Technical

Proxmox: How to Give a User Access to Only One VM’s Console

Proxmox: How to Give a User Access to Only One VM’s Console

Allow user to only access one vm’s console/terminal — here’s the exact combo of roles and ACLs that works. The forum replies are incomplete, so I’m writing down what actually got it done.

Detailed shot of Ethernet cables connected to server ports highlighting technology infrastructure.

The Role You Need

Don’t bother with the built-in PVEVMUser role. It gives too much — the user can see all VMs and even mess with some settings. Create a custom role with just the privileges needed for console access.

pveum role add VMConsoleOnly -privs "VM.Console VM.Audit"

VM.Console lets them open the noVNC console. VM.Audit lets them see the VM in the list. That’s it. No VM.Config, no VM.PowerMgmt. They can’t start, stop, or change anything.

Assign the User to the Role

Now add the user and assign the role to the specific VM. The path is /vms/{vmid} — that’s the key part everyone forgets.

pveum useradd consoleuser@pve --password yourpassword
pveum aclmod /vms/100 -user consoleuser@pve -role VMConsoleOnly

Replace 100 with your VM’s ID. The path /vms/100 restricts the role to that one VM. If you use /vms instead, they’d see every VM.

Close-up view of a computer displaying cybersecurity and data protection interfaces in green tones.

The Gotcha

After setting this up, the user logs in and sees… nothing. The VM doesn’t show up in the left panel. That’s because VM.Audit only gives permission to see the VM if they know the path. The GUI hides it from the resource tree unless you also grant VM.Config.Options or use a different approach.

Honestly, the simplest fix is to grant VM.Config.Options too. It lets them see the VM in the tree but still can’t change anything important. So the role becomes:

pveum role add VMConsoleOnly -privs "VM.Console VM.Audit VM.Config.Options"

Now the VM shows up, they can open the console, and that’s all they can do. They can’t power it off, can’t edit hardware, can’t even see other VMs.

Testing It

Log in as the user and check. You should see only that one VM in the tree. Click on it, go to Console, and it works. If you try to open another VM’s console, you get a permission error. That’s the whole point.

One more thing: if you’re using Proxmox Backup Server or any external services, make sure they don’t need this user to have broader access. Keep it tight.

This setup is solid for a homelab where you want to give a friend access to a single VM without handing them the keys to everything. I’ve used it for a game server VM and it works fine.

Related: Uploading certificates caused access issues: fix Proxmox pveproxy user ownership

Leave a comment

Comments are reviewed before they appear. Your email is never published.