11 ms·
Show HN: WireHole combines WireGuard, Pi-hole, and Unbound with an easy UI
WireHole offers a unified docker-compose project that integrates WireGuard, PiHole, and Unbound, complete with a user interface. This solution is designed to empower users to swiftly set up and manage either a full or split-tunnel WireGuard VPN. It features ad-blocking capabilities through PiHole and enhanced DNS caching and privacy options via Unbound. The intuitive UI makes deployment and ongoing management straightforward, providing a comprehensive VPN solution with added privacy features.
- deleted 3y ago[deleted]
- josephcsible 3y agoI don't see a license.
- byteknight 3y agoAdded :)
- josephcsible 3y agoYou went with a proprietary one :(
- byteknight 3y agoNo - I had to inherit the licenses of the projects I used within it :(
- josephcsible 3y agoAh, it is indeed wg-easy that's actually to blame.
- aragilar 3y agoArguably you can't use pi-hole and wg-easy together (as the Composite Software License and EUPL are not compatible).
- LorenzoGood 3y agoCan't you use those licenses, and license your docker compose with a foss one?
- globular-toast 3y agoI don't think you have to inherit the licence. I don't see a copy of wg-easy in there. It would be nice to add a note that this uses non-free software like wg-easy, though.
- josephcsible 3y agoThis uses wg-easy, which isn't open source.
- repelsteeltje 3y agoThis wg-easy? Definitely not an OSI approved license, but does look like they made an attempt in the spirit of GPL, no? https://github.com/wg-easy/wg-easy/blob/master/LICENSE.md https://github.com/wg-easy/wg-easy/blob/master/LICENSE.md > You may: > - Use this software for yourself; > - Use this software for a company; > - Modify this software, as long as you: > * Publish the changes on GitHub as an open-source & linked fork; > * Don't remove any links to the original project or donation pages; > You may not: > - Use this software in a commercial product without a license from the original author;
- byteknight 3y agoThis is accurate. I just recently added the GUI from wg-easy as a revival of the project. If you want to fully open source version you can go back a couple commits before I added the GUI.
- josephcsible 3y agoEither there's a giant loophole in that license or it prevents you from modifying wg-easy at all. In particular, the prohibition on commercial use is clearly not open source, so the only way you could comply with the requirement to publish your changes in an open-source fork would be for your fork to have a different license. If that is allowed, then the giant loophole is that you could pick MIT, and then the rest of the world could use your fork and ignore the original's license. If that's not allowed, then there's no way for you to comply with that requirement and so you can't modify wg-easy at all.
- byteknight 3y agoI think you're misunderstanding how licenses work. Being that wire hole is a conglomerate of a multitude of projects I am required to utilize the most restrictive version of that license. I believe you're also thoroughly misunderstanding the license terms that are present. The license says that you can utilize it for a commercial settings and in a commercial environment you just cannot resell the product. This means that an Enterprise can openly use it within their Enterprise they just cannot sell it as a service that they offer. While this is not the license that I would have chosen for a Greenfield project but at the moment I am at the mercy of the licenses in place for the projects that I am using. Once I replace the UI with a proprietary one everything will be fully open source the way it's intended
- amar0c 3y agoDoes everything really need to be Docker these days? Specially "network stuff". I mean, it really makes me want to go and grow potatoes instead doing any "IT"
- deleted 3y ago[deleted]
- toomuchtodo 3y agoIt makes life so much easier. Time is non renewable, and if you want to pull a project apart for whatever reason, you still can. “docker pull”, deploy, and one can move on to the next whatever. You can deploy this to a Synology NAS, a Raspberry Pi, or Heroku with a few clicks (or even an appropriately configured router that supports containers if you’re not running something providing this functionality natively). (DevOps/infra monkey before moving to infosec, embrace the container concept)
- NexRebular 3y ago> It makes life so much easier. If running an OS that supports docker...
- byteknight 3y agoIf you're running an OS that doesnt support docker you have a very esoteric use case.
- xorcist 3y agoLet's not overstate things here. It may well look like "docker pull", deploy, nothing, ok, how do I configure this thing, oh goodie here's the uncommented yaml, deploy again, strange error, headscratch, oh it's dependent on using the .68.x network which I've already used elsewhere, let's rename those docker networks, deploy again, what?, oh it must have initialized a temporary password to the database when it didn't come up, let's wipe it all clean and pull again because I have no idea what kind of state is in those persistent volumes, deploy, rats! forgot the network renumbering, wipe clean, confiure again, deploy again, yay! Provided you already turned off everything that can interfere with this stuff, including IPv6, any security like SELinux, grsecurity and friends, and you let it administer your netfilter firewall for you. Don't forget to check if you accidentally exposed some redis instance to the public Internet. (And yes, I have embraced the concept and work daily with similar things, albeit in a larger scale. Let's just not kid ourselves it's easier than it is though. Just because an out of the box deploy goes sideways doesn't mean you are dumb.)
- A_No_Name_Mouse 3y ago> Navigate to http://{YOUR_SERVER_IP}:51821 http://{YOUR_SERVER_IP}:51821. Log in using the admin password Over http? Pretty YOLO...
- deleted 3y ago[deleted]
- 0x073 3y agoI think it's mostly for intranet setup. Most router still use http for management ui, as it's complicated to setup an working certificate, especially only with ip.
- A_No_Name_Mouse 3y agoYou might be right. There's a link for deployment to Oracle cloud, but that seems to use a different way to login.
- byteknight 3y agoI should've stipulated more clearly and will do. Thank you.
- byteknight 3y agoI should've stipulated more clearly and will do. Thank you.
- Alifatisk 3y agohttp for local networks should be fine, right?
- thekashifmalik 3y agoIt's okay but not ideal. Otherwise anyone connected to WiFi can snoop on traffic. Unfortunately my router, switches, AP and NAS don't support HTTPS either :'(
- tristanb 3y agoDoes this have any mdns reflection?
- ace2358 3y agoIs that what is required so I can do my server.local and have it work? I’ve struggled a lot of .local stuff with various routers and port openings etc. I know that .local isn’t a standard or something and I’m meant to use something else. I’ve never known what to google to fix it though
- JamesSwift 3y ago.local is a standard. Its a part of mDNS (multicast DNS). Dont use it for your own DNS records. I'm not sure what exact issue you are having, but if you are trying to resolve mDNS .local across internal networks then you need to look up mDNS reflection. If you are trying to use .local for your own DNS records then pick something else (ideally using an actual registered TLD, so e.g. if you own foo.com then you could use lan.foo.com for your internal records).
- Dathuil 3y agoI ran into this issue a few months ago when I got sometime to actually setup my home server and wanted to use urls like nas.local and homeassistant.local on my home network to make things easy for my family to access. Worked fine on windows but all the Apple devices in the house had a conniption when trying to connect. I ended up just using my personal domain replacing .local. Am currently investigating a wildecard DNS SSL cert to get HTTPS working on the LAN, but that's more out of curiosity than anything else
- pdntspa 3y agoWhy bother with the .local suffix? Just do the device's DNS name itself. http://servername/ http://servername/ should work fine, clients register themselves during the DHCP handshake and the router's DNS server records the name.
- sthlmb 3y agoOoh, this is definitely something to play around with tomorrow. A split-tunnel on my phone would be nice!
- byteknight 3y agoYup! Now we're thinking alike. Split only DNS and bingo, native ad blocking.
- yetanother-1 3y agoWould you give more explination please? How are you plannin on setting it up?
- byteknight 3y agoRun wireguard on your phone. Follow instructions for split tunneling. Only tunnel the IP of your DNS (PiHole) and boom.
- esperent 3y agoBesides self hosting, is there anything this gives you that using NextDNS with a personal blocklist and adblock turned on can't do?
- byteknight 3y agoNot really, other additional than privacy.
- poisonborz 3y agoNot routing every request through a single third party service?
- esperent 3y agoRight, that's the self hosting part.
- ThinkBeat 3y ago>* Publish the changes on GitHub as an open-source & linked fork; Great an open-source license that mandates the use of a proprietary Microsoft product.
- j45 3y agoDoesn’t seem exclusive, and could be posted elsewhere in addition. It might not be ideal or my choice but the alternative of no choice at all would probably be more concerning.
- byteknight 3y agoThis is true and only true while the project uses wg-easy. Once the new UI is done it will no longer be required.
- j45 3y agoOh that’s a great clarification, thanks!
- mcfedr 3y agoThat's what stops it being an open source license
- Nrbelex 3y agoSee also Algo VPN: https://github.com/trailofbits/algo https://github.com/trailofbits/algo
- botanicalfriend 3y agoThis looks super useful. It is a bit convoluted to setup WG/PiHole/Unbound/foo and link them all together. But, it is not tedious enough that I’d ever put in the time to make a whole UI to improve it. I’m glad someone did though, it’s these little things that you don’t realize you need :-)
- snvzz 3y agoNotably missing RISC-V support. No good reason, either. What is needed for support is already in place.
- matthews2 3y agoWhy don’t you submit a pull request to add it?
- BrandoElFollito 3y agoOne of the reasons I never switch from dnsmasq is the integrated dhcp/dns service. Unbound did not have this (nor any service I know) and you need extra care to handle your local devices registration The fact that dnsmasq is the only service I know that manages dhcp records on dns makes me wonder if I am not doing something wrong.
- spockz 3y agoI think the pihole docker image uses dnsmasq. It definitely supports being the dhcp server and integrates clients into its dns responses.
- BrandoElFollito 3y agoYes it does. I was referring to switching to unbound.
- byteknight 3y agoUnbound is not the intended to be a PiHole service. It's a resolver.
- figmert 3y agoAdguard Home does too. Anyway, regardless, you can use dnsmasq with Unbound.
- BrandoElFollito 3y ago> you can use dnsmasq with Unbound could you elaborate on that? How is the connection done?
- figmert 3y agoDnsmasq needs an upstream server to resolve the DNS queries. That upstream server can be anything, Google, Cloudflate, Quad9, or, a local Unbound instance. You run an unbound server with a static IP, and point dnsmasq to said static IP. OPs setup has this configured through Pi-hole. Look at the docker-compose file. Edit: I just remembered Pi-hole has an official guide for this: https://docs.pi-hole.net/guides/dns/unbound/ https://docs.pi-hole.net/guides/dns/unbound/
- selfhoster69 3y agoReplace Pihole and Unbound with AdGuard and this stack will instantly be more efficient, fast and significantly more powerful.
- m1chae1 3y agoI created an account after years of lurking. This does exactly what I want. Can anyone point me in the right direction? My pihole and unbound dna is working flawlessly and installation was easy. But I have lost countless bours trying to add wireguard to the mix. I got it running, I can connect but my dns stops working when the wire guard is running or my wirrguard has no internet. I have found people with the exact same issue but its still not working. This guy https://www.google.com/url?sa=t&source=web&rct=j&opi=89978449&url=https://discourse.pi-hole.net/t/pihole-unbound-wireguard-dns-not-working/54233&ved=2ahUKEwjGzrqi7pqCAxW73gIHHeESCNwQFnoECAsQAQ&usg=AOvVaw3v5Zct-NAmU4y3zS5wYoXI https://www.google.com/url?sa=t&source=web&rct=j&opi=8997844... was facing similar issues but got it running but I couldnt even with these instructions. Also, Im running this on a pi 3, and adding docker is probably going to be a preformance hit so Im not too keen
- all2 3y agoHow willing are you to start from scratch? Pack up your configs in a git repo and nuke your installation. When I run into intractable configuration issues, I typically start from scratch to see if I can get them to work. You might try doing it from scratch on your workstation in a VM/container to see if the issue crops up there as well.
- weejewel 3y agoHey, I’m the author of wg-easy, nice to see my project in here! As for all the license discussions, I just don’t want a company to pack my work and sell it as a commercial device or service. I’m open for a better license which covers that.
- jddj 3y agoElastic maybe?
- cpach 3y agoDid you consider AGPL?
- AnonC 3y agoAGPL only forces the company to release the sources even if it’s used on a SaaS platform. There’s nothing in AGPL to prevent commercial use/sale or packaging this together with something else (as long as source is made available).
- cpach 3y agoThat is indeed true, but in practice, the features of AGPL might be enough to make most people avoid trying to commercialise an AGPL project.
- Scrubbington 3y agoMy setup on Raspberry Pi 3 is - Dietpi [1] - Unbound - Wireguad via PiVPN [2] - AdGuard, as a replacement of PiHole, never went back Every time I tried to move it to a container-based solution (Portainer is quite helpful), I went into problems here and there, adding more complexcity in terms of another network layer, container volumes, updating one piece of this (unbound, pihole, vpn) conflicting with the full stack, updating Dietpi itself. Is it me getting old and lazy, neglecting container stuff? Anyway, travelling around the globe being able to surf via homeland ip ranges, reverse DNS, adblocking and access to my NAS was never easier and so far - great uptime, no major f*ckups. [1] https://dietpi.com/ https://dietpi.com/ [2] https://dietpi.com/docs/software/vpn/#pivpn https://dietpi.com/docs/software/vpn/#pivpn