mirror of
https://github.com/TheGrandWazoo/freenas-proxmox.git
synced 2026-09-30 12:01:10 +02:00
Project infrastructure: - Replace MIT license with AGPL-3.0 (KSA Technologies, LLC) - Full README rewrite with badges, compatibility table, token auth docs - Add CHANGELOG, CONTRIBUTING, DONORS, SECURITY docs - Add GitHub issue/PR templates, update FUNDING.yml and stale.yml - Replace external packer repo dispatch with self-contained CI (build.yml) - Add packaging/DEBIAN/ with postinst/postrm/triggers (no git clone at install) - Add .perlcriticrc for static analysis - Add .claude/cos/ ADRs, plans, and runbooks Bug fixes from community PRs: - Fix bearer token check in freenas_api_connect: defined() && value instead of defined() alone, so truenas_token_auth=0 no longer activates Bearer Token auth (#207) - Fix LUN 0 falsy bug in ZFSPlugin patch: !$guid -> !defined $guid in both zfs_get_lun_number and zfs_get_wwid_number, fixing VMs on LUN 0 for PVE 9 (#209) - Fix syslog typo "wtih" -> "with" in run_list_extent (#213) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
1.4 KiB
1.4 KiB
Security Policy
Supported Versions
| Version | Supported |
|---|---|
| 3.x (upcoming) | Yes |
| 2.3.x | Yes |
| 2.2.x and earlier | No — please upgrade |
Reporting a Vulnerability
Do not open a public GitHub issue for security vulnerabilities.
Email security reports to: security@ksatechnologies.com (or theprofessor@ksatechnologies.com)
Include:
- A description of the vulnerability
- Steps to reproduce
- The potential impact
- Any suggested fixes if you have them
You will receive an acknowledgment within 72 hours. We aim to release a fix within 14 days for confirmed vulnerabilities and will credit reporters in the release notes unless anonymity is requested.
Security Considerations for Operators
- API tokens are stored in
/etc/pve/storage.cfgwhich is readable only by root and replicated across the PVE cluster viapmxcfs. Treat cluster access accordingly. - Use API token authentication rather than username/password. Tokens can be revoked individually without changing your TrueNAS user password.
- Enable SSL on the TrueNAS API connection. The plugin accepts self-signed certificates (SSL verification is relaxed) — use a private CA or valid certificate where possible.
- Scope API tokens to the minimum required permissions on TrueNAS if your version supports scoped tokens.
- Restrict network access to the TrueNAS management interface to only the Proxmox nodes that need it.