summaryrefslogtreecommitdiffstats
path: root/roles/network
AgeCommit message (Collapse)AuthorFilesLines
12 daysConfigure ipv6/prefer ipv4 switches for network (and all hosts)Ahmed AbdelHalim4-5/+20
13 daysConfigure preference of ip family (ipv4 > ipv6)Ahmed AbdelHalim3-0/+20
2026-07-10Fix linting and testing gateway with dummy interfaceAhmed AbdelHalim1-1/+1
2026-07-08Route IPv6 through WireGuard VPN via radvd and static gatewayAhmed AbdelHalim4-1/+14
Add radvd to gateway role to advertise Pi as high-preference IPv6 default router using the stable ULA prefix (fd1e:.../64). With FritzBox also sending RAs, devices end up with ECMP between Pi and FritzBox. To solve this, add network_ipv6_gateway (Pi's link-local) as a static route with metric 100 to all managed hosts — beats RA metric 425, ensuring all IPv6 default traffic goes through Pi. Fix IPv6 MASQUERADE in gateway-apply-rules: - Direct mode: add MASQUERADE on end0 (LAN devices use ULA source addresses not known to FritzBox, so Pi must NAT them) - FORWARD rules: restrict to RELATED,ESTABLISHED only — previously the broad ACCEPT rule passed un-NAT'd packets alongside masqueraded copies, causing duplicate SYNs, conntrack corruption, and RSTs - MASQUERADE/clear rules: match by interface not by source subnet (devices may use any source address, not just the ULA prefix) - VPN mode return traffic: explicitly restrict to wg+→end0 direction Add network_ipv6_gateway var (optional) to network role NM templates (ethernet, wifi, bridge) — injects a static IPv6 default route at metric 100 when set. Add rpi5 static route to FritzBox link-local so Pi keeps IPv6 after FritzBox RA is disabled. Force SSH to IPv4 for *.local hosts (AddressFamily inet) — prevents Ansible from hanging on mDNS returning multiple IPv6 addresses. Update gateway and pihole READMEs with two-step IPv6 setup process. Co-Authored-By: Claude.ai
2026-07-08Fix bridge network treated as new deviceAhmed AbdelHalim1-1/+1
2026-07-08Refactor network roleAhmed AbdelHalim6-46/+4
Remove static IPv6 support from network role — all hosts use SLAAC (method=auto). Simplifies NM templates, argument_specs, and resolved.conf. gateway sysctl accept_ra=2 is now unconditional when gateway_enabled. Co-authored-by: Claude.ai
2026-07-08Revert 70d45f2 commit change on ipv6Ahmed AbdelHalim2-2/+2
2026-07-06Fix network setup on pveAhmed AbdelHalim4-11/+13
2026-07-06Fix pve network setupAhmed AbdelHalim4-2/+52
2026-07-03Use permanent MAC addresses for ehternet/LAN connectionsAhmed AbdelHalim1-0/+1
This prevents FRITZ!Box from messing up the setup when seeing a new mac address on the LAN connections (causing it to block the pi or not able to wake the pve)
2026-06-30Disable ipv6 by defaultsAhmed AbdelHalim2-2/+2
Since ipv6 seems to be causing a lot of issues with the new ISP
2026-05-07Fix mDNS not resolving because ubuntu 26.04 introduced an overrideAhmed AbdelHalim1-1/+10
2026-03-04Remove duplicate fields from argument_specs filesAhmed AbdelHalim1-2/+0
2026-02-26Remove auto-starting iwd, it's managed by network manager (as backend)Ahmed AbdelHalim3-3/+0
2026-02-26Fix iwd-wifi idempotence testingAhmed AbdelHalim2-7/+5
Co-Authored-By: Claude.ai
2026-02-26Fix using od instead of xxdAhmed AbdelHalim2-1/+4
The od is available as part of coreutils which is shipping by default on linux but added for completeness Co-Authored-By: Claude.ai
2026-02-26Remove captive portal code as it wasn't testedAhmed AbdelHalim1-8/+0
2026-02-26Fix auto-starting iwd on bootAhmed AbdelHalim2-0/+30
2026-02-26Fix network to work on mac tooAhmed AbdelHalim4-0/+12
This migrates away from using the default wpa-supplicant, and use iwd instead on all the hosts
2026-02-12Handle avahi removal in network role onlyAhmed AbdelHalim1-0/+5
Since it can cause problems (following the archlinux wiki recommendations) we keep the handling of that in the network role and ignore idempotence testing failures in other roles too
2026-01-24Fix ansible 2.20.1 deprecation warning about ansible_varsAhmed AbdelHalim2-9/+9
2026-01-09Test fixing idempotent test failure on archlinuxAhmed AbdelHalim1-4/+4
Co-authored-by: claude.ai
2025-12-16Remove company from the roles metaAhmed AbdelHalim1-1/+0
2025-09-22Attempt fixing avahi test by pinning versionsAhmed AbdelHalim1-8/+0
2025-09-22Attempt fix of avahi/dhcpcd uninstall in debian/ubuntuAhmed AbdelHalim1-1/+9
2025-09-21Disable connectivity detectionAhmed AbdelHalim1-1/+1
2025-09-20Migrate to the new loop syntaxAhmed AbdelHalim1-4/+4
2025-09-15Update network role to remove dhcpcd dependencyAhmed AbdelHalim6-6/+15
Fix install on ubuntu not having networking service stated by default on ubuntu
2025-09-10Add recommended argument_specsAhmed AbdelHalim1-0/+2
2025-09-10Follow the ansible recommendation of using systemd_serviceAhmed AbdelHalim2-5/+5
2025-09-10Refactor role dependencies to be more module modularAhmed AbdelHalim3-6/+7
This modularity means that each role can be installed in a playbook by itself as long as the other roles exist around it. This also straps the ensure dependency packages exist in any of the roles tasks, they should be moved to their own roles and configured properly if needed.
2025-09-03Fix archlinux failureAhmed AbdelHalim1-0/+1
The root causes why the idempotence test to fail is that Docker bridge creation sends netlink events to socket Socket activation starts systemd-networkd.service despite disabled state Idempotence test finds service running when expecting stopped
2025-09-02Add dig and nslookup deps for debugging networking issuesAhmed AbdelHalim2-1/+2
2025-09-02Refactor the network fix for piholeAhmed AbdelHalim1-14/+4
2025-09-02Fix pihole and network manger DNS when VPN isn't activeAhmed AbdelHalim3-6/+12
2025-09-01Fix networking issues when VPN isn't activeAhmed AbdelHalim5-5/+33
2025-09-01Fix wireguard_gateway role being slowAhmed AbdelHalim1-2/+4
The pihole lookup DNS queries when the VPN connection is up was slow. One of the culprits was the quad9 servers were taking long time when using VPN The other issue was the previous routing tables that used to work with the fritzbox (with DHCP) which wasn't fully working was conflicting with the VPN route tables and causing loops and delays. Now most of the VPN queries are working fast but some requests are taking some time, probably due to the VPN trying to check/block ads and malware! Also minor fixing to the pre tasks and documentation
2025-08-31Allow network role to configure ipv6Ahmed AbdelHalim3-0/+18
2025-08-21Fix the wireguard installAhmed AbdelHalim1-6/+0
The conflict was due to resolvconf was removing the systemd-resolved configuration and that was causing the network to go down and the fallback on the statically managed resolv.conf (which wasn't able to resolve the DNS) due to how network manager requiring the DNS resolution to happen through systemd-resolved
2025-08-21Fix network role to install via chrootAhmed AbdelHalim2-4/+6
The removal of the resolv.conf DNS configuration is required by the wireguard not to have conflicting DNS configuration resolvers between the static system fallback and the NetworkManager resolver (using systemd-resolved) and the VPN DNS
2025-08-21Add wireguard role and fix testingAhmed AbdelHalim1-0/+2
The testing was failing because the use of the example files with the same domain names, resulted in the files and the molecule variable were being merged and therefore running tasks that would fail on test (example, setting a fake VPN connection that wouldn't start).
2025-08-19Fix install ubuntu and wifi configsAhmed AbdelHalim2-1/+1
2025-08-19Fix meta strings quotingAhmed AbdelHalim1-9/+8
2025-08-19Fix pihole install to work on raspberry and simplify on archAhmed AbdelHalim1-2/+5
2025-08-16Refactor network role to remove NetworkManager/dhcpcd/networkd conflictAhmed AbdelHalim7-67/+43
2025-08-16Fix conflicting NetworkManger/systemd-networkdAhmed AbdelHalim4-3/+16
2025-08-11Add network ipv4 configurationsAhmed AbdelHalim4-1/+26
2025-08-11Refactor: move hostname into its own roleAhmed AbdelHalim3-27/+0
2025-08-11Use quad9 as the main DNS with cloudflare/google fallbacksAhmed AbdelHalim1-3/+2
2025-08-11Clean up the archlinux network roleAhmed AbdelHalim1-3/+1