driftfile /var/lib/ntp/ntp.drift leapfile /usr/share/zoneinfo/leap-seconds.list # Redundant upstream time sources: pfv-netinfra-01/02 (Technitium/Pi-hole hosts # also serving NTP). IPs are used (not hostnames) because the knel.net name for # these hosts resolves to a Tailscale CGNAT address, not the LAN address, and # because NTP must come up before DNS is available. iburst speeds initial sync. {% for srv in ntp_servers %} server {{ srv }} iburst {% endfor %} # Hardened client: sync from the configured servers but never serve time to # anyone else. Note: `interface listen 127.0.0.1` must NOT be used here — it # binds ntpd to loopback, making outbound queries carry a 127.0.0.1 source # address that upstream servers cannot reply to (symptoms: peers stuck in # .INIT. with reach 0). Use restrict rules to control access instead. restrict default ignore restrict 127.0.0.1 restrict ::1 {% for srv in ntp_servers %} restrict {{ srv }} nomodify notrap nopeer {% endfor %}