Proxmox VE API permissions for PowerShell
The module works through the API, so a script can do exactly what its account is allowed to do, no
more. Use a dedicated user with an API token rather than root@pam, and give it only the privileges
the script needs.
User and token
Section titled “User and token”Create a user or an API token and assign it a role with the privileges below, on / or on the smallest path that covers what the script touches (/vms/100, /pool/web, /storage/local).
Privileges
Section titled “Privileges”The built-in PVEAuditor role covers the *.Audit privileges: enough for scripts that only read. For
anything else, create a role with just the privileges the script needs from the table.
| Privilege | On | Used for |
|---|---|---|
VM.Audit |
/vms |
Reading VMs and containers: Get-PveGuest, configuration, snapshots |
Sys.Audit |
/nodes |
Reading nodes, and tasks started by other users |
Datastore.Audit |
/storage |
Reading storage and its content |
VM.PowerMgmt |
/vms |
Start, stop, shut down, suspend, resume, reset |
VM.Snapshot |
/vms |
Taking, deleting and rolling back snapshots |
VM.Snapshot.Rollback |
/vms |
Rolling back only, without taking snapshots |
VM.Config.* |
/vms |
Changing the configuration; Unlock-PveGuest on containers |
VM.Console |
/vms |
Invoke-PveSpice |
VM.GuestAgent.Audit |
/vms |
Reading from the guest agent: OS, IP addresses |
VM.GuestAgent.Unrestricted |
/vms |
Running commands in the guest |
VM.Backup |
/vms |
Backups, with Datastore.AllocateSpace on the storage |
VM.Allocate |
/vms or /pool |
Creating VMs and containers, with Datastore.AllocateSpace and SDN.Use on the bridge |
VM.Clone |
/vms |
Cloning, with VM.Allocate on the new id |
Without a privilege a call that reads a list returns the list without what you may not see; any other
call returns a response with status code 403: see below.
Get-PveVersion, Get-PveClusterNextid and /cluster/resources (behind Get-PveGuest and Get-PveNode)
need no privilege: they answer every authenticated account, with only what it may see.
On Proxmox VE 8 the VM.GuestAgent.* privileges do not exist: the guest agent endpoints need
VM.Monitor. The exact privilege of every endpoint is in the
Proxmox VE API viewer, linked from each page of the
cmdlet reference.
How missing privileges are reported
Section titled “How missing privileges are reported”Proxmox VE answers a request the caller is only partly entitled to by filtering the response, not
by failing it. /cluster/resources drops the guests, storages and pools you cannot audit, a node’s VM
list drops the VMs without VM.Audit, a storage listing drops the volumes you cannot access. All return
200 OK: Get-PveGuest returning nothing may mean a token without privileges, not an empty cluster.
A request that is refused outright returns a PveResponse with StatusCode 403 and the reason in
ReasonPhrase, without throwing: see Errors.