Proxmox VE OS template builder with Web Console, cloud-init automation & integrated NFS server.
229
puqcloud/pve-os-builder)A self-contained Docker appliance designed to automate the generation of production-ready Proxmox VE Virtual Machine Templates (.vma.zst), specifically engineered for the PUQ Proxmox KVM WHMCS Moduleā and automated hosting infrastructure.
Features an integrated NFS-Ganesha Storage Server (allowing direct Proxmox VE storage mounting), a modern Console-Style Dark Web UI, an autonomous OS customization engine (virt-customize, vma, zstd, cloud-init), and a resilient sequential image downloader with auto-retry logic.
PermitRootLogin yes, PasswordAuthentication yes).cloud-init, cloud-initramfs-growroot, and cloud-utils-growpart for dynamic disk expansion upon provisioning.qemu-guest-agent for full lifecycle status reporting in WHMCS./etc/machine-id, removes stale SSH host keys, and purges default cloud user accounts (ubuntu, debian, centos, rocky, almalinux)./dev/kvm hardware virtualization acceleration when available./dev/kvm is absent.images_catalog.json, localization_groups.json) synchronize automatically between the embedded SQLite database and /data/configs on disk.The recommended deployment uses network_mode: host to allow Proxmox VE nodes to seamlessly mount the built-in NFS storage on port 2049 without complex port mapping.
docker-compose.ymlservices:
pve-os-builder:
container_name: pve-os-builder
image: puqcloud/pve-os-builder:latest
restart: unless-stopped
network_mode: host
privileged: true
environment:
- TZ=America/Winnipeg
- ADMIN_USER=admin
- ADMIN_PASSWORD=admin-secure-password
- JWT_SECRET=change-this-to-a-very-long-random-secret-key
- PORT=8080
- LIBGUESTFS_BACKEND=direct
volumes:
- ./data/db:/data/db
- ./data/downloads:/data/downloads
- ./data/configs:/data/configs
- ./data/repository:/data/repository
- ./data/scratch:/data/scratch
# Optional: KVM acceleration if running on bare-metal or nested virtualization
# - /dev/kvm:/dev/kvm
docker compose up -d
Open your browser at http://<SERVER_IP>:8080 and log in with your configured ADMIN_USER and ADMIN_PASSWORD.
docker run)docker run -d \
--name pve-os-builder \
--restart unless-stopped \
--network host \
--privileged \
-e TZ=America/Winnipeg \
-e ADMIN_USER=admin \
-e ADMIN_PASSWORD=admin-secure-password \
-e JWT_SECRET=change-this-to-a-very-long-random-secret-key \
-e PORT=8080 \
-e LIBGUESTFS_BACKEND=direct \
-v $(pwd)/data/db:/data/db \
-v $(pwd)/data/downloads:/data/downloads \
-v $(pwd)/data/configs:/data/configs \
-v $(pwd)/data/repository:/data/repository \
-v $(pwd)/data/scratch:/data/scratch \
puqcloud/pve-os-builder:latest
Note on Ports: If using standard bridge networking instead of
network_mode: host, ensure the following ports are exposed:
8080/tcp(Web Console & API)2049/tcp(NFS Server)111/tcpand111/udp(RPC Portmapper)
The builder exports /data/repository over NFS at the mount path /export using an embedded read-only NFS-Ganesha service.
Run this command on your Proxmox VE host:
pvesm add nfs os-builder-storage \
--server <BUILDER_IP> \
--export /export \
--content backup \
--options ro
https://<PROXMOX_IP>:8006).os-builder-storage<BUILDER_IP>/exportVZDump backup fileroos-builder-storage.vzdump-qemu-9000-debian-13-eu.vma.zst).local-lvm or ceph), assign a VM ID, and click Restore.| Variable | Default | Description |
|---|---|---|
ADMIN_USER | admin | Web Console administrator username |
ADMIN_PASSWORD | admin | Web Console administrator password (change in production!) |
JWT_SECRET | puq-pve-builder-... | Secret key used to sign browser session JWT tokens |
PORT | 8080 | Web Console listening port |
TZ | America/Winnipeg | Container timezone |
DATA_DIR | /data | Root path for persistent data volumes |
DOWNLOADS_DIR | /data/downloads | Storage path for cached upstream base OS images (.qcow2) |
CONFIGS_DIR | /data/configs | Storage path for JSON configuration catalogs |
OUTPUT_DIR | /data/repository | Output path containing /dump/ (.vma.zst templates and NFS export) |
SCRATCH_DIR | /data/scratch | Temporary workspace for in-flight image customization |
LIBGUESTFS_BACKEND | direct | direct mode is required for libguestfs inside Docker |
All container state is persisted in /data:
data/
āāā db/
ā āāā pve-builder.db # Embedded SQLite database (WAL mode)
āāā downloads/ # Cached upstream cloud images (Debian, Ubuntu, AlmaLinux, etc.)
āāā configs/
ā āāā images_catalog.json # Editable OS base image catalog
ā āāā localization_groups.json # Regional localization definitions
āāā repository/
ā āāā dump/ # Standard Proxmox backup storage directory
ā āāā vzdump-qemu-9000.vma.zst
ā āāā vzdump-qemu-9000.notes
āāā scratch/ # Transient scratch directory for active build jobs
Pre-configured in the default catalog with direct upstream download mirrors:
| Operating System | Supported Releases & Versions | Default Architecture |
|---|---|---|
| Ubuntu Linux (7) | 26.10 (Stonking), 26.04 LTS (Resolute), 24.10 (Oracular), 24.04 LTS (Noble), 22.04 LTS (Jammy), 20.04 LTS (Focal), 18.04 LTS (Bionic) | amd64 |
| Debian GNU/Linux (4) | 13 (Trixie), 12 (Bookworm), 11 (Bullseye), 10 (Buster) | amd64 |
| AlmaLinux OS (3) | 10, 9, 8 | amd64 |
| Rocky Linux (3) | 10, 9, 8 | amd64 |
| CentOS Stream (3) | 10, 9, 8 | amd64 |
| Alpine Linux (6) | 3.24, 3.23, 3.22, 3.21, 3.20, 3.19 | amd64 |
| Fedora Cloud (3) | 43, 42, 41 | amd64 |
| openSUSE Leap (3) | 15.6, 15.5, 15.4 | amd64 |
| Arch Linux (3) | Official Monthly Cloud Releases (2026.09.01, 2026.08.15, 2026.08.01) | amd64 |
| Custom OS Images | Any cloud-init ready .qcow2 or .img via Web UI or JSON catalog | amd64 |
192.168.1.50, 192.168.1.51) or private subnets (e.g. 10.0.0.0/24).ro (read-only) options, preventing accidental deletion or tampering from client nodes.In addition to NFS storage, the builder serves a public HTTP/HTML directory browser at / (or /repository) allowing remote Proxmox nodes or automated provisioning scripts to download templates directly over HTTP:
wget -O /var/lib/vz/dump/vzdump-qemu-9000-debian-13-eu.vma.zst \
http://<BUILDER_IP>:8080/repository/vzdump-qemu-9000-debian-13-eu.vma.zst
This project is licensed under the MIT License - see the LICENSEā file for details.
Free and open-source software for personal, commercial, hosting provider, and datacenter use.
Content type
Image
Digest
sha256:4422aec52ā¦
Size
393.7 MB
Last updated
about 17 hours ago
docker pull puqcloud/pve-os-builder