This repository has been archived on 2026-08-17. You can view files and clone it. You cannot open issues or pull requests or push a commit.
beatzaplentyandClaude Sonnet 4.6 2d5472a59d add setup-admin-sudo.sh for passwordless Proxmox tool access
The nixos flake's create-proxmox-resource.sh runs pvesh/qm/pct over
non-interactive SSH, which requires NOPASSWD sudo for those binaries.
pvesh moved from /usr/sbin to /usr/bin in PVE 8.x, so the script
resolves paths at runtime rather than hardcoding them, preventing the
silent NOPASSWD-miss that caused ipcc_send_rec errors.

- scripts/setup-admin-sudo.sh: new script, takes username, writes
  /etc/sudoers.d/<user>-proxmox with correct resolved paths and
  validates it with visudo -c before leaving it in place
- scripts/bootstrap.sh: add setup-admin-sudo.sh to post-steps list
- scripts/audit.sh: check that a *-proxmox sudoers file exists with
  NOPASSWD for all three tools

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-23 09:20:48 +10:00
2026-07-21 23:14:20 +00:00
2026-07-21 23:14:20 +00:00
2026-07-21 23:14:20 +00:00
2026-07-21 23:14:20 +00:00

Proxmox Configuration

Base configuration and hardening toolset for Proxmox VE hosts, plus planning docs for eventually growing this into a 3-node HA/Ceph cluster. See docs/00-overview.md for the staging: Stage 1 (base config/hardening, applies to any host — active) vs. Stage 2 (multi-node HA/Ceph — future, deferred).

Goals

  • Stage 1: a reusable, idempotent base-hardening toolset (scripts/) that can be run against any new Proxmox host — repo/updates, SSH, firewall, PVE user/access hardening — verified with scripts/audit.sh.
  • Stage 2 (future): 3-node cluster, quorum via corosync, HA-managed VMs backed by Ceph. Needs dedicated hardware node 1 (pve1, an ASUS PN53 mini PC) doesn't have — see docs/01-hardware-node1.md.

See CLAUDE.md for the guardrails Claude Code follows when working against these hosts (pve1 is production and off-limits by default; pve-test is the sandbox).

Repo layout

  • docs/ — planning docs: hardware layout, storage migration, networking, security hardening, node roles. Read docs/00-overview.md first, then docs/05-node-roles.md for what pve1/pve-test actually are.
  • scripts/ — scripts to apply configuration on a node (SSH hardening, repo switch, firewall, updates, wifi/bond networking, etc). Idempotent, safe to re-run. scripts/bootstrap.sh runs the full Stage 1 sequence end to end; scripts/audit.sh verifies it (read-only). scripts/setup-wifi-bond-network.sh reproduces pve-test's wifi network (see docs/06-pve-test-wifi-network.md). scripts/lib/ holds shared helpers (common.sh) sourced by the other scripts.
  • config/ — reference config files/snippets to drop onto a node (firewall rules, sshd config, etc.).

Quick start (Stage 1, on a fresh node)

MGMT_CIDR=192.168.2.0/24 ./scripts/bootstrap.sh
./scripts/create-admin-user.sh <username>
# then enable 2FA for that user + root@pam via the web UI
./scripts/audit.sh

Status

pve1 built (ASUS PN53 mini PC, ZFS mirror boot+VM storage, single 2.5GbE NIC) and already running production VMs/CTs. Stage 1 base hardening applied and verified (scripts/audit.sh all green): enterprise repos removed, SSH key-only + fail2ban, unattended security upgrades, PVE firewall (mgmt-only), subscription nag disabled, named admin user (wayne@pve) created. Remaining manual step: enable 2FA/TOTP for wayne@pve and root@pam via the web UI. Stage 2 (cluster/Ceph) not started — needs nodes 2/3 on hardware that can actually support it.

S
Description
No description provided
Readme
195 KiB
Languages
Shell 100%