This was a pain to get up and running, but I did it. The main reason is that I was installing it on Alpine linux which is a very stripped back distro. A blessing and a curse. I've summarised my various attempts to get it working here. This is not particularly thorough. No need to go into depth with things that didn't work. Believe me though, this was going on for a few days.

Guides:

Pihole requirements

Create Alpine LXC

First thing is to create a linux container running Alpine linux. This is just going to run a single application so it doesn't need anything with a big footprint. I've documented my process for ding this over here.

Firewall rules for Pi-hole

Add the iptables rules. Firewall rules, straight from the Pi-hole docs.

iptables -I INPUT 1 -s 192.168.1.0/24 -p tcp -m tcp --dport 80 -j ACCEPT
iptables -I INPUT 1 -s 192.168.1.0/24 -p tcp -m tcp --dport 443 -j ACCEPT
iptables -I INPUT 1 -s 192.168.1.0/24 -p tcp -m tcp --dport 53 -j ACCEPT
iptables -I INPUT 1 -s 192.168.1.0/24 -p udp -m udp --dport 53 -j ACCEPT
iptables -I INPUT 1 -s 127.0.0.0/8 -p tcp -m tcp --dport 53 -j ACCEPT
iptables -I INPUT 1 -s 127.0.0.0/8 -p udp -m udp --dport 53 -j ACCEPT
iptables -I INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
rc-service iptables save

# The rules below are in the Pi-hole docs but are only needed if using Pi-hope from DHCP, which I'm not.
# iptables -I INPUT 1 -p udp --dport 67:68 --sport 67:68 -j ACCEPT
# iptables -I INPUT 1 -p udp --dport 123 -j ACCEPT

Pi-hole was a bit of an ordeal. My notes show four attempts to get it up and running.

Attempt #1: Official Pi-hole install script

I ran the official install script which appeared to execute just fine but gave an error when I tried to update the the application itself (/usr/local/bin/pihole -up). This gave the error Web Admin repo is missing from system! and suggested I re-run the install script. I tried to repair this (/usr/local/bin/pihole -r) and was told Unable to reset /usr/share/pihole/admin-web/admin/, exiting installer. I re-ran the installer, which was fine. Re-ran the update, got the same error.

Tried this. It didn’t work.

sudo rm -rf /var/www/html/admin
sudo git clone https://github.com/pi-hole/AdminLTE.git /var/www/html/admin

Tried this. It didn’t work.

sudo rm -rf /var/www/html/admin
sudo git clone https://github.com/pi-hole/web.git /var/www/html/admin

Searching came up empty.

pihole uninstall

Attempt #2: Package from testing repo

Found here. Someone ported Pi-hole to Alpine linux but as of now, it's still in the testing repo.

Installed via Alpine package manager but running pihole status gave an error ss: command not found. This lives in iproute2, I installed that, re-ran the status check, everything looked good.

Checked the application in the rowser and was told to "Update the list of ad-serving domains". I ran pihole -g, which should update the blocklists. This gave me a DNS error. I got nowhere trying to sort this one out either.

apk del pihole

Attempt #3: Install script modified for Alpine

I came across a version of the official install script that had been modified to run on Alpine. Long story short, it didn't work.

pihole uninstall

Attempt #4: Re-try the official install script

Nothing was working. I had spent a lot of time on this. I was getting desperate (I ran a scipt I found on github in Attempt #3 which will tell you how desperate I was). It was suggested on a forum that I stick with the official install script. Sure may as well like.

curl -sSL https://install.pi-hole.net | bash

This looked all good. It brought up the install interface that I had only seen in Attempt #3 and tutorials. opening the app in the browser I'm told "Domains on list 93,156". Very nice. pihole -v showed latest versions. pihole -g ran just fine. pihole -up showed everything up to date. Alright. It's running.

Making it actually work

I'm not going to go through the troubleshooting here but there are a few important points I learned. To test, I used some arbitrary websites and this. For the adtest website, I had to turn off all privacy extensions and features in the browser. I tested with Brave and Firefox. I had to do this to actually see some ads in the first place before testing if Pi-hole was blocking them.

VPN

I use NordVPN (currently). I have this set up on each device - laptop, phone. If I'm connected to the VPN, DNS requests are routed to the VPN provider's DNS service - the VPN app overwrites /etc/resolv.conf. If I'm on the VPN, the Pi-hole is ignored. To test the Pi-hole from the laptop, I need to disconnect from the VPN. So I did, for the duration of testing.

DHCP

By default, the router sets the DNS server IP. The local machine will get the address from the router and make the query. I can set the DNS IP on the local machine (laptop) and on the router. Below are some experiments changeing these values and the outcome of each.

Router DNS: auto
Local machine DNS: 192.168.1.15 (pihole)
Result: dashoard show queries received, queries blocked
Conclusion: Pi-hole works, but only on one machine.

Router DNS: 192.168.1.15 (pihole)
Local machine DNS: 192.168.1.1 (router)
Result: "page not found" in browser, `curl: (6) Could not resolve host: google.com`
Conclusion: Router won't use pihole

Router DNS: 8.8.8.8 (google)
Local machine DNS: 192.168.1.1 (router)
Result: Pages load.
Conclusion: Router will use any other custom DNS.

The trick in the end was to turn on DHCP on the Pi-hole and turn it off on the router. Turns out, and this was new to me, the DHCP server also hands out the DNS address. Just let the Pi-hole take care of everything and it'll all be ok.

The next question is how to use the VPN and the Pi-hole. Makes sense to have the VPN configured at the router level then all traffic will go through the VPN but the Pi-hole will still be filtering the DNS queries. This would be for everything on the network. The problem is that the ISP standard issue router I'm using only has options for older VPN protocols and not the one that NordVPN uses. So now I need to buy a router and ask the ISP if I can use it.