restrict token roles

Signed-off-by: Kiara Grouwstra <kiara@procolix.eu>
This commit is contained in:
Kiara Grouwstra 2025-10-22 13:01:25 +02:00
parent 0e22347713
commit 1eb570c42a
Signed by: kiara
SSH key fingerprint: SHA256:COspvLoLJ5WC5rFb9ZDe5urVCkK4LJZOsjfF4duRJFU

View file

@ -160,7 +160,7 @@ in
pvesh create /pools --poolid Fediversity
pvesh set /storage/local --content "vztmpl,rootdir,backup,snippets,import,iso,images" 1>/dev/null
pvesh create /access/users/root@pam/token/mytoken --output-format json | jq -r .value
pvesh set /access/acl --path "/" --token "root@pam!mytoken" --roles "Administrator"
pvesh set /access/acl --path "/" --token "root@pam!mytoken" --roles "PVEVMAdmin PVEDatastoreAdmin PVESDNUser PVETemplateUser"
""").strip()
# skip indent for EOF