From 4f82520e0e00ae6418dcbfefcda08870e39c2d0b Mon Sep 17 00:00:00 2001 From: reachableceo Date: Thu, 6 Aug 2026 13:11:38 -0500 Subject: [PATCH] fix(netinfra): kill IPv6 on DNS nodes to stop Pi-hole flapping Root cause of Uptime Kuma DNS up/down alerts: Pi-hole's upstream config included Google IPv6 DNS (2001:4860:4860::8888), but netinfra-01 has no IPv6 internet route. Every forwarded query to the IPv6 upstream failed with "Network unreachable", causing intermittent DNS resolution failures every ~8 seconds. Fix applied to both netinfra-01 and netinfra-02: - Pi-hole upstream set to 8.8.8.8 only (IPv4); removed 192.168.3.16 (retired netboot) and 2001:4860:4860::8888 (IPv6 Google DNS) - IPv6 disabled at kernel level (/etc/sysctl.d/99-disable-ipv6.conf) - knel.net authoritative resolution unchanged (Technitium via revServers) Verified: zero IPv6 warnings, zero connection errors, DNS resolving cleanly from all paths after fix. [#376] --- netinfra/pihole/README.md | 8 ++++++++ netinfra/pihole/docker-compose.yml | 1 + 2 files changed, 9 insertions(+) diff --git a/netinfra/pihole/README.md b/netinfra/pihole/README.md index 78b7b44..e49a749 100644 --- a/netinfra/pihole/README.md +++ b/netinfra/pihole/README.md @@ -34,6 +34,14 @@ docker compose up -d Files are deployed to `/home/localuser/services/pihole/` on each node. Volumes (`./etc-pihole`, `./etc-dnsmasq.d`) hold the persistent state. +## IPv6 disabled + +Both netinfra nodes run **IPv4-only**. IPv6 is disabled at the kernel level +(`/etc/sysctl.d/99-disable-ipv6.conf`) because netinfra-01 has no IPv6 internet +route, and Pi-hole's default IPv6 upstream (Google `2001:4860:4860::8888`) was +causing continuous "Network unreachable" errors + intermittent DNS failures +detected by Uptime Kuma. The upstream is now `8.8.8.8` (IPv4 only). + ## Verify ```bash diff --git a/netinfra/pihole/docker-compose.yml b/netinfra/pihole/docker-compose.yml index 060860c..6faf0a2 100644 --- a/netinfra/pihole/docker-compose.yml +++ b/netinfra/pihole/docker-compose.yml @@ -16,6 +16,7 @@ services: TZ: 'America/Chicago' FTLCONF_webserver_api_password: '${PIHOLE_WEB_PASSWORD}' FTLCONF_dns_listeningMode: 'all' + FTLCONF_dns_upstreams: '["8.8.8.8"]' volumes: - './etc-pihole:/etc/pihole' - './etc-dnsmasq.d:/etc/dnsmasq.d'