summaryrefslogtreecommitdiffstats
path: root/host_vars/rpi5.local.yml.example
AgeCommit message (Collapse)AuthorFilesLines
2 daysDisable ipv6 completely and remove related codeAhmed Abdelhalim1-4/+0
Co-Authored-By: Claude.ai
3 daysAdd awscli role with configuration on pi for garage backend w/testingAhmed Abdelhalim1-0/+6
3 daysAdd missing vars and fix mappings in examplesAhmed Abdelhalim1-0/+2
6 daysRename backup -> mount as a roleAhmed Abdelhalim1-1/+1
8 daysFix deploying cgit locallyAhmed Abdelhalim1-1/+4
10 daysRename services to use .home.arpa network instead .localAhmed Abdelhalim1-0/+1
12 daysConfigure preference of ip family (ipv4 > ipv6)Ahmed Abdelhalim1-0/+1
2026-07-08Route IPv6 through WireGuard VPN via radvd and static gatewayAhmed Abdelhalim1-0/+2
Add radvd to gateway role to advertise Pi as high-preference IPv6 default router using the stable ULA prefix (fd1e:.../64). With FritzBox also sending RAs, devices end up with ECMP between Pi and FritzBox. To solve this, add network_ipv6_gateway (Pi's link-local) as a static route with metric 100 to all managed hosts — beats RA metric 425, ensuring all IPv6 default traffic goes through Pi. Fix IPv6 MASQUERADE in gateway-apply-rules: - Direct mode: add MASQUERADE on end0 (LAN devices use ULA source addresses not known to FritzBox, so Pi must NAT them) - FORWARD rules: restrict to RELATED,ESTABLISHED only — previously the broad ACCEPT rule passed un-NAT'd packets alongside masqueraded copies, causing duplicate SYNs, conntrack corruption, and RSTs - MASQUERADE/clear rules: match by interface not by source subnet (devices may use any source address, not just the ULA prefix) - VPN mode return traffic: explicitly restrict to wg+→end0 direction Add network_ipv6_gateway var (optional) to network role NM templates (ethernet, wifi, bridge) — injects a static IPv6 default route at metric 100 when set. Add rpi5 static route to FritzBox link-local so Pi keeps IPv6 after FritzBox RA is disabled. Force SSH to IPv4 for *.local hosts (AddressFamily inet) — prevents Ansible from hanging on mDNS returning multiple IPv6 addresses. Update gateway and pihole READMEs with two-step IPv6 setup process. Co-Authored-By: Claude.ai
2026-07-08Refactor network roleAhmed Abdelhalim1-3/+1
Remove static IPv6 support from network role — all hosts use SLAAC (method=auto). Simplifies NM templates, argument_specs, and resolved.conf. gateway sysctl accept_ra=2 is now unconditional when gateway_enabled. Co-authored-by: Claude.ai
2026-07-07Enable ipv6 on the rpiAhmed Abdelhalim1-0/+3
2026-07-03Disable unstable ipv6 setup for nowAhmed Abdelhalim1-3/+0
2026-06-30Fix ipv6 with examplesAhmed Abdelhalim1-0/+3
2026-06-30Disable ipv6 by defaultsAhmed Abdelhalim1-2/+0
Since ipv6 seems to be causing a lot of issues with the new ISP
2026-06-27Refactor garage role for better stability and defaultsAhmed Abdelhalim1-1/+4
2026-06-23Update backup path to /backupAhmed Abdelhalim1-1/+1
The /mnt/* paths were ignored from the default grafana disk monitoring so moving the backup dir to a separate directory that follows the linux practices solves the issue and follows better practice
2026-06-22Refactor installing grafana dashboards using URL onlyAhmed Abdelhalim1-9/+15
Refactor prometheus extra scraping jobs
2026-06-22Add garage to rpi to use as s3-compatible backend for backupsAhmed Abdelhalim1-1/+5
2026-06-22Add readme on using backup role and fix testingAhmed Abdelhalim1-1/+1
2026-06-22Add backup role for mounting a backup device on a rpi machineAhmed Abdelhalim1-0/+2
2026-06-17Refactor pi roles to use .home.arpa subdomains for servicesAhmed Abdelhalim1-0/+10
2025-11-13Add mechanism to clean up wireguard configurationsAhmed Abdelhalim1-2/+4
When a wireguard configuration gets removed from the group/host variables, the role now removes them and make sure only the files found in the vars are the ones to be configured on the hosts
2025-09-23Use static values for defaults instead of ansible varsAhmed Abdelhalim1-1/+1
The ansible vars fail on CI because the validate arguments task runs way before the setting of the variables, which causes the ansible undefined vars on CI to cause errors. This is a way better approach of having the static values as defaults and allowing setting the variables to ansible vars in the host/group vars
2025-09-20Update the prometheus/grafana role varsAhmed Abdelhalim1-0/+29
2025-09-12Update example/test variablesAhmed Abdelhalim1-4/+8
2025-09-11Update vars to rename the wireguard interfaces wg-x (standard)Ahmed Abdelhalim1-3/+4
2025-09-10Remove wireguard_gatewayAhmed Abdelhalim1-1/+0
This implementation doesn't work properly after testing. The iptable configuration didn't allow for changing the VPN state without running into networking issues. Either have to change the VPN by running the role, which is inconvenient or reimplement the role differently to allow for control over network/interfaces
2025-09-03Revert "Refactor: rename wireguard_gateway to gateway"Ahmed Abdelhalim1-1/+1
This reverts commit fdd0b5b58f0ebd39ad05e2dcb17faa6603145f97.
2025-09-03Refactor: rename wireguard_gateway to gatewayAhmed Abdelhalim1-1/+1
As the role now functions as a gateway and not just a wireguard gateway it's better name for clarity
2025-09-02Configure dhcp hosts in pihole roleAhmed Abdelhalim1-0/+7
2025-09-02Refactor the network fix for piholeAhmed Abdelhalim1-2/+1
2025-09-02Fix pihole and network manger DNS when VPN isn't activeAhmed Abdelhalim1-2/+2
2025-09-01Fix networking issues when VPN isn't activeAhmed Abdelhalim1-1/+5
2025-09-01Fix wireguard_gateway role being slowAhmed Abdelhalim1-0/+1
The pihole lookup DNS queries when the VPN connection is up was slow. One of the culprits was the quad9 servers were taking long time when using VPN The other issue was the previous routing tables that used to work with the fritzbox (with DHCP) which wasn't fully working was conflicting with the VPN route tables and causing loops and delays. Now most of the VPN queries are working fast but some requests are taking some time, probably due to the VPN trying to check/block ads and malware! Also minor fixing to the pre tasks and documentation
2025-08-31Update wireguard connectionsAhmed Abdelhalim1-0/+13
2025-08-14Update host variablesAhmed Abdelhalim1-1/+2
2025-08-11Add pihole role to configure raspberry piAhmed Abdelhalim1-0/+3
2025-08-11Add network ipv4 configurationsAhmed Abdelhalim1-1/+2
2025-08-11Fix when running from distro-install playbook and fix testingAhmed Abdelhalim1-0/+1
2025-08-11Add ansible inventoryAhmed Abdelhalim1-0/+1