From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id EDCDF1FF0B3 for ; Wed, 09 Sep 2026 12:40:23 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id AD661215DC; Wed, 09 Sep 2026 12:40:02 +0200 (CEST) X-Envelope-From: DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=elettra.eu; s=esgkey1; t=1788949802; bh=LtLgJLFtd/DvHENncGcYQZA4avBLVUkoLT8bUyE7S/w=; h=Date:To:From:Subject:From; b=Llrl4AOnbsaVs/KkV8Z4biEzMIoUAmfiXvpoMTsaauk5p712mDaQpmbINDDYUx1A8 1xvnoj/u0qP7MJ3K48QwAbnBRt8C/nIW+CKqXqIQfz8lVqfBwYD3o2+R6OQqB8gL73 5FX4sW5pLe3cq+WOfWsJS1U9LWj51Jk3BOtx/zHw= X-Virus-Scanned: amavis at zmp.elettra.eu Message-ID: <1294fddd-69a3-4fc8-841b-5ece917ca7e6@elettra.eu> Date: Wed, 9 Sep 2026 12:30:02 +0200 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird To: pve-user@lists.proxmox.com From: Iztok Gregori Content-Language: it, en-US Subject: Puppet/Openvox and ssh authorized_keys file Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-elettra-Libra-ESVA-Information: Please contact elettra for more information X-elettra-Libra-ESVA-ID: 4hfxrp4vyKzCT8N X-elettra-Libra-ESVA: No virus found X-elettra-Libra-ESVA-From: iztok.gregori@elettra.eu X-elettra-Libra-ESVA-Watermark: 1789554603.25239@GavpAEJWmvwenC5lAyXEYA X-SPAM-LEVEL: Spam detection results: 0 DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid DKIM_VALID -0.1 Message has at least one valid DKIM or DK signature DKIM_VALID_AU -0.1 Message has a valid DKIM or DK signature from author's domain DKIM_VALID_EF -0.1 Message has a valid DKIM or DK signature from envelope-from domain DMARC_PASS -0.1 DMARC pass policy RCVD_IN_MSPIKE_H2 0.001 Average reputation (+2) SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: UF6MLCBOOTUEPA3OAMVZPYRYZQVWHNKB X-Message-ID-Hash: UF6MLCBOOTUEPA3OAMVZPYRYZQVWHNKB X-MailFrom: iztok.gregori@elettra.eu X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE user list List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Hi to all! I have some specific questions regarding how Proxmox handles authorized_keys file and how to manage that file with puppet/openvox. - When the "/etc/pve/priv/authorized_keys" is created/updated by Proxmox? I suspect on the cluster creation and after a node is added/removed, but I'm not certain. - If is a regular file or is missing, when the symbolic link "/root/.ssh/authorized_keys" (which points to "/etc/pve/priv/authorized_key") is recreated? At node startup? - Is it safe to let openvox/puppet manage directly "/etc/pve/priv/authorized_keys" (so we can automatically add/remove administrator ssh keys as needed)? Thank you for your time Iztok Gregori -- Iztok Gregori ICT Systems and Services Elettra - Sincrotrone Trieste S.C.p.A. http://www.elettra.eu