Issue
Does KernelCare support Proxmox VE, and if so, which Proxmox VE versions and kernel branches are covered?
What is the licensing basis for a Proxmox cluster whose nodes run entirely on private IP addresses (with a single public IP used only for the Proxmox management UI)?
Does license activation and patch delivery require direct outbound internet access from each node, or is there an offline option for nodes without public IPs?
Can a license purchased through Manage2/cPanel (IP-based) be used for a private-IP Proxmox cluster?
How is a multi-node license ordered — is a quote required, or can it be purchased directly?
Environment
Proxmox VE (multi-node cluster)
KernelCare Enterprise
Cluster nodes on private IP addresses; a single public IP is used only for the Proxmox management UI
Solution
Proxmox VE compatibility. KernelCare Enterprise supports Proxmox VE hosts and patches the
-pvehost kernel itself. Proxmox VE 8, with its default 6.8 kernel series (proxmox-kernel-6.8), is the supported platform and is actively patched. Proxmox VE 9 is not supported and is not currently on the roadmap — on Proxmox VE 9, kernel updates require the conventional install-and-reboot path; in a cluster, live-migrate guests and reboot nodes one at a time to avoid VM downtime. See KernelCare support for Proxmox VE 9 for details, or contact the Sales team atsales@tuxcare.comwith a node count and timeframe if Proxmox VE 9 support matters for a rollout. Confirm coverage for any specific kernel build with the compatibility checker.Licensing basis. Licensing is per server, one license per node. Key-based and IP-based licenses work identically and differ only in the activation method — see What is the difference between an IP-based license and a key-based license?
-
Which license type fits a private-IP cluster. An IP-based license — including one issued through Manage2/cPanel — requires each server to present its own licensed public IP, which nodes sitting behind one shared address cannot do. For a cluster where nodes only have private IPs, key-based licensing is the right fit: purchase a key-based KernelCare Enterprise license and register each node with:
kcarectl --register KEYSee How to activate KernelCare Enterprise license? A single key can cover multiple servers, so one key can license an entire cluster — but the server count a key covers is fixed at purchase, and any node beyond that count is rejected.
-
Connectivity for patch delivery. Nodes need outbound HTTPS only (NAT is fine) to:
cln.cloudlinux.com patches.kernelcare.com repo.cloudlinux.comNo direct public IP is required for patch delivery. Standard
http_proxy/https_proxyenvironment variables are also supported. Offline option. For nodes with no internet access at all, ePortal is the on-prem patch server option — only the ePortal machine itself needs outbound access.
Ordering. Key-based KernelCare Enterprise licenses are self-serve, via card checkout, on monthly or annual billing, for deployments up to 999 servers. The quote form on the website is only required for larger environments or custom terms; alternatively, email the Sales team at
sales@tuxcare.comand they will handle the order directly. A trial license is also available for testing before purchase.If a node returns
HTTP Error 401: Unauthorizedfrompatches.kernelcare.com: this means the patch server is rejecting that node's license check, not a network problem. Confirm the node was registered with the key the same way as the working nodes (re-runkcarectl --register KEYand check the output), and confirm the total number of registered nodes does not exceed the count the key was issued for.
Comments
0 comments
Article is closed for comments.