Best way to handle it is to just reconfigure your router to hand out the pihole dns server to all the clients on your network. That way it's automatic when at home, and doesn't override anything when you're away.
Best way to handle it is to just reconfigure your router to hand out the pihole dns server to all the clients on your network. That way it's automatic when at home, and doesn't override anything when you're away.
Another hack to consider is running pi-hole in a VM or container on the laptop itself, and have it act as a filtering cache for a more public resolver. Though this imparts an administrative load, you no longer have a single pi-hole so either need to configure it separately or arrange for it to be able to sync with config on your main instance.
Both these arrangements will have trouble if you find yourself on a network that blocks DNS requests to anything other than its local resolvers (though for the pi-hole-on-laptop you can always reconfigure pi-hole to look at the local resolvers if/when needed), so the VPN option is better where available. If you have no static IP at your base of operations, there is always the option of a cheap VPS somewhere to be the VPN endpoint – essentially my first paragraph but your “port knocking” is connecting to the VPN, with pi-hole either on that machine or a machine also connected to the same VPN to get around its lack of fixed public address. Though back to the adversarial local network problem: if the network blocks DNS queries to non-local resolvers it is not unlikely to try block VPNs too.
You can configure the default DNS for devices when they connect to tailscale. This way, pi hole is opt in for users who want to set up tailscale.
Disclaimer: I haven't tried this myself since I have Mullvad ad blocking setup and I'm lazy
But as others mention tailscale also works