Skip to content

Permissions

cv4pve-autosnap works through the API, so it can snapshot exactly the guests its account is allowed to see. Use a dedicated user with an API token rather than root@pam.

Create a user or an API token and assign it the privileges below, on /.

Privilege On Used for Without it
VM.Audit /vms Listing the guests, reading their configuration and snapshots The guest is not selected: VMs with '…' NOT FOUND
VM.Snapshot /vms Creating and removing snapshots The task fails: snap and clean exit with 1
Datastore.Audit /storage Storage usage for --max-perc-storage The storage check is skipped and snapshots are taken anyway, with POSSIBLE PROBLEM PERMISSION 'Datastore.Audit'
Pool.Audit /pool Resolving --vmid=@pool-… The pool selects no guests: VMs with '…' NOT FOUND

Pool.Audit is needed only to select guests by pool. On Proxmox VE 8 and earlier the pool list required Pool.Allocate instead (#122). Snapshots with the RAM (--state) need no other privilege.

To limit the tool to some guests, grant VM.Audit and VM.Snapshot on those guests or on a pool (/pool/<name>) instead of /vms.

Proxmox VE answers a request the caller is only partly entitled to by filtering the response, not by failing it. /cluster/resources drops the guests and storages you cannot audit, and the pool list drops the pools. Both return 200 OK, so a filtered result looks exactly like an empty one: a guest missing VM.Audit simply is not selected.

That is why cv4pve-autosnap cannot tell a wrong --vmid from a missing privilege: when nothing is found it prints VMs with '…' NOT FOUND followed by the privileges that may be missing. With VM.Snapshot missing, instead, the request fails outright and the error of Proxmox VE is printed for that guest. See Troubleshooting.