diff options
| author | Ahmed Abdelhalim <[email protected]> | 2026-07-23 00:42:43 +0200 |
|---|---|---|
| committer | Ahmed Abdelhalim <[email protected]> | 2026-07-23 00:42:43 +0200 |
| commit | ff4eb129eea3f3743f82e5f1f7858d43625dba3d (patch) | |
| tree | c737e5354cb0622f28db6565c3dfea445e389b06 /roles/pihole | |
| parent | f7c8bd8143d6bc1e5b55bfd9591101ed41651d25 (diff) | |
Disable ipv6 completely and remove related code
Co-Authored-By: Claude.ai
Diffstat (limited to 'roles/pihole')
| -rw-r--r-- | roles/pihole/README.md | 46 | ||||
| -rw-r--r-- | roles/pihole/defaults/main.yml | 8 | ||||
| -rw-r--r-- | roles/pihole/meta/argument_specs.yml | 8 | ||||
| -rw-r--r-- | roles/pihole/tasks/main.yml | 6 |
4 files changed, 7 insertions, 61 deletions
diff --git a/roles/pihole/README.md b/roles/pihole/README.md index e7e0bb20..2f2383ab 100644 --- a/roles/pihole/README.md +++ b/roles/pihole/README.md @@ -37,54 +37,8 @@ This role configure the [pihole](https://github.com/pi-hole/pi-hole) DNS Sinkhol - Internet > Account Information > DNS Server > DNSv4 Server > Use Other DNSv4 Servers > {{ pihole_ipv4 }} -#### No IPv6 Support (default) - - Home Network > Network > Network Settings > Change Advanced Network Settings > IPv6 > - Router advertisement enable in the LAN > ❌ - DNSv6 Server in the Home Network > Also announce DNSv6 server via router advertisement (RFC5006) > ❌ - Internet > Account Information > IPv6 > IPv6 Support > ❌ - -#### With IPv6 Support - -Setup is a two-step process: first enable FritzBox RA to get the Pi's stable ULA address, -then disable FritzBox RA so Pi becomes the sole IPv6 default router. - -**Step 1 — Enable FritzBox RA temporarily to get Pi's ULA address:** - -- Internet > Account Information > - - IPv6 > IPv6 Support > ✅ - - IPv6 > IPv6 Connectivity > Native IPv4 connection > Use IPv6 via landline connection or Mobile network > ✅ - - IPv6 > Connection Settings > Use DHCPv6 Rapid Commit > ❌ - - IPv6 > Connection Settings > Require certain length of the LAN prefix > ❌ - -- Home Network > Network > Network Settings > Change Advanced Network Settings > IPv6 > - - Router advertisement enable in the LAN > ✅ - - Always assign ULA addresses > ✅ - - Set ULA prefix > https://www.unique-local-ipv6.com/ example: `fd00:1234:5678::` > ✅ - - This FRITZ!Box provides the standard internet connection > Low - - DNSv6 Server in the Home Network > - - Also announce DNSv6 server via router advertisement (RFC5006) > ✅ - - Local DNSv6 Server > {{ pihole_ipv6 `ip address | grep "inet6 fd"`}} - - DHCPv6 Server in the home network > - - Disable DHCPv6 server in the FRITZ!Box for the home network > ✅ - - There are no other DHCPv6 servers in the home network. > ✅ - -- Internet > Account Information > Internet DNS Server > DNSv6 Server > Use Other DNSv6 Servers > {{ pihole_ipv6 }} - -On the Pi, get the ULA address and the FritzBox link-local default route: -```bash -ip address | grep "inet6 fd" # use the mngtmpaddr address as pihole_ipv6 -ip -6 route show default | grep ra # use the nexthop as network_ipv6_gateway in rpi5 host_vars -``` - -Set `network_ipv6_gateway` in `host_vars/rpi5.local.yml` and run the playbook to deploy the static IPv6 route on Pi. - -**Step 2 — Disable FritzBox RA so Pi becomes sole IPv6 default router:** - -- Home Network > Network > Network Settings > Change Advanced Network Settings > IPv6 > - - Router advertisement enable in the LAN > ❌ - -NOTE: Pi's radvd (deployed by the `gateway` role) takes over sending RAs with `AdvDefaultPreference high`. -All LAN devices use Pi as their IPv6 default router → traffic routes VPN or direct mode. -Pi keeps IPv6 connectivity via the static route to FritzBox set in Step 1. diff --git a/roles/pihole/defaults/main.yml b/roles/pihole/defaults/main.yml index d980c67c..e9d72266 100644 --- a/roles/pihole/defaults/main.yml +++ b/roles/pihole/defaults/main.yml @@ -2,12 +2,8 @@ pihole_password: "{{ ('changeme' | hash('sha256') | hash('sha256'))[:64] }}" pihole_totp_secret: "CHANGEME" pihole_dns: - # Cloudflare - - "1.1.1.1" - - "2606:4700:4700::1111" - # Google - - "8.8.8.8" - - "2001:4860:4860:0:0:0:0:8888" + - "1.1.1.1" # Cloudflare + - "8.8.8.8" # Google pihole_interface: "eth0" pihole_dns_blocking_enabled: true pihole_dhcp_enabled: false diff --git a/roles/pihole/meta/argument_specs.yml b/roles/pihole/meta/argument_specs.yml index 40662436..c86fd5a0 100644 --- a/roles/pihole/meta/argument_specs.yml +++ b/roles/pihole/meta/argument_specs.yml @@ -15,12 +15,8 @@ argument_specs: description: "The list of DNS servers to use as upstreams" elements: "str" default: - # Cloudflare - - "1.1.1.1" - - "2606:4700:4700::1111" - # Google - - "8.8.8.8" - - "2001:4860:4860:0:0:0:0:8888" + - "1.1.1.1" # Cloudflare + - "8.8.8.8" # Google pihole_interface: type: "str" description: "The interface to bind the pi-hole on" diff --git a/roles/pihole/tasks/main.yml b/roles/pihole/tasks/main.yml index ccd4bd9f..63e034d8 100644 --- a/roles/pihole/tasks/main.yml +++ b/roles/pihole/tasks/main.yml @@ -1,8 +1,8 @@ --- -- name: "Validate network_ipv*_dns params" +- name: "Validate network_ipv4_dns param" ansible.builtin.fail: - msg: "Pihole role cannot work when network_ipv4_dns or network_ipv6_dns are defined" - when: network_ipv4_dns is defined or network_ipv6_dns is defined + msg: "Pihole role cannot work when network_ipv4_dns is defined" + when: network_ipv4_dns is defined - name: "Validate pihole_dhcp_* params" ansible.builtin.assert: |
