Compare commits

..

3 commits

Author SHA1 Message Date
82a02be85a Use DNS over TLS & enable DNSSEC 2025-04-26 17:11:03 +02:00
6f393b4c39 Add BindCarrier directive
To disable wireguard interfaces whenever applicable
2025-04-26 17:10:24 +02:00
0bf6345ff3 Keep mpv open after finishing 2025-04-26 16:23:44 +02:00
12 changed files with 29 additions and 12 deletions

View file

@ -2,7 +2,7 @@ lan_interface: enp1s0
lan_interface_mac: 00:d8:61:9f:52:65
local_network_address: 192.168.2.15/24
local_network_dns: 192.168.2.254
local_network_dns: 9.9.9.9 149.112.112.112
local_network_gateway: 192.168.2.254
hostname: desktop

View file

@ -3,12 +3,14 @@ wireless_interface_mac: 98:2c:bc:e3:ff:bc
local_network_ssid: KPNAE51C6
local_network_address: 192.168.2.9/24
local_network_dns: 192.168.2.254
local_network_dns: 9.9.9.9 149.112.112.112
local_network_gateway: 192.168.2.254
frans_network_ssid: KPNDD1056
frans_network_address: 192.168.2.9/24
frans_network_dns: 192.168.2.254
frans_network_dns: 9.9.9.9 149.112.112.112
frans_network_gateway: 192.168.2.254
default_network_dns: 9.9.9.9 149.112.112.112
hostname: xps

View file

@ -29,7 +29,8 @@
- name: Personal provisiong
when: "'personal' in group_names"
block:
# TODO: require (w)lan interfaces before configuring these
# Note: set `network.dns.native_https_query` in about:config to prevent
# DoH requests by default. See https://github.com/arkenfox/user.js/issues/1881
- name: Wireguard provisioning
ansible.builtin.import_tasks: 'tasks/personal/all/wireguard.yml'
tags: wireguard

View file

@ -8,3 +8,6 @@ hwdec=vaapi
audio-samplerate=128000
audio-format=s64
# Do not close the window on exit
keep-open=yes

View file

@ -5,13 +5,13 @@ Name={{ lan_interface }}
[Network]
Address={{ local_network_address }}
DNS={{ local_network_dns }}
Gateway={{ local_network_gateway }}
DHCP=no
DNS={{ local_network_dns }}
MulticastDNS=yes
DNSOverTLS=yes
DNSSEC=yes
DHCP=no
LinkLocalAddressing=no
IPv6AcceptRA=no
IPv6SendRA=no
[Link]
RequiredForOnline=routable

View file

@ -7,3 +7,4 @@ Name={{ vpn_default.interface }}
Address={{ vpn_default.ip }}/{{ vpn_default.prefix }}
DNS={{ vpn_default.dns }}
Domains={{ vpn_default.domains | join(' ') }}
BindCarrier={{ lan_interface }}

View file

@ -7,3 +7,4 @@ Name={{ vpn_media.interface }}
Address={{ vpn_media.ip }}/{{ vpn_media.prefix }}
DNS={{ vpn_media.dns }}
Domains={{ vpn_media.domains | join(' ') }}
BindCarrier={{ lan_interface }}

View file

@ -7,3 +7,4 @@ Name={{ vpn_default.interface }}
Address={{ vpn_default.ip }}/{{ vpn_default.prefix }}
DNS={{ vpn_default.dns }}
Domains={{ vpn_default.domains | join(' ') }}
BindCarrier={{ wireless_interface }}

View file

@ -7,3 +7,4 @@ Name={{ vpn_media.interface }}
Address={{ vpn_media.ip }}/{{ vpn_media.prefix }}
DNS={{ vpn_media.dns }}
Domains={{ vpn_media.domains | join(' ') }}
BindCarrier={{ wireless_interface }}

View file

@ -6,10 +6,12 @@ SSID={{ frans_network_ssid }}
[Network]
Address={{ frans_network_address }}
DNS={{ frans_network_dns }}
Gateway={{ frans_network_gateway }}
DHCP=no
DNS={{ frans_network_dns }}
MulticastDNS=yes
DNSOverTLS=yes
DNSSEC=yes
DHCP=no
LinkLocalAddressing=no
IPv6AcceptRA=no
IPv6SendRA=no

View file

@ -6,10 +6,12 @@ SSID={{ local_network_ssid }}
[Network]
Address={{ local_network_address }}
DNS={{ local_network_dns }}
Gateway={{ local_network_gateway }}
DHCP=no
DNS={{ local_network_dns }}
MulticastDNS=yes
DNSOverTLS=yes
DNSSEC=yes
DHCP=no
LinkLocalAddressing=no
IPv6AcceptRA=no
IPv6SendRA=no

View file

@ -2,6 +2,9 @@
MACAddress={{ wireless_interface_mac }}
[Network]
DNS={{ default_network_dns }}
DNSOverTLS=yes
DNSSEC=yes
DHCP=yes
RequiredForOnline=routable
IgnoreCarrierLoss=3s