summaryrefslogtreecommitdiffstats
path: root/roles/network/templates
AgeCommit message (Collapse)AuthorFilesLines
2 daysDisable ipv6 completely and remove related codeAhmed Abdelhalim6-33/+3
Co-Authored-By: Claude.ai
11 daysConfigure ipv6/prefer ipv4 switches for network (and all hosts)Ahmed Abdelhalim2-5/+9
13 daysConfigure preference of ip family (ipv4 > ipv6)Ahmed Abdelhalim1-0/+10
2026-07-08Route IPv6 through WireGuard VPN via radvd and static gatewayAhmed Abdelhalim3-1/+10
Add radvd to gateway role to advertise Pi as high-preference IPv6 default router using the stable ULA prefix (fd1e:.../64). With FritzBox also sending RAs, devices end up with ECMP between Pi and FritzBox. To solve this, add network_ipv6_gateway (Pi's link-local) as a static route with metric 100 to all managed hosts — beats RA metric 425, ensuring all IPv6 default traffic goes through Pi. Fix IPv6 MASQUERADE in gateway-apply-rules: - Direct mode: add MASQUERADE on end0 (LAN devices use ULA source addresses not known to FritzBox, so Pi must NAT them) - FORWARD rules: restrict to RELATED,ESTABLISHED only — previously the broad ACCEPT rule passed un-NAT'd packets alongside masqueraded copies, causing duplicate SYNs, conntrack corruption, and RSTs - MASQUERADE/clear rules: match by interface not by source subnet (devices may use any source address, not just the ULA prefix) - VPN mode return traffic: explicitly restrict to wg+→end0 direction Add network_ipv6_gateway var (optional) to network role NM templates (ethernet, wifi, bridge) — injects a static IPv6 default route at metric 100 when set. Add rpi5 static route to FritzBox link-local so Pi keeps IPv6 after FritzBox RA is disabled. Force SSH to IPv4 for *.local hosts (AddressFamily inet) — prevents Ansible from hanging on mDNS returning multiple IPv6 addresses. Update gateway and pihole READMEs with two-step IPv6 setup process. Co-Authored-By: Claude.ai
2026-07-08Fix bridge network treated as new deviceAhmed Abdelhalim1-1/+1
2026-07-08Refactor network roleAhmed Abdelhalim4-29/+4
Remove static IPv6 support from network role — all hosts use SLAAC (method=auto). Simplifies NM templates, argument_specs, and resolved.conf. gateway sysctl accept_ra=2 is now unconditional when gateway_enabled. Co-authored-by: Claude.ai
2026-07-08Revert 54ab1be commit change on ipv6Ahmed Abdelhalim2-2/+2
2026-07-06Fix network setup on pveAhmed Abdelhalim2-7/+9
2026-07-06Fix pve network setupAhmed Abdelhalim2-2/+39
2026-07-03Use permanent MAC addresses for ehternet/LAN connectionsAhmed Abdelhalim1-0/+1
This prevents FRITZ!Box from messing up the setup when seeing a new mac address on the LAN connections (causing it to block the pi or not able to wake the pve)
2026-06-30Disable ipv6 by defaultsAhmed Abdelhalim2-2/+2
Since ipv6 seems to be causing a lot of issues with the new ISP
2026-02-26Fix iwd-wifi idempotence testingAhmed Abdelhalim1-2/+0
Co-Authored-By: Claude.ai
2026-02-26Fix auto-starting iwd on bootAhmed Abdelhalim1-0/+2
2026-02-26Fix network to work on mac tooAhmed Abdelhalim1-0/+3
This migrates away from using the default wpa-supplicant, and use iwd instead on all the hosts
2025-09-21Disable connectivity detectionAhmed Abdelhalim1-1/+1
2025-09-15Update network role to remove dhcpcd dependencyAhmed Abdelhalim1-1/+1
Fix install on ubuntu not having networking service stated by default on ubuntu
2025-09-02Refactor the network fix for piholeAhmed Abdelhalim1-14/+4
2025-09-02Fix pihole and network manger DNS when VPN isn't activeAhmed Abdelhalim2-0/+8
2025-09-01Fix networking issues when VPN isn't activeAhmed Abdelhalim3-3/+15
2025-09-01Fix wireguard_gateway role being slowAhmed Abdelhalim1-2/+4
The pihole lookup DNS queries when the VPN connection is up was slow. One of the culprits was the quad9 servers were taking long time when using VPN The other issue was the previous routing tables that used to work with the fritzbox (with DHCP) which wasn't fully working was conflicting with the VPN route tables and causing loops and delays. Now most of the VPN queries are working fast but some requests are taking some time, probably due to the VPN trying to check/block ads and malware! Also minor fixing to the pre tasks and documentation
2025-08-31Allow network role to configure ipv6Ahmed Abdelhalim2-0/+12
2025-08-21Add wireguard role and fix testingAhmed Abdelhalim1-0/+2
The testing was failing because the use of the example files with the same domain names, resulted in the files and the molecule variable were being merged and therefore running tasks that would fail on test (example, setting a fake VPN connection that wouldn't start).
2025-08-19Fix pihole install to work on raspberry and simplify on archAhmed Abdelhalim1-2/+5
2025-08-11Add network ipv4 configurationsAhmed Abdelhalim2-1/+12
2025-08-11Use quad9 as the main DNS with cloudflare/google fallbacksAhmed Abdelhalim1-3/+2
2025-08-11Replace avahi with systemd-resolved/systemd-networkdAhmed Abdelhalim2-0/+26
2025-08-11Refactor to simplify debian network roleAhmed Abdelhalim1-0/+4
2025-08-11Add network roleAhmed Abdelhalim3-0/+61