| Age | Commit message (Collapse) | Author | Files | Lines |
|
|
|
|
|
|
|
Add radvd to gateway role to advertise Pi as high-preference IPv6
default router using the stable ULA prefix (fd1e:.../64). With
FritzBox also sending RAs, devices end up with ECMP between Pi and
FritzBox. To solve this, add network_ipv6_gateway (Pi's link-local)
as a static route with metric 100 to all managed hosts — beats RA
metric 425, ensuring all IPv6 default traffic goes through Pi.
Fix IPv6 MASQUERADE in gateway-apply-rules:
- Direct mode: add MASQUERADE on end0 (LAN devices use ULA source
addresses not known to FritzBox, so Pi must NAT them)
- FORWARD rules: restrict to RELATED,ESTABLISHED only — previously
the broad ACCEPT rule passed un-NAT'd packets alongside masqueraded
copies, causing duplicate SYNs, conntrack corruption, and RSTs
- MASQUERADE/clear rules: match by interface not by source subnet
(devices may use any source address, not just the ULA prefix)
- VPN mode return traffic: explicitly restrict to wg+→end0 direction
Add network_ipv6_gateway var (optional) to network role NM templates
(ethernet, wifi, bridge) — injects a static IPv6 default route at
metric 100 when set. Add rpi5 static route to FritzBox link-local so
Pi keeps IPv6 after FritzBox RA is disabled.
Force SSH to IPv4 for *.local hosts (AddressFamily inet) — prevents
Ansible from hanging on mDNS returning multiple IPv6 addresses.
Update gateway and pihole READMEs with two-step IPv6 setup process.
Co-Authored-By: Claude.ai
|
|
|
|
Remove static IPv6 support from network role — all hosts use SLAAC
(method=auto). Simplifies NM templates, argument_specs, and resolved.conf.
gateway sysctl accept_ra=2 is now unconditional when gateway_enabled.
Co-authored-by: Claude.ai
|
|
|
|
|
|
|
|
This prevents FRITZ!Box from messing up the setup when seeing a new mac
address on the LAN connections (causing it to block the pi or not able
to wake the pve)
|
|
Since ipv6 seems to be causing a lot of issues with the new ISP
|
|
|
|
|
|
|
|
Co-Authored-By: Claude.ai
|
|
The od is available as part of coreutils which is shipping by default on
linux but added for completeness
Co-Authored-By: Claude.ai
|
|
|
|
|
|
This migrates away from using the default wpa-supplicant, and use iwd
instead on all the hosts
|
|
Since it can cause problems (following the archlinux wiki
recommendations) we keep the handling of that in the network role and
ignore idempotence testing failures in other roles too
|
|
|
|
Co-authored-by: claude.ai
|
|
|
|
|
|
|
|
|
|
|
|
Fix install on ubuntu not having networking service stated by default on
ubuntu
|
|
|
|
|
|
This modularity means that each role can be installed in a playbook by
itself as long as the other roles exist around it.
This also straps the ensure dependency packages exist in any of the
roles tasks, they should be moved to their own roles and configured
properly if needed.
|
|
The root causes why the idempotence test to fail
is that Docker bridge creation sends netlink events to socket
Socket activation starts systemd-networkd.service despite disabled state
Idempotence test finds service running when expecting stopped
|
|
|
|
|
|
|
|
|
|
The pihole lookup DNS queries when the VPN connection is up was slow.
One of the culprits was the quad9 servers were taking long time when
using VPN
The other issue was the previous routing tables that used to work with
the fritzbox (with DHCP) which wasn't fully working was conflicting with
the VPN route tables and causing loops and delays.
Now most of the VPN queries are working fast but some requests are
taking some time, probably due to the VPN trying to check/block ads and
malware!
Also minor fixing to the pre tasks and documentation
|
|
|
|
The conflict was due to resolvconf was removing the systemd-resolved
configuration and that was causing the network to go down and the
fallback on the statically managed resolv.conf (which wasn't able to
resolve the DNS) due to how network manager requiring the DNS resolution
to happen through systemd-resolved
|
|
The removal of the resolv.conf DNS configuration is required by the
wireguard not to have conflicting DNS configuration resolvers between
the static system fallback and the NetworkManager resolver (using
systemd-resolved) and the VPN DNS
|
|
The testing was failing because the use of the example files with the
same domain names, resulted in the files and the molecule variable were
being merged and therefore running tasks that would fail on test
(example, setting a fake VPN connection that wouldn't start).
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|