Pi-hole DNS¶
Pi-hole provides DNS resolution and ad-blocking for the entire infrastructure.
Configuration¶
| Property | Value |
|---|---|
| Container IP | 172.20.10.53 |
| Network | docker-egress |
| Version | v6 |
| Dashboard | https://pihole.clsxx.de |
DNS Resolution Chain¶
VM (192.168.10.10)
→ 192.168.10.1 (virbr0 gateway)
→ dnsmasq (host)
→ Pi-hole (172.20.10.53)
├── Gravity (blocklist) → NXDOMAIN
└── Upstream → Cloudflare/Google DNS
VPN Client DNS¶
VPN clients on the strato-host tunnel use Pi-hole for DNS through NAT rules:
This means admin DNS queries also appear in Pi-hole's logs.
Custom DNS Entries¶
Pi-hole's custom DNS maps admin domains to the VPN IP:
| Domain | IP | Purpose |
|---|---|---|
firewall.clsxx.de |
10.0.0.1 | Control Center |
pihole.clsxx.de |
10.0.0.1 | Pi-hole Dashboard |
traefik.clsxx.de |
10.0.0.1 | Traefik Dashboard |
fail2ban.clsxx.de |
10.0.0.1 | Fail2ban Dashboard |
docs.clsxx.de |
10.0.0.1 | Documentation |
These resolve to the VPN gateway IP, ensuring dashboards are only accessible through VPN.
API¶
v6 API¶
Pi-hole v6 uses session-based authentication:
# Authenticate
curl -X POST http://172.20.10.53/api/auth \
-d '{"password": "..."}' \
-H "Content-Type: application/json"
# Returns: {"session": {"sid": "..."}}
# Query with session
curl http://172.20.10.53/api/stats/summary \
-H "sid: <session-id>"
Monitoring via Control Center¶
The Control Center exposes Pi-hole data through its own API:
GET /api/dns/summary— StatisticsGET /api/dns/queries— Recent lookupsGET /api/dns/top-domains— Most queriedGET /api/dns/top-blocked— Most blockedPOST /api/dns/toggle— Toggle ad-blocking
Gravity Lists¶
Pi-hole maintains blocklists ("gravity") of known ad/tracker domains. The default configuration blocks ~82,000 domains.