summaryrefslogtreecommitdiffstats
path: root/host_vars/macbook.local.yml
AgeCommit message (Collapse)AuthorFilesLines
2 daysDisable ipv6 completely and remove related codeAhmed Abdelhalim1-0/+0
Co-Authored-By: Claude.ai
2 daysCleanup and normalize the duplicate network addressesAhmed Abdelhalim1-0/+0
11 daysRemove the gt750m role after multiple attempts of fixing itAhmed Abdelhalim1-0/+0
Since this role has never worked properly, this state with updating the resolution and keeping the nouveau driver working with acceptable performance on external monitors
13 daysConfigure preference of ip family (ipv4 > ipv6)Ahmed Abdelhalim1-0/+0
2026-07-10Replace hyprland monitors with kanshi profilesAhmed Abdelhalim1-0/+0
2026-07-10Extract logind lid configuration into it's own roleAhmed Abdelhalim1-0/+0
2026-07-09Fix IPv6 direct mode routing for LAN clientsAhmed Abdelhalim1-0/+0
- Remove static network_ipv6_gateway from LAN hosts so they pick up Pi's radvd RA (pref high) instead of FritzBox (pref low) - Add missing ip6tables FORWARD ACCEPT rule for new connections in direct mode (only ESTABLISHED was present, blocking new flows) - Flush ip6tables nat POSTROUTING table on clear instead of fragile per-rule -D deletion to prevent stale rule accumulation
2026-07-08Route IPv6 through WireGuard VPN via radvd and static gatewayAhmed Abdelhalim1-0/+0
Add radvd to gateway role to advertise Pi as high-preference IPv6 default router using the stable ULA prefix (fd1e:.../64). With FritzBox also sending RAs, devices end up with ECMP between Pi and FritzBox. To solve this, add network_ipv6_gateway (Pi's link-local) as a static route with metric 100 to all managed hosts — beats RA metric 425, ensuring all IPv6 default traffic goes through Pi. Fix IPv6 MASQUERADE in gateway-apply-rules: - Direct mode: add MASQUERADE on end0 (LAN devices use ULA source addresses not known to FritzBox, so Pi must NAT them) - FORWARD rules: restrict to RELATED,ESTABLISHED only — previously the broad ACCEPT rule passed un-NAT'd packets alongside masqueraded copies, causing duplicate SYNs, conntrack corruption, and RSTs - MASQUERADE/clear rules: match by interface not by source subnet (devices may use any source address, not just the ULA prefix) - VPN mode return traffic: explicitly restrict to wg+→end0 direction Add network_ipv6_gateway var (optional) to network role NM templates (ethernet, wifi, bridge) — injects a static IPv6 default route at metric 100 when set. Add rpi5 static route to FritzBox link-local so Pi keeps IPv6 after FritzBox RA is disabled. Force SSH to IPv4 for *.local hosts (AddressFamily inet) — prevents Ansible from hanging on mDNS returning multiple IPv6 addresses. Update gateway and pihole READMEs with two-step IPv6 setup process. Co-Authored-By: Claude.ai
2026-07-03Disable unstable ipv6 setup for nowAhmed Abdelhalim1-0/+0
2026-06-30Fix ipv6 with examplesAhmed Abdelhalim1-0/+0
2026-06-30Disable ipv6 by defaultsAhmed Abdelhalim1-0/+0
Since ipv6 seems to be causing a lot of issues with the new ISP
2026-06-12Update ip address for device mappingsAhmed Abdelhalim1-0/+0
2026-04-23Update tooling on laptop and macAhmed Abdelhalim1-0/+0
2026-04-23Change the host_var mappings and inventory namesAhmed Abdelhalim1-0/+0