Security Architecture
Understand the outbound-only Agent model, credential boundaries and console relay design.
Outbound-only Site connectivity
The Site Agent initiates communication to HSVE Cloud. Normal Portal operation does not require HSVE to initiate an inbound connection to your Proxmox management interface.
Browser ──HTTPS/WSS──> HSVE Portal / Cloud
▲
│ outbound authenticated Agent channel
│
HSVE Agent
│ verified local HTTPS
▼
Proxmox VECredential boundaries
- Portal enrolment tokens are short-lived and single-use.
- The Agent has its own HSVE cloud credential stored on the Proxmox host.
- The Agent uses a dedicated privilege-separated Proxmox API token rather than your normal Proxmox administrator password.
- Local Proxmox HTTPS certificate validation is enforced; the installer does not silently disable TLS verification.
Console sessions
Virtual KVM uses a short-lived Portal session. The browser connects to HSVE Portal, the Agent establishes the Proxmox console path from inside the Site, and the relay exists only for the authenticated console session.
Optional Windows RDP follows the same private model: Portal's RDP service is not public, TCP 3389 is not exposed to the internet, and the Site Agent connects internally to the selected Windows VM.
Authorisation
Site roles are checked for each protected capability. Viewer is read-only, Operator can perform day-to-day operations, Admin can also manage access and Agents, and Owner retains permanent Site ownership/deletion authority.
Customer-controlled infrastructure data
Portal coordinates Proxmox operations but does not move backup archives into HSVE Cloud. Proxmox-native backups remain on storage configured by the customer. VM disks and guest data stay in the customer Proxmox environment unless a chosen workflow explicitly moves them.
Ready to use HSVE Portal?
Open Portal to connect Sites, operate guests and deploy your purchased HSVE Templates.
