This repository has been archived on 2026-08-17. You can view files and clone it. You cannot open issues or pull requests or push a commit.
Files
beatzaplentyandClaude Sonnet 4.6 4aadef8e97
Secret Scan / Scan for secrets and sensitive config (push) Failing after 3s
Secret Scan / Scan for secrets and sensitive config (pull_request) Failing after 3s
docs: update documentation for debian-configuration repo rename
- Root README.md: new, describes overall repo layout (proxmox/, pihole/,
  scripts/) and secret-scanning workflow
- Root CLAUDE.md: new, cross-section guardrails and instructions for
  adding new machine types; references proxmox/CLAUDE.md and pihole/
  section-specific rules
- pihole/README.md: new, covers scripts usage, notable DHCP/PXE config,
  EFI VM requirements (VirtIO RNG, Secure Boot), and secrets handling
- proxmox/README.md: add repo-context note pointing back to root README

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XRzqNDrbnYR22ZgZj1Bg3s
2026-07-23 12:35:30 +10:00
..

pihole

Pi-hole v6 configuration management for pihole.sweet.home.

What's here

config/
  pihole.toml                  Pi-hole v6 main config (sanitised snapshot)
  dnsmasq.d/
    99-ipxe-chainload.conf     Custom DHCP rules for EFI/BIOS iPXE PXE boot
pull-config.sh                 Pull live config from a Pi-hole to a local dir
apply-config.sh                Apply a local config dir to a Pi-hole instance
sanitize-config.sh             Redact sensitive fields from pihole.toml in-place

Usage

Snapshot the live config

# Pulls pihole.toml + custom dnsmasq.d/ drop-ins, auto-redacts sensitive fields
./pull-config.sh root@pihole ./config

Apply config to a new Pi-hole

# Destination must have Pi-hole v6 already installed
./apply-config.sh ./config root@pihole-new

Both scripts take <source> <destination> as positional arguments. Source/destination is an SSH target (e.g. root@pihole, root@192.168.2.253) for the live side and a local directory path for the config side.

Restore blocklists after applying

apply-config.sh transfers config only — not the gravity database. Run this on the destination after applying to rebuild blocklists:

ssh root@pihole-new "pihole updateGravity"

Notable config

dnsmasq.d/99-ipxe-chainload.conf

Enables architecture-aware PXE boot via DHCP:

Client Vendor class Boot file served
EFI iPXE already running arch 7 + option 175 http://.../boot.ipxe
BIOS iPXE already running arch 0 + option 175 http://.../boot.ipxe
EFI, no iPXE yet PXEClient:Arch:00007 ipxe.efi via TFTP
BIOS/legacy, no iPXE yet PXEClient:Arch:00000 undionly.kpxe via TFTP

Proxmox EFI VMs also require a VirtIO RNG device (gives OVMF enough entropy to complete PXE negotiation) and Secure Boot disabled (pre-enrolled-keys=0 on the EFI disk, or disabled in UEFI setup).

Secrets

pihole.toml is stored with pwhash, totp_secret, and app_pwhash redacted to empty strings. pull-config.sh does this automatically. To redact manually: ./sanitize-config.sh config/pihole.toml.