summaryrefslogtreecommitdiffstats
path: root/roles/pihole
AgeCommit message (Collapse)AuthorFilesLines
2 daysDisable ipv6 completely and remove related codeAhmed Abdelhalim4-61/+7
Co-Authored-By: Claude.ai
4 daysFix pihole port allocation, this fixes caddy testingAhmed Abdelhalim1-2/+2
domain = {{ pihole_domain }} rendered as an unquoted bareword containing a dot (e.g. "pi.hole"), which is invalid TOML. TOML parsing is all-or-nothing, not line-by-line, so pihole-FTL rejected the entire config file on that one line and silently fell back to its compiled-in defaults — including binding its webserver directly to ports 80/443. That collided with caddy, which wants the same ports, causing caddy to crash-loop and get reported as "changed" (needing a restart) on every subsequent ansible run. Quoting the domain value lets the file parse successfully, which in turn surfaces a second, previously-unreachable bug: the custom webserver port (pihole_port) was rendered as a bare number, but Pi-hole v6 FTL requires each listener address to carry a trailing flag character (o = optional, s = TLS). Without it FTL rejects the value the same way and reverts to the 80/443 default. Appending "o" fixes that. Both bugs had to be fixed together: the quoting bug was blocking the parser from ever reaching the port line, so the port fix alone had no effect until parsing succeeded end-to-end. Co-Authored-By: Claude.ai
4 daysFix nginx to use conventional ngix conf.dAhmed Abdelhalim2-1/+4
2026-07-08Route IPv6 through WireGuard VPN via radvd and static gatewayAhmed Abdelhalim1-5/+22
Add radvd to gateway role to advertise Pi as high-preference IPv6 default router using the stable ULA prefix (fd1e:.../64). With FritzBox also sending RAs, devices end up with ECMP between Pi and FritzBox. To solve this, add network_ipv6_gateway (Pi's link-local) as a static route with metric 100 to all managed hosts — beats RA metric 425, ensuring all IPv6 default traffic goes through Pi. Fix IPv6 MASQUERADE in gateway-apply-rules: - Direct mode: add MASQUERADE on end0 (LAN devices use ULA source addresses not known to FritzBox, so Pi must NAT them) - FORWARD rules: restrict to RELATED,ESTABLISHED only — previously the broad ACCEPT rule passed un-NAT'd packets alongside masqueraded copies, causing duplicate SYNs, conntrack corruption, and RSTs - MASQUERADE/clear rules: match by interface not by source subnet (devices may use any source address, not just the ULA prefix) - VPN mode return traffic: explicitly restrict to wg+→end0 direction Add network_ipv6_gateway var (optional) to network role NM templates (ethernet, wifi, bridge) — injects a static IPv6 default route at metric 100 when set. Add rpi5 static route to FritzBox link-local so Pi keeps IPv6 after FritzBox RA is disabled. Force SSH to IPv4 for *.local hosts (AddressFamily inet) — prevents Ansible from hanging on mDNS returning multiple IPv6 addresses. Update gateway and pihole READMEs with two-step IPv6 setup process. Co-Authored-By: Claude.ai
2026-07-08Refactor network roleAhmed Abdelhalim1-4/+2
Remove static IPv6 support from network role — all hosts use SLAAC (method=auto). Simplifies NM templates, argument_specs, and resolved.conf. gateway sysctl accept_ra=2 is now unconditional when gateway_enabled. Co-authored-by: Claude.ai
2026-07-08Update pihole docsAhmed Abdelhalim1-7/+15
2026-07-07Enable ipv6 on the rpiAhmed Abdelhalim1-11/+10
2026-07-03Disable unstable ipv6 setup for nowAhmed Abdelhalim1-1/+5
2026-07-03Attempt to enable ipv6 on the network but doesn't work stable enoughAhmed Abdelhalim1-6/+2
2026-07-01Update the README for gateway and pihole setup with details about ipv6Ahmed Abdelhalim1-17/+50
2026-06-30Disable ipv6 by defaultsAhmed Abdelhalim1-1/+0
Since ipv6 seems to be causing a lot of issues with the new ISP
2026-06-18Implement support for conditional proxy (nginx or caddy)Ahmed Abdelhalim3-2/+28
2026-06-17Refactor pi roles to use .home.arpa subdomains for servicesAhmed Abdelhalim6-20/+50
2026-06-14Fix pihole nginx condition always evaluating true when disabledAhmed Abdelhalim1-1/+1
`false != ""` is True in Jinja2 — nginx config was created even when `pihole_by_nginx: false`. Use `| bool` filter to coerce correctly.
2026-06-14Update pihole docs and fix minor issue with handlersAhmed Abdelhalim2-2/+7
2026-06-12Fix handler order issue in releasing port 53 bindAhmed Abdelhalim2-6/+14
2026-06-12Fix pihole network overridesAhmed Abdelhalim1-1/+7
2026-03-04Remove duplicate fields from argument_specs filesAhmed Abdelhalim1-2/+0
2025-12-16Remove company from the roles metaAhmed Abdelhalim1-1/+0
2025-12-12Fix warning in ideompotence testing about pihole_install.stdout missingAhmed Abdelhalim2-4/+5
2025-12-11Add no_logs to semi-sensitive tasks to follow best practicesAhmed Abdelhalim1-0/+1
2025-11-10Fix running rpi configuration as root alwaysAhmed Abdelhalim2-0/+10
The dotfile/vim/password_store required to run as user with root permissions, that's why reverting these changes on rpi and resolving to using a more normal role (in pihole where it was broken)
2025-10-20Implement a better download/install for python, pihole and go roleAhmed Abdelhalim1-0/+7
2025-09-23Use static values for defaults instead of ansible varsAhmed Abdelhalim3-8/+13
The ansible vars fail on CI because the validate arguments task runs way before the setting of the variables, which causes the ansible undefined vars on CI to cause errors. This is a way better approach of having the static values as defaults and allowing setting the variables to ansible vars in the host/group vars
2025-09-20Migrate to the new loop syntaxAhmed Abdelhalim1-1/+1
2025-09-13Add pihole port configurations and integration with nginxAhmed Abdelhalim4-0/+43
2025-09-10Add recommended argument_specsAhmed Abdelhalim1-0/+2
2025-09-10Follow the ansible recommendation of using systemd_serviceAhmed Abdelhalim1-3/+3
2025-09-10Refactor role dependencies to be more module modularAhmed Abdelhalim2-4/+6
This modularity means that each role can be installed in a playbook by itself as long as the other roles exist around it. This also straps the ensure dependency packages exist in any of the roles tasks, they should be moved to their own roles and configured properly if needed.
2025-09-09Remove old pihole 5 related pathsAhmed Abdelhalim1-3/+0
2025-09-02Fix pihole_dhcp_lease_time configurationsAhmed Abdelhalim3-5/+5
2025-09-02Configure dhcp hosts in pihole roleAhmed Abdelhalim3-0/+7
2025-09-02Refactor the network fix for piholeAhmed Abdelhalim1-25/+4
2025-09-02Fix pihole and network manger DNS when VPN isn't activeAhmed Abdelhalim1-0/+26
2025-09-01Fix wireguard_gateway role being slowAhmed Abdelhalim2-8/+14
The pihole lookup DNS queries when the VPN connection is up was slow. One of the culprits was the quad9 servers were taking long time when using VPN The other issue was the previous routing tables that used to work with the fritzbox (with DHCP) which wasn't fully working was conflicting with the VPN route tables and causing loops and delays. Now most of the VPN queries are working fast but some requests are taking some time, probably due to the VPN trying to check/block ads and malware! Also minor fixing to the pre tasks and documentation
2025-08-31Update pihole role to function as dhcp for the networkAhmed Abdelhalim4-2/+36
2025-08-21Fix the instruction on setting up pihole on fritz!boxAhmed Abdelhalim1-0/+1
2025-08-19Fix meta strings quotingAhmed Abdelhalim1-7/+6
2025-08-19Ignore docker/podman specific failures in test/idempotent testAhmed Abdelhalim1-0/+9
2025-08-19Fix pihole install to work on raspberry and simplify on archAhmed Abdelhalim3-13/+38
2025-08-16Fix Pihole setup with systemd-resolvedAhmed Abdelhalim2-0/+18
2025-08-16Update pihole readmeAhmed Abdelhalim1-0/+14
2025-08-11Fix molecule test fail ansible_default_ipv4 is undefinedAhmed Abdelhalim1-0/+2
2025-08-11Add pihole role to configure raspberry piAhmed Abdelhalim7-0/+204