Connection
cv4pve-autosnap talks to the Proxmox VE REST API of any node of the cluster. Create the user and API token first: see Permissions.
Options
Section titled “Options”| Option | What it does |
|---|---|
--host | One or more nodes, comma-separated: pve1,pve2:8006,[fe80::1]. The port defaults to 8006. At startup the first node that accepts a connection is used, so the tool runs while a node is down; if the login on that node fails, the others are not tried. Any node gives the view of the whole cluster. |
--api-token | USER@REALM!TOKENID=UUID, Proxmox VE 6.2 or later. Recommended. Quote it on the command line: ! is special in bash. |
--username / --password | Alternative to the token, e.g. --username=autosnap@pve (without a realm, pam is used). Accounts with two-factor authentication cannot log in this way: use a token.--password=file:/path/secret asks for the password the first time and saves it in that file obfuscated, not encrypted (the key is built into the tool): protect the file like the password itself. |
--validate-certificate | Verify the node TLS certificate. Off by default, so the default self-signed Proxmox certificate is accepted; turn it on if the nodes have a trusted certificate. |
The options you repeat can go in a file, passed with @. On error the tool prints ERROR: … and exits with code 1.
Options in a file
Section titled “Options in a file”A job run by cron or Task Scheduler repeats the same connection every time: keep it in a file.
Put the options you repeat (the connection above all) in a file and pass it with @. The file is read as if its content were typed on the command line, so no shell quoting is needed: an API token with ! goes in as it is.
# Any node of the cluster; list several so the tool runs while one is down--host=pve01,pve02,pve03
# API token (recommended)--api-token=autosnap@pve!snap=<uuid>
# ...or user and password, for accounts without two-factor authentication# --username=autosnap@pve# --password=<password># ...or the password in a file: asked on a first, interactive run, then read from it# --password=file:/etc/cv4pve/password
# Only if the nodes have a certificate from a trusted CA# --validate-certificate
# Guests to snapshot, see Choosing guests--vmid=@tag-snapshotcv4pve-autosnap @production.rsp snap --label=daily --keep=7@production.rspis replaced by its content where it stands, so put it where those options are valid: with the other options of the command, before or after them.- Options are separated by spaces, one or more per line:
--option=valueor--option value. A value with spaces goes in quotes:--settings-file="C:\My Files\settings.json". - A line that starts with
#is a comment: handy to keep alternatives ready, as above. A#after an option is not: it is read as an argument and the command fails. @other.rspinside a file includes another file, for example one with the connection, shared by files with different options.
A file with a password or an API token is as sensitive as the password itself: keep it readable only by the account that runs the tool (chmod 600 on Linux). TheSystem.CommandLine library the tools are built on calls such a file a response file.
--vmid goes before snap, so it can live in the same file as the connection. An option can be given
only once: with --vmid in the file, do not repeat it on the command line: see
Scheduling.