Allow user to only access one vm’s console/terminal — here’s the exact combo of roles and ACLs that works. The forum replies are incomplete, so I’m writing down what actually got it done.

The Role You Need
Don’t bother with the built-in PVEVMUser role. It gives too much — the user can see all VMs and even mess with some settings. Create a custom role with just the privileges needed for console access.
pveum role add VMConsoleOnly -privs "VM.Console VM.Audit"
VM.Console lets them open the noVNC console. VM.Audit lets them see the VM in the list. That’s it. No VM.Config, no VM.PowerMgmt. They can’t start, stop, or change anything.
Assign the User to the Role
Now add the user and assign the role to the specific VM. The path is /vms/{vmid} — that’s the key part everyone forgets.
pveum useradd consoleuser@pve --password yourpassword
pveum aclmod /vms/100 -user consoleuser@pve -role VMConsoleOnly
Replace 100 with your VM’s ID. The path /vms/100 restricts the role to that one VM. If you use /vms instead, they’d see every VM.

The Gotcha
After setting this up, the user logs in and sees… nothing. The VM doesn’t show up in the left panel. That’s because VM.Audit only gives permission to see the VM if they know the path. The GUI hides it from the resource tree unless you also grant VM.Config.Options or use a different approach.
Honestly, the simplest fix is to grant VM.Config.Options too. It lets them see the VM in the tree but still can’t change anything important. So the role becomes:
pveum role add VMConsoleOnly -privs "VM.Console VM.Audit VM.Config.Options"
Now the VM shows up, they can open the console, and that’s all they can do. They can’t power it off, can’t edit hardware, can’t even see other VMs.
Testing It
Log in as the user and check. You should see only that one VM in the tree. Click on it, go to Console, and it works. If you try to open another VM’s console, you get a permission error. That’s the whole point.
One more thing: if you’re using Proxmox Backup Server or any external services, make sure they don’t need this user to have broader access. Keep it tight.
This setup is solid for a homelab where you want to give a friend access to a single VM without handing them the keys to everything. I’ve used it for a game server VM and it works fine.
Related: Uploading certificates caused access issues: fix Proxmox pveproxy user ownership