Independent Proxmox VE iOS app

Proxmox VE, managed from iPhone and iPad.

Monitor nodes, manage VMs and LXCs, and connect with Smart Connect, VNC, SSH, or App-level Tailnet.

Available on the App Store

Built around the work

A clear path from status to action.

Six capabilities, organized around the decisions you make while managing the infrastructure you are authorized to access.

01

Infrastructure at a glance

See the state of your fleet before you decide what to do next.

Dashboard summaries bring nodes, VMs, LXCs, CPU, memory, storage, and recent tasks into one native view. Refresh when you need it and arrange supported cards around your workflow.

02

VM and LXC lifecycle

Browse, search, filter, and act on the workloads you are authorized to manage.

Review guest state and configuration, then use supported power, snapshot, backup, creation, and management workflows. Every action remains subject to the capabilities and permissions of your Proxmox VE server.

Creation and advanced management workflows remain subject to server capabilities and permissions.

03

VNC and SSH, in context

Open the right console or terminal from the resource you are already viewing.

Use the in-app VNC console for running VMs, or connect with SSH Profiles bound to a Node, VM, or LXC. SSH supports password or private-key authentication and confirms SSH Host Keys before trust is saved.

VNC Console and SSH Terminal require a running VM or valid SSH host and credentials as applicable.

04

Smart Connect

Use a route plan that respects the network you are actually on.

When your current Wi-Fi matches a configured home SSID, Prox Deck uses the Local route only; if it fails, it does not fall back. On other networks, without Wi-Fi, or when iOS cannot provide the SSID, enabled Public and Tailnet routes are tried in the order you choose.

Location permission is used only when Smart Connect needs the current Wi-Fi SSID; Prox Deck does not maintain a location history.

05

App-level Tailnet

Authorize Tailscale inside Prox Deck without changing traffic for the rest of your device.

A single App-level Tailnet runtime is shared by Prox Deck requests across your configured servers. It can reach the Tailnet or a configured subnet route, but it is not a system VPN and does not route traffic from other apps.

App-level Tailnet connectivity requires Tailscale authorization plus a reachable Tailnet or subnet route.

06

Security and optional sync

Keep credentials, trust decisions, and optional sync boundaries explicit.

Secrets use Keychain, runtime sessions stay in memory, and self-signed TLS trust is scoped to the selected route. Optional iCloud Sync is explicitly enabled, uses your private CloudKit database for an allowlisted set of configuration data, and converges when devices are available rather than promising real-time sync.

When optional iCloud Sync is enabled, only password-auth PVE passwords may use iCloud Keychain.

Smart Connect

One server. The right route for the network you are on.

Smart Connect keeps a server-level plan clear instead of guessing at a global network state.

  1. At homeA matching configured Wi-Fi SSID uses the Local route only. A failure stays a Local-route failure; there is no fallback.
  2. ElsewhereOn another network, with no Wi-Fi, or when iOS cannot provide the SSID, enabled Public and Tailnet routes are tried in your configured order.
  3. Tailnet scopeOne shared App-level Tailnet runtime serves Prox Deck requests. It is not a system VPN and does not route traffic from other apps.

iOS location permission is used only when Smart Connect needs the current Wi-Fi SSID. Prox Deck does not maintain a location history.

Security summary

Clear boundaries for secrets, trust, and control.

Secrets

Passwords, API Token secrets, SSH keys, and passphrases use Keychain. PVE Ticket, CSRF token, cookies, authorization headers, and active SSH sessions stay in memory.

Trust

HTTPS verification is the default. Self-signed TLS trust is scoped to a selected route, while SSH Host Key trust stays device-local.

Control

Face ID or Touch ID can protect selected servers and sensitive setting changes. Saved operation logs contain summaries and exclude sensitive values.

Requirements

Bring your own infrastructure.

Prox Deck connects to the PVE endpoint you configure. Features remain subject to your server, network, and permissions.

  • An iPhone or iPad with iOS or iPadOS 18.1 or later.
  • A Proxmox VE server you own or are authorized to access.
  • A valid PVE account and the permissions required for each action.
  • Network reachability to the PVE endpoint you configure.
  • An SSH host and valid credentials for SSH features.
  • A running VM and appropriate PVE permissions for VNC.
  • A Tailscale account or authorization and a reachable Tailnet or subnet route for Tailnet features.
  • An available iCloud account and network connection when you choose to enable optional iCloud Sync.

FAQ

Answers before you connect.

What is Prox Deck?

Prox Deck is an independent third-party native iPhone and iPad client for monitoring and managing Proxmox VE infrastructure. It is not a Proxmox product or an official Proxmox client.

What can I manage with Prox Deck?

You can monitor Proxmox VE nodes, storage, tasks, VMs, and LXCs; use supported guest lifecycle actions; and open VNC or SSH sessions when the resource, account permissions, and network allow it.

What do I need to use it?

You need an iPhone or iPad running iOS or iPadOS 18.1 or later, a Proxmox VE server you own or are authorized to access, a valid account with the permissions needed for each action, and network reachability to the endpoint you configure.

Does Prox Deck send my PVE management traffic through its own cloud?

Routine PVE management traffic connects to the endpoint you configure. Optional services have separate data flows: iCloud Sync, App Store and RevenueCat purchase services, Tailscale connectivity, and approved icon libraries are described in the Privacy Policy.

How does Smart Connect choose a route?

When the current Wi-Fi matches one of your configured home SSIDs, Smart Connect uses the Local route only. If that route fails, it does not fall back. On other networks, with no Wi-Fi, or when iOS cannot provide the SSID, enabled Public and Tailnet routes are tried in the order you configure.

Is the built-in Tailnet a system-wide VPN?

No. Tailnet connectivity is used only for Prox Deck requests. It does not configure a system-wide VPN or route traffic from other apps.