mirror of
https://github.com/pocket-id/pocket-id.git
synced 2025-12-06 09:13:19 +03:00
🚀 Feature: How to Set up Proxmox VE OIDC #460
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @Node815 on GitHub.
Feature description
This will allow you to log into Proxmox VE with your fingerprint for easy administration while on the road!
Pitch
Create your OIDC Client as usual in Pocket-ID and keep that window/tab open so you can copy/paste the keys to Proxmox.
The following dialog will appear:

This is how I have mine set and it works:
The Realm Name is what you will see when you login and also shows in the username such as email@realm
Mine Realm in this case is titled SSO. :)
For the ISSUER URL, This is VERY IMPORTANT!!! (I spent a good hour or two troubleshooting this).
Use your domain or sub.domain.com that you use for your Pocket-ID system. For example, sso.example.com would be https://sso.example.com AVOID Using a trailing slash, it will tell you it's wrong and give a 500 error.
Any other trailing information will give you an instant 500 OIDC Redirect error which is of no use and it will never direct you to the server.
Once you save your settings, Open up a private browser tab, or incognito window to test the login, go to your Proxmox server and login using your shiny new log in. It should take you to your login page for Pocket-ID and after you authenticate, Proxmox will assign a new account with your email@realm with basic permissions. From there, in your other window with your root/admin Proxmox still logged in, manage the desired permissions for your shiny new user.
@stonith404 commented on GitHub:
Thanks for sharing.