# netbox-proxbox v0.0.29

v0.0.29

| Field |Value |
| --- | --- |
| Canonical URL | https://emersonfelipesp.com/netbox-proxbox/releases/v0.0.29 |
| GitHub URL | https://github.com/emersonfelipesp/netbox-proxbox/releases/tag/v0.0.29 |
| Tag | v0.0.29 |
| State | latest |
| Author | emersonfelipesp |
| Created | 2026-10-05 12:49 UTC |
| Published | 2026-10-05 12:54 UTC |
| Target | main |
| Synced | 2026-10-05 13:36 UTC |
| Assets | 0 |

## Release notes

## netbox-proxbox 0.0.29 — security hardening

Supports NetBox 4.5.8 through 4.7.0. Pairs with proxbox-api 0.0.23.post3, proxmox-sdk 0.0.15, and netbox-sdk 0.0.13.

### Security
- **Sensitive data:** credential export, SSH credential secret reads, and the settings runtime key require an active superuser or an explicit per-user sensitive-data grant. Change-log snapshots of credential-bearing objects are redacted.
- **Connection-target approval:** credentials are sent only to a Proxmox or NetBox endpoint whose exact connection target was approved; editing the target clears the approval.
- **Scoped reads and actions:** plugin settings reads require view permission; HA data covers only endpoints the caller may view; HA arm/disarm requires the grantable `run_proxmox_action` action, skips endpoints with writes disabled, and reports per-cluster backend errors as failures.
- **WebSocket sync:** the server-side sync route no longer starts work on GET; syncs require an authorized, CSRF-protected POST.
- **Input validation:** Proxmox node, storage, guest type, VM ID, and firewall identifiers are validated before they reach backend request paths.
- **Secure defaults:** new endpoints default to HTTPS and TLS verification, the process-wide certificate bundle override is removed, and new encryption keys must be canonical Fernet keys. System checks `netbox_proxbox.W100`–`W105` report insecure existing configuration.
- **Dependencies:** raised security floors for Django, oauthlib, PyJWT, social-auth-core, urllib3, and virtualenv.

### Fixes
- The Proxbox home page and the NetBox endpoint list no longer fail with a server error on NetBox 4.7.
- Virtual-machine synchronization no longer stops with a duplicate node-device claim when paired with proxbox-api 0.0.23.post3.
- Cluster virtual-machine bulk deletion is limited to the active cluster and reports missing or mismatched records.

### Upgrade notes
- Apply the single migration `0104_security_hardening`. Existing endpoints keep their stored transport settings.
- Approve each endpoint's connection target before synchronization resumes.
- Grant `run_proxmox_action` to operators who use HA arm/disarm.
- Automation that creates plain-HTTP backend endpoints must send `use_https: false`.
- Rotate legacy raw encryption keys (`netbox_proxbox.W104`).

### Known limitation
Node device identity is not yet scoped by Proxmox endpoint. If two Proxmox endpoints use the same cluster name and node name, give them distinct names until a later release adds endpoint scoping.

### Version note
Version 0.0.28 is not used: its only published candidate predates this release's schema change, and each release ships exactly one migration.

Full notes: [docs/release-notes/version-0.0.29.md](https://github.com/emersonfelipesp/netbox-proxbox/blob/main/docs/release-notes/version-0.0.29.md)

## Assets

No binary assets attached.

Source archives:

| Format |URL |
| --- | --- |
| zip | https://api.github.com/repos/emersonfelipesp/netbox-proxbox/zipball/v0.0.29 |
| tar.gz | https://api.github.com/repos/emersonfelipesp/netbox-proxbox/tarball/v0.0.29 |
