Skip to content

Proxmox VE Permissions

cv4pve-admin connects to Proxmox VE via API and requires specific permissions depending on which modules and features you use.


The simplest and recommended setup is to assign the built-in PVEAdmin role at path / to the Proxmox user or API token used by cv4pve-admin.

This grants full functionality for all modules without any further configuration.

Automatic API Token Creation

cv4pve-admin can create a dedicated Proxmox user and API token for you automatically. Learn more


Minimum permissions

If you prefer a least-privilege setup, assign a custom Proxmox role at path / with only the permissions required for the features you use.

Base (required for all modules)

These are the permissions included in the built-in PVEAuditor role — equivalent and simpler to assign directly.

Permission Purpose
Sys.Audit Cluster status, node info, tasks, firewall, HA
VM.Audit VM/CT list, status, config
Datastore.Audit Storage list, status, content
Pool.Audit Resource pool list
SDN.Audit SDN zones, VNets, subnets

Additional permissions by module

Module Additional permissions (beyond base)
Dashboard
Resources
• VM.PowerMgmt (start/stop/reboot buttons)
• VM.Console (console button)
• VM.GuestAgent.Audit (hostname/IP info)
Replication Analytics —
Backup Analytics —
Metrics Exporter —
Diagnostics —
System Report —
AutoSnap • VM.Snapshot
• VM.Snapshot.Rollback
• Datastore.AllocateSpace
• Pool.Allocate
• VM.PowerMgmt (only if Include RAM is enabled)
Node Protect Base only — uses SSH to operate on nodes
Update Manager Base only — uses SSH to operate on nodes/VMs
UPS Monitor — (SNMP only, no PVE API)
VM Performance • VM.Monitor
AI Server Depends on which tools are enabled:
• Power state: VM.PowerMgmt
• Snapshots: VM.Snapshot, VM.Snapshot.Rollback
• Migrate: VM.Migrate
• Backup: VM.Backup, Datastore.AllocateSpace
• Delete backups / storage content: Datastore.Allocate
• Download ISO: Datastore.AllocateTemplate
(read-only tools need base only; each tool is individually grantable)
Bots Depends on the commands enabled in the bot (power and snapshot commands need VM.PowerMgmt and VM.Snapshot)
Portal • VM.PowerMgmt
• VM.Console
• VM.Snapshot
• VM.Snapshot.Rollback
• VM.Backup
• Datastore.AllocateSpace
(depends on tenant permissions configured)
Workflow Depends on configured activities:
• Clone: VM.Clone, Datastore.AllocateSpace
• Backup: VM.Backup, Datastore.AllocateSpace
• Resize disk: VM.Config.Disk
• HA operations: Sys.Modify
• Node reboot/shutdown: Sys.PowerMgmt
• Convert to template: VM.Allocate

Example: monitoring + AutoSnap custom role

Sys.Audit
VM.Audit
VM.Snapshot
VM.Snapshot.Rollback
Datastore.Audit
Datastore.AllocateSpace
Pool.Audit
Pool.Allocate

Assign at path / to your cv4pve-admin user or API token.

Warning

Features that lack required permissions will show errors or empty data — other features will continue to work normally.