feat: proxmox import diagnostics, node style fix, and cluster edges
Scan History: - Proxmox is now a first-class scan kind (badge, filter chip, Server icon, completion toast) instead of being mislabeled as an IP scan. - A done run carrying a non-fatal advisory renders amber (info) with a warning toast, distinct from red failures. Import diagnostics: - test-connection probes /access/permissions and warns when the API token has no ACL (VMs/LXC would be invisible) — points at the PVEAuditor grant. - import surfaces an advisory when hosts import but no guests are visible (privilege-separated token whose rights are the intersection with the user), rather than a silent "done". Node style: - Proxmox container mode is now opt-in (container_mode === true), matching the rest of the codebase (App.tsx nesting logic). Imported proxmox nodes leave the flag unset and render like a manually-created node instead of an empty group container. Cluster edges: - Hosts from one import are chained with 'cluster' edges via left/right handles, distinct from the vertical host->guest 'virtual' edges. Wired for both the direct "Add to Canvas" path and the pending -> approve path (host<->host proxmox_cluster links, resolved to cluster edges on approve; cluster hosts get left/right handles). Tests added on both sides. ha-relevant: maybe
This commit is contained in:
@@ -192,6 +192,21 @@ def build_proxmox_properties(node: dict[str, Any]) -> list[dict[str, Any]]:
|
||||
return props
|
||||
|
||||
|
||||
def build_proxmox_cluster_links(nodes: list[dict[str, Any]]) -> list[tuple[str, str]]:
|
||||
"""Chain host nodes (``type == 'proxmox'``) into cluster links.
|
||||
|
||||
Hosts from one import belong to the same cluster, so they are linked
|
||||
host↔host (rendered as ``cluster`` edges via left/right handles, distinct
|
||||
from the vertical host→guest ``virtual`` edges). Returns consecutive
|
||||
``(source_ieee, target_ieee)`` pairs, or ``[]`` for a single host. Mirrors
|
||||
the frontend ``buildProxmoxClusterEdges``.
|
||||
"""
|
||||
hosts = [n["ieee_address"] for n in nodes if n.get("type") == "proxmox" and n.get("ieee_address")]
|
||||
if len(hosts) < 2:
|
||||
return []
|
||||
return [(hosts[i], hosts[i + 1]) for i in range(len(hosts) - 1)]
|
||||
|
||||
|
||||
def _parse_inventory(
|
||||
hosts_raw: list[dict[str, Any]],
|
||||
guests_by_host: dict[str, list[dict[str, Any]]],
|
||||
@@ -231,6 +246,23 @@ async def _get_json(client: httpx.AsyncClient, path: str) -> Any:
|
||||
return resp.json().get("data")
|
||||
|
||||
|
||||
async def _token_has_permissions(client: httpx.AsyncClient) -> bool:
|
||||
"""True if the API token holds *any* ACL.
|
||||
|
||||
Proxmox list endpoints (``/qemu``, ``/lxc``) silently return an empty
|
||||
``200`` when the token lacks ``VM.Audit`` — indistinguishable from a host
|
||||
that genuinely has no guests. ``GET /access/permissions`` returns ``{}`` for
|
||||
a token with no ACL at all, which is the common misconfiguration (a
|
||||
privilege-separated token created without its own permission). Best-effort:
|
||||
on any error assume permissions exist so we never block a valid import.
|
||||
"""
|
||||
try:
|
||||
perms = await _get_json(client, "/access/permissions")
|
||||
except httpx.HTTPError:
|
||||
return True
|
||||
return bool(perms) if isinstance(perms, dict) else True
|
||||
|
||||
|
||||
async def fetch_proxmox_inventory(
|
||||
host: str,
|
||||
port: int,
|
||||
@@ -339,8 +371,16 @@ async def test_proxmox_connection(
|
||||
timeout=timeout,
|
||||
) as client:
|
||||
data = await _get_json(client, "/version")
|
||||
has_perms = await _token_has_permissions(client)
|
||||
version = (data or {}).get("version", "?") if isinstance(data, dict) else "?"
|
||||
return True, f"Connected to Proxmox VE {version}"
|
||||
message = f"Connected to Proxmox VE {version}"
|
||||
if not has_perms:
|
||||
message += (
|
||||
" — warning: this API token has no permissions, so VMs and LXC "
|
||||
"will not be visible. Assign the PVEAuditor role at path '/' to the "
|
||||
"token in Proxmox (Datacenter → Permissions → API Token Permission)."
|
||||
)
|
||||
return True, message
|
||||
except httpx.HTTPError as exc:
|
||||
return False, _sanitize_proxmox_error(exc)
|
||||
except Exception as exc: # noqa: BLE001 — surface a safe message, log the rest
|
||||
|
||||
Reference in New Issue
Block a user