ops-proxmox — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited ops-proxmox (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Proxmox VE infrastructure management with Terraform: provisioning of virtual machines, LXC containers, network configuration, storage and backup.
This skill is automatically activated when the conversation mentions:
All Proxmox infrastructure must be managed via Terraform:
environments/
├── dev/ # Can be destroyed
├── staging/ # Mirrors prod
└── prod/ # CriticalEach environment has its own variables (terraform.tfvars), its own Terraform state and its own credentials.
modules/
├── vm/ # QEMU/KVM virtual machine
├── lxc/ # LXC container
├── network/ # Network configuration
├── storage/ # Storage configuration
└── backup/ # PBS configurationDatacenter
├── Cluster (optional)
│ ├── Node 1 (pve1) → VMs, LXC, Storage, Network
│ ├── Node 2 (pve2)
│ └── Node 3 (pve3)
├── Storage (datacenter level)
│ ├── local, local-lvm (per node)
│ ├── nfs-shared (shared)
│ └── ceph (distributed)
└── SDN (Zones, VNets, Subnets)| Type | Description | Use case |
|---|---|---|
| VM (QEMU) | Full virtual machine | Heavy workloads, strong isolation |
| LXC | System container | Lightweight services, high density |
| Template | Base image | Fast cloning of VMs/LXC |
| Snippet | cloud-init files | Automated configuration |
Modern, well-maintained provider, full coverage of the Proxmox API.
terraform {
required_version = ">= 1.5.0"
required_providers {
proxmox = {
source = "bpg/proxmox"
version = "~> 0.50"
}
}
}
provider "proxmox" {
endpoint = var.proxmox_endpoint
api_token = var.proxmox_api_token # Recommended token
insecure = var.proxmox_insecure # Dev only
ssh {
agent = true
username = "root"
}
}# On the Proxmox node
pveum user token add terraform@pve terraform-token --privsep=0
# Minimal permissions
pveum aclmod / -user terraform@pve -role PVEVMAdmin
pveum aclmod /storage -user terraform@pve -role PVEDatastoreUserFormat: terraform@pve!terraform-token=xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
| Environment | Pattern | Example |
|---|---|---|
| Production | prod-{role}-{index} | prod-web-01 |
| Staging | stg-{role}-{index} | stg-api-01 |
| Development | dev-{role}-{index} | dev-db-01 |
| Test | test-{purpose} | test-migration |
| Range | Usage |
|---|---|
| 100-199 | Infrastructure (DNS, DHCP, etc.) |
| 200-299 | Production |
| 300-399 | Staging |
| 400-499 | Development |
| 500-599 | Test/Temporary |
| 9000-9099 | Templates |
environment:prod
role:webserver
team:platform
backup:daily
managed-by:terraform
criticality:high# Dedicated role
pveum role add TerraformRole -privs "VM.Allocate VM.Clone VM.Config.CDROM VM.Config.CPU VM.Config.Cloudinit VM.Config.Disk VM.Config.HWType VM.Config.Memory VM.Config.Network VM.Config.Options VM.Monitor VM.Audit VM.PowerMgmt Datastore.AllocateSpace Datastore.AllocateTemplate Datastore.Audit SDN.Use"
# User + assignment
pveum user add terraform@pve
pveum aclmod / -user terraform@pve -role TerraformRoleThis SKILL.md section contains the core principles. For technical details with full HCL examples, see the reference files:
| File | Content |
|---|---|
references/terraform-modules.md | VM modules, LXC, usage, network, storage |
references/cloud-init.md | cloud-config templates, snippet uploads |
references/backup-ha.md | PBS schedule, commands, HA configuration |
references/troubleshooting.md | Common issues, diagnostic commands, recovery |
IMPORTANT: NEVER manage Proxmox manually via the UI. Always via Terraform.
IMPORTANT: Use unprivileged LXC by default (limited privilege escalation).
IMPORTANT: One Terraform state per environment (dev/staging/prod isolated).
YOU MUST use the bpg/proxmox provider (modern, maintained) rather than telmate/proxmox (deprecated).
YOU MUST use API tokens with minimal permissions, never root.
NEVER hardcode secrets in committed HCL. Use gitignored tfvars or Vault.
NEVER skip PBS backups on critical VMs.
This skill is based on:
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.