Datastore.AllocateTemplate, Sys.Audit and Sys.Modify for the button to be enabled. See also here [1] and here [2] (under the "required permissions" section) Sys.Modify is a way too high privilege for our user.Sys.Modify (create/modify/remove node network parameters [1]) and Sys.Audit (view node status/config, Corosync cluster config, and HA config [1]).When you download a file, the URL gets resolved on the PVE host itself. If your server is sitting in a locked-down/separate network, this might allow a user to probe for different hosts that they shouldn't even be allowed to access. You can also check the original commit message (with this exact reasoning) here [1]. We've thought about whether this might be too harsh of a restriction, and you're welcome to open a report on our bugzilla instance [2], where others can chime in too.To be honest, I don't understand the connection between uploading ISO files andSys.Modify
this might allow a user to probe for different hosts that they shouldn't even be allowed to access
Sys.Modify:Hi, I know it's more than a year later, but I've just made it work.I believe this change should allow downloading from URL without grantingSys.Modify:
https://lists.proxmox.com/pipermail/pve-devel/2024-February/061842.html
However, I haven't been able to get it to work. Are there instructions somewhere on exactly what permissions need to be granted upon what resources for this to work?
We use essential cookies to make this site work, and optional cookies to enhance your experience.