Provision through durable work.
Approved allocations enqueue Django-Q jobs for cloning, configuring, activating, patching, reconciling, and retiring virtual machines.
Sqoia Labs tool · Open source
Turn approved ColdFront allocations into managed Proxmox VE virtual machines, with network assignment, guest policy, access, and lifecycle state kept in one administrator-controlled workflow.
What it adds to ColdFront
The plugin keeps the requester, operator, VM, address, and guest-policy state connected instead of scattering the lifecycle across one-off scripts.
Approved allocations enqueue Django-Q jobs for cloning, configuring, activating, patching, reconciling, and retiring virtual machines.
Configure the IPv4 range, prefix, gateway, DNS, and VMID pool in Django admin. The built-in ledger works by default; NetBox is an optional inventory mirror.
Versioned policy can reconcile packages, non-secret managed files, systemd units, allocation users, and an administrator-selected patch cadence through a reviewed helper.
Requesters can generate an Ed25519 pair in the browser. The private key downloads locally while ColdFront and cloud-init receive only the public key.
How it works
ColdFront remains the source of allocation authority. The plugin adds persistent VM, address, job, event, and policy state around that record.
The requester selects a VM flavor and supplies or generates an SSH public key.
The approved allocation transition enqueues durable provisioning work.
The job reserves an address, clones the template, and applies cloud-init configuration.
An optional version-matched guest helper applies the bounded policy manifest.
Membership changes, patch schedules, and retirement create explicit follow-up jobs.
OPERATING GUARDRAILS
Rendered interface
These views come from a disposable ColdFront fixture populated with synthetic users, addresses, jobs, and virtual machines. The plugin inherits the adopting site's ColdFront branding.
The admin form centralizes VMID and IP ranges, gateway and DNS, optional NetBox, packages, services, patch policy, and managed files.
Open full rendering ↗
Durable job records expose the action, target VM, status, and attempt history instead of hiding the work in an ad hoc script.
Open full rendering ↗
The VM record keeps desired and applied access, policy hash, patch time, errors, address, and retirement metadata together.
Open full rendering ↗
The request form can create and download an Ed25519 private key locally while placing only the public key into the allocation request.
Open full rendering ↗Operating requirements
This is an installable ColdFront plugin, not a hosted provisioning service. Adopters own their credentials, templates, networks, directory policy, and production validation.
COLDFRONT
ColdFront, Django-Q, the plugin migrations, and one active administrator-managed provisioner configuration.
PROXMOX VE
PVE API access, an approved cloud-init template, a storage and bridge configuration, and QEMU guest agent support where guest policy is enabled.
GUEST POLICY
An operator-installed, version-matched helper on supported Linux guests, plus site-specific package, service, LDAP or SSSD, and patch choices.
Validate provisioning, access, reconciliation, patching, failure recovery, and retirement on an isolated VM before enabling the workflow for real allocations.
The source, migrations, reference guest helper, configuration examples, and operator documentation are public.