Protected guests and their recovery point objective, across every DR Site Pair.
SRM / Zerto-class DR · Proxmox VE
Disaster recovery you can rehearse.
Near-continuous replication to a second Proxmox site, non-disruptive DR tests, and one-click failover and failback. On any storage.
From the founder
Why we built Asternodis
Proxmox VE runs real production workloads, yet it ships nothing like VMware SRM or Zerto: no recovery plans, no non-disruptive DR tests, no one-click failover. Teams end up scripting it by hand and hoping, or paying enterprise prices for tooling that was never built for Proxmox.
Asternodis is the layer that was missing: near-continuous replication on any storage, disaster recovery you can actually rehearse, and failover (and near-instant failback) from one console at either site.
Capabilities
Everything the failover actually needs
Purpose-built for Proxmox VE: replication, point-in-time recovery, testing, and orchestration in one console. Four capability groups; every plan includes them all.
Replication
Ship only changed blocks to the recovery site, on any storage, at the RPO you set, to the pool you choose.
-
Near-continuous replication. VM and LXC container replication from every 10 minutes down to ~1 minute, on any storage backend, not just ZFS or…
-
Works on any storage. A storage-agnostic engine built on QEMU dirty bitmaps brings DR to LVM-thin and other backends Proxmox can't…
-
VMs and LXC containers. Containers are protected at full parity with VMs (replication, non-disruptive testing, failover with re-IP, and…
-
Put replicas where you want. Place each guest's recovery replica on any storage you choose (a directory, NFS or CIFS share, or a native ZFS…
-
See every replica, live. Watch the first full sync with a real-time progress bar, transfer rate and ETA, then use the Shadows view to see…
Recovery
Roll back to a known-good, continuously verified moment, and fall back to backups when there's no live replica.
-
Point-in-time recovery. Roll back to a known-good moment, not just the latest. Recovery points are integrity-checked at capture…
-
Restore in place, without failing over. Roll a guest back to an earlier recovery point on the primary itself: no failover, no topology change, nothing…
-
Continuous integrity scrubbing. Recovery points aren't verified just once. A background scrub re-reads each retained point over its whole life…
-
Ransomware & corruption guard. A change-rate anomaly detector pauses replication when a guest looks mass-encrypted or corrupted, and tells the…
-
Catch a frozen guest. Replication health isn't guest health: a crashed or frozen VM keeps replicating a static disk, so its RPO stays…
Testing & orchestration
Prove recovery without touching production, then fail over (and back, near-instantly) with ordered, health-gated runbooks.
-
Non-disruptive DR testing. Boot replicated VMs on an isolated DR-test network you map to prove recovery. Production keeps running, and…
-
Orchestrated failover. Recovery plans with ordered boot groups, health gates, re-IP and network mapping, so an application comes back in…
-
Near-instant failback. While your recovered guests run at the recovery site, Asternodis reverse-replicates changes back to your primary…
-
Live progress for every operation. Failover, failback, DR test and planned migration each get their own live page: ordered steps, bytes transferred…
-
Drive it from the command line. A CLI, asternodis dr, runs recovery operations from a terminal or a script (and a failover prints the same…
Scale & governance
Run DR across many sites with the resilience, access controls, approvals, and audit trail teams need.
-
Multi-site & DRaaS. Two-site, many-to-one hub (DRaaS), and mesh topologies, managed from one web UI at every site.
-
Operate DR from either site. Both sites run the identical web UI. Drive every recovery operation from whichever controller you can reach.…
-
No single point of failure. A full instance runs at each site. If your primary site is gone, you drive recovery from the surviving side.
-
Self-healing controller. A failover cut short (by a lost peer link or a controller restart) is detected, and its guest is restarted at the…
-
Alerts that lead somewhere. Every alert names the guest, says plainly what it means, and links to the page where you act on it. Silence the…
See it work
One console for the entire recovery lifecycle
Replication, recovery points, non-disruptive testing, failover and failback: every stage managed from a single interface, at either site.
Recovery points: VMID 210
+ Snapshot nowRoll back to a known-good moment. Points are integrity-checked at capture and continuously re-scrubbed over their whole retention life.
Point-in-time recovery
Recover to a moment you can trust
Asternodis keeps many retained recovery points, not just the latest. Each is integrity-checked at capture, and continuously re-scrubbed over its whole life. If a point drifts from silent bit-rot, it's automatically quarantined, so you can never fail over to a corrupt one.
Failback: Uptime-Kuma VMID 210
In progress · 00:16Runs on the server. You can leave this page or close the browser; it won't stop.
Near-instant failback. Continuous reverse sync kept asternodis-nyc current while you ran at the recovery site, so returning home applies a 5.2 MiB delta instead of re-copying the full 32 GiB disk.
- Quiesce DR copy at asternodis-sfo 20:14:02guest paused
- Apply reverse-synced delta to primary disk 20:14:055.2 MiB applied
- Verify primary disk 20:14:14scoped extents · matched · 9s
- Fence DR copy & boot guest at asternodis-nycstarting…
- Resume forward protection (NYC → SFO)
Near-instant failback
Fail back in seconds, not hours
While your recovered guests run at the recovery site, Asternodis reverse-replicates changes back to your primary the whole time. So when the primary is healthy, failback applies a few MiB of delta, not a full disk re-copy. A copy you deliberately leave powered off has nothing tracking its changes, so its failback reads the whole disk instead: safe, just not instant. Every step is live either way: bytes, timings, errors. Start it and walk away; it runs on the server.
Health and scale across your Proxmox estate.
2 of 2 connected sites responding to the Proxmox API.
2 pairs configured · replication, failover, and DR testing enabled.
Multi-site
Every site, one pane
A full Asternodis instance runs at each site, no single point of failure. If your primary is gone, you drive recovery from the surviving side. The Overview shows health and scale across your whole Proxmox estate at a glance.
vs SRM / Zerto
The enterprise DR you know, for Proxmox
The capabilities teams expect from VMware SRM and Zerto, brought to Proxmox VE at a fraction of the cost.
How it works
From paired to protected in four steps
Pair two sites
Run Asternodis at your production and recovery sites and pair them over a mutually authenticated TLS channel, no VPN required.
Replicate continuously
Choose the VMs and containers to protect. Asternodis ships only changed data to the recovery site, tracking your target RPO per guest.
Test without disruption
Boot the replicated VMs on an isolated DR-test network you map to prove they recover. Production keeps running, and each tested guest resumes replicating as soon as its test copy is up.
Fail over, then fail back fast
Declare a disaster and run your recovery plan in order. Asternodis reverse-syncs to your primary while your recovered guests run at the recovery site, so failback is near-instant when the site returns.
Pricing
Priced on what you actually protect
A DR Site Pair is one production site paired with one recovery site. Business tiers scale on protected nodes (the Proxmox nodes hosting guests you've chosen to protect). Unlimited VMs and containers on every tier, and every tier includes the full feature set.
Home Lab
non-commercialFor personal home labs, learning, and testing. The full feature set, unlimited nodes, unlimited VMs. Not for running or protecting a business.
Business & commercial use
Multi-site & MSP packs
A protected node is a Proxmox node hosting at least one guest you've chosen to protect. Recovery-site nodes don't count. Pack allowances are pooled, so a single large client can draw more than its share while smaller ones draw less. Need more than 25 pairs, more nodes than a pack pools, or an MSP / multi-tenant agreement? Talk to us. All business plans are for commercial use. See the license terms.
Extended evaluation
Run Asternodis on your own estate
Asternodis is in extended evaluation, running against real Proxmox estates. Join to put it against yours (two sites is the ideal, and a nested or non-production pair is perfectly fine) with a direct line to the people building it.
-
Run the whole cycle, replication, a non-disruptive DR test, failover to a point in time, then a clean failback.
-
A direct line to our team, so what you hit gets looked at properly, by people who know the internals.
-
Shape what ships, the sharp edges evaluation teams find are the ones that get fixed first.
Support
Answered by engineers who know the internals
Support is handled in writing, by engineers who know Asternodis's internals, so you reach someone who can read the stack trace, not a first-tier queue. During an incident that's usually what you want anyway: commands you can paste, and a record that drops straight into your post-incident review.
| Home Lab | Business | Plus & packs | Enterprise | |
|---|---|---|---|---|
| Documentation & community forum | Included | Included | Included | Included |
| Email support | community | next business day | next business day | priority |
| Disaster escalation | Not included | Included | Included | Included |
| Async configuration review | Not included | Not included | Included | Included |
| Custom agreement | Not included | Not included | Not included | talk to us |
Disaster escalation
A dedicated channel for when a site is actually down, not for routine questions. Written, and monitored outside business hours.
One-command diagnostics
Run asternodis support-bundle and attach the file. It carries no keys, tokens, or passwords, and no guest data. Open it and check.
Licensing never blocks recovery
Failover, failback and abort keep working even if a licence lapses or we're unreachable. The worst support outcome is designed out rather than escalated.
Support covers Asternodis itself. When the root cause is your storage, network, or Proxmox cluster, we'll pinpoint it. Resolving it is your team's, or a paid engagement. Business hours are Monday to Friday, US Eastern.
Does Proxmox have built-in disaster recovery?
Proxmox VE offers built-in ZFS replication (pvesr, between nodes of one cluster), Ceph's own RBD mirroring if you set it up yourself, and backups via Proxmox Backup Server, but it has no SRM/Zerto-class DR orchestration: no recovery plans, non-disruptive DR testing, or one-click failover. Asternodis adds that layer, and works on storage backends Proxmox can't natively replicate.
What RPO can Asternodis achieve?
You set a target per guest, from about 1 minute up, and Asternodis replicates continuously toward it, on any storage backend, not just ZFS or Ceph. The storage support matrix lists the validated storage backings. What you actually achieve depends on how much the guest writes and how fast the link between your sites is.
How fast is failback after a disaster?
Near-instant. While you run at the recovery site, Asternodis reverse-replicates your changes back to the primary continuously. When the primary is healthy again, failback applies only the small delta accumulated since (often a few megabytes, in seconds) instead of re-copying the whole disk.
Can I recover to a point before a ransomware attack?
Yes. Asternodis retains multiple integrity-verified, point-in-time recovery points, so you can fail over to a known-good moment rather than the latest (possibly-encrypted) state. A background scrub re-verifies each point over its whole retention life and quarantines any that silently rot, and a change-rate anomaly detector pauses replication on the signature of mass encryption to preserve a clean pre-attack point.
Is this a VMware SRM or Zerto alternative for Proxmox?
Yes. Asternodis brings the DR capabilities teams expect from VMware Live Site Recovery/SRM and Zerto (replication, DR testing, recovery plans, failover and failback) to Proxmox VE, at a fraction of the price.
Do I need a VPN between sites?
No. Control traffic between the two controllers rides one mutually authenticated TLS channel, and replication data moves node to node over separately encrypted links: mutually authenticated TLS for VM disks, SSH for containers and ZFS send. You open the ports the install guide lists between the sites, or ride an existing site-to-site VPN or Tailscale if you prefer.
How much does it cost?
Home Lab (non-commercial) is $99/year per DR Site Pair, with unlimited protected nodes. Home labs are never node-capped. Business licensing starts at $995/year for one pair covering up to 4 protected nodes, $2,495 for up to 12, and $4,995 for unlimited nodes. Multi-pair packs for MSPs and multi-site estates run from $3,995 for 5 pairs to $14,995 for 25, with their node allowance pooled across all the pairs in the pack. A DR Site Pair is one production site paired with one recovery site. Every tier includes the full DR feature set.
What support is included, and how fast do you answer?
Every tier includes the documentation and the community forum. Business and above add email support with a next-business-day response target (Monday to Friday, US Eastern) and a disaster escalation channel for when a site is actually down. Support is handled in writing, which during an incident is usually better anyway: you get commands you can paste and a record you can drop into your own post-incident review. Enterprise and multi-site agreements can be arranged to fit how your team works.
What counts as a protected node?
A Proxmox node that hosts at least one VM or container Asternodis is protecting. Nodes at the recovery site don't count, and neither do nodes running only guests you haven't protected, so you pay for the footprint you actually cover, not the size of your clusters. Asternodis shows the current count on its License page.
What if one site in a multi-pair pack has more nodes than the others?
That's fine: a pack's node allowance is pooled across every pair in it, not fixed per pair. A 5-Pack includes 20 protected nodes, so one client running 8 and four running 3 fits comfortably. You only need a bigger pack, or a custom agreement, when the whole pool runs out.
What's the difference between Home Lab and Business?
It's the same software, fully featured, either way. Home Lab is the discounted non-commercial tier for personal home labs, learning, and testing, not for running or protecting a business. Business licensing covers any commercial, production, or organizational use.
Prove recovery works in your own environment
Start a 14-day trial with the full feature set. Pair two sites, protect a VM, run a DR test, and watch it fail over before you pay.