Azure Active Directory (AAD) Auth¶
This gist assumes a working Azure AD (not Azure AD-DS is already up and fully configured) This gist assumes working DNS / name resolution on your internal network.
this gist is part of this series
Create App Registrations¶
All of these steps will be done in the Azure Portal AAD UI
- Select App Registration from the nav bar
- Click new registration in the task pane
- name it
proxmox - set initial redirect URI to web https://node.mydomain.com:8006 (this assume you are not publishing externaly)
-
click register
nav should change to the the proxmox app reg
-
click certificans & secrets
- click the client secrets tab
- click new client secret
- set description to say proxmox-auth
- set expires to 730 days
- copy the value
<a string hash> -
copy the secret id
<a guid>very important - you will never see the value again - must copy it down now
-
click authentication in the left nav
-
add all the internally and externally accessible node names, in my case this is as follows for my 3 internal node names, the pbs server name and cluster name via internal nginx.
-
nothing else needs to be changed here so click save once these have been added
- navigate to overview > endpoints
- Copy the OpenID Connect metadata document link and remove /.well-known/openid-configuration this part from the link, so you end up with something like this https://login.microsoftonline.com/{Your-Tenant-ID}/v2.0
Add realm on PVE Cluster¶
- go to
datacenter > realmsclickaddat the top of page and selectOpenID Connect Server - issuer URL = https://login.microsoftonline.com/{Your-Tenant-ID}/v2.0
- realm is domain name
- client ID = GUID (from AAD app reg > proxmox > overview > application (client ID)
- client key = hashed value (should be the secret value from earlier)
- default = checked
- autocreate users = checked
- username claim = email or username (it gives same result in my system - the username will alwasy be name@mydomain.com)
Create a Group¶
- click
datacenter > permissions > groups> - click
create - name = admins
- click
create
Assign Permissions to group¶
- click
datacenter > permissions - click
add - path = /
- group = admins
- role = administrator
- propogate = checked
create user¶
- user name = name@mydomain.com
- realm = Azure AAD
- Group = Admins
- name = folks names of course
- email = ususally the same as name@mydomain.com
login with AAD!¶
webauthn keys on every node¶
a security key or passkey is bound to one "relying party ID", set for the whole cluster in datacenter → options → webauthn settings. i set it to the domain, so every node's name and the cluster's name share it.
-
set it from a shell on any node:
pvesh set /cluster/options --webauthn 'rp=mydomain.com,origin=https://mydomain.com,id=mydomain.com,allow-subdomains=1'- the settings dialog has no subdomain box, so
allow-subdomainsis only set this way, and saving the dialog again can drop it - changing the ID breaks every key registered under the old one. add a TOTP entry and recovery keys first
- the settings dialog has no subdomain box, so
-
register the key again, from a name served on port 443. mine is the cluster's name through traefik
- the origin check compares the port, so a key works on names served on
443 and not on a node's own
:8006. i use TOTP there
- the origin check compares the port, so a key works on names served on
443 and not on a node's own
if a key stops working, the web UI's second factor doesn't cover ssh or the
console. as root on a node, with ENTRY_ID set to an ID from the list:
pveum user tfa list root@pam
pveum user tfa delete root@pam --id "$ENTRY_ID"
pveum user tfa unlock root@pam
deletewithout--idremoves all of the user's entries, leaving a password-only login until you add them again
This page started as a gist: the original, with its comments