summaryrefslogtreecommitdiffstats
path: root/roles
AgeCommit message (Collapse)AuthorFilesLines
2026-07-09Fix IPv6 first-request failure caused by ICMPv6 RedirectsAhmed Abdelhalim2-12/+52
Root cause: Pi, the ISP router (FritzBox), and LAN clients share the same L2 segment. When Pi forwards a client's IPv6 packet to an external GUA destination, the Linux kernel detects that the ISP router is a "better" next-hop on the same link and sends an ICMPv6 Redirect (type 137) to the client. The client obeys the redirect and sends its first SYN to the ISP router directly — Pi never forwards the original packet. The ISP router applies per-device content filtering to the unmasqueraded client GUA and issues a RST. This produced the symptom of the first IPv6 request failing with "Connection reset by peer" every ~30-60 seconds (matching the FritzBox RA interval, after which clients re-resolve their default gateway). Diagnosis method: tcpdump with MAC addresses (-e flag) on Pi's end0 caught the ICMPv6 Redirect being sent immediately after the first SYN arrived. Inserting a DROP rule for icmpv6-type redirect at position 1 in ip6tables OUTPUT confirmed the fix — 0 failures across extended testing. Fix: - Drop ICMPv6 Redirect (type 137) in ip6tables OUTPUT as the first rule, before the ACCEPT rule, in both direct and VPN modes - Flush ip6tables OUTPUT chain on clear_rules() instead of per-rule -D deletion, which was fragile and left stale rules accumulating across mode switches (previously caused duplicate/conflicting OUTPUT rules) - Flush ip6tables nat POSTROUTING table instead of per-rule -D deletion for the same reason Also documents the ICMPv6 Redirect issue and IPv6 masquerade rationale in roles/gateway/README.md for future reference. Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
2026-07-09Fix IPv6 direct mode routing for LAN clientsAhmed Abdelhalim1-2/+2
- Remove static network_ipv6_gateway from LAN hosts so they pick up Pi's radvd RA (pref high) instead of FritzBox (pref low) - Add missing ip6tables FORWARD ACCEPT rule for new connections in direct mode (only ESTABLISHED was present, blocking new flows) - Flush ip6tables nat POSTROUTING table on clear instead of fragile per-rule -D deletion to prevent stale rule accumulation
2026-07-08Route IPv6 through WireGuard VPN via radvd and static gatewayAhmed Abdelhalim7-24/+55
Add radvd to gateway role to advertise Pi as high-preference IPv6 default router using the stable ULA prefix (fd1e:.../64). With FritzBox also sending RAs, devices end up with ECMP between Pi and FritzBox. To solve this, add network_ipv6_gateway (Pi's link-local) as a static route with metric 100 to all managed hosts — beats RA metric 425, ensuring all IPv6 default traffic goes through Pi. Fix IPv6 MASQUERADE in gateway-apply-rules: - Direct mode: add MASQUERADE on end0 (LAN devices use ULA source addresses not known to FritzBox, so Pi must NAT them) - FORWARD rules: restrict to RELATED,ESTABLISHED only — previously the broad ACCEPT rule passed un-NAT'd packets alongside masqueraded copies, causing duplicate SYNs, conntrack corruption, and RSTs - MASQUERADE/clear rules: match by interface not by source subnet (devices may use any source address, not just the ULA prefix) - VPN mode return traffic: explicitly restrict to wg+→end0 direction Add network_ipv6_gateway var (optional) to network role NM templates (ethernet, wifi, bridge) — injects a static IPv6 default route at metric 100 when set. Add rpi5 static route to FritzBox link-local so Pi keeps IPv6 after FritzBox RA is disabled. Force SSH to IPv4 for *.local hosts (AddressFamily inet) — prevents Ansible from hanging on mDNS returning multiple IPv6 addresses. Update gateway and pihole READMEs with two-step IPv6 setup process. Co-Authored-By: Claude.ai
2026-07-08Fix bridge network treated as new deviceAhmed Abdelhalim1-1/+1
2026-07-08Refactor network roleAhmed Abdelhalim8-53/+7
Remove static IPv6 support from network role — all hosts use SLAAC (method=auto). Simplifies NM templates, argument_specs, and resolved.conf. gateway sysctl accept_ra=2 is now unconditional when gateway_enabled. Co-authored-by: Claude.ai
2026-07-08Implement a working ipv6 on gatewayAhmed Abdelhalim4-3/+58
2026-07-08Fix install proxmoxer using pipAhmed Abdelhalim2-5/+11
Using mise or python role broke on other machines so went with the simplest solution for now, it's safe to break the system packages for python as this is not used internally in other ways Also proxmoxer 2+ is needed to work with the proxmox module
2026-07-08Update pihole docsAhmed Abdelhalim1-7/+15
2026-07-08Revert 54ab1be commit change on ipv6Ahmed Abdelhalim2-2/+2
2026-07-08Revert 524d62e changes on gateway roleAhmed Abdelhalim4-73/+5
2026-07-07Add cgit role with testing of molecule serviceAhmed Abdelhalim7-0/+155
2026-07-07Fix the proxmox_template linting issueAhmed Abdelhalim1-3/+6
2026-07-07Remove unneeded GSSAPIAuthenticationAhmed Abdelhalim1-1/+0
2026-07-07Refactor mise not to use package managerAhmed Abdelhalim4-34/+22
2026-07-07Enable ipv6 on the rpiAhmed Abdelhalim2-12/+11
2026-07-06Fix starting the created containerAhmed Abdelhalim1-0/+1
2026-07-06Fix network setup on pveAhmed Abdelhalim5-12/+13
2026-07-06Fix pve network setupAhmed Abdelhalim12-115/+42
2026-07-06Use conventional storage nameAhmed Abdelhalim3-3/+3
2026-07-04Add pve-lxc role to create containersAhmed Abdelhalim4-0/+111
2026-07-04Add notes about notest tagsAhmed Abdelhalim3-2/+10
2026-07-04Ignore failing tests in containersAhmed Abdelhalim1-0/+3
2026-07-03Refactor pve roles to create storage separatelyAhmed Abdelhalim8-23/+63
2026-07-03Refactor pve and add pve-network role to configure the pve networkAhmed Abdelhalim10-12/+162
2026-07-03Disable unstable ipv6 setup for nowAhmed Abdelhalim1-1/+5
2026-07-03Attempt to enable ipv6 on the network but doesn't work stable enoughAhmed Abdelhalim5-12/+76
2026-07-03Update ethtool to handle laptop lid suspend issuesAhmed Abdelhalim6-2/+43
When using WoL with laptops (ex Lenovo) closing the lid suspends the laptop and breaks WoL, this is to allow configuring the lid behavior
2026-07-03Add ethtool and configure interface for pveAhmed Abdelhalim1-0/+59
2026-07-03Use permanent MAC addresses for ehternet/LAN connectionsAhmed Abdelhalim1-0/+1
This prevents FRITZ!Box from messing up the setup when seeing a new mac address on the LAN connections (causing it to block the pi or not able to wake the pve)
2026-07-02Add role to install ethtool (Wake-on-LAN)Ahmed Abdelhalim6-0/+67
2026-07-01Update the README for gateway and pihole setup with details about ipv6Ahmed Abdelhalim2-17/+67
2026-07-01Add proxmoxer dependency roleAhmed Abdelhalim3-0/+23
2026-07-01Allow router advertisement on gateway interfacesAhmed Abdelhalim1-0/+3
2026-06-30Fix hyprland role and documentationAhmed Abdelhalim1-14/+19
2026-06-30Disable ipv6 by defaultsAhmed Abdelhalim3-3/+2
Since ipv6 seems to be causing a lot of issues with the new ISP
2026-06-27Add restic role w/testingAhmed Abdelhalim4-0/+40
2026-06-27Refactor garage role for better stability and defaultsAhmed Abdelhalim4-53/+81
2026-06-26Merge configuration tasks using loops and update defaultsAhmed Abdelhalim3-37/+20
2026-06-24Add garage health check before provisioning keysAhmed Abdelhalim2-3/+5
2026-06-24Fix hex defaults for garageAhmed Abdelhalim1-3/+3
2026-06-23Fix testingAhmed Abdelhalim1-2/+4
The timezone module was reading back the Etc/GMT instead of GMT, this fixes the issue and avoid unnecessary code that needs to handle different distro quirks (debian) Fix grafana testing to use the URL
2026-06-23Reorder ssh keygen to avoid issues of starting ssh before keys existingAhmed Abdelhalim1-15/+15
2026-06-23Update backup path to /backupAhmed Abdelhalim3-4/+4
The /mnt/* paths were ignored from the default grafana disk monitoring so moving the backup dir to a separate directory that follows the linux practices solves the issue and follows better practice
2026-06-22Refactor installing grafana dashboards using URL onlyAhmed Abdelhalim5-12/+22
Refactor prometheus extra scraping jobs
2026-06-22Add garage to rpi to use as s3-compatible backend for backupsAhmed Abdelhalim8-0/+239
2026-06-22Add readme on using backup role and fix testingAhmed Abdelhalim2-1/+76
2026-06-22Use more stable approach for testing devices and fix linting issuesAhmed Abdelhalim1-3/+3
This approach uses losetup to query the devices instead of flaky unstable cache!
2026-06-22Add backup role for mounting a backup device on a rpi machineAhmed Abdelhalim4-0/+53
2026-06-22Rename proxmox-ve role to pveAhmed Abdelhalim6-11/+11
2026-06-19Ignore the failing task from the test as it is irrelevant to real PVEAhmed Abdelhalim1-0/+2