Status: Stable release.
Proxmox® is a registered trademark of Proxmox Server Solutions GmbH.
Ultimate Updater is an independent project and is not an official program from Proxmox Server Solutions GmbH.
This software is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY. See the GNU General Public License for more details. You are responsible for validating the configuration and maintaining suitable backups before using it on important systems.
IN CASE OF EMERGENCY, I HOPE YOU HAVE BACKUPS FROM YOUR MACHINES!
YOU HAVE BEEN WARNED!
Central, safety-conscious updates and checks for Proxmox hosts, LXC containers, VMs, and selected external systems.
Ultimate Updater helps you update everything from one place — without giving up control.
Automation is supported, but control stays with you.
5.1.3 is a stability, correctness, and hardening release focused on reliable update execution, checks, remote operation, notifications, result handling, installer/self-update behavior, and terminal handling.
The next development cycle is planned to focus on broader system support and continued UI evolution:
- Web UI evolution, including theme and skin support while preserving Ultimate Updater's independent visual identity.
- More mature Windows integration through the existing QGA and PowerShell direction, including update detection, execution, reboot-required state, capability handling, and production-quality validation.
- More complete first-class External system support, with consistent checks, updates, package-manager capabilities, status integration, notifications, and stronger APT/RPM handling.
These are planned focus areas, not guarantees of specific 5.2 scope or ordering.
Ultimate Updater is installed once on a Proxmox cluster and gives you one place to check and update hosts, LXC containers, VMs, and configured external systems. It supports interactive and headless operation, persistent jobs, status reporting, notifications, snapshots/backups, filters, and a central Web UI.
Key features include:
- A central cluster-aware CLI and Web UI.
- Read-only checks separated from mutating updates.
- APT, DNF/YUM, Pacman, APK, Windows, and FreeBSD/pfSense paths according to the current support matrix.
- VM access through QEMU Guest Agent or SSH, with lifecycle restoration.
- Persistent server-side jobs that continue after a browser or SSH session disconnects.
- Interactive Web terminal support for supported update jobs and read-only live output for Checks and other non-interactive jobs.
- Scheduler support for weekdays and selected month days, plus job-scoped notification controls.
- Optional Web UI-managed target selection with independent Check/Update tri-state rules; legacy Proxmox tag selection remains the default.
- Separate normal/security counts where classification is supported; other systems show a total count.
- Snapshot and backup safety controls, filters, notifications, and logs.
Start with these three guides:
- Install Ultimate Updater
- Review configuration and safety settings.
- Learn the difference between checks and updates.
Then use the Web UI to review the inventory and run a check before deliberately starting an update.
The authenticated Web UI is served by ultimate-updater-web.service on port
8765, preferably over HTTPS. It provides the dashboard, target details,
checks, updates, settings, Internal SSH management, persistent jobs/logs, and
version/build information. See Web UI.
Web UI dashboard from a dedicated test environment. More views are shown in the Web UI guide.
Proxmox hosts and Linux LXC/VM guests are the primary supported paths. APT
systems provide a normal/security split. pkg (FreeBSD/pfSense), Pacman,
APK, DNF/YUM, and Windows use total-only update presentation where a reliable
security split is not available. Windows remains experimental/deferred from
the supported 5.1 baseline pending dedicated validation.
External Linux systems can be configured over SSH. Read the complete matrix and limitations in Supported systems and External systems.
- Check and Update are separate operations. A check is read-only as far as technically possible and never reboots a VM.
- A check may temporarily start or resume a stopped/paused guest when enabled, then restores its original lifecycle state, including after errors.
REBOOT_IF_NEEDEDapplies to the update path only.- Snapshot and backup are independent controls. An invalid or inactive backup storage is rejected rather than silently ignored.
- Jobs run server-side and retain their status/log after the client disconnects.
- Do not expose the action-enabled Web UI to an untrusted network.
- Installation
- Configuration
- Checks and updates
- Cluster operation
- Web UI
- SSH and VM access
- External systems
- Backup and snapshots
- Notifications
- Supported systems
- Troubleshooting
- Upgrading
- Advanced operation
Additional project documents: Testing, 5.1 release notes, 5.1 upgrade notes, security policy, and code of conduct.
Report reproducible bugs through GitHub Issues or join the Discord. Keep secrets, private keys, and production credentials out of reports.
BassT23 💻 🚧 |
Gauvino 💻 📖 |
elbim 💻 📖 |
Ultimate Updater is free software under the GNU General Public License. See the LICENSE and SECURITY.md for project policies.
AI-assisted development: OpenAI ChatGPT & Codex are used for code review, debugging, test planning, documentation, and release preparation. Changes are reviewed and validated before inclusion in a release.


