Skip to content

PVE Launch Node

Cloud Codger edited this page Sep 4, 2026 · 1 revision

Launch a new PVE Node

Directions for creating a basic stand-alone PVE node named gismo.

This assumes a working and configured Ansible Control Node and that all prerequisites have been met.

Steps:

  1. Install PVE
  2. Update inventory
  3. Acquire Images
  4. Create SSH key
  5. Configure SSH access
  6. Install Ansible Collections
  7. Run playbook

Objective:

  • Configure APT repositories for No-Subscription and update PVE node.
  • Configure authorized_keys for root to include (and remove) desired SSH public keys.
  • Upload Cloud-init image files to PVE nodes.

Showcased roles

  • cloudcodger.proxmox_ve.apt
  • cloudcodger.proxmox_ve.upload
  • cloudcodger.proxmox_openssh.datacenter

The links to Ansible Collections.

Regarding the cloudcodger.proxmox_ve.upload role variables. These have been configured to lookup the files that exist with the assumption that all Cloud-Init images end with .qcow2, all ISO images end in .iso and all LXC templates end with .zst. If you would like to change what gets uploaded, either edit the basic/group_vars/proxmox_hosts.yml file to set specific lists or update the contents of the files directory before running the playbook. Keep in mind that this does not remove any files on the PVE nodes and only uploads new or changed files.

Install PVE

First install the PVE software on the machine that will be your node. For experimentation purposes, this could be VM. Keep track of the root password that you set during the installation process as this will be needed when configuring SSH access.

This showcase uses the hostname of gismo for the PVE node.

Update Inventory

Make sure the IP address in basic/pve.yml is correct for the PVE node.

Acquire Images

Download any cloud-init images, ISO images and LXC container templates you want uploaded to the PVE node during the Run playbook step. These are listed in the upload_cloud_init_files, upload_iso_images and upload_lxc_templates variables respectively. To simplify things, these are set in the basic/group_vars/proxmox_hosts.yml file, where it looks up the existing files by the extention for each of the types.

The acquire.yml playbook will download the images and templates listed in the loop values for each task. Update the playbook with the desired items before running it.

This step can be skipped if the desired files already exist in the files directory. Make sure you have any files to be uploaded by the cloudcodger.proxmox_ve.upload role. This playbook runs on localhost, which does not require an inventory. However, this will produce the messages

[WARNING]: No inventory was parsed, only implicit localhost is available

[WARNING]: provided hosts list is empty, only localhost is available. Note that the implicit localhost does not match 'all'

Providing an inventory file with -i prevents these warning messages. The local_aliases.yml from any of the Inventory directories can be used for this command.

ansible-playbook -i basic/local_aliases.yml acquire.yml
ansible-playbook -i lab/local_aliases.yml acquire.yml

Create SSH key

If an ed25519 type SSH key hasn't been created yet, create one. The file name needs to match the one in basic/group_vars/proxmox_hosts.yml. Otherwise the lookup will fail.

ssh-keygen -t ed25519 -N "" -f ~/.ssh/showcase_ed25519

The -N sets an empty passphrase which is OK for a lab and using one is left up to the reader.

Configure SSH access

The known_hosts.yml playbook, with the specific inventory file basic/pve.yml, will scan each host and add the SSH hostkey to ~/.ssh/known_hosts file on the Ansible Control Node.

ansible-playbook -i basic/pve.yml known_hosts.yml -e host_list=proxmox_hosts

Set up passwordless SSH access to the PVE nodes by configuring an SSH key pair for the root user. Use ssh-copy-id to copy up a public key. This will prompt for the password that was set during the install.

ssh-copy-id -i ~/.ssh/showcase_ed25519.pub root@192.168.6.230
ssh-copy-id -i ~/.ssh/showcase_ed25519.pub root@gismo

Ansible Collections

The pve.yml playbook requires multiple collections and roles. If not done as part of creating the Ansible Control Node, install them using the requirements.yml file.

ansible-galaxy collection install -r requirements.yml

Run playbook

Run the pve_node.yml Ansible playbook with the specific inventory file basic/pve.yml. This must be able to validate certificates on the PVE node. The PVE Certificates page describes one method of configuring them.

ansible-playbook -i basic/pve.yml pve_node.yml

Playbook Contents

This playbook demonstrates the showcased roles in two plays. Described here.

The configure hosts play

The first play runs on each PVE node in the proxmox_hosts group (set in basic/pve.yml) with settings in basic/group_vars/proxmox_hosts.yml.

Roles executed:

  • cloudcodger.proxmox_ve.apt to:

    • update the APT repositories
    • run apt dist-upgrade
    • reboot the PVE node if needed
  • cloudcodger.proxmox_ve.upload to:

    • upload cloud-init images
    • upload ISO images
    • upload template images

Configure Datacenter play

The second play runs on local_pve_datacenter (an alias for localhost in basic/local_aliases.yml) with settings in basic/host_vars/local_pve_datacenter.yml.

Role executed:

  • The cloudcodger.proxmox_openssh.datacenter role will:
    • Create a .pve_secrets directory on the control node.
    • Update the local storage allowed content, so images is included.
    • Create Administrator and Auditor groups, users, tokens, and permission ACLs. Storing token secrets in the .pve_secrets directory.

Clone this wiki locally