you need Datastore.AllocateTemplate, Sys.Audit and Sys.Modify for the button to be enabled. See also here [1] and here [2] (under the "required permissions" section) .
Thanks for your fast reply and for pointing to the definition.
Unfortunately Sys.Modify is a way too high privilege for our user.
To be honest, I don't understand the connection between uploading ISO files and Sys.Modify (create/modify/remove node network parameters [1]) and Sys.Audit (view node status/config, Corosync cluster config, and HA config [1]).
I really look forward to the roadmaps point Project "Cattle and Pets" hoping it lets me define the privileges better.
When you download a file, the URL gets resolved on the PVE host itself. If your server is sitting in a locked-down/separate network, this might allow a user to probe for different hosts that they shouldn't even be allowed to access. You can also check the original commit message (with this exact reasoning) here [1]. We've thought about whether this might be too harsh of a restriction, and you're welcome to open a report on our bugzilla instance [2], where others can chime in too.
However, I haven't been able to get it to work. Are there instructions somewhere on exactly what permissions need to be granted upon what resources for this to work?
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.