Ok good to know , so if i use token instead of Username/password , is it all good ?first, we already only use tokens for communication. when you set up the remote with a user/password, we automatically create a token on the cluster that will be used instead
You did not quite pin point the question.the answer to the actual question is: what ever permissions you give to the tokenof course if some action on the pdm side requires more permissions than the token has it's not possible. but e.g. a pure 'Audit' token should still see all of the information, but will not be able to start/stop/migrate/etc. guests

Great.Our plan is to flesh out the ACL system a bit more so that one can maybe give also some permissions on the pdm side for pdm users
currently, you'd need *.Audit for most things (e.g. the status/metrics/etc) and for start/stop/shutdown/migrate you need the same privs as on pve itself, so e.g. VM.Migrate, VM.PowerMgmt, Datastore.Allocate for e.g. a remote migration ( so we can allocate disks) etc.what the minimum permission is required for PDM to be fully operational ?
this may make sense as we're nearing the first stable release, but for now this will be very much in flux so it would be a moving target and outdated most of the time.and if it is not too much , can we have a sort of table :
We use essential cookies to make this site work, and optional cookies to enhance your experience.