summaryrefslogtreecommitdiffstats
path: root/host_vars
AgeCommit message (Collapse)AuthorFilesLines
2 daysDisable ipv6 completely and remove related codeAhmed Abdelhalim10-16/+0
Co-Authored-By: Claude.ai
2 daysCleanup and normalize the duplicate network addressesAhmed Abdelhalim8-9/+9
3 daysUpdate secretsAhmed Abdelhalim2-0/+0
3 daysAdd awscli role with configuration on pi for garage backend w/testingAhmed Abdelhalim3-0/+6
3 daysAdd missing vars and fix mappings in examplesAhmed Abdelhalim2-1/+3
3 daysUpdate cgit varsAhmed Abdelhalim1-0/+0
4 daysFix restic install and add backup roleAhmed Abdelhalim2-0/+9
Co-Authored-By: Claude.ai
6 daysRename backup -> mount as a roleAhmed Abdelhalim2-1/+1
7 daysUpdate cgit view (remove owner) and example varsAhmed Abdelhalim2-2/+2
8 daysRefactor proxy setup on cgit to simplify setupAhmed Abdelhalim1-0/+0
8 daysFix deploying cgit locallyAhmed Abdelhalim4-1/+4
9 daysUpdate git hostnameAhmed Abdelhalim1-0/+0
9 daysAdd pve-ssh support with hardeningAhmed Abdelhalim4-0/+2
9 daysRefactor pve cgit to use generic proxyAhmed Abdelhalim5-4/+20
This is refactoring the PoC for deploying cgit on pve, to now move to a more standard deployment with dedicated agnonstic proxy role/container
10 daysRename services to use .home.arpa network instead .localAhmed Abdelhalim4-2/+1
11 daysReplace hyprland_nvidia boolean with a fact from the roleAhmed Abdelhalim3-2/+0
This to make the role have less configurations, and less prune to human errors
11 daysRemove the gt750m role after multiple attempts of fixing itAhmed Abdelhalim1-0/+0
Since this role has never worked properly, this state with updating the resolution and keeping the nouveau driver working with acceptable performance on external monitors
11 daysConfigure ipv6/prefer ipv4 switches for network (and all hosts)Ahmed Abdelhalim1-0/+0
12 daysConfigure 2.4GHz for desktop, since 5GHz signal is too weakAhmed Abdelhalim1-0/+0
12 daysUpdate desktop monitor placementAhmed Abdelhalim1-0/+0
13 daysConfigure preference of ip family (ipv4 > ipv6)Ahmed Abdelhalim10-0/+5
2026-07-10Replace hyprland monitors with kanshi profilesAhmed Abdelhalim6-4/+28
2026-07-10Extract logind lid configuration into it's own roleAhmed Abdelhalim6-1/+5
2026-07-09Fix IPv6 direct mode routing for LAN clientsAhmed Abdelhalim4-0/+0
- Remove static network_ipv6_gateway from LAN hosts so they pick up Pi's radvd RA (pref high) instead of FritzBox (pref low) - Add missing ip6tables FORWARD ACCEPT rule for new connections in direct mode (only ESTABLISHED was present, blocking new flows) - Flush ip6tables nat POSTROUTING table on clear instead of fragile per-rule -D deletion to prevent stale rule accumulation
2026-07-08Route IPv6 through WireGuard VPN via radvd and static gatewayAhmed Abdelhalim10-0/+13
Add radvd to gateway role to advertise Pi as high-preference IPv6 default router using the stable ULA prefix (fd1e:.../64). With FritzBox also sending RAs, devices end up with ECMP between Pi and FritzBox. To solve this, add network_ipv6_gateway (Pi's link-local) as a static route with metric 100 to all managed hosts — beats RA metric 425, ensuring all IPv6 default traffic goes through Pi. Fix IPv6 MASQUERADE in gateway-apply-rules: - Direct mode: add MASQUERADE on end0 (LAN devices use ULA source addresses not known to FritzBox, so Pi must NAT them) - FORWARD rules: restrict to RELATED,ESTABLISHED only — previously the broad ACCEPT rule passed un-NAT'd packets alongside masqueraded copies, causing duplicate SYNs, conntrack corruption, and RSTs - MASQUERADE/clear rules: match by interface not by source subnet (devices may use any source address, not just the ULA prefix) - VPN mode return traffic: explicitly restrict to wg+→end0 direction Add network_ipv6_gateway var (optional) to network role NM templates (ethernet, wifi, bridge) — injects a static IPv6 default route at metric 100 when set. Add rpi5 static route to FritzBox link-local so Pi keeps IPv6 after FritzBox RA is disabled. Force SSH to IPv4 for *.local hosts (AddressFamily inet) — prevents Ansible from hanging on mDNS returning multiple IPv6 addresses. Update gateway and pihole READMEs with two-step IPv6 setup process. Co-Authored-By: Claude.ai
2026-07-08Update gateway/ip configurations for the piAhmed Abdelhalim1-0/+0
2026-07-08Refactor network roleAhmed Abdelhalim1-3/+1
Remove static IPv6 support from network role — all hosts use SLAAC (method=auto). Simplifies NM templates, argument_specs, and resolved.conf. gateway sysctl accept_ra=2 is now unconditional when gateway_enabled. Co-authored-by: Claude.ai
2026-07-08Fix install proxmoxer using pipAhmed Abdelhalim1-2/+2
Using mise or python role broke on other machines so went with the simplest solution for now, it's safe to break the system packages for python as this is not used internally in other ways Also proxmoxer 2+ is needed to work with the proxmox module
2026-07-07Add pve-lxc service provisioning using service.yml and containers groupAhmed Abdelhalim2-0/+21
2026-07-07Enable ipv6 on the rpiAhmed Abdelhalim2-0/+3
2026-07-06Fix network setup on pveAhmed Abdelhalim2-2/+1
2026-07-06Fix pve network setupAhmed Abdelhalim2-7/+1
2026-07-06Use conventional storage nameAhmed Abdelhalim1-0/+0
2026-07-03Refactor pve roles to create storage separatelyAhmed Abdelhalim2-4/+3
2026-07-03Refactor pve and add pve-network role to configure the pve networkAhmed Abdelhalim2-2/+6
2026-07-03Disable unstable ipv6 setup for nowAhmed Abdelhalim10-15/+0
2026-07-03Update ethtool to handle laptop lid suspend issuesAhmed Abdelhalim2-0/+3
When using WoL with laptops (ex Lenovo) closing the lid suspends the laptop and breaks WoL, this is to allow configuring the lid behavior
2026-07-03Add ethtool and configure interface for pveAhmed Abdelhalim1-0/+0
2026-07-01Add prometheus node exporter to pveAhmed Abdelhalim1-0/+0
2026-06-30Fix ipv6 with examplesAhmed Abdelhalim10-0/+15
2026-06-30Update rpi dns upstreamsAhmed Abdelhalim1-0/+0
2026-06-30Disable ipv6 by defaultsAhmed Abdelhalim10-14/+0
Since ipv6 seems to be causing a lot of issues with the new ISP
2026-06-30Update pve admin password in example and real configurationsAhmed Abdelhalim2-0/+3
2026-06-27Add restic role w/testingAhmed Abdelhalim3-0/+3
2026-06-27Refactor garage role for better stability and defaultsAhmed Abdelhalim2-1/+4
2026-06-25Add dhcp hosts to dnsAhmed Abdelhalim1-0/+0
2026-06-24Use hostvars lookup for rpi prometheus ip configurationsAhmed Abdelhalim1-0/+0
2026-06-23Update backup path to /backupAhmed Abdelhalim1-1/+1
The /mnt/* paths were ignored from the default grafana disk monitoring so moving the backup dir to a separate directory that follows the linux practices solves the issue and follows better practice
2026-06-22Refactor installing grafana dashboards using URL onlyAhmed Abdelhalim2-9/+15
Refactor prometheus extra scraping jobs
2026-06-22Add garage to rpi to use as s3-compatible backend for backupsAhmed Abdelhalim2-1/+5