fix(netinfra): disable Pi-hole rate-limiting causing Uptime Kuma flapping
Root cause of intermittent DNS up/down alerts: Pi-hole's default
rate-limit (1000 queries/60s per client) was throttling Uptime Kuma
on the Cloudron VPS (tsys-cloudron, 100.107.35.78). Uptime Kuma sends
high-volume DNS queries to monitor dozens of hosts; when it exceeded
the limit, Pi-hole responded REFUSED, which Uptime Kuma detected as
DNS being down. This happened every 1-2 minutes.
Evidence: 40 rate-limiting events against 100.107.35.78 in recent
netinfra-01 Pi-hole logs. Also 10.53.0.1 (Docker bridge gateway) hit
4852 queries in a single 60s window.
Fix: Set dns.rateLimit.count=0 and dns.rateLimit.interval=0 on both
nodes (private tailnet, no DNS amplification risk). Also persisted in
docker-compose.yml via FTLCONF env vars.
Combined with prior IPv6 fix (4f82520), this resolves all known causes
of DNS flapping.
[#376]
This commit is contained in:
@@ -34,14 +34,24 @@ docker compose up -d
|
|||||||
Files are deployed to `/home/localuser/services/pihole/` on each node. Volumes
|
Files are deployed to `/home/localuser/services/pihole/` on each node. Volumes
|
||||||
(`./etc-pihole`, `./etc-dnsmasq.d`) hold the persistent state.
|
(`./etc-pihole`, `./etc-dnsmasq.d`) hold the persistent state.
|
||||||
|
|
||||||
## IPv6 disabled
|
## IPv6 disabled + Rate-limiting disabled
|
||||||
|
|
||||||
|
### IPv6
|
||||||
Both netinfra nodes run **IPv4-only**. IPv6 is disabled at the kernel level
|
Both netinfra nodes run **IPv4-only**. IPv6 is disabled at the kernel level
|
||||||
(`/etc/sysctl.d/99-disable-ipv6.conf`) because netinfra-01 has no IPv6 internet
|
(`/etc/sysctl.d/99-disable-ipv6.conf`) because netinfra-01 has no IPv6 internet
|
||||||
route, and Pi-hole's default IPv6 upstream (Google `2001:4860:4860::8888`) was
|
route, and Pi-hole's default IPv6 upstream (Google `2001:4860:4860::8888`) was
|
||||||
causing continuous "Network unreachable" errors + intermittent DNS failures
|
causing continuous "Network unreachable" errors + intermittent DNS failures
|
||||||
detected by Uptime Kuma. The upstream is now `8.8.8.8` (IPv4 only).
|
detected by Uptime Kuma. The upstream is now `8.8.8.8` (IPv4 only).
|
||||||
|
|
||||||
|
### Rate-limiting
|
||||||
|
Pi-hole's default rate-limit (1000 queries / 60 seconds per client) was
|
||||||
|
**the root cause of Uptime Kuma DNS flapping**. Uptime Kuma runs on the
|
||||||
|
Cloudron VPS (`tsys-cloudron`, `100.107.35.78`) and sends high-volume DNS
|
||||||
|
queries to monitor dozens of hosts. When it exceeded 1000 queries/60s,
|
||||||
|
Pi-hole responded with REFUSED, which Uptime Kuma detected as DNS being
|
||||||
|
down. Rate-limiting is now disabled (`count=0, interval=0`) since this is a
|
||||||
|
private tailnet with no risk of DNS amplification attacks.
|
||||||
|
|
||||||
## Verify
|
## Verify
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
|
|||||||
@@ -16,6 +16,11 @@ services:
|
|||||||
TZ: 'America/Chicago'
|
TZ: 'America/Chicago'
|
||||||
FTLCONF_webserver_api_password: '${PIHOLE_WEB_PASSWORD}'
|
FTLCONF_webserver_api_password: '${PIHOLE_WEB_PASSWORD}'
|
||||||
FTLCONF_dns_listeningMode: 'all'
|
FTLCONF_dns_listeningMode: 'all'
|
||||||
|
# Rate-limiting disabled (count=0). Uptime Kuma on Cloudron VPS sends
|
||||||
|
# high-volume DNS queries for monitoring; default 1000/60s limit was
|
||||||
|
# causing intermittent REFUSED responses → Uptime Kuma flapping.
|
||||||
|
FTLCONF_dns_rateLimit_count: '0'
|
||||||
|
FTLCONF_dns_rateLimit_interval: '0'
|
||||||
FTLCONF_dns_upstreams: '["8.8.8.8"]'
|
FTLCONF_dns_upstreams: '["8.8.8.8"]'
|
||||||
volumes:
|
volumes:
|
||||||
- './etc-pihole:/etc/pihole'
|
- './etc-pihole:/etc/pihole'
|
||||||
|
|||||||
Reference in New Issue
Block a user