| Age | Commit message (Collapse) | Author | Files | Lines | |
|---|---|---|---|---|---|
| 12 days | Configure ipv6/prefer ipv4 switches for network (and all hosts) | Ahmed AbdelHalim | 1 | -0/+10 | |
| 2026-07-10 | Fix linting and testing gateway with dummy interface | Ahmed AbdelHalim | 1 | -1/+1 | |
| 2026-07-08 | Route IPv6 through WireGuard VPN via radvd and static gateway | Ahmed AbdelHalim | 1 | -0/+4 | |
| Add radvd to gateway role to advertise Pi as high-preference IPv6 default router using the stable ULA prefix (fd1e:.../64). With FritzBox also sending RAs, devices end up with ECMP between Pi and FritzBox. To solve this, add network_ipv6_gateway (Pi's link-local) as a static route with metric 100 to all managed hosts — beats RA metric 425, ensuring all IPv6 default traffic goes through Pi. Fix IPv6 MASQUERADE in gateway-apply-rules: - Direct mode: add MASQUERADE on end0 (LAN devices use ULA source addresses not known to FritzBox, so Pi must NAT them) - FORWARD rules: restrict to RELATED,ESTABLISHED only — previously the broad ACCEPT rule passed un-NAT'd packets alongside masqueraded copies, causing duplicate SYNs, conntrack corruption, and RSTs - MASQUERADE/clear rules: match by interface not by source subnet (devices may use any source address, not just the ULA prefix) - VPN mode return traffic: explicitly restrict to wg+→end0 direction Add network_ipv6_gateway var (optional) to network role NM templates (ethernet, wifi, bridge) — injects a static IPv6 default route at metric 100 when set. Add rpi5 static route to FritzBox link-local so Pi keeps IPv6 after FritzBox RA is disabled. Force SSH to IPv4 for *.local hosts (AddressFamily inet) — prevents Ansible from hanging on mDNS returning multiple IPv6 addresses. Update gateway and pihole READMEs with two-step IPv6 setup process. Co-Authored-By: Claude.ai | |||||
| 2026-07-08 | Refactor network role | Ahmed AbdelHalim | 1 | -9/+0 | |
| Remove static IPv6 support from network role — all hosts use SLAAC (method=auto). Simplifies NM templates, argument_specs, and resolved.conf. gateway sysctl accept_ra=2 is now unconditional when gateway_enabled. Co-authored-by: Claude.ai | |||||
| 2026-07-06 | Fix network setup on pve | Ahmed AbdelHalim | 1 | -2/+2 | |
| 2026-07-06 | Fix pve network setup | Ahmed AbdelHalim | 1 | -0/+4 | |
| 2026-03-04 | Remove duplicate fields from argument_specs files | Ahmed AbdelHalim | 1 | -2/+0 | |
| 2026-02-26 | Fix using od instead of xxd | Ahmed AbdelHalim | 1 | -0/+1 | |
| The od is available as part of coreutils which is shipping by default on linux but added for completeness Co-Authored-By: Claude.ai | |||||
| 2025-12-16 | Remove company from the roles meta | Ahmed AbdelHalim | 1 | -1/+0 | |
| 2025-09-10 | Add recommended argument_specs | Ahmed AbdelHalim | 1 | -0/+2 | |
| 2025-09-10 | Refactor role dependencies to be more module modular | Ahmed AbdelHalim | 1 | -1/+2 | |
| This modularity means that each role can be installed in a playbook by itself as long as the other roles exist around it. This also straps the ensure dependency packages exist in any of the roles tasks, they should be moved to their own roles and configured properly if needed. | |||||
| 2025-09-01 | Fix networking issues when VPN isn't active | Ahmed AbdelHalim | 1 | -0/+6 | |
| 2025-08-31 | Allow network role to configure ipv6 | Ahmed AbdelHalim | 1 | -0/+6 | |
| 2025-08-19 | Fix meta strings quoting | Ahmed AbdelHalim | 1 | -9/+8 | |
| 2025-08-16 | Refactor network role to remove NetworkManager/dhcpcd/networkd conflict | Ahmed AbdelHalim | 1 | -12/+0 | |
| 2025-08-11 | Add network ipv4 configurations | Ahmed AbdelHalim | 1 | -0/+6 | |
| 2025-08-11 | Refactor: move hostname into its own role | Ahmed AbdelHalim | 1 | -3/+0 | |
| 2025-08-11 | Add network role | Ahmed AbdelHalim | 2 | -0/+48 | |
