Trying to understand namespace and user permissions

luison

Renowned Member
Feb 22, 2010
109
4
83
Spain
alsur.es
Hi. New to PBS we are trying to configure a server that syncs backups from two others and retains them for long term.
We have created two namespaces as production and staging on that server named "pve-archive" which is syncing correctly.

We would now like to be able to access from one of those PVE servers for testing purposes all of those backups (all namespaces sources and CT), so we've created a user and assigned "root level" access to pve-archive with the DataStore admin permissions.

All working fine, but we don't see any backups on that storage in PVE. Wondering if we are not understanding correctly the ACL/namespace or if PVE would only see "its own" backups on the remote PBS server. Or could it be that "root level" access to a storage does not inherit bellow namespaces?

What would be the correct configuration for something like this?
 
if i understand you correctly, you don't see the backups in a namespace in pve? so in pve, the listing is not recursive, so you have to add the namespace to the pve storage configuration
 
Yes I assummed that "root" access to a storage implies inheriting all the bellow namespaces. Is this not the case? Is it configurable on the connection, ACL or storage definition?
Thanks.
 
when you add the storage to pve, there should be a 'namespace' field. pve only shows the content of the chosen namespance (and if nothing is given, the root namespace)
 
Noted then, thank you.
From my point of view, considering the way ACL is built... root should have access to all namespaces. Not being the case I would suggest at least a feature to allow to "duplicate" an already defined storage so one can just add one per each namespace you want to have access to without having to redo manually all the connection configuration.

thanks again.
 
this has nothing to do with ACLs, it's simply that the pbs client in pve only uses one namespace and does not enters into the nested namespaces.
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!