Letting Auditors into My Hypervisors
Introduction I would like to showcase an internet-accessible, hardened homelab some time in 2026. Before I forget, I need to document how to let people log into my Proxmox nodes with their Google accounts as auditors. This post assumes that network access has been provided one way or another. Ingredients A domain name (managed by CloudflareDNS) PVE 9.1: Just-In-Time login target Cloudflared (for exposing Authentik’s ACME client) Authentik: OpenID login broker Google Cloud - Google Auth Platform Client A Google account Chatbot of your liking Pre-Requisites Proxmox VE with HTTPS For authentication to work, services being exposed should have secured subdomains. This short blog by Ikiesow covers most of the process. Create API key from Cloudflare dashboard to be used by Proxmox VE under Datacenter/ACME for DNS-01 or HTTP-01 challanges. ...