Root cause of Uptime Kuma DNS up/down alerts: Pi-hole's upstream config included Google IPv6 DNS (2001:4860:4860::8888), but netinfra-01 has no IPv6 internet route. Every forwarded query to the IPv6 upstream failed with "Network unreachable", causing intermittent DNS resolution failures every ~8 seconds. Fix applied to both netinfra-01 and netinfra-02: - Pi-hole upstream set to 8.8.8.8 only (IPv4); removed 192.168.3.16 (retired netboot) and 2001:4860:4860::8888 (IPv6 Google DNS) - IPv6 disabled at kernel level (/etc/sysctl.d/99-disable-ipv6.conf) - knel.net authoritative resolution unchanged (Technitium via revServers) Verified: zero IPv6 warnings, zero connection errors, DNS resolving cleanly from all paths after fix. [#376]
52 lines
2.1 KiB
Markdown
52 lines
2.1 KiB
Markdown
# netinfra/pihole/ — Pi-hole recursive DNS (pfv-netinfra-01/02)
|
|
|
|
> **Redmine:** [#376](https://projects.knownelement.com/issues/376) (up/down alerts + commit hardening) · [#357](https://projects.knownelement.com/issues/357) (cluster build, closed)
|
|
|
|
Pi-hole v6 runs as the recursive resolver on port 53 of both DNS nodes.
|
|
Technitium (`tsys-dns`) runs as the authoritative server on port 5300; the two
|
|
share the `dnsnet` Docker network so Pi-hole can conditional-forward `knel.net`
|
|
zones to Technitium.
|
|
|
|
## Hardening (defense-in-depth against gravity.db corruption)
|
|
|
|
The operator hit a production outage when Pi-hole's `/dev/shm` was too small,
|
|
corrupting `gravity.db`. The live config on both nodes now includes:
|
|
|
|
- **`shm_size: 1024M`** — fixes the root cause (default 64M was too small).
|
|
- **`gravity-validate.sh`** — entrypoint that checks the SQLite header of
|
|
`gravity.db` before start; auto-moves a corrupt/empty DB aside so Pi-hole
|
|
can regenerate it cleanly.
|
|
- **Healthcheck** — `dig +norecurse @127.0.0.1 pi.hole` + gravity.db non-empty;
|
|
fails the container if DNS or the DB is broken.
|
|
- **`autoheal`** sidecar — restarts any container labeled `autoheal=true` that
|
|
goes unhealthy.
|
|
|
|
## Deploy
|
|
|
|
The compose reads the web UI password from a gitignored `.env`:
|
|
|
|
```bash
|
|
cd netinfra/pihole/
|
|
cp .env.example .env # then edit .env and set PIHOLE_WEB_PASSWORD
|
|
docker compose up -d
|
|
```
|
|
|
|
Files are deployed to `/home/localuser/services/pihole/` on each node. Volumes
|
|
(`./etc-pihole`, `./etc-dnsmasq.d`) hold the persistent state.
|
|
|
|
## IPv6 disabled
|
|
|
|
Both netinfra nodes run **IPv4-only**. IPv6 is disabled at the kernel level
|
|
(`/etc/sysctl.d/99-disable-ipv6.conf`) because netinfra-01 has no IPv6 internet
|
|
route, and Pi-hole's default IPv6 upstream (Google `2001:4860:4860::8888`) was
|
|
causing continuous "Network unreachable" errors + intermittent DNS failures
|
|
detected by Uptime Kuma. The upstream is now `8.8.8.8` (IPv4 only).
|
|
|
|
## Verify
|
|
|
|
```bash
|
|
dig @127.0.0.1 +short google.com # recursive
|
|
dig @127.0.0.1 +short git.knownelement.com # knel.net via Technitium forward
|
|
docker inspect pihole --format '{{.State.Health.Status}}'
|
|
```
|