The nixos flake's create-proxmox-resource.sh runs pvesh/qm/pct over
non-interactive SSH, which requires NOPASSWD sudo for those binaries.
pvesh moved from /usr/sbin to /usr/bin in PVE 8.x, so the script
resolves paths at runtime rather than hardcoding them, preventing the
silent NOPASSWD-miss that caused ipcc_send_rec errors.
- scripts/setup-admin-sudo.sh: new script, takes username, writes
/etc/sudoers.d/<user>-proxmox with correct resolved paths and
validates it with visudo -c before leaving it in place
- scripts/bootstrap.sh: add setup-admin-sudo.sh to post-steps list
- scripts/audit.sh: check that a *-proxmox sudoers file exists with
NOPASSWD for all three tools
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>