From: Michal Fox <me@dualfroz.com>
To: pve-devel@lists.proxmox.com
Subject: [PATCH docs] fix #7560: user management: privileges: document Sys.AccessNetwork
Date: Sun, 4 Oct 2026 12:28:27 +0000 [thread overview]
Message-ID: <20261004122827.7-1-me@dualfroz.com> (raw)
The Sys.AccessNetwork privilege got added with pve-access-control
commit 36c1814 ("add Sys.AccessNetwork privilege") and is part of the
built-in Administrator role, but it is missing in the list of
privileges.
Document it with examples from the API calls that currently check for
it, which are downloading ISO images, templates and other images from a
URL to a storage and querying the metadata of such a URL, querying the
tags of and pulling OCI images, and creating or updating notification
targets.
Signed-off-by: Michal Fox <me@dualfroz.com>
---
Notes:
the list of API calls is from the privilege checks in pve-manager and
pve-storage. rendered the chapter with asciidoc, without new warnings.
pveum.adoc | 3 +++
1 file changed, 3 insertions(+)
diff --git a/pveum.adoc b/pveum.adoc
index d089cb6..c28eae5 100644
--- a/pveum.adoc
+++ b/pveum.adoc
@@ -889,6 +889,9 @@ Node / System related privileges::
* `Realm.Allocate`: create/modify/remove authentication realms
* `SDN.Allocate`: manage SDN configuration
* `SDN.Audit`: view SDN configuration
+* `Sys.AccessNetwork`: access the network from the node, for example to
+ download ISO images or templates from a URL, to pull OCI images or to set up
+ notification targets
* `Sys.Audit`: view node status/config, Corosync cluster config, and HA config
* `Sys.Console`: console access to node
* `Sys.Incoming`: allow incoming data streams from other clusters (experimental)
--
2.43.0
reply other threads:[~2026-10-04 12:28 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261004122827.7-1-me@dualfroz.com \
--to=me@dualfroz.com \
--cc=pve-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox