777926487b
initial QEMU slice, backed by imported contracts for majors 6–9. - Implement durable handlers for access/auth, cluster, LXC, storage, HA, firewall, Ceph, SDN, ACME, notifications, pools, mapping, and node ops - Serve an interactive Web UI with catalog browsing, demo seed controls, and OpenAPI/help surfaces - Bundle PVE 6.4-15, 7.4-16, and 8.4.5 contract revisions alongside 9.2.3 - Support in-memory runtime contract Apply (POST /ui/api/contract/apply) so /version and /api2 routes follow the selected major until restart - Expand seed profiles (including demo-cluster), migrations 007–008, TLS gateway config, Compose/Makefile tooling, and compatibility evidence - Tighten .gitignore for macOS, hidden directories (.*/), and local secrets
17 lines
594 B
Markdown
17 lines
594 B
Markdown
# Access
|
|
|
|
Durable identity and authorization: users, groups, roles, ACL entries, realms,
|
|
passwords, API tokens, permissions queries, tickets, TFA, OpenID, VNC tickets.
|
|
|
|
## Highlights
|
|
|
|
- Ticket login and CSRF — see [Authentication](../authentication.md).
|
|
- Token create returns the secret once; only hashes are stored.
|
|
- ACL inheritance and token ∩ owner privilege intersection.
|
|
- Realm / TFA / OpenID state is **local**; no live directory or IdP calls.
|
|
|
|
## Seeded personas
|
|
|
|
`root@pam`, `auditor@pve`, `operator@pve`, `storage@pve` — see the
|
|
authentication guide for passwords and tokens.
|