I'm trying to figure out how to use accounts managed by the Proxmox VE Authentication Server in such a way that I can get CLI access (elevated/sudo/whatever) to the nodes in the cluster. Whether it's all nodes, limited notes, or whatever.
I can't find anyone talking about this so far, and the documentation doesn't seem to cover this.
So far whenever I go to the CLI for a node after logging into a PVE Auth Server account that is granted role "Administrator" it prompts for login and rejects the PVE Auth Server creds when I try to re-enter them.
To me this seems like the PAM on each node isn't really set up to honour PVE Auth Server functionality, but that's speculation as I cannot find anything saying "yes" or "no" to this being a thing. But honestly this really should be a capability as the PVE Auth Server (and maybe even other auth methods like LDAP/whatever) really should have the mechanism to get CLI access like this (at least when sufficient access is granted).
So... does anyone know how to do this? Or if this is "not a thing" yet or what?
I can't find anyone talking about this so far, and the documentation doesn't seem to cover this.
So far whenever I go to the CLI for a node after logging into a PVE Auth Server account that is granted role "Administrator" it prompts for login and rejects the PVE Auth Server creds when I try to re-enter them.
To me this seems like the PAM on each node isn't really set up to honour PVE Auth Server functionality, but that's speculation as I cannot find anything saying "yes" or "no" to this being a thing. But honestly this really should be a capability as the PVE Auth Server (and maybe even other auth methods like LDAP/whatever) really should have the mechanism to get CLI access like this (at least when sufficient access is granted).
So... does anyone know how to do this? Or if this is "not a thing" yet or what?