You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
TLS trust and pinning without rejectUnauthorized: false in production paths — FM-600: the pinned-fingerprint rustls verifier; verification never disabled
Health, privilege diagnostics, and least-privilege credential documentation — FM-600: honest auth/privilege/mismatch/connect states; least-privilege token documentation lands with the guest epics
API compatibility matrix covering PVE 8.x and 9.x — 9.2.2 live-verified (FM-600 + the FM-S08 spike); the 8.x leg is the recorded FM-S08 deviation, validated through fixtures until the real-cluster suite reaches a second host
Cluster, node, storage, and template discovery — FM-600: normalized observations with provenance and per-resource isolation
Constrained by
docs/PLAN.md — M6 and Supported platform baseline; ADR-0005
FM-000 fixed the compatibility target at PVE 8.x and 9.x; passing one major is not a pass
Non-goals
Replacing Proxmox, its console, or its storage/network configuration
Adopting the experimental typed crate without the FM-S08 evidence
Tracking issue. Dependency and status checklists only — implementation stays in narrow linked issues.
Outcome
Fleet authenticates to one or more Proxmox accounts with verified TLS trust and reports health and privilege problems clearly.
Supersedes
Replaces the "Proxmox API client/adapter (auth)" and "credential/secrets handling for the Proxmox API token" scope items of #3.
Depends on
Scope checklist
rejectUnauthorized: falsein production paths — FM-600: the pinned-fingerprint rustls verifier; verification never disabledConstrained by
docs/PLAN.md— M6 and Supported platform baseline; ADR-0005Non-goals