summaryrefslogtreecommitdiffstats
path: root/roles/network/meta
AgeCommit message (Collapse)AuthorFilesLines
2 daysDisable ipv6 completely and remove related codeAhmed Abdelhalim1-14/+0
Co-Authored-By: Claude.ai
11 daysConfigure ipv6/prefer ipv4 switches for network (and all hosts)Ahmed Abdelhalim1-0/+10
2026-07-10Fix linting and testing gateway with dummy interfaceAhmed Abdelhalim1-1/+1
2026-07-08Route IPv6 through WireGuard VPN via radvd and static gatewayAhmed Abdelhalim1-0/+4
Add radvd to gateway role to advertise Pi as high-preference IPv6 default router using the stable ULA prefix (fd1e:.../64). With FritzBox also sending RAs, devices end up with ECMP between Pi and FritzBox. To solve this, add network_ipv6_gateway (Pi's link-local) as a static route with metric 100 to all managed hosts — beats RA metric 425, ensuring all IPv6 default traffic goes through Pi. Fix IPv6 MASQUERADE in gateway-apply-rules: - Direct mode: add MASQUERADE on end0 (LAN devices use ULA source addresses not known to FritzBox, so Pi must NAT them) - FORWARD rules: restrict to RELATED,ESTABLISHED only — previously the broad ACCEPT rule passed un-NAT'd packets alongside masqueraded copies, causing duplicate SYNs, conntrack corruption, and RSTs - MASQUERADE/clear rules: match by interface not by source subnet (devices may use any source address, not just the ULA prefix) - VPN mode return traffic: explicitly restrict to wg+→end0 direction Add network_ipv6_gateway var (optional) to network role NM templates (ethernet, wifi, bridge) — injects a static IPv6 default route at metric 100 when set. Add rpi5 static route to FritzBox link-local so Pi keeps IPv6 after FritzBox RA is disabled. Force SSH to IPv4 for *.local hosts (AddressFamily inet) — prevents Ansible from hanging on mDNS returning multiple IPv6 addresses. Update gateway and pihole READMEs with two-step IPv6 setup process. Co-Authored-By: Claude.ai
2026-07-08Refactor network roleAhmed Abdelhalim1-9/+0
Remove static IPv6 support from network role — all hosts use SLAAC (method=auto). Simplifies NM templates, argument_specs, and resolved.conf. gateway sysctl accept_ra=2 is now unconditional when gateway_enabled. Co-authored-by: Claude.ai
2026-07-06Fix network setup on pveAhmed Abdelhalim1-2/+2
2026-07-06Fix pve network setupAhmed Abdelhalim1-0/+4
2026-03-04Remove duplicate fields from argument_specs filesAhmed Abdelhalim1-2/+0
2026-02-26Fix using od instead of xxdAhmed Abdelhalim1-0/+1
The od is available as part of coreutils which is shipping by default on linux but added for completeness Co-Authored-By: Claude.ai
2025-12-16Remove company from the roles metaAhmed Abdelhalim1-1/+0
2025-09-10Add recommended argument_specsAhmed Abdelhalim1-0/+2
2025-09-10Refactor role dependencies to be more module modularAhmed Abdelhalim1-1/+2
This modularity means that each role can be installed in a playbook by itself as long as the other roles exist around it. This also straps the ensure dependency packages exist in any of the roles tasks, they should be moved to their own roles and configured properly if needed.
2025-09-01Fix networking issues when VPN isn't activeAhmed Abdelhalim1-0/+6
2025-08-31Allow network role to configure ipv6Ahmed Abdelhalim1-0/+6
2025-08-19Fix meta strings quotingAhmed Abdelhalim1-9/+8
2025-08-16Refactor network role to remove NetworkManager/dhcpcd/networkd conflictAhmed Abdelhalim1-12/+0
2025-08-11Add network ipv4 configurationsAhmed Abdelhalim1-0/+6
2025-08-11Refactor: move hostname into its own roleAhmed Abdelhalim1-3/+0
2025-08-11Add network roleAhmed Abdelhalim2-0/+48