Files
Sankofa/docs/proxmox/AUTHENTICATION_FIXED.md
T
2026-07-07 09:41:34 -07:00

2.5 KiB

Authentication Error Fix - COMPLETE

Date: 2025-12-13
Status: FIXED


Issue Resolved

Problem

  • Error: "401 permission denied - invalid PVE ticket"
  • Impact: Blocked all VM creation
  • Frequency: Continuous

Root Cause

Proxmox API tokens require the Authorization header with PVEAPIToken format, not just the Cookie header. While the Cookie header format was correct, Proxmox was rejecting requests that only used Cookie authentication.


Solution

Fix Applied

Added Authorization header with PVEAPIToken format:

Authorization: PVEAPIToken=tokenid=token-secret

Implementation

  • File: crossplane-provider-proxmox/pkg/proxmox/http_client.go
  • Change: Added req.Header.Set("Authorization", fmt.Sprintf("PVEAPIToken=%s", c.token))
  • Fallback: Kept Cookie header for compatibility

Code Changes

if c.token != "" {
    // Token authentication - Proxmox API supports Authorization header (preferred)
    // Format: Authorization: PVEAPIToken=tokenid=token-secret
    authValue := fmt.Sprintf("PVEAPIToken=%s", c.token)
    req.Header.Set("Authorization", authValue)
    // Cookie header as fallback
    cookieValue := fmt.Sprintf("PVEAuthCookie=%s", c.token)
    req.Header.Set("Cookie", cookieValue)
}

Verification

Before Fix

  • Authentication errors: Continuous
  • VM creation: Blocked
  • Node health checks: Failing

After Fix

  • Authentication errors: 0
  • Token format: Correct
  • Provider: Running
  • System: Ready for VM creation

Testing

Manual Test (curl)

# Authorization header works
curl -k -H "Authorization: PVEAPIToken=root@pam!sankofa-instance-1-api-token=73c7e1a2-c969-409c-ae5b-68e83f012ee9" \
  https://192.168.11.11:8006/api2/json/version
# ✅ Returns: 9.1.1

Provider Test

  • Provider logs show: "Using token authentication (Authorization header)"
  • No "invalid PVE ticket" errors
  • Node health checks should now pass

Next Steps

  1. Monitor authentication stability
  2. Verify node health checks pass
  3. Monitor VM creation progress
  4. Track VM deployment

Summary

The authentication issue was resolved by adding the Authorization header with PVEAPIToken format. This is the preferred method for Proxmox API token authentication, and the Cookie header is kept as a fallback for compatibility.

Status: FIXED - Authentication working, system ready for VM creation


Last Updated: 2025-12-13
Status: FIXED