| Age | Commit message (Collapse) | Author | Files | Lines | |
|---|---|---|---|---|---|
| 2 days | Disable ipv6 completely and remove related code | Ahmed Abdelhalim | 1 | -0/+0 | |
| Co-Authored-By: Claude.ai | |||||
| 3 days | Update secrets | Ahmed Abdelhalim | 1 | -0/+0 | |
| 3 days | Add awscli role with configuration on pi for garage backend w/testing | Ahmed Abdelhalim | 1 | -0/+0 | |
| 6 days | Rename backup -> mount as a role | Ahmed Abdelhalim | 1 | -0/+0 | |
| 8 days | Fix deploying cgit locally | Ahmed Abdelhalim | 1 | -0/+0 | |
| 9 days | Update git hostname | Ahmed Abdelhalim | 1 | -0/+0 | |
| 9 days | Refactor pve cgit to use generic proxy | Ahmed Abdelhalim | 1 | -0/+0 | |
| This is refactoring the PoC for deploying cgit on pve, to now move to a more standard deployment with dedicated agnonstic proxy role/container | |||||
| 10 days | Rename services to use .home.arpa network instead .local | Ahmed Abdelhalim | 1 | -0/+0 | |
| 11 days | Configure ipv6/prefer ipv4 switches for network (and all hosts) | Ahmed Abdelhalim | 1 | -0/+0 | |
| 12 days | Configure preference of ip family (ipv4 > ipv6) | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2026-07-08 | Route IPv6 through WireGuard VPN via radvd and static gateway | Ahmed Abdelhalim | 1 | -0/+0 | |
| Add radvd to gateway role to advertise Pi as high-preference IPv6 default router using the stable ULA prefix (fd1e:.../64). With FritzBox also sending RAs, devices end up with ECMP between Pi and FritzBox. To solve this, add network_ipv6_gateway (Pi's link-local) as a static route with metric 100 to all managed hosts — beats RA metric 425, ensuring all IPv6 default traffic goes through Pi. Fix IPv6 MASQUERADE in gateway-apply-rules: - Direct mode: add MASQUERADE on end0 (LAN devices use ULA source addresses not known to FritzBox, so Pi must NAT them) - FORWARD rules: restrict to RELATED,ESTABLISHED only — previously the broad ACCEPT rule passed un-NAT'd packets alongside masqueraded copies, causing duplicate SYNs, conntrack corruption, and RSTs - MASQUERADE/clear rules: match by interface not by source subnet (devices may use any source address, not just the ULA prefix) - VPN mode return traffic: explicitly restrict to wg+→end0 direction Add network_ipv6_gateway var (optional) to network role NM templates (ethernet, wifi, bridge) — injects a static IPv6 default route at metric 100 when set. Add rpi5 static route to FritzBox link-local so Pi keeps IPv6 after FritzBox RA is disabled. Force SSH to IPv4 for *.local hosts (AddressFamily inet) — prevents Ansible from hanging on mDNS returning multiple IPv6 addresses. Update gateway and pihole READMEs with two-step IPv6 setup process. Co-Authored-By: Claude.ai | |||||
| 2026-07-08 | Update gateway/ip configurations for the pi | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2026-07-07 | Enable ipv6 on the rpi | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2026-07-03 | Disable unstable ipv6 setup for now | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2026-07-01 | Add prometheus node exporter to pve | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2026-06-30 | Fix ipv6 with examples | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2026-06-30 | Update rpi dns upstreams | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2026-06-30 | Disable ipv6 by defaults | Ahmed Abdelhalim | 1 | -0/+0 | |
| Since ipv6 seems to be causing a lot of issues with the new ISP | |||||
| 2026-06-27 | Refactor garage role for better stability and defaults | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2026-06-25 | Add dhcp hosts to dns | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2026-06-24 | Use hostvars lookup for rpi prometheus ip configurations | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2026-06-22 | Refactor installing grafana dashboards using URL only | Ahmed Abdelhalim | 1 | -0/+0 | |
| Refactor prometheus extra scraping jobs | |||||
| 2026-06-22 | Add garage to rpi to use as s3-compatible backend for backups | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2026-06-22 | Add readme on using backup role and fix testing | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2026-06-22 | Add backup role for mounting a backup device on a rpi machine | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2026-06-17 | Refactor pi roles to use .home.arpa subdomains for services | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2026-06-12 | Update ip address for device mappings | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2026-03-02 | Create specific prometheus node exporter role | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2026-03-02 | Refactor prometheus to move node_exporter role out of the server role | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2025-11-09 | Re-enable ipv6 back again | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2025-11-09 | Disable ipv6 on machines as not all vpns are ipv6 compatible | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2025-09-20 | Update the prometheus/grafana role vars | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2025-09-18 | Update host vars with pinned python versions | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2025-09-13 | Add wg_portal and pihole port and nginx configurations | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2025-09-12 | Update variables and ignore claud.md file | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2025-09-10 | Add wg_portal role to install vpn web interface manager | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2025-09-03 | Fix pihole interface configuration | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2025-09-03 | Revert change to network and disable filtering | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2025-09-03 | Revert "Refactor: rename wireguard_gateway to gateway" | Ahmed Abdelhalim | 1 | -0/+0 | |
| This reverts commit fdd0b5b58f0ebd39ad05e2dcb17faa6603145f97. | |||||
| 2025-09-03 | Refactor: rename wireguard_gateway to gateway | Ahmed Abdelhalim | 1 | -0/+0 | |
| As the role now functions as a gateway and not just a wireguard gateway it's better name for clarity | |||||
| 2025-09-02 | Fix pihole_dhcp_lease_time configurations | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2025-09-02 | Configure dhcp hosts in pihole role | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2025-09-02 | Refactor the network fix for pihole | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2025-09-02 | Fix pihole and network manger DNS when VPN isn't active | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2025-09-01 | Fix networking issues when VPN isn't active | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2025-09-01 | Fix wireguard_gateway role being slow | Ahmed Abdelhalim | 1 | -0/+0 | |
| The pihole lookup DNS queries when the VPN connection is up was slow. One of the culprits was the quad9 servers were taking long time when using VPN The other issue was the previous routing tables that used to work with the fritzbox (with DHCP) which wasn't fully working was conflicting with the VPN route tables and causing loops and delays. Now most of the VPN queries are working fast but some requests are taking some time, probably due to the VPN trying to check/block ads and malware! Also minor fixing to the pre tasks and documentation | |||||
| 2025-08-31 | Add wireguard gate way role to configure traffic through vpn | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2025-08-31 | Update wireguard connections | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2025-08-21 | Add wireguard role and fix testing | Ahmed Abdelhalim | 1 | -0/+0 | |
| The testing was failing because the use of the example files with the same domain names, resulted in the files and the molecule variable were being merged and therefore running tasks that would fail on test (example, setting a fake VPN connection that wouldn't start). | |||||
| 2025-08-14 | Update host variables | Ahmed Abdelhalim | 1 | -0/+0 | |
