LibrePortal/containers/pihole/pihole.config
librelad ab811440e4 fix(pihole): use the official image, ported to Pi-hole v6
The app shipped cbcrowe/pihole-unbound — a third-party bundle last
rebuilt 841 days ago. Pi-hole itself is fine: the official
pihole/pihole was rebuilt 42 days ago. We packaged an abandoned fork,
not a dead project.

Not a tag swap. The official image is v6, which replaced nearly every
v5 environment variable with an FTLCONF_ equivalent — and the container
ACCEPTS the old names and ignores them, so a v5-style block looks
correct while configuring nothing, including the admin password:

  WEBPASSWORD         -> FTLCONF_webserver_api_password
  WEBTHEME            -> FTLCONF_webserver_interface_theme
  PIHOLE_DNS_         -> FTLCONF_dns_upstreams   (";" separates values)
  DNSSEC              -> FTLCONF_dns_dnssec
  DNSMASQ_LISTENING   -> FTLCONF_dns_listeningMode
  REV_SERVER{,_TARGET,_DOMAIN,_CIDR} -> FTLCONF_dns_revServers, one
                         combined "<enabled>,<cidr>,<target>,<domain>"
  FTLCONF_LOCAL_IPV4  -> gone in v6

listeningMode is ALL rather than the old "single": on a bridge network
queries arrive via the docker gateway, and "single" drops them.

The bundled unbound is gone, so PIHOLE_DNS_=127.0.0.1#5335 pointed at
nothing. New CFG_PIHOLE_UPSTREAM_DNS defaults to Quad9, with the config
documenting how to point it at the unbound app for full recursion. The
freed port slot becomes the (disabled) DHCP port, which v6 supports.

Volumes: v6 keeps config, databases and gravity under /etc/pihole, and
ignores /etc/dnsmasq.d unless explicitly re-enabled — so the old
two-mount layout is replaced by a single ./etc-pihole.

Variable names taken from the official v5->v6 upgrade doc, not memory.
Substitution verified end to end: every placeholder resolves and
revServers renders in the documented format.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-18 02:30:13 +01:00

81 lines
4.4 KiB
Plaintext
Executable File

#
# =============================================================================
# GENERAL CONFIGURATION
# =============================================================================
# APP_NAME = name of application for use in scripts
# COMPOSE_FILE = default for no app_name in docker-compose file name, app if there is
# BACKUP = if true, include this application in backup operations
# UPDATE_TYPE = auto: new image builds are applied automatically (a recovery snapshot is taken first), manual: only when you press Update
# HEALTHCHECK = if true, default docker health checks for that container will be enabled
# AUTHELIA = if true, use Authelia authentication, if false turned off.
# HEADSCALE = options : false, local, remote (see general config). e.g false or local,remote
# MONITORING = if true, export this app's metrics to Prometheus + Grafana (needs both apps installed)
#
CFG_PIHOLE_APP_NAME=pihole
CFG_PIHOLE_BACKUP=true
CFG_PIHOLE_BACKUP_STRATEGY=auto
CFG_PIHOLE_UPDATE_TYPE=auto
CFG_PIHOLE_COMPOSE_FILE=default
CFG_PIHOLE_HEALTHCHECK=true
CFG_PIHOLE_AUTHELIA=false
CFG_PIHOLE_HEADSCALE=false
CFG_PIHOLE_MONITORING=false
#
# =============================================================================
# APPLICATION CONFIGURATION
# =============================================================================
# ADMIN_PASSWORD = web interface admin password (will be generated if set to RANDOMIZEDPASSWORD)
# WEB_THEME = web interface theme (default-dark, default-light, or custom themes)
#
CFG_PIHOLE_ADMIN_PASSWORD=RANDOMIZEDPASSWORD1
CFG_PIHOLE_WEB_THEME=default-dark
CFG_PIHOLE_UPSTREAM_DNS=9.9.9.9;149.112.112.112
#
# =============================================================================
# METADATA
# =============================================================================
# CATEGORY = application category for grouping
# TITLE = display name for the application
# DESCRIPTION = short description of the application
# LONG_DESCRIPTION = detailed description of the application
# URL = source repository or documentation URL
# ACTIONS = available actions for this application
#
CFG_PIHOLE_CATEGORY="networking"
CFG_PIHOLE_TITLE="PiHole"
CFG_PIHOLE_DESCRIPTION="DNS-based Ad Blocking"
CFG_PIHOLE_LONG_DESCRIPTION="Pi-hole is a DNS sinkhole that protects your devices from unwanted content without installing any client-side software"
CFG_PIHOLE_URL="https://github.com/pi-hole/pi-hole"
CFG_PIHOLE_ACTIONS="configure|install|restart|shutdown|uninstall"
#
# =============================================================================
# NETWORK CONFIGURATION
# =============================================================================
# DOMAIN = number of domain from the general config, useful when using multiple domains
# WHITELIST = if true only allow whitelisted ips on traefik, if false allow all
#
CFG_PIHOLE_DOMAIN=1
CFG_PIHOLE_WHITELIST=false
CFG_PIHOLE_NETWORK=default
#
# =============================================================================
# PORT CONFIGURATION
# =============================================================================
# PORT_ = port configuration: app|name|external:internal|access|protocol|login|traefik|webui|description
# - app: application name
# - name: service identifier (webui, dns, ssh, etc.)
# - external:internal: port mapping (external can be 'random' for auto-allocation)
# - access: 'public' (internet accessible), 'private' (local network only), 'disabled' (not running)
# - protocol: 'tcp' or 'udp'
# - login: if true, this port requires basic-auth via Traefik (only meaningful when traefik=true)
# - traefik: if true, Traefik handles this port (reverse proxy)
# - webui: if true, this port serves the main web interface
# - description: human-readable description of the service
#
CFG_PIHOLE_PORT_1="pihole-service|webui|random:80|private|tcp|false|false|true|Admin Interface|/admin/|pihole"
CFG_PIHOLE_PORT_2="pihole-service|dns-tcp|53:53|private|tcp|false|false|false|DNS Server (TCP)|"
CFG_PIHOLE_PORT_3="pihole-service|dns-udp|53:53|private|udp|false|false|false|DNS Server (UDP)|"
CFG_PIHOLE_PORT_4="pihole-service|https|random:443|disabled|tcp|false|false|false|HTTPS Interface|"
CFG_PIHOLE_PORT_5="pihole-service|dhcp|67:67|disabled|udp|false|false|false|DHCP Server (enable to let Pi-hole hand out leases)|"
CFG_PIHOLE_PORT_6="pihole-exporter|metrics|9617:9617|disabled|tcp|false|false|false|Metrics Exporter (sidecar, docker-network only)|"