Permission needed to update/upgrade

fatex

Member
Nov 15, 2020
5
0
6
37
Hi
try to assign more granular rights via the config-> access control and not do everything with the root account.

I previously had this issue that turned out to be a bug ( https://forum.proxmox.com/threads/permissons-not-working-for-network-settings.147899 )

Now I am trying to have the user able to run updates via the webui.
Upgrade is currently greyed out for non-root users on PVE and on PBS.
(access set to admin on /)

Second point is able to use the console. I would like to allow some user to use the console to have the ability to run command via cli or gain root rights via sudo.

In PVE users can use the console but not login with their account. They get a simple login screen able to relog to root for example.

In PBS user cannot use console (they get error 400).

Not sure if this is a bug or feature request ;)

Regards
 
Hi!
updating is currently only possible when using the root@pam account. This is enforced at the frontend level only.
The shell is only available for users from the realm 'pam' + SYS_CONSOLE permission.
 
Is there any roadmap to allow users other than root@pam to perform the updates ? (both PVE and PBS)
 
Hi!
actually I was wrong, this is also enforced on the backend.
Is there any roadmap to allow users other than root@pam to perform the updates ? (both PVE and PBS)
Probably not, because there is always a risk that the `apt full-upgrade` drops you into a root shell (f.e. with apt-hooks) and that is a big no no.
If you'd really like this, you can open a bug (https://bugzilla.proxmox.com/), because we could do something like a dry run, show the packages "to-be-upgraded" to the user and then run the actual upgrade in the background (although this is kind of flimsy, i.e. what if the packages to be upgraded change in the meantime, etc.).
 
Last edited:

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!