From a13a971d006f1f1a36980a6aa7e215eb9edcb6e8 Mon Sep 17 00:00:00 2001 From: Dylan Whyte Date: Fri, 1 Oct 2021 17:30:50 +0200 Subject: [PATCH] pveum: add intro to 'limited API Token' section Add a short introduction to the section "Limited API Token for Monitoring", to provide some context Signed-off-by: Dylan Whyte --- pveum.adoc | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/pveum.adoc b/pveum.adoc index a0fabfb..97e0005 100644 --- a/pveum.adoc +++ b/pveum.adoc @@ -793,7 +793,13 @@ members of the group `customers` and within the realm `pve`. Limited API Token for Monitoring ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -Given a user `joe@pve`, with the PVEVMAdmin role on all VMs: +Permissions on API tokens are always a subset of those of their corresponding +user, meaning that an API token can't be used to carry out a task that the +backing user has no permission to do. This section will demonstrate how you can +use an API token with separate privileges, to limit the token owner's +permissions further. + +Give the user `joe@pve` the role PVEVMAdmin on all VMs: [source,bash] pveum acl modify /vms -user joe@pve -role PVEVMAdmin