WireHole: Set up Pihole, WireGuard, and Unbound instantly
github.com
github.com
I found personally that there are several aspects of this automation that needs tweaking.
* If you need ipv6 support this config needs to be overhauled.
* Wireguard config should have ipv6 addresses set to avoid potential leakages (even if ipv6 is disabled).
* This setup would benefit from some ddns mechanism as most people do not have static ip setups.
* Firefox is beginning to have https only modes in which case maybe I would like to adjust lighthttp to work with that.
The list goes on.
* Also the wireguard config
* I will look into how I can allow the user to provide that information as the IP is pulled within the doctor container
* Noted on Firefox
Thanks for the detailed comment
EDIT:
Just provided instructions in the repo for how to configure DDNS: https://github.com/IAmStoxe/wirehole#configuring-for-dynamic...
Also modifed it so only the port 51820 is exposed preventing any unintentional exposure.
Will check it out
If you care to please elaborate as to why I would be better off piping to bash rather than installing per the documentation? I am honestly interested in your take.
First is that trusting my suggestion is no different than trusting the instructions in your repo. Both can equally harbor nefarious things. So, the question is: do I trust Docker's script over someone that was just on the front page of HN? Probably.
To address the technical side - there are a number of things that can be improved from a security point of view in your compose file:
1) Restrict any new privs. security_opt: - no-new-privileges
2) Drop all privs then selectively add. cap_drop: - ALL cap_add: - NETADMIN
3) Limit CPU and memory. deploy: resources: limits: cpus: '0.50' memory: 50M reservations: cpus: '0.25' memory: 20M
4) Change the running users - looks like all the containers are running as root, which is no different from the system user.
There are others, but.. Just because the container isn't explicitly 'privileged' doesn't mean it's operationally safe.
I would have never gotten into email self-hosting if someone hadn't done the hard work of creating an all-in-one solution, because it would have taken more time than I would be willing to invest.
I have seen pihole alone go down because one of the gravity sources goes down or because of a dhcp misconfiguration.
It involves setting up a VPN and that by itself needs some monitoring/debugging to understand what to do when things necessarily go wrong, especially in regards to routing, setting up splitVPNs etc..
Speaking as someone who has all of this setup manually, there is a bunch of fine tuning and fiddling that makes a set and forget not particularly ideal. On my setup I have to work with a custom cloudflare script to enable DNS records to update. I need a custom lighthttpd config to enable https with letsencrypt. My setup uses DNSCryptProxy instead of unbound (to enable ESNI + DoH for Firefox through my pihole) and as such caching needs to be disabled.... Just a bunch of random tweaks here and there that need to be thought out.
Take an example of simply adding multiple other peers to wireguard. Something that people would reasonably want to do with a pihole/VPN. There are no instructions how to do it with this.
EDIT 2:
Just provided instructions in the repo for how to configure DDNS: https://github.com/IAmStoxe/wirehole#configuring-for-dynamic...
Also modified it so only the port 51820 is exposed preventing any unintentional exposure.
> Either specify both ports (HOST:CONTAINER), or just the container port (an ephemeral host port is chosen).
It sounds like you get a random publicly accessible port unless you specify a non publicly accessible IP. I'm not sure whether having a DNS server listening on a non standard port would be an issue though.
but nonetheless you're ingress rules in your cloud provider will not allow anything but that's single port so it's not really a big deal provided you close everything else off in your firewall.
I will make an update to see how I can work around this
That's all that's required for a DNS amplification attack. :)
FD: My employer maintains Algo.
I originally wanted to use that for "baremetal" type deployments, but ultimately was having trouble with the systemd-resolve service. Probably my own ignorance, but ultimately felt I could make a more secure alternative with docker :)
I wanted to run a pihole for years but never got around to building it into my dns infrastructure. Nextdns, on the other hand, was a quick afternoon setup ...
50ms latency vs <1ms for unbound cached entries
If you configure NextDNS on a router, your router will perform the exact same caching pi-hole is doing, so it will make no difference performance-wise.
https://medium.com/@devinjaystokes/automating-the-deployment...
Why the extra unbound DNS server? I assume PiHole is using it, but why not just point PiHole at the final server?
You can set up DNS records
I have similar setup and custom unbound docker container based on distroless.
One suggestion: In unbound use more privacy-centric dns providers. https://www.privacytools.io/providers/dns/
I will also update the README with a guide on choosing other providers.
https://github.com/IAmStoxe/wirehole#configuring-for-dynamic...
their router's UI is built on top of OpenWrt, so you can always fall back to OpenWrt GUI as well for configuring more advanced setups.
variable "availability_domain_number" {
default = 2
}
it works now, for someone not very technical for average HN user, this is awesome. How do I add more peers ?https://github.com/IAmStoxe/wirehole/blob/master/docker-comp...