Prepare Proxmox VE
Run on any cluster node. This creates a dedicated user with only the rights the panel needs, scoped to a pool that holds customer servers.
pveum user add panel@pve --comment "Customer panel"
# PVE 9 names. On PVE 8 use VM.Monitor instead of VM.GuestAgent.Audit.
pveum role add PanelCustomer --privs "VM.Audit VM.PowerMgmt VM.Console VM.Snapshot VM.Snapshot.Rollback VM.GuestAgent.Audit"
pveum pool add customers
pveum acl modify /pool/customers --users panel@pve --roles PanelCustomer
# --privsep 0: the token inherits exactly the user's permissions
pveum user token add panel@pve panel --privsep 0
Copy the token secret shown at the end. Then put each customer server into the pool:
pveum pool modify customers --vms 101,102
Servers outside the pool are invisible to the panel even if someone assigns them by mistake, which is a useful second safety net.
Extra permissions if customers may create servers
Skip this if you only assign servers yourself.
# Rights to clone, configure (CPU, RAM, cloud-init, disk size) and delete VMs
pveum role modify PanelCustomer --append 1 \
--privs "VM.Allocate VM.Clone VM.Config.CPU VM.Config.Memory VM.Config.Disk VM.Config.Cloudinit VM.Config.Options VM.Config.Network Datastore.AllocateSpace Datastore.Audit"
# Windows templates (password + computer name through the guest agent)
pveum role modify PanelCustomer --append 1 --privs "VM.GuestAgent.Unrestricted"
# Templates customers can pick from live in their own pool
pveum pool add templates
pveum pool modify templates --vms 9000,9001
pveum acl modify /pool/templates --users panel@pve --roles PanelCustomer
# Storage that new disks are created on
pveum acl modify /storage/VMStorage --users panel@pve --roles PanelCustomer
If Proxmox rejects a step with a permission error, the message names the missing privilege; add it to the role the same way.
New servers are placed into the customers pool (PVE_POOL), so the panel's
normal permissions cover them automatically.