==== PiHole ====
Serveur DNS et DHCP dans le réseau filaire et WiFi.
Bouffe les DNS lookup des fournisseurs de publicité
Assez stable et il y a un restart chaque matin à 05:45 [[unraid#cronjob]]
=== upgrade ===
pihole -up
==== Config pour le réseau local ====
https://discourse.pi-hole.net/t/howto-using-pi-hole-as-lan-dns-server/533
Pour un docker sur unraid: /mnt/cache/cache_only/appdata/pihole/dnsmask.d/09-lan.conf
Pour le raspberry pi: /etc/dnsmask.d/09-lan.conf
addn-hosts=/etc/pihole/lan.list
Pour un docker sur unraid: /mnt/cache/cache_only/appdata/pihole/lan.list
Pour le raspberry pi: /etc/pihole/lan.list
192.168.1.111 patatemagique.biz
192.168.1.111 gallery.patatemagique.biz
192.168.1.111 unifi.patatemagique.biz
192.168.1.111 blog.patatemagique.biz
192.168.1.111 nextcloud.patatemagique.biz
192.168.1.111 heimdall.patatemagique.biz
192.168.1.111 tower.patatemagique.biz
192.168.1.111 grocy.patatemagique.biz
192.168.1.111 bw.patatemagique.biz
192.168.1.111 dokuwiki.patatemagique.biz
192.168.1.111 budget.patatemagique.biz
192.168.1.111 qbt.patatemagique.biz
==== DNS over HTTPS (Raspberry Pi) ====
https://docs.pi-hole.net/guides/dns-over-https/
=== Installing cloudflared ===
wget https://bin.equinox.io/c/VdrWdbjqyF/cloudflared-stable-linux-arm.tgz
tar -xvzf cloudflared-stable-linux-arm.tgz
sudo cp ./cloudflared /usr/local/bin
sudo chmod +x /usr/local/bin/cloudflared
cloudflared -v
=== Configuring cloudflared to run on startup ===
== Create a cloudflared user to run the daemon ==
sudo useradd -s /usr/sbin/nologin -r -M cloudflared
== Create a configuration file for cloudflared ==
Copying the following in to /etc/default/cloudflared. This file contains the command-line options that get passed to cloudflared on startup:
# Commandline args for cloudflared
CLOUDFLARED_OPTS=--port 5053 --upstream https://1.1.1.1/dns-query --upstream https://1.0.0.1/dns-query
Update the permissions for the configuration file and cloudflared binary to allow access for the cloudflared user:
sudo chown cloudflared:cloudflared /etc/default/cloudflared
sudo chown cloudflared:cloudflared /usr/local/bin/cloudflared
Then create the systemd script by copying the following in to /etc/systemd/system/cloudflared.service. This will control the running of the service and allow it to run on startup:
[Unit]
Description=cloudflared DNS over HTTPS proxy
After=syslog.target network-online.target
[Service]
Type=simple
User=cloudflared
EnvironmentFile=/etc/default/cloudflared
ExecStart=/usr/local/bin/cloudflared proxy-dns $CLOUDFLARED_OPTS
Restart=on-failure
RestartSec=10
KillMode=process
[Install]
WantedBy=multi-user.target
Enable the systemd service to run on startup, then start the service and check its status:
sudo systemctl enable cloudflared
sudo systemctl start cloudflared
sudo systemctl status cloudflared
== Test ==
Now test that it is working! Run the following dig command, a response should be returned similar to the one below:
dig @127.0.0.1 -p 5053 google.com
; <<>> DiG 9.10.3-P4-Ubuntu <<>> @127.0.0.1 -p 5053 google.com
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 65181
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1536
;; QUESTION SECTION:
;google.com. IN A
;; ANSWER SECTION:
google.com. 299 IN A 243.65.127.221
;; Query time: 3 msec
;; SERVER: 127.0.0.1#5053(127.0.0.1)
;; MSG SIZE rcvd: 65
== Configuring Pi-hole ==
Finally, configure Pi-hole to use the local cloudflared service as the upstream DNS server:
Custom 1 (IPv4): 127.0.0.1#5053