summaryrefslogtreecommitdiffstats
AgeCommit message (Collapse)AuthorFilesLines
2025-09-11Remove claudeAhmed Abdelhalim1-138/+0
2025-09-11Update vars to rename the wireguard interfaces wg-x (standard)Ahmed Abdelhalim5-10/+11
2025-09-11Fix the wg-portal role to be idempotent and withstand install/uninsallAhmed Abdelhalim1-5/+42
2025-09-10Refactor site playbooks to be more host orientedAhmed Abdelhalim4-21/+55
This also improves the dependency management, making the roles less repeating when not needing to execute multiple times
2025-09-10Add recommended argument_specsAhmed Abdelhalim24-4/+91
2025-09-10Follow the ansible recommendation of using systemd_serviceAhmed Abdelhalim7-14/+14
2025-09-10Remove wireguard_gatewayAhmed Abdelhalim10-237/+0
This implementation doesn't work properly after testing. The iptable configuration didn't allow for changing the VPN state without running into networking issues. Either have to change the VPN by running the role, which is inconvenient or reimplement the role differently to allow for control over network/interfaces
2025-09-10Refactor role dependencies to be more module modularAhmed Abdelhalim22-49/+157
This modularity means that each role can be installed in a playbook by itself as long as the other roles exist around it. This also straps the ensure dependency packages exist in any of the roles tasks, they should be moved to their own roles and configured properly if needed.
2025-09-10Add wg_portal role to install vpn web interface managerAhmed Abdelhalim7-0/+72
2025-09-10Fix password policy on debian don't have gnome installed by defaultAhmed Abdelhalim1-0/+2
2025-09-09Remove old pihole 5 related pathsAhmed Abdelhalim1-3/+0
2025-09-04[skip-ci] fix typo in notesAhmed Abdelhalim1-2/+2
2025-09-04Make the testing commands genericAhmed Abdelhalim1-2/+2
2025-09-04Skip idempotence test because the ipv6 default isn't set on CIAhmed Abdelhalim1-10/+6
2025-09-04Fix CIAhmed Abdelhalim8-3/+54
2025-09-04Refactor molecule testing to run a scenario per distro and fix ipv6Ahmed Abdelhalim12-6/+22
2025-09-04Refactor molecule testing to run a scenario per distroAhmed Abdelhalim14-66/+282
2025-09-03Fix archlinux failureAhmed Abdelhalim1-0/+1
The root causes why the idempotence test to fail is that Docker bridge creation sends netlink events to socket Socket activation starts systemd-networkd.service despite disabled state Idempotence test finds service running when expecting stopped
2025-09-03Fix pihole interface configurationAhmed Abdelhalim1-0/+0
2025-09-03Add ansible roleAhmed Abdelhalim8-0/+223
2025-09-03Update claudeAhmed Abdelhalim1-15/+16
2025-09-03Revert change to network and disable filteringAhmed Abdelhalim3-0/+0
2025-09-03Revert "Fix networking issue"Ahmed Abdelhalim1-24/+0
This reverts commit 06e686bc12ee10697431f056efbaecdcba1681d2.
2025-09-03Revert "Refactor: rename wireguard_gateway to gateway"Ahmed Abdelhalim13-25/+25
This reverts commit fdd0b5b58f0ebd39ad05e2dcb17faa6603145f97.
2025-09-03Revert "Experimental: adding iptables persistence through reboots"Ahmed Abdelhalim2-48/+1
This reverts commit 025abf3ce9497f51d21b14aa31907c0c3bd75ecf.
2025-09-03Add Claude contextAhmed Abdelhalim1-0/+112
2025-09-03Experimental: adding iptables persistence through rebootsAhmed Abdelhalim2-1/+48
2025-09-03Refactor: rename wireguard_gateway to gatewayAhmed Abdelhalim13-25/+25
As the role now functions as a gateway and not just a wireguard gateway it's better name for clarity
2025-09-03Fix networking issueAhmed Abdelhalim1-0/+24
This allows forwarding the traffic through the pi (similar to how the VPN is routing all the traffic using it's iptables) This means that the role is more of a general gateway When the vpn is activated it handles routing all the traffic through it This commits provide the same functionality when the VPN isn't active
2025-09-03Add podman role with configuration to work over ssh with cgroupfsAhmed Abdelhalim4-0/+68
2025-09-03Fix the user groups to be appendedAhmed Abdelhalim1-1/+1
It's more modular and each role can manage its own group memberships
2025-09-03Revert back to using brew module as it has better idempotency handlingAhmed Abdelhalim2-24/+23
2025-09-03Add docker roleAhmed Abdelhalim4-0/+40
2025-09-02Revert the pyenv full path changeAhmed Abdelhalim1-4/+12
It should be cosmetic, but apparently failing on debian
2025-09-02Add bash as a role and use it in role dependencies when bash is neededAhmed Abdelhalim8-15/+32
2025-09-02Fix CI failures and ignore intentionally changing tasks for idem testAhmed Abdelhalim3-2/+27
2025-09-02Fix linting issuesAhmed Abdelhalim4-11/+11
2025-09-02Add go role to playbooksAhmed Abdelhalim3-0/+2
2025-09-02Add tasks to clean up unwanted go versionsAhmed Abdelhalim1-1/+25
2025-09-02Fix homebrew to use commands instead of module to avoid issue with archAhmed Abdelhalim3-41/+30
Plus it's cleaner to see what gets installed instead of depending on the module
2025-09-02Update the go role to handle default to latestAhmed Abdelhalim3-17/+35
2025-09-02Initial go role draft implementationAhmed Abdelhalim4-0/+61
2025-09-02Fix the python role to install and clean up in idempotent mannerAhmed Abdelhalim3-1/+25
2025-09-02Fix locales role to idempotent generate regardless of system stateAhmed Abdelhalim2-14/+34
2025-09-02Add dig and nslookup deps for debugging networking issuesAhmed Abdelhalim2-1/+2
2025-09-02Fix pihole_dhcp_lease_time configurationsAhmed Abdelhalim4-5/+5
2025-09-02Configure dhcp hosts in pihole roleAhmed Abdelhalim5-0/+14
2025-09-02Add wireguard_gateway meta infoAhmed Abdelhalim2-0/+30
2025-09-02Fix wireguard_gateway test on CIAhmed Abdelhalim1-8/+4
Allow the wireguard_gateway to configure all forwarding for all the interfaces available for the connections
2025-09-02Refactor the network fix for piholeAhmed Abdelhalim4-41/+9