Proximo: a Proxmox MCP that plans before it acts
Manages Proxmox VE, Backup Server, Mail Gateway and Datacenter Manager. Read-only by default; each change shows its blast radius first and is logged.
Project and installation docs
View projecthttps://github.com/john-broadway/proximo
Handing a Proxmox cluster to an agent usually means choosing between a read-only viewer and a root token plus hope. Proximo takes the middle road: the agent can make changes, but each one first comes back as a plan naming the guests, nodes and disks at risk, runs only after you confirm, and is recorded in a hash-chained audit ledger. It’s a community project, since Proxmox has no official MCP server, and it had about 50 stars as of 2026-10-06.
What it does
- Four products: tools for Proxmox VE, Proxmox Backup Server, Proxmox Mail Gateway and Datacenter Manager in one server.
- Plan, then act: the first call for any mutation returns a recorded plan and blast radius; it runs only when called again with
confirm=true. - Undo where possible: config changes return the prior config for
pve_guest_config_revert, andct_execwithsnapshot=truesnapshots first and refuses to run if it can’t. - Tamper-evident records: an HMAC-SHA256 hash-chained ledger logs every action, and
audit_verifycatches edited, reordered or inserted entries. - Diagnostics inside containers: optional command execution inside LXC containers, gated by a container ID allowlist, for questions like why container 105 is thrashing.
Who it’s for
- Homelab owners running a stack of VMs and containers on Proxmox who want help with status checks and routine upkeep.
- Small ops teams that want a human sign-off before any agent touches infrastructure.
Setup
Needs uv and a Proxmox API token, ideally read-only to start. The token lives in a file referenced by path, never inlined in config:
claude mcp add proximo --env PROXIMO_API_BASE_URL=https://your-pve:8006/api2/json \
--env PROXIMO_NODE=your-node --env PROXIMO_TOKEN_PATH=/path/to/token-file -- uvx proximo-proxmox
No token yet? uvx proximo-proxmox mint prints a least-privilege runbook, and uvx proximo-proxmox doctor checks what your token can actually do.
Our take
A small project worth watching, because it takes the question of trusting agents with infrastructure seriously: plans, an audit ledger, rollback, out-of-band approval (PROXIMO_CONSENT_DIR) and a kill switch (PROXIMO_CONTAIN_TRIP_PATH) stack on top of each other. There are 924 tools in total, but by default only a handful of search-and-call entry tools load, about 1,700 tokens, with the rest callable by name. Caveats: the README itself says risk ratings are an advisory heuristic and LOW doesn’t mean safe; the real floor is the Proxmox token you mint. One person maintains it, it was created in June 2026, and the docs are written in a flamboyant style, so judge it by SECURITY.md and VERIFY.md. Licensed Apache-2.0.