Host-based backup of Proxmox VE VMs.
Post Reply
jbender81
Novice
Posts: 9
Liked: 4 times
Joined: Jul 09, 2026 9:33 am
Full Name: Jörg Bender
Contact:

PVE Role privileges

Post by jbender81 » 1 person likes this post

Moin,
Is there a list of required Proxmox privileges for "veeam@pam" for the API-Connection
There is already a very nice list for sudo here https://www.veeam.com/kb4701 for the user "veeam" for the SSH-connection.

Cheers
Jörg
rovshan.pashayev
Product Manager
Posts: 827
Liked: 185 times
Joined: Jul 03, 2023 12:44 pm
Full Name: Rovshan Pashayev
Location: Czechia
Contact:

Re: PVE Role privileges

Post by rovshan.pashayev »

Hi Jörg,

As written in the same KB, administrator role is needed.

"Add the Administrator role for the root path ( Path: / ) to that user."
Rovshan Pashayev
Analyst
Veeam Agent for Linux, Mac, AIX & Solaris
jbender81
Novice
Posts: 9
Liked: 4 times
Joined: Jul 09, 2026 9:33 am
Full Name: Jörg Bender
Contact:

Re: PVE Role privileges

Post by jbender81 »

Hi,
Thank you.
I had hoped for a little bit more granular privileges, like it is provided for sudo.
This is pretty much the equivalent to "veeam ALL=(ALL:ALL) ALL" for sudo.

Cheers
Jörg
rovshan.pashayev
Product Manager
Posts: 827
Liked: 185 times
Joined: Jul 03, 2023 12:44 pm
Full Name: Rovshan Pashayev
Location: Czechia
Contact:

Re: PVE Role privileges

Post by rovshan.pashayev »

Hello,

Have you ever faced any security issues or is this general concern?
Rovshan Pashayev
Analyst
Veeam Agent for Linux, Mac, AIX & Solaris
jbender81
Novice
Posts: 9
Liked: 4 times
Joined: Jul 09, 2026 9:33 am
Full Name: Jörg Bender
Contact:

Re: PVE Role privileges

Post by jbender81 »

Moin,
No immediate concern, but just a proponent of "least privileges".
For example, I'm pretty positive, that the veeam@pam does not need to have access to the clusters realm, role and user configuration, especially no write access.

To clarify: This is no show stopper but just an inquiry.

Cheers
Jörg
XxPatrickxX
Novice
Posts: 5
Liked: 1 time
Joined: Oct 28, 2024 1:04 pm
Contact:

Re: PVE Role privileges

Post by XxPatrickxX »

Agreed, it's overly permissive currently. With Sudoers access, I'm not sure how much it matters though. Beyond what's mentioned I'd like to see the service account loose sudo, cluster-wide write access, non-vm specific host configuration access.

While it works, the concern is if ever the account gets compromised beyond breaking the vm's it can break the hosts as well.
Post Reply

Who is online

Users browsing this forum: Asahi and 1 guest