| Age | Commit message (Collapse) | Author | Files | Lines | |
|---|---|---|---|---|---|
| 2 days | Disable ipv6 completely and remove related code | Ahmed Abdelhalim | 10 | -16/+0 | |
| Co-Authored-By: Claude.ai | |||||
| 2 days | Cleanup and normalize the duplicate network addresses | Ahmed Abdelhalim | 8 | -9/+9 | |
| 3 days | Update secrets | Ahmed Abdelhalim | 2 | -0/+0 | |
| 3 days | Add awscli role with configuration on pi for garage backend w/testing | Ahmed Abdelhalim | 3 | -0/+6 | |
| 3 days | Add missing vars and fix mappings in examples | Ahmed Abdelhalim | 2 | -1/+3 | |
| 3 days | Update cgit vars | Ahmed Abdelhalim | 1 | -0/+0 | |
| 4 days | Fix restic install and add backup role | Ahmed Abdelhalim | 2 | -0/+9 | |
| Co-Authored-By: Claude.ai | |||||
| 6 days | Rename backup -> mount as a role | Ahmed Abdelhalim | 2 | -1/+1 | |
| 7 days | Update cgit view (remove owner) and example vars | Ahmed Abdelhalim | 2 | -2/+2 | |
| 8 days | Refactor proxy setup on cgit to simplify setup | Ahmed Abdelhalim | 1 | -0/+0 | |
| 8 days | Fix deploying cgit locally | Ahmed Abdelhalim | 4 | -1/+4 | |
| 9 days | Update git hostname | Ahmed Abdelhalim | 1 | -0/+0 | |
| 9 days | Add pve-ssh support with hardening | Ahmed Abdelhalim | 4 | -0/+2 | |
| 9 days | Refactor pve cgit to use generic proxy | Ahmed Abdelhalim | 5 | -4/+20 | |
| This is refactoring the PoC for deploying cgit on pve, to now move to a more standard deployment with dedicated agnonstic proxy role/container | |||||
| 10 days | Rename services to use .home.arpa network instead .local | Ahmed Abdelhalim | 4 | -2/+1 | |
| 11 days | Replace hyprland_nvidia boolean with a fact from the role | Ahmed Abdelhalim | 3 | -2/+0 | |
| This to make the role have less configurations, and less prune to human errors | |||||
| 11 days | Remove the gt750m role after multiple attempts of fixing it | Ahmed Abdelhalim | 1 | -0/+0 | |
| Since this role has never worked properly, this state with updating the resolution and keeping the nouveau driver working with acceptable performance on external monitors | |||||
| 11 days | Configure ipv6/prefer ipv4 switches for network (and all hosts) | Ahmed Abdelhalim | 1 | -0/+0 | |
| 12 days | Configure 2.4GHz for desktop, since 5GHz signal is too weak | Ahmed Abdelhalim | 1 | -0/+0 | |
| 12 days | Update desktop monitor placement | Ahmed Abdelhalim | 1 | -0/+0 | |
| 13 days | Configure preference of ip family (ipv4 > ipv6) | Ahmed Abdelhalim | 10 | -0/+5 | |
| 2026-07-10 | Replace hyprland monitors with kanshi profiles | Ahmed Abdelhalim | 6 | -4/+28 | |
| 2026-07-10 | Extract logind lid configuration into it's own role | Ahmed Abdelhalim | 6 | -1/+5 | |
| 2026-07-09 | Fix IPv6 direct mode routing for LAN clients | Ahmed Abdelhalim | 4 | -0/+0 | |
| - Remove static network_ipv6_gateway from LAN hosts so they pick up Pi's radvd RA (pref high) instead of FritzBox (pref low) - Add missing ip6tables FORWARD ACCEPT rule for new connections in direct mode (only ESTABLISHED was present, blocking new flows) - Flush ip6tables nat POSTROUTING table on clear instead of fragile per-rule -D deletion to prevent stale rule accumulation | |||||
| 2026-07-08 | Route IPv6 through WireGuard VPN via radvd and static gateway | Ahmed Abdelhalim | 10 | -0/+13 | |
| Add radvd to gateway role to advertise Pi as high-preference IPv6 default router using the stable ULA prefix (fd1e:.../64). With FritzBox also sending RAs, devices end up with ECMP between Pi and FritzBox. To solve this, add network_ipv6_gateway (Pi's link-local) as a static route with metric 100 to all managed hosts — beats RA metric 425, ensuring all IPv6 default traffic goes through Pi. Fix IPv6 MASQUERADE in gateway-apply-rules: - Direct mode: add MASQUERADE on end0 (LAN devices use ULA source addresses not known to FritzBox, so Pi must NAT them) - FORWARD rules: restrict to RELATED,ESTABLISHED only — previously the broad ACCEPT rule passed un-NAT'd packets alongside masqueraded copies, causing duplicate SYNs, conntrack corruption, and RSTs - MASQUERADE/clear rules: match by interface not by source subnet (devices may use any source address, not just the ULA prefix) - VPN mode return traffic: explicitly restrict to wg+→end0 direction Add network_ipv6_gateway var (optional) to network role NM templates (ethernet, wifi, bridge) — injects a static IPv6 default route at metric 100 when set. Add rpi5 static route to FritzBox link-local so Pi keeps IPv6 after FritzBox RA is disabled. Force SSH to IPv4 for *.local hosts (AddressFamily inet) — prevents Ansible from hanging on mDNS returning multiple IPv6 addresses. Update gateway and pihole READMEs with two-step IPv6 setup process. Co-Authored-By: Claude.ai | |||||
| 2026-07-08 | Update gateway/ip configurations for the pi | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2026-07-08 | Refactor network role | Ahmed Abdelhalim | 1 | -3/+1 | |
| Remove static IPv6 support from network role — all hosts use SLAAC (method=auto). Simplifies NM templates, argument_specs, and resolved.conf. gateway sysctl accept_ra=2 is now unconditional when gateway_enabled. Co-authored-by: Claude.ai | |||||
| 2026-07-08 | Fix install proxmoxer using pip | Ahmed Abdelhalim | 1 | -2/+2 | |
| Using mise or python role broke on other machines so went with the simplest solution for now, it's safe to break the system packages for python as this is not used internally in other ways Also proxmoxer 2+ is needed to work with the proxmox module | |||||
| 2026-07-07 | Add pve-lxc service provisioning using service.yml and containers group | Ahmed Abdelhalim | 2 | -0/+21 | |
| 2026-07-07 | Enable ipv6 on the rpi | Ahmed Abdelhalim | 2 | -0/+3 | |
| 2026-07-06 | Fix network setup on pve | Ahmed Abdelhalim | 2 | -2/+1 | |
| 2026-07-06 | Fix pve network setup | Ahmed Abdelhalim | 2 | -7/+1 | |
| 2026-07-06 | Use conventional storage name | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2026-07-03 | Refactor pve roles to create storage separately | Ahmed Abdelhalim | 2 | -4/+3 | |
| 2026-07-03 | Refactor pve and add pve-network role to configure the pve network | Ahmed Abdelhalim | 2 | -2/+6 | |
| 2026-07-03 | Disable unstable ipv6 setup for now | Ahmed Abdelhalim | 10 | -15/+0 | |
| 2026-07-03 | Update ethtool to handle laptop lid suspend issues | Ahmed Abdelhalim | 2 | -0/+3 | |
| When using WoL with laptops (ex Lenovo) closing the lid suspends the laptop and breaks WoL, this is to allow configuring the lid behavior | |||||
| 2026-07-03 | Add ethtool and configure interface for pve | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2026-07-01 | Add prometheus node exporter to pve | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2026-06-30 | Fix ipv6 with examples | Ahmed Abdelhalim | 10 | -0/+15 | |
| 2026-06-30 | Update rpi dns upstreams | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2026-06-30 | Disable ipv6 by defaults | Ahmed Abdelhalim | 10 | -14/+0 | |
| Since ipv6 seems to be causing a lot of issues with the new ISP | |||||
| 2026-06-30 | Update pve admin password in example and real configurations | Ahmed Abdelhalim | 2 | -0/+3 | |
| 2026-06-27 | Add restic role w/testing | Ahmed Abdelhalim | 3 | -0/+3 | |
| 2026-06-27 | Refactor garage role for better stability and defaults | Ahmed Abdelhalim | 2 | -1/+4 | |
| 2026-06-25 | Add dhcp hosts to dns | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2026-06-24 | Use hostvars lookup for rpi prometheus ip configurations | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2026-06-23 | Update backup path to /backup | Ahmed Abdelhalim | 1 | -1/+1 | |
| The /mnt/* paths were ignored from the default grafana disk monitoring so moving the backup dir to a separate directory that follows the linux practices solves the issue and follows better practice | |||||
| 2026-06-22 | Refactor installing grafana dashboards using URL only | Ahmed Abdelhalim | 2 | -9/+15 | |
| Refactor prometheus extra scraping jobs | |||||
| 2026-06-22 | Add garage to rpi to use as s3-compatible backend for backups | Ahmed Abdelhalim | 2 | -1/+5 | |
