Lockout recovery — PVE firewall

For the specific failure of being locked out of the Proxmox UI by the PVE firewall (historically: firewall allowed a home IP that changed; today management is tailscale-only so this is rare, kept for DR).

Requires Hetzner rescue mode — then, from the rescue shell:

mkdir /mnt/proxmox
vgscan
vgchange -ay
lvs
mount /dev/mapper/vg0-root /mnt/proxmox
mount -t proc /proc /mnt/proxmox/proc
mount --rbind /sys /mnt/proxmox/sys
mount --rbind /dev /mnt/proxmox/dev
chroot /mnt/proxmox /bin/bash

systemctl disable pve-firewall
systemctl mask pve-firewall
exit
reboot

Then:

  1. Log in to the PVE portal, fix the firewall/ipset (or disable the rules that locked you out).
  2. From a server shell:
systemctl unmask pve-firewall
systemctl enable pve-firewall
systemctl start pve-firewall
  1. Optionally reboot and test.

Note: if the Hetzner firewall is what blocked you, fix that first in the Hetzner console — it’s upstream of everything here.