Frequently asked questions
Proxmox VE iOS app questions, answered.
Connection routes, optional services, credentials, and trust decisions have precise boundaries. Read the Privacy Policy and Security pages for more detail.
What is Prox Deck?
Prox Deck is an independent third-party native iPhone and iPad client for monitoring and managing Proxmox VE infrastructure. It is not a Proxmox product or an official Proxmox client.
What can I manage with Prox Deck?
You can monitor Proxmox VE nodes, storage, tasks, VMs, and LXCs; use supported guest lifecycle actions; and open VNC or SSH sessions when the resource, account permissions, and network allow it.
What do I need to use it?
You need an iPhone or iPad running iOS or iPadOS 18.1 or later, a Proxmox VE server you own or are authorized to access, a valid account with the permissions needed for each action, and network reachability to the endpoint you configure.
Does Prox Deck send my PVE management traffic through its own cloud?
Routine PVE management traffic connects to the endpoint you configure. Optional services have separate data flows: iCloud Sync, App Store and RevenueCat purchase services, Tailscale connectivity, and approved icon libraries are described in the Privacy Policy.
How does Smart Connect choose a route?
When the current Wi-Fi matches one of your configured home SSIDs, Smart Connect uses the Local route only. If that route fails, it does not fall back. On other networks, with no Wi-Fi, or when iOS cannot provide the SSID, enabled Public and Tailnet routes are tried in the order you configure.
Is the built-in Tailnet a system-wide VPN?
No. Tailnet connectivity is used only for Prox Deck requests. It does not configure a system-wide VPN or route traffic from other apps.
Why does Smart Connect request location access?
iOS places access to the current Wi-Fi SSID behind location permission. Prox Deck reads the current SSID only when Smart Connect needs it and does not keep a location history. If you enable iCloud Sync, saved home SSIDs are part of the server configuration you choose to sync.
Where are credentials stored?
PVE passwords, API Token secrets, SSH passwords, private keys, and passphrases use Keychain. PVE runtime sessions, including Tickets, CSRF tokens, cookies, and authorization headers, remain in memory. Custom HTTP Header values are server configuration, not Keychain secrets.
Can PVE passwords sync with iCloud?
When you explicitly enable iCloud Sync, only password-auth PVE passwords may use iCloud Keychain. API Token secrets, SSH secrets, certificate trust, and SSH Host Key trust remain on the device where they were configured.
Does allowing a self-signed certificate disable TLS verification globally?
No. HTTPS certificates are verified by default. Allowing a self-signed certificate is limited to the selected server route and does not disable TLS checks globally.
What does iCloud Sync include?
With explicit opt-in, your private CloudKit database can sync an allowlisted set of server configuration, Smart Connect endpoints and home SSIDs, custom headers, SSH Profile metadata, limited preferences, and deletion records. It is designed for eventual consistency when devices are available, not guaranteed real-time background sync.
Are selected photos uploaded?
A custom icon is imported only after you choose a photo with the system Photo Picker, then is processed into a local icon file. Icon files do not enter CloudKit. Browsing approved network icon libraries contacts their restricted HTTPS hosts.