summaryrefslogtreecommitdiffstats
path: root/host_vars/rpi5.local.yml
AgeCommit message (Collapse)AuthorFilesLines
2 daysDisable ipv6 completely and remove related codeAhmed Abdelhalim1-0/+0
Co-Authored-By: Claude.ai
3 daysUpdate secretsAhmed Abdelhalim1-0/+0
3 daysAdd awscli role with configuration on pi for garage backend w/testingAhmed Abdelhalim1-0/+0
6 daysRename backup -> mount as a roleAhmed Abdelhalim1-0/+0
8 daysFix deploying cgit locallyAhmed Abdelhalim1-0/+0
9 daysUpdate git hostnameAhmed Abdelhalim1-0/+0
9 daysRefactor pve cgit to use generic proxyAhmed Abdelhalim1-0/+0
This is refactoring the PoC for deploying cgit on pve, to now move to a more standard deployment with dedicated agnonstic proxy role/container
10 daysRename services to use .home.arpa network instead .localAhmed Abdelhalim1-0/+0
11 daysConfigure ipv6/prefer ipv4 switches for network (and all hosts)Ahmed Abdelhalim1-0/+0
12 daysConfigure preference of ip family (ipv4 > ipv6)Ahmed Abdelhalim1-0/+0
2026-07-08Route IPv6 through WireGuard VPN via radvd and static gatewayAhmed Abdelhalim1-0/+0
Add radvd to gateway role to advertise Pi as high-preference IPv6 default router using the stable ULA prefix (fd1e:.../64). With FritzBox also sending RAs, devices end up with ECMP between Pi and FritzBox. To solve this, add network_ipv6_gateway (Pi's link-local) as a static route with metric 100 to all managed hosts — beats RA metric 425, ensuring all IPv6 default traffic goes through Pi. Fix IPv6 MASQUERADE in gateway-apply-rules: - Direct mode: add MASQUERADE on end0 (LAN devices use ULA source addresses not known to FritzBox, so Pi must NAT them) - FORWARD rules: restrict to RELATED,ESTABLISHED only — previously the broad ACCEPT rule passed un-NAT'd packets alongside masqueraded copies, causing duplicate SYNs, conntrack corruption, and RSTs - MASQUERADE/clear rules: match by interface not by source subnet (devices may use any source address, not just the ULA prefix) - VPN mode return traffic: explicitly restrict to wg+→end0 direction Add network_ipv6_gateway var (optional) to network role NM templates (ethernet, wifi, bridge) — injects a static IPv6 default route at metric 100 when set. Add rpi5 static route to FritzBox link-local so Pi keeps IPv6 after FritzBox RA is disabled. Force SSH to IPv4 for *.local hosts (AddressFamily inet) — prevents Ansible from hanging on mDNS returning multiple IPv6 addresses. Update gateway and pihole READMEs with two-step IPv6 setup process. Co-Authored-By: Claude.ai
2026-07-08Update gateway/ip configurations for the piAhmed Abdelhalim1-0/+0
2026-07-07Enable ipv6 on the rpiAhmed Abdelhalim1-0/+0
2026-07-03Disable unstable ipv6 setup for nowAhmed Abdelhalim1-0/+0
2026-07-01Add prometheus node exporter to pveAhmed Abdelhalim1-0/+0
2026-06-30Fix ipv6 with examplesAhmed Abdelhalim1-0/+0
2026-06-30Update rpi dns upstreamsAhmed Abdelhalim1-0/+0
2026-06-30Disable ipv6 by defaultsAhmed Abdelhalim1-0/+0
Since ipv6 seems to be causing a lot of issues with the new ISP
2026-06-27Refactor garage role for better stability and defaultsAhmed Abdelhalim1-0/+0
2026-06-25Add dhcp hosts to dnsAhmed Abdelhalim1-0/+0
2026-06-24Use hostvars lookup for rpi prometheus ip configurationsAhmed Abdelhalim1-0/+0
2026-06-22Refactor installing grafana dashboards using URL onlyAhmed Abdelhalim1-0/+0
Refactor prometheus extra scraping jobs
2026-06-22Add garage to rpi to use as s3-compatible backend for backupsAhmed Abdelhalim1-0/+0
2026-06-22Add readme on using backup role and fix testingAhmed Abdelhalim1-0/+0
2026-06-22Add backup role for mounting a backup device on a rpi machineAhmed Abdelhalim1-0/+0
2026-06-17Refactor pi roles to use .home.arpa subdomains for servicesAhmed Abdelhalim1-0/+0
2026-06-12Update ip address for device mappingsAhmed Abdelhalim1-0/+0
2026-03-02Create specific prometheus node exporter roleAhmed Abdelhalim1-0/+0
2026-03-02Refactor prometheus to move node_exporter role out of the server roleAhmed Abdelhalim1-0/+0
2025-11-09Re-enable ipv6 back againAhmed Abdelhalim1-0/+0
2025-11-09Disable ipv6 on machines as not all vpns are ipv6 compatibleAhmed Abdelhalim1-0/+0
2025-09-20Update the prometheus/grafana role varsAhmed Abdelhalim1-0/+0
2025-09-18Update host vars with pinned python versionsAhmed Abdelhalim1-0/+0
2025-09-13Add wg_portal and pihole port and nginx configurationsAhmed Abdelhalim1-0/+0
2025-09-12Update variables and ignore claud.md fileAhmed Abdelhalim1-0/+0
2025-09-10Add wg_portal role to install vpn web interface managerAhmed Abdelhalim1-0/+0
2025-09-03Fix pihole interface configurationAhmed Abdelhalim1-0/+0
2025-09-03Revert change to network and disable filteringAhmed Abdelhalim1-0/+0
2025-09-03Revert "Refactor: rename wireguard_gateway to gateway"Ahmed Abdelhalim1-0/+0
This reverts commit fdd0b5b58f0ebd39ad05e2dcb17faa6603145f97.
2025-09-03Refactor: rename wireguard_gateway to gatewayAhmed Abdelhalim1-0/+0
As the role now functions as a gateway and not just a wireguard gateway it's better name for clarity
2025-09-02Fix pihole_dhcp_lease_time configurationsAhmed Abdelhalim1-0/+0
2025-09-02Configure dhcp hosts in pihole roleAhmed Abdelhalim1-0/+0
2025-09-02Refactor the network fix for piholeAhmed Abdelhalim1-0/+0
2025-09-02Fix pihole and network manger DNS when VPN isn't activeAhmed Abdelhalim1-0/+0
2025-09-01Fix networking issues when VPN isn't activeAhmed Abdelhalim1-0/+0
2025-09-01Fix wireguard_gateway role being slowAhmed Abdelhalim1-0/+0
The pihole lookup DNS queries when the VPN connection is up was slow. One of the culprits was the quad9 servers were taking long time when using VPN The other issue was the previous routing tables that used to work with the fritzbox (with DHCP) which wasn't fully working was conflicting with the VPN route tables and causing loops and delays. Now most of the VPN queries are working fast but some requests are taking some time, probably due to the VPN trying to check/block ads and malware! Also minor fixing to the pre tasks and documentation
2025-08-31Add wireguard gate way role to configure traffic through vpnAhmed Abdelhalim1-0/+0
2025-08-31Update wireguard connectionsAhmed Abdelhalim1-0/+0
2025-08-21Add wireguard role and fix testingAhmed Abdelhalim1-0/+0
The testing was failing because the use of the example files with the same domain names, resulted in the files and the molecule variable were being merged and therefore running tasks that would fail on test (example, setting a fake VPN connection that wouldn't start).
2025-08-14Update host variablesAhmed Abdelhalim1-0/+0