48df10b17e
- Harden DB-backed handlers and seed profiles; align client wire shapes for cluster resources, QEMU config, and node SSL fields - Serve plain HTTP on Compose :8006; keep TLS optional (--profile tls) and terminate HTTPS at Kubernetes Ingress - Add pulumi-tests (full contract surface majors 6–9 + BPG lifecycle) and make pulumi-tests - Ship bilingual docs, CHANGELOG, SECURITY, CONTRIBUTING, and GitHub Actions (make ci + Compose/Helm validation)
19 lines
685 B
Markdown
19 lines
685 B
Markdown
**Language / Язык:** [English](access.md) | [Русский](../ru/domains/access.md)
|
|
|
|
# Access
|
|
|
|
Durable identity and authorization: users, groups, roles, ACL entries, realms,
|
|
passwords, API tokens, permissions queries, tickets, TFA, OpenID, VNC tickets.
|
|
|
|
## Highlights
|
|
|
|
- Ticket login and CSRF — see [Authentication](../authentication.md).
|
|
- Token create returns the secret once; only hashes are stored.
|
|
- ACL inheritance and token ∩ owner privilege intersection.
|
|
- Realm / TFA / OpenID state is **local**; no live directory or IdP calls.
|
|
|
|
## Seeded personas
|
|
|
|
`root@pam`, `auditor@pve`, `operator@pve`, `storage@pve` — see the
|
|
authentication guide for passwords and tokens.
|