Skip to content

Connection

cv4pve-autosnap talks to the Proxmox VE REST API of any node of the cluster. Create the user and API token first: see Permissions.

OptionWhat it does
--hostOne or more nodes, comma-separated: pve1,pve2:8006,[fe80::1]. The port defaults to 8006. At startup the first node that accepts a connection is used, so the tool runs while a node is down; if the login on that node fails, the others are not tried. Any node gives the view of the whole cluster.
--api-tokenUSER@REALM!TOKENID=UUID, Proxmox VE 6.2 or later. Recommended. Quote it on the command line: ! is special in bash.
--username / --passwordAlternative to the token, e.g. --username=autosnap@pve (without a realm, pam is used). Accounts with two-factor authentication cannot log in this way: use a token.--password=file:/path/secret asks for the password the first time and saves it in that file obfuscated, not encrypted (the key is built into the tool): protect the file like the password itself.
--validate-certificateVerify the node TLS certificate. Off by default, so the default self-signed Proxmox certificate is accepted; turn it on if the nodes have a trusted certificate.

The options you repeat can go in a file, passed with @. On error the tool prints ERROR: … and exits with code 1.

A job run by cron or Task Scheduler repeats the same connection every time: keep it in a file.

Put the options you repeat (the connection above all) in a file and pass it with @. The file is read as if its content were typed on the command line, so no shell quoting is needed: an API token with ! goes in as it is.

production.rsp
# Any node of the cluster; list several so the tool runs while one is down
--host=pve01,pve02,pve03
# API token (recommended)
--api-token=autosnap@pve!snap=<uuid>
# ...or user and password, for accounts without two-factor authentication
# --username=autosnap@pve
# --password=<password>
# ...or the password in a file: asked on a first, interactive run, then read from it
# --password=file:/etc/cv4pve/password
# Only if the nodes have a certificate from a trusted CA
# --validate-certificate
# Guests to snapshot, see Choosing guests
--vmid=@tag-snapshot
cv4pve-autosnap @production.rsp snap --label=daily --keep=7
  • @production.rsp is replaced by its content where it stands, so put it where those options are valid: with the other options of the command, before or after them.
  • Options are separated by spaces, one or more per line: --option=value or--option value. A value with spaces goes in quotes: --settings-file="C:\My Files\settings.json".
  • A line that starts with # is a comment: handy to keep alternatives ready, as above. A# after an option is not: it is read as an argument and the command fails.
  • @other.rsp inside a file includes another file, for example one with the connection, shared by files with different options.

A file with a password or an API token is as sensitive as the password itself: keep it readable only by the account that runs the tool (chmod 600 on Linux). TheSystem.CommandLine library the tools are built on calls such a file a response file.

--vmid goes before snap, so it can live in the same file as the connection. An option can be given only once: with --vmid in the file, do not repeat it on the command line: see Scheduling.