# State Files

This page describes the three `.go_qemu_*` files go-pve-qemu reads and writes in its working directory.

## `.go_qemu_disabled`

The disabled list: listed VMIDs still appear in the VM list but cannot be controlled through the API.

```text
101:gateway-router
102:nas
```

| Rule | Description |
|---|---|
| Format | One `<vmid>:<name>` per line; blank lines, lines without a colon, and non-numeric VMIDs are skipped |
| List output | Overrides that VMID with `os: "-"`, `node: "-"`, `running: true` |
| Operation lock | Every state-checked endpoint returns `400 this IP is not allowed to be controlled` |
| Presence | **Required**; without it `/api/vm/list` returns 500 and every lifecycle and resource endpoint fails |

Use it to protect VMs in the same cluster that are managed elsewhere (routers, storage, core services).

## `.go_qemu_pubkey_admin`

Optional. Its contents are appended to every new VM's `authorized_keys`; put one public key per line.

Keys for a new VM are merged in this order:

1. The service user's public key: the first of `~/.ssh/id_ed25519.pub`, `id_rsa.pub`, `id_ecdsa.pub`
2. The full contents of `.go_qemu_pubkey_admin`
3. The request's `pubkey` field

The merged result is written to cloud-init with `qm set --sshkeys`.

## `.go_qemu_cpu_type`

An auto-generated cluster CPU type cache holding a single line such as `x86-64-v3`.

| When | Behavior |
|---|---|
| First VM install | Detects the cluster CPU level and writes it |
| Every later install | Reads it directly without calling `pvesh` |
| Node hardware changes | Delete it manually; the next install re-detects |

Detection is covered in [CPU Baseline](/cpu-baseline).
