Sqoia Labs tool · Open source

PVE VM Provisioner for ColdFront

Turn approved ColdFront allocations into managed Proxmox VE virtual machines, with network assignment, guest policy, access, and lifecycle state kept in one administrator-controlled workflow.

What it adds to ColdFront

From allocation approval to a configured guest.

The plugin keeps the requester, operator, VM, address, and guest-policy state connected instead of scattering the lifecycle across one-off scripts.

01 / JOBS

Provision through durable work.

Approved allocations enqueue Django-Q jobs for cloning, configuring, activating, patching, reconciling, and retiring virtual machines.

02 / NETWORK

Use built-in IPAM or add NetBox.

Configure the IPv4 range, prefix, gateway, DNS, and VMID pool in Django admin. The built-in ledger works by default; NetBox is an optional inventory mirror.

03 / GUEST

Declare the guest state.

Versioned policy can reconcile packages, non-secret managed files, systemd units, allocation users, and an administrator-selected patch cadence through a reviewed helper.

04 / ACCESS

Keep generated private keys client-side.

Requesters can generate an Ed25519 pair in the browser. The private key downloads locally while ColdFront and cloud-init receive only the public key.

How it works

One allocation record drives the VM lifecycle.

ColdFront remains the source of allocation authority. The plugin adds persistent VM, address, job, event, and policy state around that record.

  1. 01Request

    The requester selects a VM flavor and supplies or generates an SSH public key.

  2. 02Approve

    The approved allocation transition enqueues durable provisioning work.

  3. 03Provision

    The job reserves an address, clones the template, and applies cloud-init configuration.

  4. 04Configure

    An optional version-matched guest helper applies the bounded policy manifest.

  5. 05Maintain

    Membership changes, patch schedules, and retirement create explicit follow-up jobs.

OPERATING GUARDRAILS

Power stays inside a reviewed contract.

  • The built-in database allocator remains authoritative; NetBox support is opt-in inventory mirroring.
  • Managed files are for non-secret configuration and reject private-key material, executable modes, and account or privilege paths.
  • The guest helper accepts a bounded, versioned schema rather than administrator-provided shell commands.
  • Generated private keys remain in the requester's browser and are never submitted to ColdFront.

Rendered interface

See the operator and requester surfaces.

These views come from a disposable ColdFront fixture populated with synthetic users, addresses, jobs, and virtual machines. The plugin inherits the adopting site's ColdFront branding.

ColdFront Django admin form for PVE network, NetBox, guest policy, patching, and managed-file settings
Configure networking and guest policy

The admin form centralizes VMID and IP ranges, gateway and DNS, optional NetBox, packages, services, patch policy, and managed files.

Open full rendering ↗
ColdFront Django admin list showing successful reconcile-guest and patch-guest jobs
Track reconciliation and patch jobs

Durable job records expose the action, target VM, status, and attempt history instead of hiding the work in an ad hoc script.

Open full rendering ↗
ColdFront Django admin virtual-machine record with guest-policy hash, patch status, address, and retirement metadata
Inspect VM and policy status

The VM record keeps desired and applied access, policy hash, patch time, errors, address, and retirement metadata together.

Open full rendering ↗
ColdFront allocation request form with VM flavor, SSH public-key field, and browser-local Ed25519 generator
Generate SSH access in the browser

The request form can create and download an Ed25519 private key locally while placing only the public key into the allocation request.

Open full rendering ↗

Operating requirements

Bring the control plane. Configure the site policy.

This is an installable ColdFront plugin, not a hosted provisioning service. Adopters own their credentials, templates, networks, directory policy, and production validation.

COLDFRONT

Host application

ColdFront, Django-Q, the plugin migrations, and one active administrator-managed provisioner configuration.

PROXMOX VE

Virtualization target

PVE API access, an approved cloud-init template, a storage and bridge configuration, and QEMU guest agent support where guest policy is enabled.

GUEST POLICY

Optional reconciliation

An operator-installed, version-matched helper on supported Linux guests, plus site-specific package, service, LDAP or SSSD, and patch choices.

CANARY FIRST

Validate provisioning, access, reconciliation, patching, failure recovery, and retirement on an isolated VM before enabling the workflow for real allocations.

Use it, inspect it, adapt it.

The source, migrations, reference guest helper, configuration examples, and operator documentation are public.