From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [IPv6:2a0f:8001:1:32::40]) by lore.proxmox.com (Postfix) with ESMTPS id 511731FF0AD for ; Sun, 04 Oct 2026 14:28:39 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 0F367215E8; Sun, 04 Oct 2026 14:28:38 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=dualfroz.com; s=dkim; t=1791116909; h=from:subject:date:message-id:to:mime-version: content-transfer-encoding; bh=r07uFDNB9iCQ+nsKhAPxdcgJbqpYzGzXx+utR9btgpM=; b=Sat+lr9QrzKnEJ3FW5+gNTyCml2ChWjQy78uMrMDuZuejNJist7g/BZEVVlGjRdHMLMJZY hcZwVMFgMYacfYj6CmeTcNXxCKcAL1HnpjE/jsTYB6HVofIxZ89offP3CYIyc9mQ+E51JP YSJXx3PUj+SPzOBUtALmGdhdLUaPAXB60D+/RTSzpoZok1OrFXQJ9IyH0c8Luqo9a850lv 9Mtcd8Rdj1F9qRiMkdw026Tzq1bCLZ1No77q64RVPsffMyJNblzjkx2qoAMoxHqo0rQrnF mCNCniLr3Y6L/9z9KmrTGlo+MYc5L3vfbMlGW/VbBmBF0gZqWd5iPh8mPvgDRA== From: Michal Fox To: pve-devel@lists.proxmox.com Subject: [PATCH docs] fix #7560: user management: privileges: document Sys.AccessNetwork Date: Sun, 4 Oct 2026 12:28:27 +0000 Message-ID: <20261004122827.7-1-me@dualfroz.com> X-Mailer: git-send-email 2.47.3 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Last-TLS-Session-Version: TLSv1.3 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.209 Adjusted score from AWL reputation of From: address DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid DKIM_VALID -0.1 Message has at least one valid DKIM or DK signature DKIM_VALID_AU -0.1 Message has a valid DKIM or DK signature from author's domain DKIM_VALID_EF -0.1 Message has a valid DKIM or DK signature from envelope-from domain DMARC_PASS -0.1 DMARC pass policy SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: EZANGYJLYBU5HLLS24ISMSD7Q4EIIZFU X-Message-ID-Hash: EZANGYJLYBU5HLLS24ISMSD7Q4EIIZFU X-MailFrom: me@dualfroz.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: The Sys.AccessNetwork privilege got added with pve-access-control commit 36c1814 ("add Sys.AccessNetwork privilege") and is part of the built-in Administrator role, but it is missing in the list of privileges. Document it with examples from the API calls that currently check for it, which are downloading ISO images, templates and other images from a URL to a storage and querying the metadata of such a URL, querying the tags of and pulling OCI images, and creating or updating notification targets. Signed-off-by: Michal Fox --- Notes: the list of API calls is from the privilege checks in pve-manager and pve-storage. rendered the chapter with asciidoc, without new warnings. pveum.adoc | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pveum.adoc b/pveum.adoc index d089cb6..c28eae5 100644 --- a/pveum.adoc +++ b/pveum.adoc @@ -889,6 +889,9 @@ Node / System related privileges:: * `Realm.Allocate`: create/modify/remove authentication realms * `SDN.Allocate`: manage SDN configuration * `SDN.Audit`: view SDN configuration +* `Sys.AccessNetwork`: access the network from the node, for example to + download ISO images or templates from a URL, to pull OCI images or to set up + notification targets * `Sys.Audit`: view node status/config, Corosync cluster config, and HA config * `Sys.Console`: console access to node * `Sys.Incoming`: allow incoming data streams from other clusters (experimental) -- 2.43.0