/** * Bootstrap: the part of setup that does not happen on your machine. * * Before this MCP can do anything, an operator has to create an API token * inside Proxmox itself. That step is the single biggest drop-off point: it is * a web UI form with an easily-missed checkbox, and getting it wrong produces a * 401 that looks like a bad secret rather than a permissions problem. * * So this command does not talk to Proxmox at all. It prints a block the * operator pastes into the Proxmox shell (Datacenter -> Shell in the web UI), * which needs no SSH key -- and SSH access is precisely what they do not have * yet. The block is plain `pveum`, so it is auditable before running. */ export declare const accessTiers: readonly ["read-only", "read-execute", "full"]; export type AccessTier = (typeof accessTiers)[number]; export type BootstrapOptions = { user?: string; realm?: string; tokenName?: string; tier?: string; /** Path to an SSH *public* key to authorize on the node. */ sshKey?: string; /** Generate a new keypair first, then authorize it. */ newSshKey?: boolean; }; /** * Built-in Proxmox roles per tier. * * These are Proxmox's own roles, but the mapping is our choice: it is the * smallest role that still lets every tool in that tier work. An operator who * wants tighter scoping can swap the role or narrow the ACL path; the emitted * script says so. */ export declare const rolesForTier: (tier: AccessTier) => string[]; export declare const parseTier: (value: string | undefined) => AccessTier; export declare const defaultKeyPath: () => string; export type GeneratedKey = { privateKeyPath: string; publicKeyPath: string; publicKey: string; created: boolean; }; /** * Generates an ed25519 keypair with no passphrase. * * The empty passphrase is passed as its own argv entry with `shell: false`. * Going through a shell instead is a real trap on Windows: PowerShell turns * `-N '""'` into the two-character literal passphrase `""`, producing a key * that every server rejects with "Permission denied (publickey)" -- a message * that says nothing about a passphrase and sends people to inspect * authorized_keys for hours. */ export declare const generateSshKey: (keyPath: string) => GeneratedKey; export declare const readPublicKey: (path: string) => string; export type ScriptInput = { user: string; realm: string; tokenName: string; tier: AccessTier; publicKey?: string; }; /** * The block the operator pastes into the Proxmox shell. * * It is deliberately readable rather than clever: whoever runs it is granting * an API credential over their own infrastructure and should be able to see * exactly what each line does before pressing enter. */ export declare const renderBootstrapScript: (input: ScriptInput) => string; export declare const runBootstrap: (options?: BootstrapOptions) => Promise; //# sourceMappingURL=bootstrap.d.ts.map