| Age | Commit message (Collapse) | Author | Files | Lines |
|
Co-Authored-By: Claude.ai
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Add radvd to gateway role to advertise Pi as high-preference IPv6
default router using the stable ULA prefix (fd1e:.../64). With
FritzBox also sending RAs, devices end up with ECMP between Pi and
FritzBox. To solve this, add network_ipv6_gateway (Pi's link-local)
as a static route with metric 100 to all managed hosts — beats RA
metric 425, ensuring all IPv6 default traffic goes through Pi.
Fix IPv6 MASQUERADE in gateway-apply-rules:
- Direct mode: add MASQUERADE on end0 (LAN devices use ULA source
addresses not known to FritzBox, so Pi must NAT them)
- FORWARD rules: restrict to RELATED,ESTABLISHED only — previously
the broad ACCEPT rule passed un-NAT'd packets alongside masqueraded
copies, causing duplicate SYNs, conntrack corruption, and RSTs
- MASQUERADE/clear rules: match by interface not by source subnet
(devices may use any source address, not just the ULA prefix)
- VPN mode return traffic: explicitly restrict to wg+→end0 direction
Add network_ipv6_gateway var (optional) to network role NM templates
(ethernet, wifi, bridge) — injects a static IPv6 default route at
metric 100 when set. Add rpi5 static route to FritzBox link-local so
Pi keeps IPv6 after FritzBox RA is disabled.
Force SSH to IPv4 for *.local hosts (AddressFamily inet) — prevents
Ansible from hanging on mDNS returning multiple IPv6 addresses.
Update gateway and pihole READMEs with two-step IPv6 setup process.
Co-Authored-By: Claude.ai
|
|
Remove static IPv6 support from network role — all hosts use SLAAC
(method=auto). Simplifies NM templates, argument_specs, and resolved.conf.
gateway sysctl accept_ra=2 is now unconditional when gateway_enabled.
Co-authored-by: Claude.ai
|
|
|
|
|
|
|
|
Since ipv6 seems to be causing a lot of issues with the new ISP
|
|
|
|
The /mnt/* paths were ignored from the default grafana disk monitoring
so moving the backup dir to a separate directory that follows the linux
practices solves the issue and follows better practice
|
|
Refactor prometheus extra scraping jobs
|
|
|
|
|
|
|
|
|
|
When a wireguard configuration gets removed from the group/host
variables, the role now removes them and make sure only the files found
in the vars are the ones to be configured on the hosts
|
|
The ansible vars fail on CI because the validate arguments task runs way
before the setting of the variables, which causes the ansible undefined
vars on CI to cause errors.
This is a way better approach of having the static values as defaults
and allowing setting the variables to ansible vars in the host/group vars
|
|
|
|
|
|
|
|
This implementation doesn't work properly after testing.
The iptable configuration didn't allow for changing the VPN state
without running into networking issues.
Either have to change the VPN by running the role, which is inconvenient
or reimplement the role differently to allow for control over
network/interfaces
|
|
This reverts commit fdd0b5b58f0ebd39ad05e2dcb17faa6603145f97.
|
|
As the role now functions as a gateway and not just a wireguard gateway
it's better name for clarity
|
|
|
|
|
|
|
|
|
|
The pihole lookup DNS queries when the VPN connection is up was slow.
One of the culprits was the quad9 servers were taking long time when
using VPN
The other issue was the previous routing tables that used to work with
the fritzbox (with DHCP) which wasn't fully working was conflicting with
the VPN route tables and causing loops and delays.
Now most of the VPN queries are working fast but some requests are
taking some time, probably due to the VPN trying to check/block ads and
malware!
Also minor fixing to the pre tasks and documentation
|
|
|
|
|
|
|
|
|
|
|
|
|