feat: add network: endpoint resolver, VM.Config.Options privilege requirement, top talkers dashboard widget, and automatic guest firewall enablement
Add network: prefix support in endpoint_values to resolve network names to IPAM subnet CIDRs for policy matching, extend workload_provider_target to accept vmid: prefix and bare workload names as fallback resolution methods, implement dashboard_top_talkers to aggregate traffic flows by workload with interface_traffic fallback when flows unavailable, add
This commit is contained in:
@@ -77,6 +77,7 @@ For write-enabled firewall orchestration, create a separate token or role and do
|
||||
Minimum practical write privileges for VM/LXC-level firewall rules:
|
||||
|
||||
- `VM.Audit` so NexaFabric can resolve guests and inspect existing rules.
|
||||
- `VM.Config.Options` so NexaFabric can enable the guest firewall option before writing rules.
|
||||
- `VM.Config.Network` on `/vms` or on the narrow VM/LXC paths you want NexaFabric to manage.
|
||||
|
||||
NexaFabric writes only rules that carry a `NexaFabric policy=...` comment marker. During apply it removes and replaces its own marked rules for the selected policy, leaving manually created Proxmox firewall rules untouched.
|
||||
|
||||
Reference in New Issue
Block a user