Setting up a secondary Pi-Hole on my home network
dzombak.com
dzombak.com
Finally, since 32GB is a relatively small disk, I installed a daily cron job to clean the apt cache[0]:
Which is a Debian package to run `apt-get clean` that the author of the blog created.Here you go, no package required:
# printf 'apt-get clean\n\n' > /etc/cron.daily/daily-apt-clean && chmod +x /etc/cron.daily/daily-apt-clean`
[0] - https://github.com/cdzombak/apt-daily-cleanWonder how much of that is social. E.g. processes and function calls are effectively equivalent: command line arguments are effectively positional or named parameters, while environmental variables are equivalent to dynamic binding - a powerful technique all but excised from programming languages, except for the Lisp family. And yes, this makes the shell a REPL. The main difference between a program and a function then feels like the relationship with programmers: a program is expected to be a named thing to distribute and sign with your name; a function is more ephemeral. But does this difference warrant having each in a separate, distinct, complex layer?
Common... He's talking about a home network.
I also have one of my Pi set up as a DNS server (running unbound directly not PiHole though) and this thing is rock stable solid.
We're talking about Linux here. I've had a Linux server reach years of uptime (kids: don't try this at home, it's not secure but it was a test of Linux's stability).
Redundancy is great though but I really wouldn't lose sleep over it. If anything you can "dd" the Pi's SD card to another one and just replace the Pi (or the SD card) should anything go wrong.
If my Docker setup goes down (and it did the other day with Docker's network bug on v25) I have no DNS available.
And having a firewall rule capturing ALL DNS traffic and redirecting it to this endpoint doesn't make it easy to quickly recover from.
So I like this idea.
All machines get the
Works great, but not free over a certain number of requests.
Can’t speak to its privacy levels though - as with anything, assume records will be supplied to authorities when required.
But overall it has been great - provides network wide DNS filtering and has clients for mobile and desktop devices!
With a good dashboard, reporting and setting too.
Cost is minimal and I’ve been happy to pay for it.
A local PiHole is probably faster, but NDNS is set and forget.
The product seems to be pretty stagnant as well, whereas ControlD has been improving on a regular clip. I _think_ it's more expensive than NextDNS, but I don't remember it being extremely so. (Not so expensive that I know the price offhand, after all.)
To me, it seems like the founders are not focused on customer support or making the NextDNS ecosystem better.
Works great. Rarely need to think of it. I recommend looking up the recommended whitelist and adding anything there that looks relevant to you.
Last downtime was a month ago when external circumstances forced me to move both servers. Yhe RPi, lacking a real time clock or its neighbor to bootstrap DNS, couldn't get the current time ir dns, and thus had out-of-date certificates for dnssec... Solution was to add the direct ip address to an NTP server temporarily to the list of websites to use for NTP.
macvlan is cool in theory. it lets you broadcast a "real" MAC address through your container's veth. this allows it to get a real IP from your router. you can even use VLAN trunking to assign the MAC to a VLAN on your physical NIC.
that said, i only learned about it to discuss it in my course. my dockerized Adguard Home instance uses host-mode networking since that binds the physical ifaces into the container and is just as fast as any other networked process. it's also WAY WAY WAY easier than trying to get pi-hole working in bridge mode, I've found.
(I used to use pi.hole for a long time but AdGuard Home is nicer and updates itself automatically out of the box.)
macvlan can help get you slightly better networking performance by avoiding internal SNAT but it's marginal at best in most cases compared to the work required to maintain macvlan/ipvlan containers. it's also, as you pointed out, not very well documented (because it's not used very often).
This feature along with storage drivers are relics from a time when Docker was poised to own the container orchestration space with Swarm. All of the third-party contributions to Docker Engine basically died once Kubernetes reached critical mass, which was somewhere between 2018 and 2020. Weaveworks was probably the only company with an actively maintained networking driver for Docker Engine, but they are gone now :(
Negligible on anything what can run Docker ATM.
The main benefit is what you really get the real MAC which:
totally skips Docker NAT shenanigans
provide a single MAC/IP on any node, which is useful for the single instance/multiple nodes/ shared storage situations
I suppose if you have a house full of Samsung / Huawei / etc. IoTs that you really need to keep connected to the Internet for whatever reason, I could sort of see it, but I don't and I genuinely can't figure out other use cases for it. I'm far from a networking whiz though. Am I missing something?
It's also useful for clients where I can't install client-side adblocking, ie smart TVs (which try to phone home a _ton_ of advertising/analytics information). I also don't use client-side adblock on my work laptop (can't install unapproved extensions) nor my iPhone, so Pi-Hole still lets me browse ad-free on those.
None of this bothered me until the time I tried to ssh into one of my local boxes, was and redirected to the bogus server, which prompted me for my password, which I stupidly provided out of habit.
So now some random server on the open Internet has collected the hostname, username, and password for my local machine. I reported this to the company IT department and their response was a shrug.
I set up my Pi-Hole on a Raspberry Pi Zero W. I have some brief notes here on my setup: https://www.thelis.org/blog/pi-hole. It works well.
Thanks for the info. I thought this was possible and it was the sole reason why I considered setting one up. Now I procrastinated on that project long enough to learn I can cancel it.
YouTuber makes more money on average when a YouTube Premium user watches their video than what they would get from the ad-view if the person wasn't on Premium.
All in all it's reasonable IMHO. I might purchase it some time. The only issue is that this of course doesn't remove sponsorships baked into the videos, which annoy me just the same as the YT ads. So, I would still need Sponsorblock.
Instead I sideloaded SmartTubeNext on my Fire TV and just live with the banner ads.
Imho the risk/consequences of a downtime don't justify having some hardware draining power. If all goes down ansible will have provisioned a new pi in no time.
Nevertheless i applaud the effort and am happy to have learned some things from the article
The spec only says the dns IPs should be specified in preference order. Nothing says to treat it as primary and failover.
I've got her on an exclusion list because she just cares about being able to click on Google ads also known as "search results".
But I might not have added her on the backup Pihole now that I think of it...
It’s an approach I assumed would work when I did my first setup, but since there’s really no such thing as primary and secondary (or tertiary) resolver, I quickly realized it did not work consistently on most devices.
Turns out the Pi-Hole Raspberry Pi had borked and wasn't answering at all, my computer was waiting for the primary DNS _every_time_ for multiple seconds before trying the secondary one.
What it should've done (IMO) is query both and pick the fastest.
Swapped to NextDNS and haven't looked back, I set it on my router and mobile devices once and that's it.
If you can guarantee that the PiHole will always be fastest, it should be OK. But I'd be curious to see how you'd go about guaranteeing that.
Is there a simple way to have a failover/fallback DNS configured rather than requiring two Pi's? On failure, I'd like my DNS to just fallback to my routers default DNS - yes I'd get ad's but I think that's acceptable.
A) Each client has one DNS server: the router's local IP address. The router runs dnsmasq or whatever to proxy the DNS requests.
B) Each client has one or more DNS servers, with the router's IP address not listed, or listed last.
If you set up B, I think most operating systems will usually use the servers in order, i.e. only fall back to the second (ISP) server if the primary (pi-hole) doesn't respond.
DNS Server 1 = Pi-Hole
DNS Server 2 = ISP DNS Service, OpenDNS, your router whatever
when pi-hole blocks the ad's DNS query, macOS will treat that as a DNS failure and use DNS Server 2 as a fallback. Resulting in the ad being shown.
Doing (A) was my first attempt and at least using a Ubiquiti router, if Pi-hole blocked a DNS query it would always fallback to the secondary DNS server. In my environment, the only way I was able to get pi-hole to work consistently was to set the pi-hole server as the only DNS server in the DHCP server.
My experience with OSX and Pi-Hole doesn't match your experience. There's a difference between appearing to be in a failure mode (i.e. timing out) and returning blocked (null/0.0.0.0) results.
I did go and test this now, and agree with you. On macOS I set my primary DNS to pi-hole and secondary to 8.8.8.8. running dig on api.segment.io (blocked on pi-hole by default), it resolved to 0.0.0.0 via pi-hole and did not try 8.8.8.8 on any attempt. So my earlier comment is incorrect above and setting a secondary DNS server as a back-up may work.
For the record I was assigning these DNS server IPs via docker compose. So perhaps that makes a difference.
In my mikrotik device I do have a small script to replace my DNS entry with Cloudflare in case it becomes unresponsive (and then back again once it's up). That is not very transparent though and devices will get errors until the switch happens.
What’s a 60 second side quest for us is a “wifi’s down” for them. (Any outage at my house is reported as a WiFi problem.)
in fact I think this is just prompted me to do that.
I settled on virtualising Opnsense and Adguard separately on a proxmox instance.
Theory being that it’ll provide a bit more resilience than dual locals
This post did make me setup a void-zones-tools BSD jail on the LAN and testing it now. Seems to be very similar just without web admin.