[SOLVED] Replace root user for ssh tunnel

Nicolas Lobariñas

Renowned Member
May 9, 2017
8
0
66
45
Hi, I was looking in several forums and get no info about it.
I'm working on a Proxmox 3 nodes cluster to visualize VoIP services, Web Servers and MySQL servers.
Due to the enterprise security policies I can't allow the root user to login via ssh to the servers.
What I'm looking for is to replace the root user, who does the migration of the containers and vm's between nodes.
Is that possible?
Thanks in advance!

root@svir0101lx:~# pveversion -v
proxmox-ve: 4.3-66 (running kernel: 4.4.19-1-pve)
pve-manager: 4.4-5 (running version: 4.4-5/c43015a5)
pve-kernel-4.4.19-1-pve: 4.4.19-66
lvm2: 2.02.116-pve3
corosync-pve: 2.4.0-1
libqb0: 1.0-1
pve-cluster: 4.0-48
qemu-server: 4.0-102
pve-firmware: 1.1-10
libpve-common-perl: 4.0-85
libpve-access-control: 4.0-19
libpve-storage-perl: 4.0-71
pve-libspice-server1: 0.12.8-1
vncterm: 1.2-1
pve-docs: 4.4-1
pve-qemu-kvm: 2.7.1-1
pve-container: 1.0-90
pve-firewall: 2.0-33
pve-ha-manager: 1.0-38
ksm-control-daemon: 1.2-1
glusterfs-client: 3.5.2-2+deb8u3
lxc-pve: 2.0.6-5
lxcfs: 2.0.5-pve2
criu: 1.6.0-1
novnc-pve: 0.5-8
smartmontools: 6.5+svn4324-1~pve80
zfsutils: 0.6.5.7-pve10~bpo80

root@svir0101lx:~# pvecm status
Quorum information
------------------
Date: Tue May 9 17:10:55 2017
Quorum provider: corosync_votequorum
Nodes: 3
Node ID: 0x00000001
Ring ID: 1/404
Quorate: Yes

Votequorum information
----------------------
Expected votes: 3
Highest expected: 3
Total votes: 3
Quorum: 2
Flags: Quorate

Membership information
----------------------
Nodeid Votes Name
0x00000001 1 192.168.254.249 (local)
0x00000002 1 192.168.254.250
0x00000003 1 192.168.254.251
 
What I'm looking for is to replace the root user, who does the migration of the containers and vm's between nodes.
Is that possible?

No, but you can use the firewall to block ssh access from outside, or configure /etc/hosts.allow.