Permissions
cv4pve-vdi works through the API with the account of the person logging in, so the VMs it lists and what it lets you do with them are exactly what that account is allowed to. There is no user list inside cv4pve-vdi: Proxmox VE permissions are the configuration.
Create a user for each person, in any
realm (pve, pam, LDAP, Active Directory), and
assign it the privileges
below on the guests it should use: on /vms/<vmid> for single guests, on /pool/<pool> for every guest of a
pool, on /vms for all of them.
cv4pve-vdi logs in with user and password, not with an API token: the session belongs to a person, and its password can be passed on to RDP single sign-on.
Privileges
Section titled “Privileges”| Privilege | On | Used for | Without it |
|---|---|---|---|
VM.Audit |
/vms |
Listing the guest, its status and configuration (SPICE display, OS type, badges); the container’s IP address for services | The guest is not in the list |
VM.Console |
/vms |
SPICE and VNC consoles | No SPICE or VNC in the Connect menu; a running guest is shown only if it is a VM with a SPICE display |
VM.PowerMgmt |
/vms |
Start and Shutdown buttons | No power buttons; a stopped VM is shown only if its display is SPICE, a stopped container not at all |
VM.GuestAgent.Audit |
/vms |
Guest agent ping, the VM’s IP address for services and Discover | The agent badge turns red (with Ping guest agent on); services need an IP override |
The built-in PVEVMUser role contains all four, and also backup, CD-ROM, cloud-init and guest agent file
privileges that cv4pve-vdi does not use. For an account limited to what cv4pve-vdi needs, create a role with
these four only; leave out VM.PowerMgmt if users should not start or shut down their VMs.
Nothing more is needed for the rest of the window: nodes are always listed (their CPU and memory figures
only with Sys.Audit on the node), and the datacenter tag colours are readable by every user.
How missing privileges are reported
Section titled “How missing privileges are reported”Proxmox VE answers a request the caller is only partly entitled to by filtering the response:
/cluster/resources leaves out the guests the account cannot audit, with 200 OK. A guest without
VM.Audit is therefore simply missing from cv4pve-vdi, with no error.
For the other privileges cv4pve-vdi does not wait for an error: after login it reads the account’s
effective permissions (GET /access/permissions) and shows SPICE, VNC, Start and Shutdown only on the
guests where the account holds VM.Console or VM.PowerMgmt. The exact rules for which guests appear are
in The main window.
A call that fails anyway (a console refused by Proxmox VE, a node that does not answer) shows the Proxmox VE message in a notification at the bottom right of the window.