Proxmox VE
Proxmox VE can authenticate users against an OpenID Connect (OIDC) realm. With Casdoor as the realm, administrators sign in to the Proxmox VE web interface with their Casdoor account, and Proxmox VE permissions follow their Casdoor groups.
Create the application in Casdoor
-
In the Casdoor admin console, open the organization of your users and add an application, or open an existing one.
-
Add the address of the Proxmox VE web interface to Redirect URLs, with the port:
https://pve.example.com:8006Proxmox VE sends the address that the browser opened as the redirect URL, so add every address you use, for example the address of each node.
-
On the OIDC/OAuth tab, set Token group format to
Name (group), so groups arrive aspve-adminsinstead ofmy-org/pve-admins. -
Save, and note the Client ID and Client secret.
Add an OpenID Connect realm
-
On a Proxmox VE node, run:
pveum realm add casdoor --type openid \
--issuer-url https://door.example.com \
--client-id "<your-client-id>" \
--client-key "<your-client-secret>" \
--username-claim username \
--autocreate 1 \
--groups-claim groups \
--groups-autocreate 1You can enter the same values in the web interface under Datacenter > Permissions > Realms > Add > OpenID Connect Server.
--issuer-url: The URL of Casdoor, without a trailing slash.--username-claim username: Reads thepreferred_usernameclaim, so users appear asalice@casdoor. The default,subject, uses the Casdoor user ID.--groups-claim groups,--groups-autocreate 1: Create Proxmox VE groups from the user's Casdoor groups. On versions without these options, leave them out and grant permissions to users instead.
-
Grant a role to the group. Proxmox VE appends the realm name to groups from the claim, so
pve-adminsbecomespve-admins-casdoor:pveum acl modify / --groups pve-admins-casdoor --roles Administrator
Verify the result
- Open the Proxmox VE web interface, choose the casdoor realm, and click Login (OpenID redirect).
- Sign in to Casdoor as a member of
pve-admins. Proxmox VE opens with the user signed in asalice@casdoorand administrator rights.
Troubleshooting
| Symptom | Cause and fix |
|---|---|
Casdoor shows Redirect URI: ... doesn't exist in the allowed Redirect URI list | Add the exact address from the error, with the port, to Redirect URLs. |
| The user signs in but sees nothing | No permissions apply. Grant a role to the user's group or to the user with pveum acl modify. |
Sign-in fails with missing claim 'preferred_username' | The realm can't read the username. Keep Query userinfo endpoint on, and request the profile scope. |
See also
- User management in the Proxmox VE wiki