Storage-domain control
One controller protects one shared bottleneck. Disk envelopes express minimums, maximums, and weights without creating competing feedback loops.
REFERENCE INCIDENT · ANONYMIZED
A single bulk disk reached 115.36 MiB/s while shared ZFS write wait peaked at 348.87 ms. Capacity checks stayed green; SSH and durability-sensitive services did not.
Storage-domain control
One controller protects one shared bottleneck. Disk envelopes express minimums, maximums, and weights without creating competing feedback loops.
Dry-run by default
Observer and shadow modes produce detections, proposed budgets, and a full explanation without mutating PVE.
Safe under uncertainty
Stale telemetry never increases a limit. Unknown effective state, policy drift, lease conflict, and read-back mismatch stop actuation.
Built for operations
Prometheus metrics, decision events, multi-signal alerts, replay, runbooks, and rollback make the controller inspectable under pressure.
The offline reference replay evaluated 972 bounded AIMD policies. 198 passed a safety gate requiring no more unsafe seconds than a fixed 20 MiB/s limit in conservative, nominal, and optimistic models. The selected shadow candidate admitted 60.11–63.88% of modeled demand versus 59.26% for the fixed baseline, with the same modeled unsafe seconds.
pve-storage-guard owns the operator experience, PVE discovery, packaging, and
constrained actuator boundary. The internal storage-slo-guard engine receives
platform-neutral observations and emits bounded proposals. Future Linux,
Kubernetes, or hypervisor adapters can reuse the engine without importing PVE
semantics into policy code.
PVE Storage Guard is an independent community project. It is not affiliated with, endorsed by, or sponsored by Proxmox Server Solutions GmbH.