196 lines
4.5 KiB
Markdown
196 lines
4.5 KiB
Markdown
# Pihole
|
|
|
|
**🟡 Security Service**
|
|
|
|
## 📋 Service Overview
|
|
|
|
| Property | Value |
|
|
|----------|-------|
|
|
| **Service Name** | pihole |
|
|
| **Host** | Atlantis |
|
|
| **Category** | Security |
|
|
| **Difficulty** | 🟡 |
|
|
| **Docker Image** | `pihole/pihole` |
|
|
| **Compose File** | `Atlantis/pihole.yml` |
|
|
| **Directory** | `Atlantis` |
|
|
|
|
## 🎯 Purpose
|
|
|
|
Pi-hole is a DNS sinkhole that protects your devices from unwanted content, without installing any client-side software.
|
|
|
|
## 🚀 Quick Start
|
|
|
|
### Prerequisites
|
|
- Docker and Docker Compose installed
|
|
- Basic understanding of REDACTED_APP_PASSWORD
|
|
- Access to the host system (Atlantis)
|
|
|
|
### Deployment
|
|
```bash
|
|
# Navigate to service directory
|
|
cd Atlantis
|
|
|
|
# Start the service
|
|
docker-compose up -d
|
|
|
|
# Check service status
|
|
docker-compose ps
|
|
|
|
# View logs
|
|
docker-compose logs -f pihole
|
|
```
|
|
|
|
## 🔧 Configuration
|
|
|
|
### Docker Compose Configuration
|
|
```yaml
|
|
container_name: pihole
|
|
environment:
|
|
- WEB_PORT=9000
|
|
- WEBPASSWORD="REDACTED_PASSWORD"
|
|
- FTLCONF_LOCAL_IPV4=10.0.0.250
|
|
- TZ=American/Los_Angeles
|
|
- DNSMASQ_USER=root
|
|
- DNSMASQ_LISTENING=local
|
|
image: pihole/pihole
|
|
network_mode: host
|
|
restart: always
|
|
volumes:
|
|
- /volume1/docker/pihole/dnsmasq.d:/etc/dnsmasq.d
|
|
- /volume1/docker/pihole/pihole:/etc/pihole
|
|
|
|
```
|
|
|
|
### Environment Variables
|
|
| Variable | Value | Description |
|
|
|----------|-------|-------------|
|
|
| `WEB_PORT` | `9000` | Configuration variable |
|
|
| `WEBPASSWORD` | `***MASKED***` | Configuration variable |
|
|
| `FTLCONF_LOCAL_IPV4` | `10.0.0.250` | Configuration variable |
|
|
| `TZ` | `American/Los_Angeles` | Timezone setting |
|
|
| `DNSMASQ_USER` | `root` | Configuration variable |
|
|
| `DNSMASQ_LISTENING` | `local` | Configuration variable |
|
|
|
|
|
|
### Port Mappings
|
|
No ports exposed.
|
|
|
|
### Volume Mappings
|
|
| Host Path | Container Path | Type | Purpose |
|
|
|-----------|----------------|------|----------|
|
|
| `/volume1/docker/pihole/dnsmasq.d` | `/etc/dnsmasq.d` | bind | Configuration files |
|
|
| `/volume1/docker/pihole/pihole` | `/etc/pihole` | bind | Configuration files |
|
|
|
|
|
|
## 🌐 Access Information
|
|
|
|
This service does not expose any web interfaces.
|
|
|
|
## 🔒 Security Considerations
|
|
|
|
- ⚠️ Consider adding security options (no-new-privileges)
|
|
- ⚠️ Consider running as non-root user
|
|
|
|
## 📊 Resource Requirements
|
|
|
|
No resource limits configured
|
|
|
|
### Recommended Resources
|
|
- **Minimum RAM**: 512MB
|
|
- **Recommended RAM**: 1GB+
|
|
- **CPU**: 1 core minimum
|
|
- **Storage**: Varies by usage
|
|
|
|
### Resource Monitoring
|
|
Monitor resource usage with:
|
|
```bash
|
|
docker stats
|
|
```
|
|
|
|
## 🔍 Health Monitoring
|
|
|
|
⚠️ No health check configured
|
|
Consider adding a health check:
|
|
```yaml
|
|
healthcheck:
|
|
test: ["CMD", "curl", "-f", "http://localhost:PORT/health"]
|
|
interval: 30s
|
|
timeout: 10s
|
|
retries: 3
|
|
```
|
|
|
|
### Manual Health Checks
|
|
```bash
|
|
# Check container health
|
|
docker inspect --format='{{.State.Health.Status}}' CONTAINER_NAME
|
|
|
|
# View health check logs
|
|
docker inspect --format='{{range .State.Health.Log}}{{.Output}}{{end}}' CONTAINER_NAME
|
|
```
|
|
|
|
## 🚨 Troubleshooting
|
|
|
|
### Common Issues
|
|
**Service won't start**
|
|
- Check Docker logs: `docker-compose logs service-name`
|
|
- Verify port availability: `netstat -tulpn | grep PORT`
|
|
- Check file permissions on mounted volumes
|
|
|
|
**Can't access web interface**
|
|
- Verify service is running: `docker-compose ps`
|
|
- Check firewall settings
|
|
- Confirm correct port mapping
|
|
|
|
**Performance issues**
|
|
- Monitor resource usage: `docker stats`
|
|
- Check available disk space: `df -h`
|
|
- Review service logs for errors
|
|
|
|
**Authentication issues**
|
|
- Verify credentials are correct
|
|
- Check LDAP/SSO configuration
|
|
- Review authentication logs
|
|
|
|
### Useful Commands
|
|
```bash
|
|
# Check service status
|
|
docker-compose ps
|
|
|
|
# View real-time logs
|
|
docker-compose logs -f pihole
|
|
|
|
# Restart service
|
|
docker-compose restart pihole
|
|
|
|
# Update service
|
|
docker-compose pull pihole
|
|
docker-compose up -d pihole
|
|
|
|
# Access service shell
|
|
docker-compose exec pihole /bin/bash
|
|
# or
|
|
docker-compose exec pihole /bin/sh
|
|
```
|
|
|
|
## 📚 Additional Resources
|
|
|
|
- **Official Documentation**: Check the official docs for pihole
|
|
- **Docker Hub**: [pihole/pihole](https://hub.docker.com/r/pihole/pihole)
|
|
- **Community Forums**: Search for community discussions and solutions
|
|
- **GitHub Issues**: Check the project's GitHub for known issues
|
|
|
|
## 🔗 Related Services
|
|
|
|
Services REDACTED_APP_PASSWORD pihole:
|
|
- Vaultwarden
|
|
- Authelia
|
|
- Pi-hole
|
|
- WireGuard
|
|
|
|
---
|
|
|
|
*This documentation is auto-generated from the Docker Compose configuration. For the most up-to-date information, refer to the official documentation and the actual compose file.*
|
|
|
|
**Last Updated**: 2025-11-17
|
|
**Configuration Source**: `Atlantis/pihole.yml`
|