
Proxmox VE GetFirewallRules
CertifiedGet firewall rules on a Proxmox VE node
Proxmox VE GetFirewallRules
Get firewall rules on a Proxmox VE node
Retrieves firewall rules from /nodes/{node}/firewall/rules. Optionally scope to a specific VM or container by providing a vmId. When vmId is set, reads /nodes/{node}/qemu/{vmid}/firewall/rules (VM) or /nodes/{node}/lxc/{vmid}/firewall/rules (container) based on resourceType.
type: io.kestra.plugin.proxmox.network.GetFirewallRulesExamples
Get node-level firewall rules
id: get_firewall_rules
namespace: company.team
tasks:
- id: rules
type: io.kestra.plugin.proxmox.network.GetFirewallRules
host: "{{ secret('PROXMOX_HOST') }}"
username: "{{ secret('PROXMOX_USERNAME') }}"
password: "{{ secret('PROXMOX_PASSWORD') }}"
node: pve
Get VM-level firewall rules
id: get_vm_firewall_rules
namespace: company.team
tasks:
- id: rules
type: io.kestra.plugin.proxmox.network.GetFirewallRules
host: "{{ secret('PROXMOX_HOST') }}"
username: "{{ secret('PROXMOX_USERNAME') }}"
password: "{{ secret('PROXMOX_PASSWORD') }}"
node: pve
vmId: "100"
resourceType: vm
Properties
host *string
Proxmox host
Hostname or IP address of the Proxmox VE node (no scheme, no port).
node *string
Proxmox node name
Name of the cluster node that scopes all API calls (e.g. pve, node1).
assets
Assets this task consumes as inputs or produces as outputs, for lineage tracking and the asset graph (Enterprise Edition). A flow declaring this property on a task is rejected in the open-source edition.
io.kestra.core.models.assets.AssetsDeclaration
IGNOREFAILWARNAsset failure behavior
Behavior applied to the task state when a declared asset fails to render, emit, or be persisted (e.g. a lock conflict): FAIL escalates it to FAILED, WARN (default) warns it if it would otherwise succeed, IGNORE leaves the state untouched.
Whether to auto-register assets referenced dynamically at runtime that are not statically declared in inputs or outputs.
The assets consumed as inputs.
io.kestra.core.models.assets.AssetIdentifier
1The assets produced as outputs.
io.kestra.plugin.ee.assets.Dataset
1150{}1150io.kestra.plugin.ee.assets.File
1150{}1150io.kestra.plugin.ee.assets.Table
1150{}1150io.kestra.plugin.ee.assets.VM
1150{}1150io.kestra.core.models.assets.External
1150{}1150io.kestra.core.models.assets.Custom
11501Custom asset type
{}1150password string
Password
Password for ticket-based authentication.
port integerstring
8006API port
Defaults to 8006.
resourceType string
VMCONTAINERResource type
Resource type: vm or container.
tokenId string
API token ID
Full token identifier in the form user@realm!tokenname (e.g. root@pam!mytoken). Use together with tokenSecret.
tokenSecret string
API token secret
The UUID secret associated with the token ID.
username string
Username
PAM or PVE user in the form user@realm (e.g. root@pam). Required when using ticket-based auth.
verifySsl booleanstring
trueVerify SSL
Validate the server TLS certificate. Defaults to true; set to false only for trusted networks with self-signed Proxmox certificates.
vmId string
VM or container ID
When set, retrieves firewall rules scoped to this VM or container instead of the node.