--- # Pi-hole native configuration - name: Generate Pi-hole admin password command: openssl rand -base64 16 register: pihole_password_gen args: creates: /etc/pihole/.phantom_password - name: Save admin password copy: content: "{{ pihole_password_gen.stdout }}" dest: /etc/pihole/.phantom_password mode: "0600" when: pihole_password_gen.changed - name: Read saved password slurp: src: /etc/pihole/.phantom_password register: pihole_password_file - name: Set Pi-hole admin password command: "pihole -a -p {{ (pihole_password_file.content | b64decode).strip() }}" changed_when: true - name: Set upstream DNS servers command: "pihole -a setdns {{ pihole_upstream | replace(';', ' ') }}" changed_when: true - name: Configure blocklist level block: - name: Update gravity (standard blocklist) command: pihole -g changed_when: true when: pihole_blocklist == "standard" - name: Add aggressive blocklists lineinfile: path: /etc/pihole/adlists.list line: "{{ item }}" create: true mode: "0644" loop: - "https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts" - "https://raw.githubusercontent.com/hagezi/dns-blocklists/main/adblock/pro.txt" when: pihole_blocklist == "aggressive" notify: update gravity - name: Update gravity after blocklist changes command: pihole -g changed_when: true when: pihole_blocklist == "aggressive" - name: Enable DNSSEC command: pihole -a dnssec on changed_when: true - name: Ensure pihole-FTL is running service: name: pihole-FTL state: started enabled: true - name: Display admin credentials debug: msg: "Pi-hole admin password saved to /etc/pihole/.phantom_password — access admin at http://{{ ansible_default_ipv4.address | default('server_ip') }}/admin"