From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [IPv6:2a0f:8001:1:32::40]) by lore.proxmox.com (Postfix) with ESMTPS id F24FC1FF0E7 for ; Thu, 13 Aug 2026 19:10:38 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 58C4321A4F; Thu, 13 Aug 2026 19:10:35 +0200 (CEST) From: Christian Ebner To: pbs-devel@lists.proxmox.com Subject: [PATCH proxmox 02/28] pbs-api-types: add remote datastore append privs and role Date: Thu, 13 Aug 2026 19:09:36 +0200 Message-ID: <20260813171002.809441-3-c.ebner@proxmox.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260813171002.809441-1-c.ebner@proxmox.com> References: <20260813171002.809441-1-c.ebner@proxmox.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1786641013036 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.222 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust RDNS_NONE 1.274 Delivered to internal network by a host with no rDNS SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: CX3NQAT32N5LAMCQ43ZJKTAFFZHIIO2Q X-Message-ID-Hash: CX3NQAT32N5LAMCQ43ZJKTAFFZHIIO2Q X-MailFrom: c.ebner@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox Backup Server development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: While allowing to push/backup to remotes like Remote.DatastoreBackup, Remote.DatastoreAppend also allows creation of namespaces, but never deletion/modification as Remote.DatastoreModify would imply, not even for owned contents. The role is intended to allow local (source) user configuration for immutable push sync jobs and is to be set on the user/token on the remote's datastore ACL path. This is intended to be used with a remote user on the push target having Datastore.Audit and Datastore.Append on the target datastore or sub-namespace. Signed-off-by: Christian Ebner --- pbs-api-types/src/acl.rs | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/pbs-api-types/src/acl.rs b/pbs-api-types/src/acl.rs index 9055dfab..f467db8d 100644 --- a/pbs-api-types/src/acl.rs +++ b/pbs-api-types/src/acl.rs @@ -61,6 +61,8 @@ constnamedbitmap! { PRIV_REMOTE_MODIFY("Remote.Modify"); /// Remote.Read allows reading data from a configured `Remote` PRIV_REMOTE_READ("Remote.Read"); + /// Remote.DatastoreAppend allows creating new snapshots and namespaces on remote datastores + PRIV_REMOTE_DATASTORE_APPEND("Remote.DatastoreAppend"); /// Remote.DatastoreBackup allows creating new snapshots on remote datastores PRIV_REMOTE_DATASTORE_BACKUP("Remote.DatastoreBackup"); /// Remote.DatastoreModify allows to modify remote datastores @@ -183,6 +185,14 @@ pub const ROLE_REMOTE_SYNC_PUSH_OPERATOR: u64 = 0 | PRIV_REMOTE_AUDIT | PRIV_REMOTE_DATASTORE_BACKUP; +#[rustfmt::skip] +#[allow(clippy::identity_op)] +/// Remote.SyncAppendOperator can read remote datastores, as well as push snapshots and create +/// namespaces on the remote. +pub const ROLE_REMOTE_SYNC_APPEND_OPERATOR: u64 = 0 + | PRIV_REMOTE_AUDIT + | PRIV_REMOTE_DATASTORE_APPEND; + #[rustfmt::skip] #[allow(clippy::identity_op)] /// Remote.DatastorePowerUser can read and push snapshots to the remote, and prune owned snapshots @@ -271,6 +281,8 @@ pub enum Role { RemoteSyncOperator = ROLE_REMOTE_SYNC_OPERATOR, /// Synchronisation Operator (push direction) RemoteSyncPushOperator = ROLE_REMOTE_SYNC_PUSH_OPERATOR, + /// Synchronisation Operator (append push direction) + RemoteSyncAppendOperator = ROLE_REMOTE_SYNC_APPEND_OPERATOR, /// Remote Datastore Prune RemoteDatastorePowerUser = ROLE_REMOTE_DATASTORE_POWERUSER, /// Remote Datastore Admin -- 2.47.3