I'm having trouble with an automated Proxmox Backup Install process, specifically using an auth token cooked into the ISO.
I use a custom endpoint to generate my answer.toml files for PVE, which works fine when I generate an ISO using
When I see PBS POST for the answer.toml, it does not include the authorization header.
For comparison, here is a lightly redacted header from a capture on my provisioning station from a PVE install (which works fine)
and here is the header from a PBS request which fails (as the authorization is not sent, the server rejects it):
The command I use to generate the PBS ISO is as follows (lightly redacted):
which is identical to the PVE version, just a different ISO to build from. The rest of the options are provided by DNS in my environment.
When I look inside the PBS ISO, I do see the `auto-installer-mode.toml` file, so it appears to be generating properly:
If I remove the auth-token validation from my configuration endpoint it will proceed with the auto-install properly, but I'd rather not do that of course!
Am I missing something special about making a Proxmox Backup Server auto-install ISO with auth?
I use a custom endpoint to generate my answer.toml files for PVE, which works fine when I generate an ISO using
proxmox-auto-install-assistant's --answer-auth-token option. I'm looking to use this same functionality for PBS, which works great, minus this auth-token issue.When I see PBS POST for the answer.toml, it does not include the authorization header.
For comparison, here is a lightly redacted header from a capture on my provisioning station from a PVE install (which works fine)
Code:
POST /api/proxmox-install/answer HTTP/1.1
accept-encoding: gzip
content-length: 566
user-agent: ureq/3.0.11
host: proxmox-ztp.example.com:8001
content-type: application/json; charset=utf-8
accept: application/json, application/toml;q=0.5
authorization: Bearer exampleconfig:123123123=
and here is the header from a PBS request which fails (as the authorization is not sent, the server rejects it):
Code:
POST /api/proxmox-install/answer HTTP/1.1
accept-encoding: gzip
content-length: 578
user-agent: ureq/3.0.11
accept: */*
host: proxmox-ztp.example.com:8001
content-type: application/json; charset=utf-8
The command I use to generate the PBS ISO is as follows (lightly redacted):
Code:
proxmox-auto-install-assistant prepare-iso proxmox-backup-server_4.2-1.iso --fetch-from http --answer-auth-token "exampleconfig:123123123=" --pxe --output ./pbs-pxe/ --pxe-loader ipxe
which is identical to the PVE version, just a different ISO to build from. The rest of the options are provided by DNS in my environment.
When I look inside the PBS ISO, I do see the `auto-installer-mode.toml` file, so it appears to be generating properly:
Code:
mode = "http"
partition_label = "proxmox-ais"
[http]
token = "exampleconfig:123123123="
If I remove the auth-token validation from my configuration endpoint it will proceed with the auto-install properly, but I'd rather not do that of course!
Am I missing something special about making a Proxmox Backup Server auto-install ISO with auth?
Last edited: