatory":true,"title":"Names of the HTTP headers set on the request, without their values","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"method":{"name":"method","type":"\u0007","is_mandatory":true,"title":"HTTP method used for the request","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Endpoint name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"origin":{"name":"origin","type":"\u0007","is_mandatory":true,"title":"Whether the endpoint is created by an operator or built in","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"secretNames":{"name":"secretNames","type":"\u0019\u0007","is_mandatory":true,"title":"Names of the configured secrets, without their values","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"url":{"name":"url","type":"\u0007","is_mandatory":true,"title":"Destination URL","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Webhook notification endpoint","desc":"Notification target that posts to an arbitrary URL, selected by `name`. The `url` scheme shows whether the payload, which can carry cluster names and failure detail, travels encrypted. The `headerNames` and `secretNames` fields list which headers and secrets are configured without their values, since a header value can itself carry an API token.","min_provider_version":"0.3.6","defaults":"name url method","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.pool":{"id":"proxmox.pool","name":"proxmox.pool","fields":{"comment":{"name":"comment","type":"\u0007","is_mandatory":true,"title":"Pool comment/description","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Pool ID","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE resource pool","desc":"Resource pool in the cluster, selected by `id` (for example `proxmox.pool(id: \"prod\")`). Pools group virtual machines and storage into a single unit that permissions can be granted against, so auditing them shows how access to those resources is delegated. The `comment` field holds the pool description.","min_provider_version":"0.1.1","defaults":"id","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.realm":{"id":"proxmox.realm","name":"proxmox.realm","fields":{"comment":{"name":"comment","type":"\u0007","is_mandatory":true,"title":"Realm description","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"config":{"name":"config","type":"\n","title":"Full realm configuration as returned by /access/domains/\u003crealm\u003e","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"default":{"name":"default","type":"\u0004","is_mandatory":true,"title":"Whether this is the default realm","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"realm":{"name":"realm","type":"\u0007","is_mandatory":true,"title":"Realm identifier","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"tfaType":{"name":"tfaType","type":"\u0007","is_mandatory":true,"title":"Realm-enforced TFA challenge type (e.g. oath, yubico); empty when not required at the realm level","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Realm type (pam, pve, ldap, ad, openid)","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE authentication realm","desc":"Authentication realm configured in the Proxmox cluster, identified by `realm`. Reports the realm `type` (pam, pve, ldap, ad, openid), whether it is the `default` realm, the realm-enforced TFA challenge in `tfaType` (empty when no realm-wide TFA is required), and full configuration via `config`, including LDAP servers, sync settings, OpenID issuer URLs, and `autocreate` flags.","min_provider_version":"0.1.9","defaults":"realm type default","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.replication":{"id":"proxmox.replication","fields":{"job":{"name":"job","type":"\u001bproxmox.replication.job","title":"Proxmox VE storage replication job","desc":"Guest replication job from /cluster/replication, keyed by `id` in the form \u003cvmid\u003e-\u003cjobnum\u003e. Each job continuously replicates a single guest from the `source` node to the `target` node according to `schedule` (a systemd-calendar expression). The `vmid` selects which guest, `rate` caps the per-job bandwidth in MB/s (0 means unlimited), and `disabled` reflects whether the job is paused. The `sourceNode` and `targetNode` references resolve the node names for traversal, while `vm` and `container` resolve the replicated guest (exactly one is non-null depending on what `vmid` refers to).","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true}},"is_extension":true},"proxmox.replication.job":{"id":"proxmox.replication.job","name":"proxmox.replication.job","fields":{"comment":{"name":"comment","type":"\u0007","is_mandatory":true,"title":"Job comment","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"container":{"name":"container","type":"\u001bproxmox.container","title":"Container counterpart of `vm`; only one of the two is non-null","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"disabled":{"name":"disabled","type":"\u0004","is_mandatory":true,"title":"Whether the job is currently disabled","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Job identifier (format: \u003cvmid\u003e-\u003cjobnum\u003e)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"rate":{"name":"rate","type":"\u0005","is_mandatory":true,"title":"Bandwidth cap in MB/s; 0 = unlimited","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"removeJob":{"name":"removeJob","type":"\u0007","is_mandatory":true,"title":"Behavior when the job is removed (full | local)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"schedule":{"name":"schedule","type":"\u0007","is_mandatory":true,"title":"Schedule expression (systemd-calendar)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"source":{"name":"source","type":"\u0007","is_mandatory":true,"title":"Source node name","desc":"Deprecated in favor of `sourceNode`, which resolves the same host as a node resource.","provider":"go.mondoo.com/mql/v13/providers/proxmox","maturity":"deprecated"},"sourceNode":{"name":"sourceNode","type":"\u001bproxmox.node","title":"Resolved source node","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"target":{"name":"target","type":"\u0007","is_mandatory":true,"title":"Target node name","desc":"Deprecated in favor of `targetNode`, which resolves the same host as a node resource.","provider":"go.mondoo.com/mql/v13/providers/proxmox","maturity":"deprecated"},"targetNode":{"name":"targetNode","type":"\u001bproxmox.node","title":"Resolved target node","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Job type (local for built-in storage replication)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"vm":{"name":"vm","type":"\u001bproxmox.vm","title":"Replicated guest when `vmid` refers to a VM; null for a container","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"vmid":{"name":"vmid","type":"\u0005","is_mandatory":true,"title":"VMID of the guest being replicated","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE storage replication job","desc":"Guest replication job from /cluster/replication, keyed by `id` in the form \u003cvmid\u003e-\u003cjobnum\u003e. Each job continuously replicates a single guest from the `source` node to the `target` node according to `schedule` (a systemd-calendar expression). The `vmid` selects which guest, `rate` caps the per-job bandwidth in MB/s (0 means unlimited), and `disabled` reflects whether the job is paused. The `sourceNode` and `targetNode` references resolve the node names for traversal, while `vm` and `container` resolve the replicated guest (exactly one is non-null depending on what `vmid` refers to).","min_provider_version":"0.1.9","defaults":"id schedule source target disabled","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.repository":{"id":"proxmox.repository","name":"proxmox.repository","fields":{"components":{"name":"components","type":"\u0019\u0007","is_mandatory":true,"title":"Repository components (main, contrib, etc.)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether the repository is enabled","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"fileType":{"name":"fileType","type":"\u0007","is_mandatory":true,"title":"File type (sources.list, sources.list.d)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Repository identifier","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Repository name/description","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"signedBy":{"name":"signedBy","type":"\u0007","is_mandatory":true,"title":"Path to the keyring used to verify repository signatures","desc":"Reads the `Signed-By` option from modern `.sources` entries. Empty when the entry doesn't declare one — older `.list` entries typically don't, and instead inherit the system trust store.","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"suites":{"name":"suites","type":"\u0019\u0007","is_mandatory":true,"title":"Repository suites (e.g. bookworm, stable)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"types":{"name":"types","type":"\u0019\u0007","is_mandatory":true,"title":"Repository types declared on the entry (e.g., deb, deb-src)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"uris":{"name":"uris","type":"\u0019\u0007","is_mandatory":true,"title":"Repository URIs","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE node APT repository","desc":"APT package repository configured on a Proxmox node, covering both the legacy `sources.list` format and modern deb822 `.sources` entries. The `enabled` flag reflects whether the entry is active, and `signedBy` records the keyring that verifies package signatures. Useful for confirming that only official, correctly signed Proxmox repositories are configured and that no untrusted or disabled entries remain.","min_provider_version":"0.1.1","defaults":"name enabled","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.role":{"id":"proxmox.role","name":"proxmox.role","fields":{"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Role ID","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"privs":{"name":"privs","type":"\u0019\u0007","is_mandatory":true,"title":"Privileges assigned to this role","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"special":{"name":"special","type":"\u0004","is_mandatory":true,"title":"Whether this is a built-in role","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE access control role","desc":"Role defined in the Proxmox cluster, identified by `id`. The `privs` list holds the privileges granted by the role, and `special` indicates whether it is a built-in role. Roles are assigned to users and groups on paths to implement Proxmox's path-based access-control model.","min_provider_version":"0.1.1","defaults":"id","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.sdn":{"id":"proxmox.sdn","fields":{"controller":{"name":"controller","type":"\u001bproxmox.sdn.controller","title":"SDN controller","desc":"Controller driving the routing protocol behind an SDN zone, selected by `controller` (for example `proxmox.sdn.controller(controller: \"evpnctl\")`). EVPN and BGP zones need one to exchange routes with the physical network, so `type`, `asn`, and `peers` describe which external routers the cluster peers with and under whose autonomous system number. The `state` field reports whether the configuration has been applied.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"dns":{"name":"dns","type":"\u001bproxmox.sdn.dns","title":"SDN DNS backend","desc":"DNS backend the SDN registers guest records in, selected by `dns`. The `type` field names the implementation, currently `powerdns`.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"ipam":{"name":"ipam","type":"\u001bproxmox.sdn.ipam","title":"SDN IP address management backend","desc":"Address management backend the SDN allocates guest addresses from, selected by `ipam`. The `type` field names the implementation: `pve` for the built-in allocator, or `netbox` and `phpipam` for external systems the cluster reaches over an API.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"subnet":{"name":"subnet","type":"\u001bproxmox.sdn.subnet","title":"Proxmox VE SDN subnet","desc":"SDN subnet attached to a vnet. The `cidr` (e.g. `10.0.0.0/24`) is the subnet's address range and `gateway` is the default route presented to guests. `snat` controls whether outbound traffic from the subnet is masqueraded behind the host, which determines whether guests reach external networks without a routable address.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"vnet":{"name":"vnet","type":"\u001bproxmox.sdn.vnet","title":"Proxmox VE SDN virtual network","desc":"Software-defined virtual network, identified by `vnet`. A vnet is the bridge guests attach to, scoped to its parent `zone`. The `tag` carries the VLAN or VXLAN identifier that isolates traffic, and `vlanAware` reports whether 802.1Q tagging from guests is preserved on the bridge rather than stripped.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"zone":{"name":"zone","type":"\u001bproxmox.sdn.zone","title":"Proxmox VE SDN zone","desc":"Software-defined networking zone, identified by `zone`. A zone groups the layer-2 fabric a set of vnets share. The `type` (simple, vlan, qinq, vxlan, evpn) selects the fabric technology, `ipam` names the IP-address management backend, and `nodes` optionally restricts the zone to specific hosts (empty means all nodes). A `pending` zone has uncommitted changes not yet applied to the running network configuration.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true}},"is_extension":true},"proxmox.sdn.controller":{"id":"proxmox.sdn.controller","name":"proxmox.sdn.controller","fields":{"asn":{"name":"asn","type":"\u0005","is_mandatory":true,"title":"Local autonomous system number, for BGP and EVPN","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"bgpMode":{"name":"bgpMode","type":"\u0007","is_mandatory":true,"title":"Whether to use external or internal BGP, or choose automatically","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"controller":{"name":"controller","type":"\u0007","is_mandatory":true,"title":"Controller name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"ebgp":{"name":"ebgp","type":"\u0004","is_mandatory":true,"title":"Whether external BGP is enabled, making peers remote-as external","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"ebgpMultihop":{"name":"ebgpMultihop","type":"\u0005","is_mandatory":true,"title":"Maximum hop count permitted to external BGP peers; 0 when unset","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"isisDomain":{"name":"isisDomain","type":"\u0007","is_mandatory":true,"title":"IS-IS domain name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"isisIfaces":{"name":"isisIfaces","type":"\u0007","is_mandatory":true,"title":"Interfaces IS-IS is active on, comma-separated","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"isisNet":{"name":"isisNet","type":"\u0007","is_mandatory":true,"title":"Network entity title for this node in the IS-IS network","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"loopback":{"name":"loopback","type":"\u0007","is_mandatory":true,"title":"Loopback interface providing the router IP, for BGP","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"node":{"name":"node","type":"\u0007","is_mandatory":true,"title":"Node the controller is active on; empty when it applies to all","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"nodes":{"name":"nodes","type":"\u0007","is_mandatory":true,"title":"Node restriction from the controller config, comma-separated","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"peers":{"name":"peers","type":"\u0007","is_mandatory":true,"title":"Peer router addresses, comma-separated","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"State of the configuration object (`new`, `changed`, `deleted`, or empty when applied)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Controller type (`evpn`, `bgp`, `isis`, `faucet`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"SDN controller","desc":"Controller driving the routing protocol behind an SDN zone, selected by `controller` (for example `proxmox.sdn.controller(controller: \"evpnctl\")`). EVPN and BGP zones need one to exchange routes with the physical network, so `type`, `asn`, and `peers` describe which external routers the cluster peers with and under whose autonomous system number. The `state` field reports whether the configuration has been applied.","min_provider_version":"0.3.6","defaults":"controller type asn","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.sdn.dns":{"id":"proxmox.sdn.dns","name":"proxmox.sdn.dns","fields":{"dns":{"name":"dns","type":"\u0007","is_mandatory":true,"title":"DNS backend name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Backend type","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"SDN DNS backend","desc":"DNS backend the SDN registers guest records in, selected by `dns`. The `type` field names the implementation, currently `powerdns`.","min_provider_version":"0.3.6","defaults":"dns type","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.sdn.ipam":{"id":"proxmox.sdn.ipam","name":"proxmox.sdn.ipam","fields":{"ipam":{"name":"ipam","type":"\u0007","is_mandatory":true,"title":"IPAM name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Backend type (`pve`, `netbox`, `phpipam`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"SDN IP address management backend","desc":"Address management backend the SDN allocates guest addresses from, selected by `ipam`. The `type` field names the implementation: `pve` for the built-in allocator, or `netbox` and `phpipam` for external systems the cluster reaches over an API.","min_provider_version":"0.3.6","defaults":"ipam type","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.sdn.subnet":{"id":"proxmox.sdn.subnet","name":"proxmox.sdn.subnet","fields":{"cidr":{"name":"cidr","type":"\u0007","is_mandatory":true,"title":"CIDR-formatted subnet (e.g. 10.0.0.0/24)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"dnsZonePrefix":{"name":"dnsZonePrefix","type":"\u0007","is_mandatory":true,"title":"DNS prefix appended to records created for this subnet","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"gateway":{"name":"gateway","type":"\u0007","is_mandatory":true,"title":"Default gateway advertised to guests","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Subnet identifier (typically `\u003czone\u003e-\u003cnetwork\u003e-\u003cprefix\u003e`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"snat":{"name":"snat","type":"\u0004","is_mandatory":true,"title":"Whether outbound traffic is SNATed by the host","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"vnet":{"name":"vnet","type":"\u0007","is_mandatory":true,"title":"Parent vnet identifier","desc":"Deprecated in favor of `vnetRef`, which resolves the same vnet as an SDN vnet resource.","provider":"go.mondoo.com/mql/v13/providers/proxmox","maturity":"deprecated"},"vnetRef":{"name":"vnetRef","type":"\u001bproxmox.sdn.vnet","title":"Resolved parent vnet","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE SDN subnet","desc":"SDN subnet attached to a vnet. The `cidr` (e.g. `10.0.0.0/24`) is the subnet's address range and `gateway` is the default route presented to guests. `snat` controls whether outbound traffic from the subnet is masqueraded behind the host, which determines whether guests reach external networks without a routable address.","min_provider_version":"0.1.9","defaults":"id cidr gateway","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.sdn.vnet":{"id":"proxmox.sdn.vnet","name":"proxmox.sdn.vnet","fields":{"alias":{"name":"alias","type":"\u0007","is_mandatory":true,"title":"Friendly alias","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"subnets":{"name":"subnets","type":"\u0019\u001bproxmox.sdn.subnet","title":"Subnets defined on this vnet","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"tag":{"name":"tag","type":"\u0005","is_mandatory":true,"title":"VLAN/VXLAN tag identifier","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"VNet type","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"vlanAware":{"name":"vlanAware","type":"\u0004","is_mandatory":true,"title":"Whether the VNet is VLAN-aware","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"vnet":{"name":"vnet","type":"\u0007","is_mandatory":true,"title":"VNet identifier","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"zone":{"name":"zone","type":"\u0007","is_mandatory":true,"title":"Parent zone identifier","desc":"Deprecated in favor of `zoneRef`, which resolves the same zone as an SDN zone resource.","provider":"go.mondoo.com/mql/v13/providers/proxmox","maturity":"deprecated"},"zoneRef":{"name":"zoneRef","type":"\u001bproxmox.sdn.zone","title":"Resolved parent zone","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE SDN virtual network","desc":"Software-defined virtual network, identified by `vnet`. A vnet is the bridge guests attach to, scoped to its parent `zone`. The `tag` carries the VLAN or VXLAN identifier that isolates traffic, and `vlanAware` reports whether 802.1Q tagging from guests is preserved on the bridge rather than stripped.","min_provider_version":"0.1.9","defaults":"vnet zone tag","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.sdn.zone":{"id":"proxmox.sdn.zone","name":"proxmox.sdn.zone","fields":{"dns":{"name":"dns","type":"\u0007","is_mandatory":true,"title":"DNS server","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"dnsZone":{"name":"dnsZone","type":"\u0007","is_mandatory":true,"title":"DNS forward zone","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"ipam":{"name":"ipam","type":"\u0007","is_mandatory":true,"title":"IPAM backend (pve, phpipam, netbox, or empty)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"mtu":{"name":"mtu","type":"\u0005","is_mandatory":true,"title":"MTU","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"nodes":{"name":"nodes","type":"\u0007","is_mandatory":true,"title":"Comma-separated node restriction; empty means all nodes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"pending":{"name":"pending","type":"\u0004","is_mandatory":true,"title":"Whether the zone has uncommitted changes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"reverseDns":{"name":"reverseDns","type":"\u0007","is_mandatory":true,"title":"Reverse DNS forward zone","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"Zone state","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Zone type (simple, vlan, qinq, vxlan, evpn)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"zone":{"name":"zone","type":"\u0007","is_mandatory":true,"title":"Zone identifier","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE SDN zone","desc":"Software-defined networking zone, identified by `zone`. A zone groups the layer-2 fabric a set of vnets share. The `type` (simple, vlan, qinq, vxlan, evpn) selects the fabric technology, `ipam` names the IP-address management backend, and `nodes` optionally restricts the zone to specific hosts (empty means all nodes). A `pending` zone has uncommitted changes not yet applied to the running network configuration.","min_provider_version":"0.1.9","defaults":"zone type","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.service":{"id":"proxmox.service","name":"proxmox.service","fields":{"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Service description","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Service unit name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"Current state (running, dead, etc.)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"unitFileState":{"name":"unitFileState","type":"\u0007","is_mandatory":true,"title":"Unit file state (enabled, disabled, static, masked)","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE node systemd service","desc":"Systemd service on a Proxmox node, selected by `name` (for example `proxmox.service(name: \"pveproxy\")`). The `state` field reports the current runtime status (running, dead, etc.) and `unitFileState` reports the boot-time enablement (enabled, disabled, static, masked). Use it to audit whether critical Proxmox services such as `pve-cluster`, `pveproxy`, or `corosync` are active and enabled.","min_provider_version":"0.1.1","defaults":"name state","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.storage":{"id":"proxmox.storage","name":"proxmox.storage","fields":{"available":{"name":"available","type":"\u0005","is_mandatory":true,"title":"Available space in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"backups":{"name":"backups","type":"\u0019\u001bproxmox.storage.volume","title":"Backup archives stored on this storage","desc":"The subset of `volumes` with a content class of `backup`. Each entry carries the guest it belongs to, when it was written, and whether it is encrypted, protected, and verified.","min_provider_version":"0.3.6","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"content":{"name":"content","type":"\u0007","is_mandatory":true,"title":"Allowed content types as a comma-separated string (e.g., \"images,rootdir,vztmpl,backup,iso,snippets\")","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether the storage is enabled","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"encrypted":{"name":"encrypted","type":"\u0004","is_mandatory":true,"title":"Whether backups written to this storage are encrypted at rest","desc":"True when the storage configuration carries an `encryption-key` (PBS-encrypted datastore). The key value itself is exposed via `encryptionKey`, which is either an explicit fingerprint or the literal `autogen` when Proxmox manages the key.","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"encryptionKey":{"name":"encryptionKey","type":"\u0007","is_mandatory":true,"title":"The raw `encryption-key` value from the storage config; empty when not configured","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Storage ID","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"nodes":{"name":"nodes","type":"\u0007","is_mandatory":true,"title":"Nodes the storage is restricted to, comma-separated","desc":"Empty when the storage is available on every node.","min_provider_version":"0.3.6","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"path":{"name":"path","type":"\u0007","is_mandatory":true,"title":"Storage path (for local storage types)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"shared":{"name":"shared","type":"\u0004","is_mandatory":true,"title":"Whether the storage is shared across nodes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"total":{"name":"total","type":"\u0005","is_mandatory":true,"title":"Total capacity in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Storage type (dir, lvm, lvmthin, nfs, cifs, zfspool, ceph, etc.)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"usagePercent":{"name":"usagePercent","type":"\u0006","is_mandatory":true,"title":"Usage percentage","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"used":{"name":"used","type":"\u0005","is_mandatory":true,"title":"Used space in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"volume":{"name":"volume","type":"\u001bproxmox.storage.volume","title":"Volume stored on a Proxmox VE storage","desc":"Single volume on a storage, selected by `volid` (for example `proxmox.storage.volume(volid: \"local:backup/vzdump-qemu-100-2024_01_01-00_00_00.vma.zst\")`). Backups are the reason this matters most: `createdAt` says when a guest was last actually captured, which scheduled backup jobs alone cannot answer, and `encrypted`, `protected`, and `verification` report whether that capture is protected and known-good. The `contentType` field separates backups from ISO images, container templates, guest disks, and snippets, and `vm` and `container` resolve the guest a volume belongs to.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"volumes":{"name":"volumes","type":"\u0019\u001bproxmox.storage.volume","title":"Volumes stored on this storage","desc":"Covers every content class the storage holds: backup archives, ISO images, container templates, guest disks, and snippets. A shared storage is listed once; a local storage is listed from each node that has it, since each node holds an independent copy.","min_provider_version":"0.3.6","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE storage pool","desc":"Storage pool configured in the cluster, identified by `id` (for example `proxmox.storage(id: \"local-lvm\")`). Reports the storage `type` (dir, lvm, lvmthin, nfs, cifs, zfspool, ceph, etc.), allowed `content` types, filesystem `path` for local types, and whether the pool is `enabled` and `shared` across nodes. Capacity is reported through `total`, `used`, `available`, and `usagePercent`, and `encrypted` flags PBS-encrypted datastores.","min_provider_version":"0.1.1","defaults":"id type enabled","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.storage.volume":{"id":"proxmox.storage.volume","name":"proxmox.storage.volume","fields":{"container":{"name":"container","type":"\u001bproxmox.container","title":"Container that owns the volume; null when the volume belongs to a virtual machine","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"contentType":{"name":"contentType","type":"\u0007","is_mandatory":true,"title":"Content class of the volume","desc":"One of `backup`, `iso`, `vztmpl`, `images`, `rootdir`, or `snippets`. Derived from the volume identifier when the storage plugin does not report it.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"When the volume was created","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"encrypted":{"name":"encrypted","type":"\u0004","is_mandatory":true,"title":"Whether the volume is encrypted at rest","desc":"Only Proxmox Backup Server storages report this. True when the backup was written with an encryption key.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"encryptionFingerprint":{"name":"encryptionFingerprint","type":"\u0007","is_mandatory":true,"title":"Encryption key fingerprint, or `1` when the key is not identified; empty when unencrypted","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"format":{"name":"format","type":"\u0007","is_mandatory":true,"title":"Format identifier (`raw`, `qcow2`, `subvol`, `iso`, `tgz`, `pbs-vm`, and so on)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"node":{"name":"node","type":"\u0007","is_mandatory":true,"title":"Node the volume was listed from","desc":"A shared storage reports one copy from a single node. A local storage holds an independent copy on each node, so the same guest can have separate volumes here per node.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"nodeRef":{"name":"nodeRef","type":"\u001bproxmox.node","title":"Host the volume was listed from","desc":"Resolves `node` against the cluster. For a local storage this is the host that physically holds this copy. Null when the named node is no longer in the cluster.","min_provider_version":"0.4.2","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"notes":{"name":"notes","type":"\u0007","is_mandatory":true,"title":"First line of the notes attached to the volume; empty when none","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"parent":{"name":"parent","type":"\u0007","is_mandatory":true,"title":"Volume identifier of the parent, for linked clones; empty when standalone","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"protected":{"name":"protected","type":"\u0004","is_mandatory":true,"title":"Whether the volume is protected from automatic pruning","desc":"A protected backup survives retention policies. Currently reported for backups only.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"size":{"name":"size","type":"\u0005","is_mandatory":true,"title":"Volume size in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"storage":{"name":"storage","type":"\u0007","is_mandatory":true,"title":"Storage holding the volume","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"storageRef":{"name":"storageRef","type":"\u001bproxmox.storage","title":"Storage pool the volume sits on","desc":"Resolves `storage` against the cluster, so a volume can be audited against the pool's encryption setting, sharing, content classes, and capacity. Null when the named storage is no longer configured.","min_provider_version":"0.4.2","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"used":{"name":"used","type":"\u0005","is_mandatory":true,"title":"Used space in bytes","desc":"Most storage plugins do not report anything meaningful here; `size` is the reliable figure.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"verification":{"name":"verification","type":"\n","is_mandatory":true,"title":"Result of the last Proxmox Backup Server verification","desc":"Holds `state` (`ok` or `failed`) and the `upid` of the verification task. Empty on storages that do not verify, so an empty value means the backup was never verified rather than that it passed.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"vm":{"name":"vm","type":"\u001bproxmox.vm","title":"Guest that owns the volume; null for ISO images, templates, and snippets","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"vmid":{"name":"vmid","type":"\u0005","is_mandatory":true,"title":"VMID the volume belongs to; 0 when the volume has no owning guest","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"volid":{"name":"volid","type":"\u0007","is_mandatory":true,"title":"Volume identifier, in `\u003cstorage\u003e:\u003cpath\u003e` form","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Volume stored on a Proxmox VE storage","desc":"Single volume on a storage, selected by `volid` (for example `proxmox.storage.volume(volid: \"local:backup/vzdump-qemu-100-2024_01_01-00_00_00.vma.zst\")`). Backups are the reason this matters most: `createdAt` says when a guest was last actually captured, which scheduled backup jobs alone cannot answer, and `encrypted`, `protected`, and `verification` report whether that capture is protected and known-good. The `contentType` field separates backups from ISO images, container templates, guest disks, and snippets, and `vm` and `container` resolve the guest a volume belongs to.","min_provider_version":"0.3.6","defaults":"volid contentType createdAt size","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.subscription":{"id":"proxmox.subscription","name":"proxmox.subscription","fields":{"key":{"name":"key","type":"\u0007","is_mandatory":true,"title":"Subscription key","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"level":{"name":"level","type":"\u0007","is_mandatory":true,"title":"Subscription level (basic, standard, premium)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"nextDueDate":{"name":"nextDueDate","type":"\u0007","is_mandatory":true,"title":"Next due date","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"productName":{"name":"productName","type":"\u0007","is_mandatory":true,"title":"Product name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"regDate":{"name":"regDate","type":"\u0007","is_mandatory":true,"title":"Registration date","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"serverId":{"name":"serverId","type":"\u0007","is_mandatory":true,"title":"Server ID","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Subscription status (active, notfound, invalid)","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE subscription","desc":"Support subscription attached to a Proxmox node, covering its entitlement `status` (active, notfound, invalid), support `level` (basic, standard, premium), registration and renewal dates, and the server identifier the key is bound to. Use it in compliance checks that require nodes to carry an active, appropriately tiered subscription and to flag entitlements approaching their renewal.","min_provider_version":"0.1.1","defaults":"status level","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.token":{"id":"proxmox.token","name":"proxmox.token","fields":{"comment":{"name":"comment","type":"\u0007","is_mandatory":true,"title":"Token comment","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"expire":{"name":"expire","type":"\u0005","is_mandatory":true,"title":"Token expiration (unix timestamp, 0 = never)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Token ID (user@realm!tokenid)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"owner":{"name":"owner","type":"\u001bproxmox.user","title":"Resolved owner of this token (everything before the `!` in `id`)","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"privsep":{"name":"privsep","type":"\u0004","is_mandatory":true,"title":"Whether privilege separation is active","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE API token","desc":"API token belonging to a Proxmox user, identified by `id` in the form `user@realm!tokenid`. Reports the token `comment`, `expire` time (Unix timestamp, 0 = never), and whether privilege separation is active via `privsep`. When `privsep` is true the token's permissions are limited to a subset of the owner's privileges, which makes tokens a useful audit surface for least-privilege review of non-interactive access.","min_provider_version":"0.1.1","defaults":"id privsep","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.user":{"id":"proxmox.user","name":"proxmox.user","fields":{"email":{"name":"email","type":"\u0007","is_mandatory":true,"title":"Email address","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"enable":{"name":"enable","type":"\u0004","is_mandatory":true,"title":"Whether the user is enabled","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"expire":{"name":"expire","type":"\u0005","is_mandatory":true,"title":"Account expiration (unix timestamp, 0 = never)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"firstname":{"name":"firstname","type":"\u0007","is_mandatory":true,"title":"First name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"groupRefs":{"name":"groupRefs","type":"\u0019\u001bproxmox.group","title":"Resolved group memberships","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"groups":{"name":"groups","type":"\u0019\u0007","is_mandatory":true,"title":"Raw group membership names","desc":"Deprecated in favor of `groupRefs`.","provider":"go.mondoo.com/mql/v13/providers/proxmox","maturity":"deprecated"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"User ID (user@realm)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"lastname":{"name":"lastname","type":"\u0007","is_mandatory":true,"title":"Last name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"realm":{"name":"realm","type":"\u0007","is_mandatory":true,"title":"Authentication realm (pam, pve, ldap, ad)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"realmType":{"name":"realmType","type":"\u0007","is_mandatory":true,"title":"Authentication realm type (pam, pve, ldap, ad, openid)","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"tfaFactors":{"name":"tfaFactors","type":"\u0019\u0007","title":"Enrolled multi-factor authentication factor types","desc":"One per enrolled second-factor: `totp`, `webauthn`, `recovery`, or `yubico`. An empty list means the user has no TFA enrolled.","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"tfaLockedUntil":{"name":"tfaLockedUntil","type":"\u0005","is_mandatory":true,"title":"Unix timestamp until which the user is locked out due to failed TFA attempts; 0 if not locked","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"tokens":{"name":"tokens","type":"\u0019\u001bproxmox.token","title":"API tokens for this user","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE user","desc":"User account in the Proxmox cluster, identified by `id` in the form `user@realm`. Auditing accounts surfaces whether each is `enable`d, its `email`, `firstname`, `lastname`, `realm` (pam, pve, ldap, ad), `groups` membership, and `expire` time (Unix timestamp, 0 = never). Multi-factor enrollment is available through `tfaFactors` and `tfaLockedUntil`, the realm authentication type through `realmType`, and API tokens belonging to the user through `tokens`.","min_provider_version":"0.1.1","defaults":"id enable realm","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.vm":{"id":"proxmox.vm","name":"proxmox.vm","fields":{"agent":{"name":"agent","type":"\u0004","title":"Whether the QEMU guest agent is enabled","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"aliases":{"name":"aliases","type":"\u0019\u001bproxmox.firewall.alias","title":"VM-level firewall aliases","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"args":{"name":"args","type":"\u0007","title":"Raw KVM/QEMU command-line arguments passed to the hypervisor","desc":"Anything in here bypasses the normal config schema and can grant the VM extra device passthrough, capabilities, or host filesystem access. Empty when no overrides are configured.","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"backups":{"name":"backups","type":"\u0019\u001bproxmox.storage.volume","title":"Backup archives held for this virtual machine","desc":"Every backup volume across all storages that owns this VMID, newest first. Reports what was actually captured, which scheduled backup jobs alone cannot confirm. Empty when the guest has never been backed up to a storage this token can read.","min_provider_version":"0.3.6","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"bios":{"name":"bios","type":"\u0007","title":"BIOS type (seabios, ovmf)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"bootOrder":{"name":"bootOrder","type":"\u0007","title":"Boot order string","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"ciCustom":{"name":"ciCustom","type":"\n","title":"Custom cloud-init snippet references","desc":"Maps the four cloud-init sections (`user`, `network`, `meta`, `vendor`) to `\u003cstorage\u003e:snippets/\u003cfile\u003e` paths. Empty when the VM uses the default Proxmox-generated config.","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"cipasswordSet":{"name":"cipasswordSet","type":"\u0004","title":"Whether a cloud-init password is configured for the VM","desc":"True when the `cipassword` config key is set. The actual value is never read or surfaced through the resource — auditing should focus on whether a password is present, not on the password itself.","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"ciuser":{"name":"ciuser","type":"\u0007","title":"Default username injected by cloud-init; empty when not configured","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"config":{"name":"config","type":"\n","title":"Raw VM configuration","desc":"The complete per-VM config as returned by the PVE API, keyed by the raw config keys (`cores`, `memory`, `ostype`, `boot`, `net0`, `scsi0`, and so on). The common keys are also exposed as their own fields on this resource (`osType`, `machine`, `bios`, `bootOrder`); this dict is the escape hatch for keys not modeled individually.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"cpu":{"name":"cpu","type":"\u0006","is_mandatory":true,"title":"Current CPU usage (fraction)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"description":{"name":"description","type":"\u0007","title":"VM description/notes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"disk":{"name":"disk","type":"\u0005","is_mandatory":true,"title":"Current disk usage in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"diskread":{"name":"diskread","type":"\u0005","is_mandatory":true,"title":"Total bytes read from disk","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"disks":{"name":"disks","type":"\u0019\u001bproxmox.vm.disk","title":"Disk devices attached to the VM","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"diskwrite":{"name":"diskwrite","type":"\u0005","is_mandatory":true,"title":"Total bytes written to disk","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"firewallOptions":{"name":"firewallOptions","type":"\u001bproxmox.firewall.options","title":"VM-level firewall options (enable, policy_in, policy_out, dhcp, ndp, macfilter)","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"firewallRules":{"name":"firewallRules","type":"\u0019\u001bproxmox.firewall.rule","title":"VM-level firewall rules","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"hookscript":{"name":"hookscript","type":"\u0007","title":"Path to a hook script run before/after VM lifecycle events","desc":"Stored as `\u003cstorage\u003e:snippets/\u003cfile\u003e`. Treat as a potential arbitrary-execution surface on the hypervisor host — anyone who can edit the snippet can run code as root during VM start, stop, pre-backup, etc.","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"id":{"name":"id","type":"\u0005","is_mandatory":true,"title":"VMID","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"ipsets":{"name":"ipsets","type":"\u0019\u001bproxmox.firewall.ipset","title":"VM-level IPsets","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"lastBackupAt":{"name":"lastBackupAt","type":"\t","title":"When this virtual machine was last backed up","desc":"Creation time of the newest backup archive owned by this guest. Null when no backup exists.","min_provider_version":"0.3.6","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"lock":{"name":"lock","type":"\u0007","title":"Acquired lock blocking other operations","desc":"One of `backup`, `migrate`, `snapshot`, `rollback`, `clone`, `create`, `destroy`, or empty when the VM is not locked.","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"machine":{"name":"machine","type":"\u0007","title":"Machine type (pc, q35)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"maxcpu":{"name":"maxcpu","type":"\u0005","is_mandatory":true,"title":"Number of configured vCPUs","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"maxdisk":{"name":"maxdisk","type":"\u0005","is_mandatory":true,"title":"Configured maximum disk size in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"maxmem":{"name":"maxmem","type":"\u0005","is_mandatory":true,"title":"Configured maximum memory in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"mem":{"name":"mem","type":"\u0005","is_mandatory":true,"title":"Current memory usage in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"VM display name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"nameserver":{"name":"nameserver","type":"\u0007","title":"DNS nameservers cloud-init writes to the guest (space-separated)","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"netin":{"name":"netin","type":"\u0005","is_mandatory":true,"title":"Total incoming network bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"netout":{"name":"netout","type":"\u0005","is_mandatory":true,"title":"Total outgoing network bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"network":{"name":"network","type":"\u001bproxmox.vm.network","title":"Proxmox VE VM network interface","desc":"Network interface attached to a virtual machine, keyed by the slot `id` (e.g. `net0`, `net1`). Covers the NIC `model` (virtio, e1000, etc.), `macAddress`, connected `bridge`, VLAN `tag`, and whether the per-NIC `firewall` is enabled.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"networks":{"name":"networks","type":"\u0019\u001bproxmox.vm.network","title":"Network interfaces attached to the VM","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"node":{"name":"node","type":"\u0007","is_mandatory":true,"title":"Node this VM is running on","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"nodeRef":{"name":"nodeRef","type":"\u001bproxmox.node","title":"Host the VM runs on","desc":"Resolves `node` against the cluster, giving access to the host's status, address, kernel, subscription level, and firewall from the VM itself. Null when the named node is no longer in the cluster.","min_provider_version":"0.4.2","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"osType":{"name":"osType","type":"\u0007","title":"OS type (l26, win10, etc.)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"pciDevice":{"name":"pciDevice","type":"\u001bproxmox.vm.pciDevice","title":"Proxmox VE VM PCI passthrough entry","desc":"PCI passthrough entry (`hostpci\u003cn\u003e`) on a virtual machine. PVE accepts two forms: a direct PCI address (`0000:01:00.0`, with an optional `.func` suffix for multi-function devices) or a named `mapping=\u003cname\u003e` reference to a cluster-defined PCI mapping. The extra knobs PVE exposes (express vs legacy bus, ROM-BAR visibility, VGA tag, mdev type for vGPU) are surfaced so audits can flag risky configurations (e.g. `xVga = true` with no IOMMU isolation).","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"pciDevices":{"name":"pciDevices","type":"\u0019\u001bproxmox.vm.pciDevice","title":"PCI devices passed through to the VM","desc":"Parsed from `hostpci0`..`hostpci15` config keys. Each entry grants the guest direct access to host PCIe hardware — an audit risk since it bypasses the virtualization boundary for that device.","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"pool":{"name":"pool","type":"\u001bproxmox.pool","title":"Resource pool this VM belongs to; null when unassigned","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"protection":{"name":"protection","type":"\u0004","title":"Whether the VM is protected from removal","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"searchDomain":{"name":"searchDomain","type":"\u0007","title":"DNS search domain cloud-init writes to the guest","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"serialPort":{"name":"serialPort","type":"\u001bproxmox.vm.serialPort","title":"Proxmox VE VM serial port","desc":"Serial port attached to a virtual machine, keyed by `id` (`serial0` through `serial3`). The `target` reports either the literal `socket` (VM speaks over a Unix-domain socket on the host) or a host device path like `/dev/ttyS0`. A host-device target is a pivot opportunity that audits should review.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"serialPorts":{"name":"serialPorts","type":"\u0019\u001bproxmox.vm.serialPort","title":"Serial ports attached to the VM","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"snapshot":{"name":"snapshot","type":"\u001bproxmox.vm.snapshot","title":"Proxmox VE VM snapshot","desc":"Point-in-time snapshot of a virtual machine. Covers the snapshot `name`, `description`, `parent` snapshot name, creation time via `snaptime` (Unix timestamp), and whether VM RAM state is captured in `vmstate`.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"snapshots":{"name":"snapshots","type":"\u0019\u001bproxmox.vm.snapshot","title":"VM snapshots","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"sshkeys":{"name":"sshkeys","type":"\u0007","title":"URL-encoded list of SSH public keys cloud-init writes to the default user; empty when not configured","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Current status (running, stopped, paused)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"tags":{"name":"tags","type":"\u0019\u0007","title":"Tags assigned to the VM","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"template":{"name":"template","type":"\u0004","is_mandatory":true,"title":"Whether this VM is a template","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"update":{"name":"update","type":"\u001bproxmox.vm.update","title":"Proxmox VE VM package update","desc":"Installed package and its update status on a virtual machine, retrieved via the QEMU guest agent. Covers the package `name`, `installedVersion`, available `newVersion`, whether an update is available via `upgradable`, and `severity` (security, enhancement).","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"updates":{"name":"updates","type":"\u0019\u001bproxmox.vm.update","title":"Installed packages and available updates","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"uptime":{"name":"uptime","type":"\u0005","is_mandatory":true,"title":"Uptime in seconds","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"usbDevice":{"name":"usbDevice","type":"\u001bproxmox.vm.usbDevice","title":"Proxmox VE VM USB passthrough entry","desc":"USB passthrough entry (`usb\u003cn\u003e`) on a virtual machine. PVE supports four target forms: vendor:product IDs (`host=1234:5678`), USB bus/port paths (`host=1-2.3`), host device paths (typically `/dev/...`), and the SPICE redirection sentinel. The `usb3` flag requests USB-3 emulation regardless of the underlying device class.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true},"usbDevices":{"name":"usbDevices","type":"\u0019\u001bproxmox.vm.usbDevice","title":"USB devices passed through to the VM","desc":"Parsed from `usb0`..`usb14`. Targets are either `host=vendor:product` vendor IDs, USB bus paths, the SPICE redirection sentinel, or host device paths — all of which surface direct host-USB access.","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"vga":{"name":"vga","type":"\u0007","title":"Display adapter configuration","desc":"Examples: `qxl`, `std`, `serial0`, `none`. Empty selects the PVE default.","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE virtual machine","desc":"QEMU virtual machine in the cluster, identified by numeric `id` and display `name`. Current `status` (running, stopped, paused), the `node` it runs on, and live resource usage (`cpu`, `mem`, `disk`, `netin`, `netout`) come from the cluster resource list, while configuration details (OS type, machine type, BIOS, boot order, guest agent state, protection, hookscript, and passthrough devices) are read from the per-VM config. Attached `networks`, `disks`, and point-in-time `snapshots` model the VM's devices; `firewallRules`, `firewallOptions`, `ipsets`, and `aliases` cover the VM-level firewall; and `updates` lists installed packages with available upgrades (requires the QEMU guest agent).","min_provider_version":"0.1.1","defaults":"id name status","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.vm.disk":{"id":"proxmox.vm.disk","name":"proxmox.vm.disk","fields":{"backup":{"name":"backup","type":"\u0004","is_mandatory":true,"title":"Whether backup is enabled for this disk","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"cache":{"name":"cache","type":"\u0007","is_mandatory":true,"title":"Cache mode (none, writethrough, writeback, etc.)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"format":{"name":"format","type":"\u0007","is_mandatory":true,"title":"Disk format (qcow2, raw, vmdk)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Disk ID (scsi0, virtio0, ide0, ...)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"iothread":{"name":"iothread","type":"\u0004","is_mandatory":true,"title":"Whether iothread is enabled","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"size":{"name":"size","type":"\u0005","is_mandatory":true,"title":"Disk size in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"storage":{"name":"storage","type":"\u0007","is_mandatory":true,"title":"Storage pool name","desc":"Deprecated in favor of `storageRef`, which resolves the same pool as a storage resource.","provider":"go.mondoo.com/mql/v13/providers/proxmox","maturity":"deprecated"},"storageRef":{"name":"storageRef","type":"\u001bproxmox.storage","title":"Resolved backing storage pool","min_provider_version":"0.1.9","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE VM disk","desc":"Disk device attached to a virtual machine, keyed by the controller slot `id` (e.g. `scsi0`, `virtio0`, `ide0`). Covers the `storage` pool name, disk `size` in bytes, `format` (qcow2, raw, vmdk), `cache` mode, and whether `iothread` and `backup` are enabled for this disk.","min_provider_version":"0.1.1","defaults":"id storage size","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.vm.network":{"id":"proxmox.vm.network","name":"proxmox.vm.network","fields":{"bridge":{"name":"bridge","type":"\u0007","is_mandatory":true,"title":"Bridge this NIC is connected to","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"firewall":{"name":"firewall","type":"\u0004","is_mandatory":true,"title":"Whether the firewall is enabled for this NIC","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Interface ID (net0, net1, ...)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"macAddress":{"name":"macAddress","type":"\u0007","is_mandatory":true,"title":"MAC address","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"model":{"name":"model","type":"\u0007","is_mandatory":true,"title":"NIC model (virtio, e1000, etc.)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"tag":{"name":"tag","type":"\u0005","is_mandatory":true,"title":"VLAN tag (0 = none)","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE VM network interface","desc":"Network interface attached to a virtual machine, keyed by the slot `id` (e.g. `net0`, `net1`). Covers the NIC `model` (virtio, e1000, etc.), `macAddress`, connected `bridge`, VLAN `tag`, and whether the per-NIC `firewall` is enabled.","min_provider_version":"0.1.1","defaults":"id model bridge","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.vm.pciDevice":{"id":"proxmox.vm.pciDevice","name":"proxmox.vm.pciDevice","fields":{"address":{"name":"address","type":"\u0007","is_mandatory":true,"title":"PCI address when configured directly; empty when `mapping` is used","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"mapping":{"name":"mapping","type":"\u0007","is_mandatory":true,"title":"Cluster-defined PCI mapping name when configured by reference; empty otherwise","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"mdev":{"name":"mdev","type":"\u0007","is_mandatory":true,"title":"Mediated-device type for vGPU passthrough; empty for direct passthrough","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"pciExpress":{"name":"pciExpress","type":"\u0004","is_mandatory":true,"title":"Whether the device is exposed as PCI Express (true) or legacy PCI (false)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"raw":{"name":"raw","type":"\u0007","is_mandatory":true,"title":"Raw `hostpci\u003cn\u003e` config line for any options not surfaced above","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"romBar":{"name":"romBar","type":"\u0004","is_mandatory":true,"title":"Whether the ROM BAR is visible to the guest","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"slot":{"name":"slot","type":"\u0007","is_mandatory":true,"title":"Config slot (`hostpci0` through `hostpci15`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"xVga":{"name":"xVga","type":"\u0004","is_mandatory":true,"title":"Whether this device is the primary VGA for the guest","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE VM PCI passthrough entry","desc":"PCI passthrough entry (`hostpci\u003cn\u003e`) on a virtual machine. PVE accepts two forms: a direct PCI address (`0000:01:00.0`, with an optional `.func` suffix for multi-function devices) or a named `mapping=\u003cname\u003e` reference to a cluster-defined PCI mapping. The extra knobs PVE exposes (express vs legacy bus, ROM-BAR visibility, VGA tag, mdev type for vGPU) are surfaced so audits can flag risky configurations (e.g. `xVga = true` with no IOMMU isolation).","min_provider_version":"0.1.9","defaults":"slot address mapping","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.vm.serialPort":{"id":"proxmox.vm.serialPort","name":"proxmox.vm.serialPort","fields":{"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Serial port slot (serial0..serial3)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"target":{"name":"target","type":"\u0007","is_mandatory":true,"title":"Target — `socket` or a host device path (e.g. `/dev/ttyS0`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE VM serial port","desc":"Serial port attached to a virtual machine, keyed by `id` (`serial0` through `serial3`). The `target` reports either the literal `socket` (VM speaks over a Unix-domain socket on the host) or a host device path like `/dev/ttyS0`. A host-device target is a pivot opportunity that audits should review.","min_provider_version":"0.1.9","defaults":"id target","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.vm.snapshot":{"id":"proxmox.vm.snapshot","name":"proxmox.vm.snapshot","fields":{"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Snapshot description","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Snapshot name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"parent":{"name":"parent","type":"\u0007","is_mandatory":true,"title":"Parent snapshot name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"snaptime":{"name":"snaptime","type":"\u0005","is_mandatory":true,"title":"Snapshot creation time (unix timestamp)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"vmstate":{"name":"vmstate","type":"\u0004","is_mandatory":true,"title":"Whether VM state (RAM) is included","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE VM snapshot","desc":"Point-in-time snapshot of a virtual machine. Covers the snapshot `name`, `description`, `parent` snapshot name, creation time via `snaptime` (Unix timestamp), and whether VM RAM state is captured in `vmstate`.","min_provider_version":"0.1.1","defaults":"name snaptime","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.vm.update":{"id":"proxmox.vm.update","name":"proxmox.vm.update","fields":{"installedVersion":{"name":"installedVersion","type":"\u0007","is_mandatory":true,"title":"Currently installed version","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Package name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"newVersion":{"name":"newVersion","type":"\u0007","is_mandatory":true,"title":"Available new version (empty if no update)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"severity":{"name":"severity","type":"\u0007","is_mandatory":true,"title":"Update severity (security, enhancement)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"upgradable":{"name":"upgradable","type":"\u0004","is_mandatory":true,"title":"Whether an update is available","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE VM package update","desc":"Installed package and its update status on a virtual machine, retrieved via the QEMU guest agent. Covers the package `name`, `installedVersion`, available `newVersion`, whether an update is available via `upgradable`, and `severity` (security, enhancement).","min_provider_version":"0.1.1","defaults":"name severity upgradable","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.vm.usbDevice":{"id":"proxmox.vm.usbDevice","name":"proxmox.vm.usbDevice","fields":{"raw":{"name":"raw","type":"\u0007","is_mandatory":true,"title":"Raw `usb\u003cn\u003e` config line","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"slot":{"name":"slot","type":"\u0007","is_mandatory":true,"title":"Config slot (`usb0` through `usb14`)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"target":{"name":"target","type":"\u0007","is_mandatory":true,"title":"Target as written in the config","desc":"One of: vendor:product (e.g. `1234:5678`), USB bus path (e.g. `1-2.3`), host device path (`/dev/...`), or the literal `spice` sentinel for redirected USB.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"usb3":{"name":"usb3","type":"\u0004","is_mandatory":true,"title":"Whether USB-3 emulation is forced","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE VM USB passthrough entry","desc":"USB passthrough entry (`usb\u003cn\u003e`) on a virtual machine. PVE supports four target forms: vendor:product IDs (`host=1234:5678`), USB bus/port paths (`host=1-2.3`), host device paths (typically `/dev/...`), and the SPICE redirection sentinel. The `usb3` flag requests USB-3 emulation regardless of the underlying device class.","min_provider_version":"0.1.9","defaults":"slot target","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"proxmox.zfs":{"id":"proxmox.zfs","fields":{"pool":{"name":"pool","type":"\u001bproxmox.zfs.pool","title":"Proxmox VE ZFS pool","desc":"ZFS storage pool managed by a Proxmox node, selected by `name` (for example `proxmox.zfs.pools.where(name == \"rpool\")`). Capacity and consumption are reported through `size`, `alloc`, and `free`, along with the average `fragmentation` percentage and the `dedupRatio`. The `health` field carries the pool condition (ONLINE, DEGRADED, FAULTED, UNAVAIL, REMOVED), the primary signal for detecting a failing or degraded array. The vdev topology, latest scrub status, and error counters from `zpool status` are exposed via `state`, `scan`, `errors`, and the recursive `children` device tree, so audits can recurse to individual leaf disks.","provider":"go.mondoo.com/mql/v13/providers/proxmox","is_implicit_resource":true}},"is_extension":true},"proxmox.zfs.pool":{"id":"proxmox.zfs.pool","name":"proxmox.zfs.pool","fields":{"alloc":{"name":"alloc","type":"\u0005","is_mandatory":true,"title":"Allocated bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"children":{"name":"children","type":"\u0019\n","title":"vdev / child-device tree","desc":"Each entry is a dict describing one vdev or device: `name` (device or vdev label), `state` (ONLINE, DEGRADED, FAULTED, etc.), `read`/`write`/`cksum` error counters, `msg` (status note from `zpool status`), `type` (topology role such as mirror or raidz), `leaf` (true for a physical leaf disk), and a recursive `children` array. The shape mirrors the `zpool status` output so audits can recurse from the pool root down to leaf disks.","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"dedupRatio":{"name":"dedupRatio","type":"\u0006","is_mandatory":true,"title":"Deduplication ratio (1.0 = no dedup, higher = more savings)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"errors":{"name":"errors","type":"\u0007","title":"Pool-wide error counter line from `zpool status`","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"fragmentation":{"name":"fragmentation","type":"\u0005","is_mandatory":true,"title":"Fragmentation percentage (0-100)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"free":{"name":"free","type":"\u0005","is_mandatory":true,"title":"Free bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"health":{"name":"health","type":"\u0007","is_mandatory":true,"title":"Pool health (ONLINE, DEGRADED, FAULTED, UNAVAIL, REMOVED)","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Pool name","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"scan":{"name":"scan","type":"\u0007","title":"Latest scrub line from `zpool status`","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"size":{"name":"size","type":"\u0005","is_mandatory":true,"title":"Pool capacity in bytes","provider":"go.mondoo.com/mql/v13/providers/proxmox"},"state":{"name":"state","type":"\u0007","title":"Pool state from `zpool status` (e.g. ONLINE)","provider":"go.mondoo.com/mql/v13/providers/proxmox"}},"title":"Proxmox VE ZFS pool","desc":"ZFS storage pool managed by a Proxmox node, selected by `name` (for example `proxmox.zfs.pools.where(name == \"rpool\")`). Capacity and consumption are reported through `size`, `alloc`, and `free`, along with the average `fragmentation` percentage and the `dedupRatio`. The `health` field carries the pool condition (ONLINE, DEGRADED, FAULTED, UNAVAIL, REMOVED), the primary signal for detecting a failing or degraded array. The vdev topology, latest scrub status, and error counters from `zpool status` are exposed via `state`, `scan`, `errors`, and the recursive `children` device tree, so audits can recurse to individual leaf disks.","min_provider_version":"0.1.9","defaults":"name health size","provider":"go.mondoo.com/mql/v13/providers/proxmox"}}}