Skip to content

Pi-hole DNS

Pi-hole provides DNS resolution and ad-blocking for the entire infrastructure.

Configuration

Property Value
Container IP 172.20.10.53
Network docker-egress
Version v6
Dashboard https://pihole.clsxx.de

DNS Resolution Chain

VM (192.168.10.10)
  → 192.168.10.1 (virbr0 gateway)
    → dnsmasq (host) 
      → Pi-hole (172.20.10.53)
        ├── Gravity (blocklist) → NXDOMAIN
        └── Upstream → Cloudflare/Google DNS

VPN Client DNS

VPN clients on the strato-host tunnel use Pi-hole for DNS through NAT rules:

iptables -t nat -A PREROUTING -i strato-host -p udp --dport 53 -j DNAT --to 172.20.10.53:53

This means admin DNS queries also appear in Pi-hole's logs.

Custom DNS Entries

Pi-hole's custom DNS maps admin domains to the VPN IP:

Domain IP Purpose
firewall.clsxx.de 10.0.0.1 Control Center
pihole.clsxx.de 10.0.0.1 Pi-hole Dashboard
traefik.clsxx.de 10.0.0.1 Traefik Dashboard
fail2ban.clsxx.de 10.0.0.1 Fail2ban Dashboard
docs.clsxx.de 10.0.0.1 Documentation

These resolve to the VPN gateway IP, ensuring dashboards are only accessible through VPN.

API

v6 API

Pi-hole v6 uses session-based authentication:

# Authenticate
curl -X POST http://172.20.10.53/api/auth \
  -d '{"password": "..."}' \
  -H "Content-Type: application/json"
# Returns: {"session": {"sid": "..."}}

# Query with session
curl http://172.20.10.53/api/stats/summary \
  -H "sid: <session-id>"

Monitoring via Control Center

The Control Center exposes Pi-hole data through its own API:

  • GET /api/dns/summary — Statistics
  • GET /api/dns/queries — Recent lookups
  • GET /api/dns/top-domains — Most queried
  • GET /api/dns/top-blocked — Most blocked
  • POST /api/dns/toggle — Toggle ad-blocking

Gravity Lists

Pi-hole maintains blocklists ("gravity") of known ad/tracker domains. The default configuration blocks ~82,000 domains.