agentsclimarketplace

Ops proxmox

Skill christopherlouet/claude-base/.claude/skills/ops-proxmox

Proxmox VE infrastructure with Terraform (VMs, LXC, network, storage, backup)From its SKILL.md

Install
npx -y skills add christopherlouet/claude-base --skill ops-proxmox

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 5 stars5 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

SKILL.md

5.9 KB, ~1.5k tokens by cl100k_base, as published. Nobody here has run it

Proxmox Infrastructure Skill

Proxmox VE infrastructure management with Terraform: provisioning of virtual machines, LXC containers, network configuration, storage and backup.

When to use this skill

This skill is automatically activated when the conversation mentions:

  • "Proxmox", "PVE", "Proxmox VE"
  • "Proxmox VM", "Proxmox LXC", "Proxmox container"
  • "Proxmox cluster", "Proxmox node"
  • "PBS", "Proxmox Backup Server"
  • "Proxmox cloud-init"
  • "QEMU/KVM" in a Proxmox context

Core principles

1. Infrastructure as Code

All Proxmox infrastructure must be managed via Terraform:

  • Reproducibility: same config = same result
  • Versioning: history in Git
  • Review: PR to validate infra changes
  • Documentation: the code IS the documentation

2. Environment separation

environments/
├── dev/           # Can be destroyed
├── staging/       # Mirrors prod
└── prod/          # Critical

Each environment has its own variables (terraform.tfvars), its own Terraform state and its own credentials.

3. Reusable modules

modules/
├── vm/            # QEMU/KVM virtual machine
├── lxc/           # LXC container
├── network/       # Network configuration
├── storage/       # Storage configuration
└── backup/        # PBS configuration

Proxmox architecture

Resource hierarchy

Datacenter
├── Cluster (optional)
│   ├── Node 1 (pve1) → VMs, LXC, Storage, Network
│   ├── Node 2 (pve2)
│   └── Node 3 (pve3)
├── Storage (datacenter level)
│   ├── local, local-lvm (per node)
│   ├── nfs-shared (shared)
│   └── ceph (distributed)
└── SDN (Zones, VNets, Subnets)

Resource types

TypeDescriptionUse case
VM (QEMU)Full virtual machineHeavy workloads, strong isolation
LXCSystem containerLightweight services, high density
TemplateBase imageFast cloning of VMs/LXC
Snippetcloud-init filesAutomated configuration

Terraform provider

bpg/proxmox (recommended)

Modern, well-maintained provider, full coverage of the Proxmox API.

terraform {
  required_version = ">= 1.5.0"
  required_providers {
    proxmox = {
      source  = "bpg/proxmox"
      version = "~> 0.50"
    }
  }
}

provider "proxmox" {
  endpoint  = var.proxmox_endpoint
  api_token = var.proxmox_api_token  # Recommended token
  insecure  = var.proxmox_insecure   # Dev only

  ssh {
    agent    = true
    username = "root"
  }
}

API token authentication

# On the Proxmox node
pveum user token add terraform@pve terraform-token --privsep=0

# Minimal permissions
pveum aclmod / -user terraform@pve -role PVEVMAdmin
pveum aclmod /storage -user terraform@pve -role PVEDatastoreUser

Format: terraform@pve!terraform-token=xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx

Naming conventions

VMs and containers

EnvironmentPatternExample
Productionprod-{role}-{index}prod-web-01
Stagingstg-{role}-{index}stg-api-01
Developmentdev-{role}-{index}dev-db-01
Testtest-{purpose}test-migration

VMID ranges

RangeUsage
100-199Infrastructure (DNS, DHCP, etc.)
200-299Production
300-399Staging
400-499Development
500-599Test/Temporary
9000-9099Templates

Recommended tags

environment:prod
role:webserver
team:platform
backup:daily
managed-by:terraform
criticality:high

Security

Best practices

  1. API Token: minimal permissions (dedicated role, not root)
  2. Firewall: enable the Proxmox firewall by default
  3. Isolation: separate VLANs per environment
  4. Unprivileged LXC: always use unprivileged containers
  5. Audit: log API and SSH access
  6. Secrets: NEVER hardcode in HCL (use Vault, TF_VAR_*, or gitignored tfvars)

Minimal Terraform permissions

# Dedicated role
pveum role add TerraformRole -privs "VM.Allocate VM.Clone VM.Config.CDROM VM.Config.CPU VM.Config.Cloudinit VM.Config.Disk VM.Config.HWType VM.Config.Memory VM.Config.Network VM.Config.Options VM.Monitor VM.Audit VM.PowerMgmt Datastore.AllocateSpace Datastore.AllocateTemplate Datastore.Audit SDN.Use"

# User + assignment
pveum user add terraform@pve
pveum aclmod / -user terraform@pve -role TerraformRole

References

This SKILL.md section contains the core principles. For technical details with full HCL examples, see the reference files:

FileContent
references/terraform-modules.mdVM modules, LXC, usage, network, storage
references/cloud-init.mdcloud-config templates, snippet uploads
references/backup-ha.mdPBS schedule, commands, HA configuration
references/troubleshooting.mdCommon issues, diagnostic commands, recovery

Rules

IMPORTANT: NEVER manage Proxmox manually via the UI. Always via Terraform.

IMPORTANT: Use unprivileged LXC by default (limited privilege escalation).

IMPORTANT: One Terraform state per environment (dev/staging/prod isolated).

YOU MUST use the bpg/proxmox provider (modern, maintained) rather than telmate/proxmox (deprecated).

YOU MUST use API tokens with minimal permissions, never root.

NEVER hardcode secrets in committed HCL. Use gitignored tfvars or Vault.

NEVER skip PBS backups on critical VMs.

Attribution

This skill is based on:

What ships with it: 4 files

12.0 KB alongside SKILL.md

Keep looking

Skills are one crate of 326,144. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.