Skip to content

M6 epic: Proxmox accounts, TLS trust, and discovery #9

Description

@Andreas-Froyland

Tracking issue. Dependency and status checklists only — implementation stays in narrow linked issues.

Outcome

Fleet authenticates to one or more Proxmox accounts with verified TLS trust and reports health and privilege problems clearly.

Supersedes

Replaces the "Proxmox API client/adapter (auth)" and "credential/secrets handling for the Proxmox API token" scope items of #3.

Depends on

  • FM-S08 — Proxmox client compatibility spike (docs/planning/spikes.md)
  • FM-102 — encrypted controller secret records (M1)

Scope checklist

  • Multi-account authentication replacing the legacy environment-variable singleton
  • TLS trust and pinning without rejectUnauthorized: false in production paths
  • Health, privilege diagnostics, and least-privilege credential documentation
  • API compatibility matrix covering PVE 8.x and 9.x
  • Cluster, node, storage, and template discovery

Constrained by

  • docs/PLAN.md — M6 and Supported platform baseline; ADR-0005
  • FM-000 fixed the compatibility target at PVE 8.x and 9.x; passing one major is not a pass

Non-goals

  • Replacing Proxmox, its console, or its storage/network configuration
  • Adopting the experimental typed crate without the FM-S08 evidence

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    epicTracking issue: dependency and status checklist only

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions