Zelogx MSL Setup - Release Notes
This page tracks the main changes for Zelogx MSL Setup Personal and Pro Corporate.
MSL Setup Basic continues to provide the open design and manual build steps,
while Pro adds automation, safety nets, and advanced features.
Note
Version numbering refers to the Pro automation bundle.
v2.1.4 - Keeps Your Own SDN Objects, Clearer Router Guidance, Simpler Pritunl Installation
Release date: 2026-09-27
Released v2.1.4.
Summary of Changes
This release contains no new features. Re-run, restore and uninstall now leave the SDN objects you created yourself alone, and the router settings are shown only once, with the correct values in cluster mode as well. The Pritunl installation has also been rebuilt so that failures are easier to diagnose.
Changes
- Re-run, restore and uninstall now delete only the SDN objects that MSL Setup creates, identified by name (zones
vpndmz/devpjXX, VNetsvpndmzvn/vnetpjXXand their subnets, and IPSetsdevpjs,mainlan,vpn_guest_pool,all_private_ipandvxlan_peers). Zones, VNets, subnets and IPSets with other names are kept, including ones you created after installing MSL Setup. - The router settings (static route and port forwards) are shown only once, at the end of
01_networkSetup.sh, and highlighted in cyan. In cluster mode, the static route points to the cluster VIP from the start, so the separate “change the route to the VIP” and “change it back” messages no longer appear.01_networkSetup.shalso no longer waits for a key press partway through. - After
01_networkSetup.sh --restoreand99_uninstall.sh, a message now lists the router settings that are no longer needed. - Pritunl is now installed by a single script that runs inside the Pritunl VM. Its progress is shown on the console and also recorded in the log file. If the installation fails, the script reports the step and command that failed, together with diagnostic information (disk space, packages, and the MongoDB / Pritunl service status and journal).
- Organizations are now created by calling the Pritunl API from the host, which retries while Pritunl is restarting.
- The helper used in the VM is now a plain Python script run with the VM’s python3, instead of a prebuilt binary.
Fixes
- Fixed an issue where
mslcmkept printing “Invalid IPv4 format.” without stopping when no terminal input was available (for example, when run from a script). In addition, ifenable-clusterstops before the cluster is configured, it now removes the packages it installed (keepalived and arping).
Known Issues
- Re-run, restore and uninstall set the Datacenter / host firewall options back to the values they had before MSL Setup was installed. See Known Issues in the README for details.
v2.1.3 - Improved Cleanup and Enhanced Protection for Existing Environments
Release date: 2026-09-25
Released v2.1.3.
Summary of Changes
This release reduces the amount of configuration and files left behind after a restore or uninstall, and provides more reliable protection for existing environments. The code has also been cleaned up. #### Fixes
- Cluster mode: Fixed
01_networkSetup.sh --restoreand99_uninstall.shso that they no longer disable the host firewall on other cluster nodes. The firewall configuration is now restored to the state it was in before MSL Setup was installed. 99_uninstall.shnow also removes the Pritunl VM’s cloud-init snippet, themsldhcpcommand and its host-side files, and the network diagram (SVG and the block in the node’s notes).- SDN / RBAC backups are now deleted after a successful restore or uninstall. Previously, if MSL Setup was reinstalled afterward, an old backup could be reused, potentially causing changes made in the meantime to be deleted or reverted.
- Fixed an issue where
0102_setupNetwork.shcould stop withSDN setup failedat the very end, after all resources had already been created successfully. - Fixed an issue where DNS servers in the
172.10.0.0–172.15.255.255range were incorrectly treated as private addresses, resulting in unnecessary firewall rules being created. ##### Changes - If any of MSL Setup’s reserved SDN Zone, VNet, or IPSet names (
vpndmz,devpjXX,vpndmzvn,vnetpjXX,devpjs,mainlan,vpn_guest_pool,all_private_ip,vxlan_peers) already exist, the first run of01_networkSetup.shnow stops without making any changes. Existing objects are no longer reused. - In cluster mode,
0102_setupNetwork.shcan no longer be run standalone. Use01_networkSetup.shinstead. 00_configNetwork.shnow starts faster by reducing the number of existing-network detection passes from two to one.- Removed the unused legacy script
0101_checkConfigNetwork.sh. - Added a
.gitignoreto the public repository for files generated at runtime, such as.envfiles, logs, and backups. - Updated messages and script headers to match the current script names. #### Upgrade Notes
- Clusters configured with v2.1.2 or earlier do not have the host firewall configuration of the other nodes recorded. Therefore, during the first restore or uninstall after upgrading, the host firewall on the other nodes will still be disabled as before. If necessary, re-enable it afterward. #### Known Issues
- Changes to SDN Zones, VNets, and IPSets created after MSL Setup was installed, as well as changes to firewall options, will be reverted by a re-run, restore, or uninstall. See the Known Issues section of the README for details.
v2.1.2 - Improved Stability of Re-runs, Uninstall, and Cluster Operations
Release date: 2026-09-24
Released v2.1.2.
Summary of Changes
This release focuses on fixes that make re-running setup, restoring, and uninstalling reliable in both single-node and cluster environments. Fixes:
- Single-node (non-cluster) environments: Fixed an issue where running
01_networkSetup.sha second time, or running99_uninstall.sh, failed with “Cluster setup restore failed”. - Corporate Edition: Fixed an issue where
99_uninstall.shstopped at the first step if the Self-Care Portal (0301_setupSelfCarePortal.sh) had never been set up. - Fixed an issue where each re-run of
01_networkSetup.shadded duplicate per-project firewall rules. Existing duplicates are cleaned up automatically on the next run. - Firewall rules created by MSL Setup (including Self-Care Portal rules) are now fully removed on re-run, restore, and uninstall, even after the number of projects or DNS settings have been changed.
- Cluster environments: Restore and uninstall no longer run
apt-get autoremoveon the Proxmox nodes, which could remove unrelated packages. Only the packages MSL Setup installed itself (keepalived / arping) are removed; packages that were already installed before MSL Setup are no longer uninstalled. - Cluster environments: Running
mslcm enable-clusteragain after nodes have been added is now refused with guidance. Re-running it regenerated the cluster settings (VIP and VRRP authentication) only on the local node, which could break VIP failover between nodes, and also prevented restore from cleaning up the added nodes. If adding a node fails midway, that node is now also cleaned up by restore. - Cluster environments:
00_configNetwork.shnow clearly explains that the cluster VIP is active and that you should run./01_networkSetup.sh --restorefirst, instead of showing a confusing “multiple IPv4 addresses” error. - Setup now stops with an error if the Datacenter or host firewall cannot be enabled, instead of completing without tenant isolation. After fixing the cause, simply re-run
01_networkSetup.sh. - Security: Self-Care Portal user passwords are no longer written to the log files (Corporate Edition).
- Self-Care Portal setup now checks that
01_networkSetup.shhas been completed before creating anything. - Improved error logging (details of failed Proxmox operations are now recorded in the log file) and removed a misleading log hint.
Notes
- Firewall rules whose comment starts with
MSLSetupare managed by MSL Setup. Do not change their comments, and do not use such comments for your own rules. - Corporate Edition: Log files created by earlier versions (logs/ directory) may contain Self-Care Portal user passwords. We recommend deleting old log files or changing those passwords.
- Cluster environments: keepalived / arping installed by earlier versions are not removed automatically by restore or uninstall. Remove them manually if they are no longer needed.
- Cluster environments: If you were already using keepalived for other purposes before MSL Setup, note that enabling cluster mode overwrites
/etc/keepalived/keepalived.conf, and restore/uninstall stops keepalived and removes that file.
v2.1.1 - Added FW rule to disallow internet access from each tenant.
Release date: 2026-07-19
Released v2.1.1.
Summary of Changes
New feature: Added a firewall rule to block internet access for each tenant. This rule is disabled by default during installation and can be enabled from Datacenter > Firewall.
v2.1.0 - Added VXLAN DHCP Server Functionality, Improved Security, and Improved Stability
Release date: 2026-07-17
Released v2.1.0.
Summary of Changes
New feature: Added tenant-specific DHCP CT creation via msldhcp (limited to the VXLAN zone and vnetpj*, for DHCP-dependent guests such as VulnHub images).
Fixes:
- ARP isolation: Fixed an issue where
netdiscovercould expose other tenants’ gateway information (both non-cluster and cluster editions). - Reduced excessive MongoDB audit logs on the Pritunl VM.
- During Pritunl reinstallation, moved the check for existing extra disks to run before downloads and improved guidance on how to resolve detected issues.
v2.0.3 - Improved setup reliability.
Release date: 2026-07-13
Summary of Changes
Added automatic installation of required packages to improve setup reliability. Also changed installation telemetry (UUID + install stage ID) to be sent to www.zelogx.com.
v2.0.2 - Improved Stability for Pritunl VM and Cluster Restore Handling
Release date: 2026-05-06
This release focuses on stability improvements for the v2.0 series, including fixes for minor Pritunl VM-related issues and improved uninstall/restore behavior in environments that were converted to cluster mode after the initial MSL Setup installation.
Summary of Changes
- Stability improvements
- Fixed an incorrect MongoDB command shown in the Pritunl VM notes for updating the sync address.
- Fixed an issue where the Pritunl VM could be created with the Proxmox OS Type set to
Other, causing excessive idle CPU usage due to unnecessary QEMU timer/IRQ handling. The Pritunl VM is now explicitly created as a Linux VM. - Fixed an issue where, if MSL Setup was first installed in non-cluster mode and later converted to cluster mode using
mslcm enable-cluster/mslcm add-node, running99_uninstall.shcould leave cluster-related components such as keepalived, VIP addresses, keepalived configuration files, VIP hooks, and cluster backend state on some nodes. cluster.envis now generated by themslcmcommand as well, allowing uninstall/restore logic to correctly identify target nodes, BACKUP node information, VIP settings, and related cluster state even when cluster mode was enabled manually after installation.
v2.0.1 - Release of Cluster Support and Stability Improvements
Release Date: 2026-04-13
This release focuses on stability improvements and post-release fixes for the initial v2.0.0 cluster support release.
Summary of Changes
- New Features
- Cluster-wide isolated project networks are now supported
- VMs/CTs on different nodes can communicate within the same project network as if they were on a single host
- Communication can continue even during node failure through gateway failover
- Implemented with VXLAN + floating gateway failover
- In cluster environments, the Proxmox dashboard can now be accessed via a virtual IP.
- Stability Improvements
- Fixed an issue where return route information for the VPN could be removed after changing SDN settings following setup completion.
- Fixed an issue where
00_configNetwork.shcould enter an infinite loop under specific conditions and fail to proceed. - Fixed an issue where the firewall rule restore process could fail to return the system to a correct state.
- Fixed an issue where
99_uninstall.shcould fail to delete the Pritunl VM under specific conditions. - Fixed an issue where
00_configNetwork.shcould fail to operate correctly when multiple IP addresses were assigned tovmbr0. - Fixed an issue that could potentially lock out the client PC during installation when MSL Setup was run from outside the local network.
- Fixed an issue where Pritunl VM creation could fail if a CT ID and VMID conflicted.
v1.4.6 - Improvements to VPN-Related Functionality
Release date: 2026-03-19
Released v1.4.6.
Overview of Changes
- Fixed an issue where specifying a private IP address for DNS IP1 could cause internet access to be lost while connected through the VPN client. (Thanks to naritomo08 for the feedback.)
- Addressed an issue in SELinux Enforcing environments where using a reserved port as the Pritunl listening port could cause an
ERROR Management socket exceptionwhen starting the VPN server.
v1.4.5 - TUI Configurator Bug Fixes and UX Improvements
Release date: 2026-03-14
Released v1.4.5 with improvements to the TUI configurator.
Overview of changes
- Further improved duplicate network address detection.
- Added support for displaying detected existing network addresses.
- Simplified editing of network addresses.
v1.4.4 - TUI Configurator Bug Fixes
Release date: 2026-03-13
Released v1.4.4.
Overview of changes
- Fixed a VPN connection issue caused by a bug in the TUI configurator’s VPN POOL network address calculation.
- Improved the TUI configurator’s duplicate network address detection. However, some cases may still not be fully covered. If a duplicate address is found when AUTO is selected, please switch to CUSTOM and adjust the settings manually.
v1.4.2 - UX Improvements and IPv6 Reachability Check Support
Release date: 2026-03-07
Released v1.4.2.
Overview of changes
- UX improvements to the TUI configurator
- Added IPv6 support for UDP reachability checks when the public IP is IPv6
- Internal process improvements (stopped embedding the ICMP rule identifier in .env file, improving compatibility with the TUI configurator)
v1.4.0 - Automated initial network configuration with the TUI configurator.
Release date: 2026-02-19
Released v1.4.0.
Overview of changes
- Automated initial network configuration with the TUI configurator.
v1.3.3 - Performance and stability update for Pritunl VM
Release date: 2026-02-17
Released v1.3.3.
Overview of changes
- Added swapfile for Pritunl VM for more Stability and Performance.
v1.3.1 - Feature additions
Release date: 2026-02-03
Released v1.3.1.
Overview of changes
- Optimize for AlmaLinux 9.7, which is officially supported by Pritunl.
v1.3.0 - Feature additions
Release date: 2026-02-01
Released v1.3.0.
Overview of changes
- Changed the Pritunl VM OS from Ubuntu 24.04 to AlmaLinux 9.7, which is officially supported by Pritunl.
- Fixed an issue where 99_uninstall.sh could fail when running in Japanese.
- Added the alias name “The Multi-tenant enabler.”
v1.2.1 - Feature additions
Release date: 2026-01-28
Release v1.2.1
Overview
- 0203_uninstall.sh supports RBAC deletion.
v1.2.0 - Feature additions
Release date: 2026-01-25
Release v1.2.0 and Personal Free License.
Overview
- Release Personal Edition (FREE).
- Stop providing Basic edition.
- Fixed an issue where the post–Pritunl VM Deployment guidance showed an outdated message for the next step.
- Migrated Pritunl Server provisioning to Python.
- Automated Pritunl Organization provisioning, attaching the Organization to the Server, and starting all Servers.
- For improved security, changed the Pritunl Web GUI bind address to Ingress only.
v1.1.2 - Demo environment feature additions
Release date: 2026-1-18
The following issues were addressed.
Overview
- For demo environments:
- Fixed an issue so that port forwarding in the demo environment is handled correctly even when its behavior is abnormal.
- Fix the issue that Static Route in Pritunl VM is not persistently added.
v1.1.1 - Bug fixes
Release date: 2026-01-15
The following issues were addressed.
Overview
- UI/display improvements:
- Fixed an issue where the gateway IP address shown in the manual configuration prompt for static route information was incorrect.
v1.1.0 - Project Self-Care Portal
Release date: 2025-12-23
VPN users can now start/stop, create/delete VMs, create snapshots, and perform backups within their own project.
Overview
This release adds a per-project “self-care portal” on top of the existing isolated SDN + VPN lab.
Project admins can log in to the Proxmox GUI over VPN and manage only their own project VMs,
without ever seeing or touching other projects or the Datacenter configuration.
This feature is available in MSL Setup Pro - Corporate.
Highlights
-
Per-project GUI access over VPN
- Each project (PJ01, PJ02, …) gets:
- its own Proxmox Pool,
- Group and User (for project admins),
- project-scoped RBAC.
- VPN project admins can:
- log in to the Proxmox dashboard,
- see only their own project VMs and storage,
- start/stop VMs, access console,
- create snapshots and backups,
- create and delete VMs inside their project.
- Each project (PJ01, PJ02, …) gets:
-
RBAC on top of isolated SDN
- Reuses the isolated SDN lab from v1.0.0 (SDN Simple zone + VNet per project).
- Adds RBAC on:
- Proxmox Pools (VMs / storage),
- SDN Zones / VNets,
- node-level firewall rules for the GUI (port 8006, VPN only).
- Ensures that:
- project admins cannot see other projects’ VMs or storage,
- Datacenter-level settings remain under core infra ownership.
-
Automation with backup & restore (Corporate)
- New automation script (internal name, example):
0203_setupSelfCarePortal.sh
- For each project (PJ01…PJNN), it:
- creates Pool / Group / User,
- assigns roles and SDN permissions,
- configures node firewall rules for GUI access from VPN,
- generates random passwords for project admin accounts,
- writes all changes to an RBAC backup folder (e.g.
./rbac_backup).
- Supports a
--restoremode to roll back to the previous RBAC state if you want to undo all changes and return to the original configuration.
- New automation script (internal name, example):
Edition differences
-
MSL Setup Basic
- Full RBAC procedure and design are documented as manual steps.
- Anyone can reproduce the same pattern by following the documentation.
-
MSL Setup Pro - Personal
- Focused on a single admin / single-owner lab on one Proxmox node.
- Designed for individual engineers and small teams.
-
MSL Setup Pro - Corporate
- Includes the automated self-care portal for multiple projects and teams.
- Adds backup / restore support around RBAC changes for safer experimentation.
- Intended for organizations hosting multiple concurrent projects on a shared Proxmox lab.
v1.0.0 - Initial Pro Release
Release date: 2025-12-18
Overview
First public release of Zelogx MSL Setup Pro.
Automates the creation of a fully isolated, single-node development lab on top of Proxmox VE.
Highlights
-
Single-node isolated SDN lab
- Proxmox VE with SDN Simple zone.
- Per-project VNets (
vnetpj01,vnetpj02, … ) inside an isolated dev zone. - Strict separation between projects at the network level.
-
Automated SDN deployment
- Environment validation and SDN setup split into:
0101_checkConfigNetwork.sh0102_setupNetwork.sh01_networkSetup.shas a wrapper/entry script.
- Automatically creates:
- SDN zone(s) for development projects,
- VNets per project,
- IP ranges and basic routing / gateway configuration.
- Environment validation and SDN setup split into:
-
Pritunl-based VPN access
- Automated deployment and basic configuration of Pritunl:
0201_createPritunlVM.sh0202_configurePritunl.sh02_vpnSetup.shas a wrapper/entry script.
- Provides per-project VPN access into the lab, without exposing Proxmox directly to the internet.
- Automated deployment and basic configuration of Pritunl:
-
Secure “multiverse” style layout
- A single strong Proxmox node hosts multiple fully isolated project labs.
- Each project gets:
- its own VNet,
- its own VPN access path,
- no L2/L3 connectivity to other projects by default.
- Designed as a reusable pattern for securing dev/test environments on a single host.
Relationship to MSL Setup Basic
-
MSL Setup Basic:
- Publishes the open design and manual build steps.
- Intended as documentation and a reference implementation.
-
MSL Setup Pro:
- Packages the same ideas into repeatable shell automation.
- Adds guardrails, checks, and operational smoothing on top of the Basic design.
Future roadmap (high level)
This section is intentionally lightweight and non-binding.
- VXLAN / EVPN-based SDN zones for cross-node project networks.
- Extended RBAC patterns for multi-node Proxmox clusters.
- Multi-node and cluster-aware lab setups (e.g. 3-node + Ceph).
- Additional tools around monitoring, audit trails, and long-term retention.
Stay tuned on the Zelogx website and the
GitHub repository for updates, examples, and real-world usage notes.