Portal ¶
Multi-tenant management portal for Proxmox VE environments, designed for MSPs and IT teams. Create, assign and isolate virtual environments for clients, departments or groups while keeping centralised control over the cluster.
Features¶
-
Isolated Tenant Management
Each tenant can access only their own virtual resources.
-
Centralized Control
Assign resources, policies and access from a single point.
-
Easy Scalability
Quickly add new tenants without impacting the existing infrastructure.
-
Intuitive Interface
Clear and well-organised frontend for administrators and tenants.
-
Secure and Segmented Access
Tenant users get their own cv4pve-admin accounts with per-VM permissions.
-
Native Proxmox Integration
Fully compatible with existing infrastructure — no invasive changes required.
Why¶
Why a portal layer when PVE has its own users and roles?
Customers see only their VMs
Tenant users log into cv4pve-admin and are granted permissions only on the VMs assigned to their tenant — no chance of accidentally touching another customer.
One tenant, one cluster
Each tenant is bound to a single cluster; its VMs/CTs are picked from that cluster's resources.
cv4pve-admin permissions, not PVE ACLs
Access is granted through cv4pve-admin's own per-VM permissions — no users or ACLs to create on the Proxmox VE cluster.
MSP-grade isolation
Customers don't see each other, can't navigate to other tenants' resources, can't enumerate VM IDs that aren't theirs.
Sections¶
- Tenants — create and manage tenants with their assigned VMs/CTs and users
Tenants¶
Each tenant belongs to one cluster and contains:
- VMs / CTs — list of Proxmox VE resources (from the tenant's cluster) assigned to the tenant
- Users — tenant users: regular cv4pve-admin accounts (a new user is created with a random password and receives a confirmation email). For each VM/CT of the tenant you pick which permissions the user gets: Read, Audit, Console, Power Management, Replication manager, Replication Schedule Now, Snapshot manager, Snapshot Rollback, Backup manager, Backup Restore, Backup Restore File. A user can also be flagged as Tenant Admin
Roles¶
| Role | Description |
|---|---|
| Portal Admin | Full access to tenant management, VMs and users |
| Portal Tenant Admin | Manages resources within their own tenant |
| Portal Tenant User | Read-only or limited access within their tenant |
Use Cases¶
- MSP / Service Providers — separate environments per customer with isolated access
- Enterprise IT — department-level resource isolation on a shared cluster
- Education — assign lab environments to student groups