🚧 In development β€” ProxDR is coming soon. You're viewing an early preview.

ProxDR

Features

Everything you need to recover from a disaster

Purpose-built for Proxmox VE β€” replication, point-in-time recovery, testing, and orchestration in one web UI. Every plan includes the full feature set.

proxdr-oly.local

Replication

Protected guests and their recovery point objective, across every DR Site Pair.

Protected
14
guests Β· 2 pairs
Meeting RPO
13/14
1 seeding
Recovery points
312
integrity-verified
GuestRPO targetRecovery pointsStatus
Uptime-Kuma
VMID 210 Β· OLY β†’ ARC
1 min
building…
Initial sync
Full seed Β· 68% 210 MB/s Β· ETA 1m 58s Β· 21.8 / 32.0 GiB
db-01
VMID 101 Β· OLY β†’ ARC
1 min
lag 11s
48 points verified
Replicating
app-02
VMID 102 Β· OLY β†’ ARC
5 min
lag 1m 12s
36 points app-consistent
Replicating
mail-01
VMID 140 Β· OLY β†’ ARC
15 min
lag 3m 40s
31 points verified
Replicating
file-svr
VMID 150 Β· OLY β†’ ARC
1 hour
lag 22m
26 points verified
Replicating
The Replication page β€” protected guests, their recovery objective, and the live initial sync.

Replication

Ship only changed blocks to the recovery site β€” on any storage, at the RPO you set, to the pool you choose.

Near-continuous replication

VM and workload replication from every 10 minutes down to ~1 minute β€” on any storage backend, not just ZFS or Ceph.

Works on any storage

A storage-agnostic engine built on QEMU dirty bitmaps brings DR to LVM-thin and other backends Proxmox can't natively replicate.

Put replicas where you want

Place each guest's recovery replica on any storage you choose β€” a directory, NFS or CIFS share, or a native ZFS or LVM-thin volume β€” per guest or per pair, with native snapshots for point-in-time recovery on block pools.

See every replica, live

Watch the first full sync with a real-time progress bar, transfer rate and ETA β€” then use the Shadows view to see every recovery replica across your sites and reclaim orphaned ones in one click.

No disruption to running guests

Replication reads changed blocks without pausing the guest β€” and never locks you out of it. The VM's console stays reachable throughout, even during the first full sync.

Recovery

Roll back to a known-good, continuously verified moment β€” and fall back to backups when there's no live replica.

Point-in-time recovery

Roll back to a known-good moment, not just the latest. Retained recovery points are integrity-checked at capture and can be application-consistent via the guest agent.

Continuous integrity scrubbing

Recovery points aren't verified just once. A background scrub re-reads each retained point over its whole life and quarantines any whose contents drift β€” catching silent bit-rot before you ever fail over to a bad point.

Ransomware & corruption guard

A change-rate anomaly detector pauses replication when a VM looks mass-encrypted or corrupted β€” preserving a clean pre-attack point to recover to.

Catch a frozen guest

Replication health isn't guest health: a crashed or frozen VM keeps replicating a static disk, so its RPO stays green while it's dead. ProxDR watches each guest's agent, alerts when one goes unreachable, and reboots it back into service in one click.

Boots even from a dirty capture

Before a recovered guest starts, ProxDR can check and repair its filesystem β€” and reinstall a missing bootloader β€” on a throwaway clone of the recovery point, never the protected data. An agent-less guest captured crash-consistent still comes up instead of dropping to a repair shell.

Recover from backups too

No live replica? Fall back to a restore from Proxmox Backup Server, or any backup-capable storage (dir/NFS/CIFS), right from the same console.

Testing & orchestration

Prove recovery without touching production, then fail over β€” and back, near-instantly β€” with ordered, health-gated runbooks.

Non-disruptive DR testing

Boot replicated VMs in an isolated network to prove recovery β€” without touching production or pausing replication. Schedule tests and export the evidence.

Orchestrated failover

Recovery plans with ordered boot groups, health gates, re-IP and network mapping β€” so an application comes back in the right order, not VM-by-VM by hand.

Near-instant failback

While you run at the recovery site, ProxDR reverse-replicates changes back to your primary continuously β€” so returning home applies a few MiB of delta in seconds instead of re-copying the whole disk.

Live progress for every operation

Failover, failback, DR test and planned migration each get their own live page β€” ordered steps, bytes transferred, and any error. Start it on the server, then close the browser; it keeps running.

Go / no-go preflight

Capacity, storage, network-mapping and machine-type compatibility are checked before failover β€” so it lands, even across Proxmox versions.

Cross-site planned migration

Move a running VM between sites with a graceful, near-zero-downtime cutover and zero data loss β€” roll back any time before you commit.

Scale & governance

Run DR across many sites with the resilience, access controls, approvals, and audit trail teams need.

Multi-site & DRaaS

Two-site, many-to-one hub (DRaaS), and mesh topologies β€” managed from one web UI at every site.

Operate DR from either site

Both sites run the identical web UI β€” drive any operation from whichever controller you can reach. ProxDR routes each action to the site that owns it, so two operators can't cause a split-brain, and the recovery site stays fully in control even with the primary completely down.

No single point of failure

A full instance runs at each site. If your primary site is gone, you drive recovery from the surviving side.

Self-healing controller

An interrupted failover, a stalled reverse lane, or a controller restart mid-cycle are detected and recovered automatically β€” and if a DR copy ever diverges, one click rebuilds it. No database surgery, no guests left stuck half-way.

Enterprise access & audit

Role-based access, optional two-person approval for failover, and a tamper-evident audit trail β€” with exportable compliance reports.

proxdr-arc.local

Recovery points β€” VMID 210

Capture now

Roll back to a known-good moment. Points are integrity-checked at capture and continuously re-scrubbed over their whole retention life.

Today Β· 14:00 hourly
verified app-consistent content-checked 2h ago
Recover
Today Β· 13:00 hourly
verified app-consistent content-checked 3h ago
Recover
Today Β· 00:00 daily
verified content-checked 14h ago
Recover
Jul 21 Β· 00:00 daily
verified app-consistent content-checked 1d ago
Recover
Jul 15 Β· 00:00 weekly
quarantined content digest changed since last check β€” bit-rot
Recover
Jul 08 Β· 00:00 weekly
verified content-checked 2d ago
Recover
Continuously scrubbed recovery points β€” one auto-quarantined after silent bit-rot.
proxdr-oly.local

Failback β€” Uptime-Kuma VMID 210

In progress Β· 00:16

Runs on the server β€” you can leave this page or close the browser; it won't stop.

Near-instant failback. Continuous reverse sync kept proxdr-oly current while you ran at the recovery site β€” so returning home applies a 5.2 MiB delta instead of re-copying the full 32 GiB disk.

Steps
  1. Quiesce DR copy at proxdr-arc 20:14:02
    guest paused
  2. Apply reverse-synced delta to primary disk 20:14:05
    5.2 MiB applied
  3. Verify primary disk 20:14:14
    scoped extents Β· matched Β· 9s
  4. Fence DR copy & boot guest at proxdr-oly
    starting…
  5. Resume forward protection β€” OLY β†’ ARC
Near-instant failback β€” a few MiB of reverse-synced delta, live step by step.

Prove it in your own environment

Start a free 14-day trial with the full feature set β€” no feature is held back on any plan.