<?xml version="1.0" encoding="utf-8" standalone="yes"?><?xml-stylesheet type="text/xsl" href="/pretty-feed-v3.xsl"?>
<rss
  version="2.0"
  xmlns:atom="http://www.w3.org/2005/Atom"
  xmlns:content="http://purl.org/rss/1.0/modules/content/"
  xmlns:source="https://source.scripting.com/"
>
  <channel>
    <title>Paul Tibbetts</title>
    <link>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/12/</link>
    <description>Posts by Paul Tibbetts published in December 2025</description>
    <generator>Hugo</generator>
    <language>en-gb</language>
    <atom:link href="https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/12/feed.xml" rel="self" type="application/rss+xml" /><item>
      <title>Favourite Games of 2025</title>
      <link>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/12/31/favourite-games-of-2025/</link>
      <pubDate>Wed, 31 Dec 2025 16:00:00 +0000</pubDate>
      <guid>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/12/31/favourite-games-of-2025/</guid>
      <category>gaming</category>
      <description>Last year I wrote my own take on the Steam Awards , and in 2025 I played less games, so instead of pretending otherwise, this is a list of my favourites from this year.</description>
      <content:encoded><![CDATA[<p>Last year I wrote <a href="https://micro.paultibbetts.uk/2025/01/03/pc-games-i-liked-in.html">my own take on the Steam Awards</a>
, and in 2025 I played less games, so instead of pretending otherwise, this is a list of my favourites from this year.</p>
<h2 id="dispatch">Dispatch</h2>
<blockquote>
<p>Single-player story-driven narrative.</p>
</blockquote>
<p><a href="https://store.steampowered.com/app/2592160/Dispatch/"><img src="https://shared.fastly.steamstatic.com/store_item_assets/steam/apps/2592160/header.jpg" alt="Dispatch hero image" title="Dispatch hero image">
</a>
</p>
<p>Dispatch might be <em>the</em> funniest game I&rsquo;ve ever played. It&rsquo;s extremely well written, absurdly well voice acted and expertly made by the team that used to be Telltale Games.</p>
<p>It gives a real glimpse into the life of a superhero dispatcher and kept me entertained the whole way through.</p>
<p>I&rsquo;ll be playing whatever <a href="https://www.adhocla.com/">Adhoc Studios</a>
 makes next. I hope it&rsquo;s Wolf Among Us 2 or another season of Dispatch. Either way, I&rsquo;m in.</p>
<p>It&rsquo;s rated <a href="https://www.protondb.com/app/2592160">Platinum</a>
 on ProtonDB, so it plays great on Linux.</p>
<p><a href="https://store.steampowered.com/app/2592160/Dispatch/">Steam</a>
</p>
<h2 id="arc-raiders">Arc Raiders</h2>
<blockquote>
<p>Third-person PvPvE extraction-shooter.</p>
</blockquote>
<p><a href="https://store.steampowered.com/app/1808500/ARC_Raiders/"><img src="https://steamcdn-a.akamaihd.net/steam/apps/1808500/header.jpg" alt="Arc Raiders hero image" title="Arc Raiders hero image">
</a>
</p>
<p>I wasn&rsquo;t expecting to like Arc Raiders as much as I did. It makes the sweaty extraction-shooter genre more accessible, even if it is still pretty sweaty.</p>
<p>Escape from Tarkov was a bit too much for me; Arc Raiders has a much better balance. It&rsquo;s not for everyone, but it&rsquo;s that well done you might enjoy it even if you don&rsquo;t like similar games.</p>
<p>Whilst you can get shot by other players, it&rsquo;s the Arc that are the real threat, and this mix of danger, plus the proximity voice chat, make it unlike any other game out right now.</p>
<p>It won The Game Awards&rsquo; <a href="https://nitter.net/ARCRaidersGame/status/1999420050785042508?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1999420050785042508%7Ctwgr%5E%7Ctwcon%5Es1_&amp;ref_url=https%3A%2F%2Fwww.gamersheroes.com%2Fgaming-news%2Farc-raiders-best-multiplayer-game-of-2025-at-the-game-awards%2F">Multiplayer Game of the Year</a>
, so don&rsquo;t just take my word for it.</p>
<p><a href="https://www.embark-studios.com/">Embark</a>
&rsquo;s previous game, <a href="https://www.reachthefinals.com/">The Finals</a>
, made it onto last year&rsquo;s list. Maybe we&rsquo;ll see a third game on next year&rsquo;s list?</p>
<p>It&rsquo;s also rated <a href="https://www.protondb.com/app/1808500">Platinum</a>
 on ProtonDB.</p>
<p><a href="https://store.steampowered.com/app/1808500/ARC_Raiders/">Steam</a>
</p>
<h2 id="battlefield-6">Battlefield 6</h2>
<blockquote>
<p>PvP FPS explosion-simulator.</p>
</blockquote>
<p><a href="https://store.steampowered.com/app/2807960/Battlefield_6/"><img src="https://shared.fastly.steamstatic.com/store_item_assets/steam/apps/2807960/c12d12ce3c7d217398d3fcad77427bfc9d57c570/header.jpg" alt="Battlefield 6 hero image" title="Battlefield 6 hero image">
</a>
</p>
<p>Battlefield is back!</p>
<p>I&rsquo;ve played BF games ever since the first one, set all the way back in World War 2. I didn&rsquo;t buy BF5, and wasn&rsquo;t that impressed by 2042, so I was happy to see Battlefield make a comeback with 6.</p>
<p>And it was quite the comeback. Two of my friends bought new computers just to play it, and its launch weekend was the most active my little Discord server&rsquo;s ever been.</p>
<p>It&rsquo;s moved away from the slower, more tactical feel of its earlier entries though. If that older style is what you&rsquo;re after, games like <a href="https://www.joinsquad.com/">Squad</a>
 and <a href="https://www.hellletloose.com/">Hell Let Loose</a>
 now occupy that space.</p>
<p>With 6, Battlefield has settled into being a faster, more accessible squad-based shooter - and judged on those terms it&rsquo;s an excellent game. No wonder it was <a href="https://bsky.app/profile/matpiscatella.bsky.social/post/3ma6t4pndwc2w">the best selling FPS of the year</a>
.</p>
<p>Its only letdown is that it needs <a href="https://www.ea.com/games/battlefield/battlefield-6/news/secure-boot-information">Secure boot</a>
 to run the anti-cheat, which means you can&rsquo;t play it on Linux, so it gets a <a href="https://www.protondb.com/app/2807960">borked</a>
 rating on ProtonDB.</p>
<p><a href="https://store.steampowered.com/app/2807960/Battlefield_6/">Steam</a>
</p>
<h2 id="dying-light-the-beast">Dying Light: The Beast</h2>
<blockquote>
<p>First-person single-player/co-op story-driven parkour-action-zombie-killing.</p>
</blockquote>
<p><a href="https://store.steampowered.com/app/3008130/Dying_Light_The_Beast/"><img src="https://steamcdn-a.akamaihd.net/steam/apps/3008130/header.jpg" alt="Dying Light: The Beast hero image" title="Dying Light: The Beast hero image">
</a>
</p>
<p>The Beast is the best of the Dying Light series. Techland have improved on every part of the experience. And best of all, since I bought the deluxe edition of the second game, I got it for free!</p>
<p>It looks awesome, it runs well, and it&rsquo;s loads of fun. I&rsquo;m still playing through it in co-op, which lets up to 4 people be Kyle Crane, the protagonist from the first game.</p>
<p>Another <a href="https://www.protondb.com/app/3008130">Platinum</a>
 rating on ProtonDB.</p>
<p><a href="https://store.steampowered.com/app/3008130/Dying_Light_The_Beast/">Steam</a>
</p>
<h2 id="jump-space">Jump Space</h2>
<blockquote>
<p>Mission-based co-op PvE for up to 4 players.</p>
</blockquote>
<p><a href="https://store.steampowered.com/app/1757300/Jump_Space/"><img src="https://images.igdb.com/igdb/image/upload/t_1080p/ar3ysa.webp" alt="Jump Ship hero image" title="Jump Ship hero image">
</a>
</p>
<p>(Previously known as Jump Ship)</p>
<p>It&rsquo;s still in early access but Jump Space is more than playable right now. It&rsquo;s the chosen game for game night for us where once a week we crew a spaceship, fight some robots and <em>one of us</em> expertly puts out fires the others don&rsquo;t even notice because they&rsquo;re busy shooting space lasers.</p>
<p>Yet another <a href="https://www.protondb.com/app/1757300">Platinum</a>
 rating on ProtonDB.</p>
<p><a href="https://store.steampowered.com/app/1757300/Jump_Space/">Steam</a>
</p>
<h2 id="anno-117-pax-romana">Anno 117: Pax Romana</h2>
<blockquote>
<p>Single-player city-builder.</p>
</blockquote>
<p><a href="https://store.steampowered.com/app/3274580/Anno_117_Pax_Romana/"><img src="https://shared.fastly.steamstatic.com/store_item_assets/steam/apps/3274580/88dbcce1c7630e2d4334fa25e835968e57e0ebfe/header.jpg?t=1764100083" alt="Anno 117: Pax Romana hero image" title="Anno 117: Pax Romana hero image">
</a>
</p>
<p>Anno 117 is apparently very similar to Anno 1800 but in a different setting with different people, which is exactly what I wanted.</p>
<p>You build up an island, or a few of them, from humble beginnings all the way up to a mighty city, managing buildings, production, and trade.</p>
<p>It&rsquo;s a more relaxing game than the other ones on this list. There is a bit of combat, but its main appeal to me is the city building and the setting.</p>
<p>It gets only a <a href="https://www.protondb.com/app/3274580">Gold</a>
 rating on ProtonDB, which I can&rsquo;t confirm, I haven&rsquo;t yet tried it on Linux.</p>
<p><a href="https://store.steampowered.com/app/3274580/Anno_117_Pax_Romana/">Steam</a>
</p>
<h2 id="rv-there-yet">RV There Yet?</h2>
<blockquote>
<p>Co-op friendslop.</p>
</blockquote>
<p><a href="https://store.steampowered.com/app/3949040/RV_There_Yet/"><img src="https://shared.fastly.steamstatic.com/store_item_assets/steam/apps/3949040/cae24b4ed7f4531be51f0d63f785b7d253f92dc3/header.jpg?t=1766020280" alt="RV There Yet? hero image" title="RV There Yet? hero image">
</a>
</p>
<p>Friendslop is a new word for me. It&rsquo;s meant to define the low-stakes co-op games that are sold at low prices so that everyone in the group can afford to play them.</p>
<p>I don&rsquo;t know how true that definition is, I&rsquo;ve only ever played it with one person, who I can safely say is not qualified to drive an RV, whilst drinking a beer, smoking a cigarette, cooking burgers, being chased by a bear.</p>
<p>I almost put <a href="https://peak-game.com/">Peak</a>
 here, but so far I&rsquo;ve had more fun in RV There Yet?.</p>
<p>This game gets the last <a href="https://www.protondb.com/app/3949040">Platinum</a>
 rating on ProtonDB for games released in 2025, because this is the last of that list.</p>
<p><a href="https://store.steampowered.com/app/3949040/RV_There_Yet/">Steam</a>
</p>
<h2 id="not-released-in-2025">Not released in 2025</h2>
<p>These weren&rsquo;t released this year; they made the list anyway.</p>
<h3 id="the-beginners-guide">The Beginner&rsquo;s Guide</h3>
<blockquote>
<p>Single-player narrative-exploration-art.</p>
</blockquote>
<p><a href="https://store.steampowered.com/app/303210/The_Beginners_Guide/"><img src="https://shared.fastly.steamstatic.com/store_item_assets/steam/apps/303210/header.jpg?t=1765833998" alt="The Beginner&rsquo;s Guide hero image" title="The Beginner&#39;s Guide hero image">
</a>
</p>
<p>The Beginner&rsquo;s Guide took me a decade to play, and I&rsquo;m glad I finally did. It came out in 2015 and I got it this year as a Christmas present (thank you!). I played and finished it that same day.</p>
<p>It&rsquo;s made by the same developer as <a href="https://www.stanleyparable.com/">The Stanley Parable</a>
, which I really enjoyed, and it was a very different experience for this one. Whereas TSP was an interesting game, I&rsquo;d describe TBG as art. It doesn&rsquo;t involve much gameplay, and instead uses the medium of video games to do interactive storytelling.</p>
<p>Despite the rest of my list, I think you might need to view video games as an art-form, not just zombie-killing-space-laser-shooting-explosion-simulators, to really appreciate this one.</p>
<p>It gets a <a href="https://www.protondb.com/app/303210">Platinum</a>
 rating on ProtonDB and was natively released on Linux. I had to <a href="https://micro.paultibbetts.uk/2025/12/31/how-to-play-the-beginners.html">change a setting</a>
 to make it playable.</p>
<p><a href="https://store.steampowered.com/app/303210/The_Beginners_Guide/">Steam</a>
</p>
<h3 id="ministry-of-broadcast">Ministry of Broadcast</h3>
<blockquote>
<p>Single-player platformer</p>
</blockquote>
<p><a href="https://store.steampowered.com/app/874040/Ministry_of_Broadcast/"><img src="https://images.igdb.com/igdb/image/upload/t_1080p/ardda.webp" alt="Ministry of Broadcast hero image" title="Ministry of Broadcast hero image">
</a>
</p>
<p>Another Christmas present I&rsquo;m really enjoying. It&rsquo;s perfectly suited for the Steam Deck, so it also works well with a controller, and is the only game on this list where I get to lean back in my chair instead of forward.</p>
<p>It&rsquo;s inspired by George Orwell&rsquo;s 1984, which might be why I&rsquo;m liking it so much. Though I don&rsquo;t remember Winston falling off as many buildings as I have.</p>
<p><a href="https://www.protondb.com/app/874040">Platinum</a>
 rated on ProtonDB.</p>
<p><a href="https://store.steampowered.com/app/874040/Ministry_of_Broadcast/">Steam</a>
</p>
<h3 id="baldurs-gate-3">Baldur&rsquo;s Gate 3</h3>
<blockquote>
<p>Single-player / online co-op party-based RPG</p>
</blockquote>
<p><a href="https://store.steampowered.com/app/1086940/Baldurs_Gate_3/"><img src="https://shared.fastly.steamstatic.com/store_item_assets/steam/apps/1086940/48a2fcbda8565bb45025e98fd8ebde8a7203f6a0/header.jpg?t=1765505948" alt="Baldur&rsquo;s Gate 3 hero image" title="Baldur&#39;s Gate 3 hero image">
</a>
</p>
<p>I am still playing Baldur&rsquo;s Gate 3. I am still in Act 1. I know.</p>
<p>This is such a good game that I can&rsquo;t just turn it on mindlessly for 20 minutes. I need to settle in for an afternoon and play for a few hours at a time - to get into the right mind-frame and settle into being a powerful sorcerer.</p>
<p>Or whatever I am, I don&rsquo;t know, I&rsquo;ve never played D&amp;D before. My character keeps wanting to kill things, and I am happy to oblige.</p>
<p>I am sorry bard, I don&rsquo;t know what came over me.</p>
<p><a href="https://www.protondb.com/app/1086940">Gold</a>
 rated on ProtonDB, which is weird because it has a <a href="https://larian.com/support/faqs/steam-deck-native-version_121">native Linux build</a>
.</p>
<p><a href="https://store.steampowered.com/app/1086940/Baldurs_Gate_3/">Steam</a>
</p>]]></content:encoded><source:markdown>
Last year I wrote [my own take on the Steam Awards](https://micro.paultibbetts.uk/2025/01/03/pc-games-i-liked-in.html), and in 2025 I played less games, so instead of pretending otherwise, this is a list of my favourites from this year.

&lt;!--more--&gt;

## Dispatch

&gt; Single-player story-driven narrative.

[![Dispatch hero image](https://shared.fastly.steamstatic.com/store_item_assets/steam/apps/2592160/header.jpg &#34;Dispatch hero image&#34;)](https://store.steampowered.com/app/2592160/Dispatch/)

Dispatch might be _the_ funniest game I&#39;ve ever played. It&#39;s extremely well written, absurdly well voice acted and expertly made by the team that used to be Telltale Games.

It gives a real glimpse into the life of a superhero dispatcher and kept me entertained the whole way through.

I&#39;ll be playing whatever [Adhoc Studios](https://www.adhocla.com/) makes next. I hope it&#39;s Wolf Among Us 2 or another season of Dispatch. Either way, I&#39;m in.

It&#39;s rated [Platinum](https://www.protondb.com/app/2592160) on ProtonDB, so it plays great on Linux.

[Steam](https://store.steampowered.com/app/2592160/Dispatch/)

## Arc Raiders

&gt; Third-person PvPvE extraction-shooter.

[![Arc Raiders hero image](https://steamcdn-a.akamaihd.net/steam/apps/1808500/header.jpg &#34;Arc Raiders hero image&#34;)](https://store.steampowered.com/app/1808500/ARC_Raiders/)

I wasn&#39;t expecting to like Arc Raiders as much as I did. It makes the sweaty extraction-shooter genre more accessible, even if it is still pretty sweaty.

Escape from Tarkov was a bit too much for me; Arc Raiders has a much better balance. It&#39;s not for everyone, but it&#39;s that well done you might enjoy it even if you don&#39;t like similar games.

Whilst you can get shot by other players, it&#39;s the Arc that are the real threat, and this mix of danger, plus the proximity voice chat, make it unlike any other game out right now.

It won The Game Awards&#39; [Multiplayer Game of the Year](https://nitter.net/ARCRaidersGame/status/1999420050785042508?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1999420050785042508%7Ctwgr%5E%7Ctwcon%5Es1_&amp;ref_url=https%3A%2F%2Fwww.gamersheroes.com%2Fgaming-news%2Farc-raiders-best-multiplayer-game-of-2025-at-the-game-awards%2F), so don&#39;t just take my word for it.

[Embark](https://www.embark-studios.com/)&#39;s previous game, [The Finals](https://www.reachthefinals.com/), made it onto last year&#39;s list. Maybe we&#39;ll see a third game on next year&#39;s list?

It&#39;s also rated [Platinum](https://www.protondb.com/app/1808500) on ProtonDB.

[Steam](https://store.steampowered.com/app/1808500/ARC_Raiders/)

## Battlefield 6

&gt; PvP FPS explosion-simulator.

[![Battlefield 6 hero image](https://shared.fastly.steamstatic.com/store_item_assets/steam/apps/2807960/c12d12ce3c7d217398d3fcad77427bfc9d57c570/header.jpg &#34;Battlefield 6 hero image&#34;)](https://store.steampowered.com/app/2807960/Battlefield_6/)

Battlefield is back!

I&#39;ve played BF games ever since the first one, set all the way back in World War 2. I didn&#39;t buy BF5, and wasn&#39;t that impressed by 2042, so I was happy to see Battlefield make a comeback with 6.

And it was quite the comeback. Two of my friends bought new computers just to play it, and its launch weekend was the most active my little Discord server&#39;s ever been.

It&#39;s moved away from the slower, more tactical feel of its earlier entries though. If that older style is what you&#39;re after, games like [Squad](https://www.joinsquad.com/) and [Hell Let Loose](https://www.hellletloose.com/) now occupy that space.

With 6, Battlefield has settled into being a faster, more accessible squad-based shooter - and judged on those terms it&#39;s an excellent game. No wonder it was [the best selling FPS of the year](https://bsky.app/profile/matpiscatella.bsky.social/post/3ma6t4pndwc2w).

Its only letdown is that it needs [Secure boot](https://www.ea.com/games/battlefield/battlefield-6/news/secure-boot-information) to run the anti-cheat, which means you can&#39;t play it on Linux, so it gets a [borked](https://www.protondb.com/app/2807960) rating on ProtonDB.

[Steam](https://store.steampowered.com/app/2807960/Battlefield_6/)

## Dying Light: The Beast

&gt; First-person single-player/co-op story-driven parkour-action-zombie-killing.

[![Dying Light: The Beast hero image](https://steamcdn-a.akamaihd.net/steam/apps/3008130/header.jpg &#34;Dying Light: The Beast hero image&#34;)](https://store.steampowered.com/app/3008130/Dying_Light_The_Beast/)

The Beast is the best of the Dying Light series. Techland have improved on every part of the experience. And best of all, since I bought the deluxe edition of the second game, I got it for free!

It looks awesome, it runs well, and it&#39;s loads of fun. I&#39;m still playing through it in co-op, which lets up to 4 people be Kyle Crane, the protagonist from the first game.

Another [Platinum](https://www.protondb.com/app/3008130) rating on ProtonDB.

[Steam](https://store.steampowered.com/app/3008130/Dying_Light_The_Beast/)

## Jump Space

&gt; Mission-based co-op PvE for up to 4 players.

[![Jump Ship hero image](https://images.igdb.com/igdb/image/upload/t_1080p/ar3ysa.webp &#34;Jump Ship hero image&#34;)](https://store.steampowered.com/app/1757300/Jump_Space/)

(Previously known as Jump Ship)

It&#39;s still in early access but Jump Space is more than playable right now. It&#39;s the chosen game for game night for us where once a week we crew a spaceship, fight some robots and _one of us_ expertly puts out fires the others don&#39;t even notice because they&#39;re busy shooting space lasers.

Yet another [Platinum](https://www.protondb.com/app/1757300) rating on ProtonDB.

[Steam](https://store.steampowered.com/app/1757300/Jump_Space/)

## Anno 117: Pax Romana

&gt; Single-player city-builder.

[![Anno 117: Pax Romana hero image](https://shared.fastly.steamstatic.com/store_item_assets/steam/apps/3274580/88dbcce1c7630e2d4334fa25e835968e57e0ebfe/header.jpg?t=1764100083 &#34;Anno 117: Pax Romana hero image&#34;)](https://store.steampowered.com/app/3274580/Anno_117_Pax_Romana/)

Anno 117 is apparently very similar to Anno 1800 but in a different setting with different people, which is exactly what I wanted.

You build up an island, or a few of them, from humble beginnings all the way up to a mighty city, managing buildings, production, and trade.

It&#39;s a more relaxing game than the other ones on this list. There is a bit of combat, but its main appeal to me is the city building and the setting.

It gets only a [Gold](https://www.protondb.com/app/3274580) rating on ProtonDB, which I can&#39;t confirm, I haven&#39;t yet tried it on Linux.

[Steam](https://store.steampowered.com/app/3274580/Anno_117_Pax_Romana/)

## RV There Yet?

&gt; Co-op friendslop.

[![RV There Yet? hero image](https://shared.fastly.steamstatic.com/store_item_assets/steam/apps/3949040/cae24b4ed7f4531be51f0d63f785b7d253f92dc3/header.jpg?t=1766020280 &#34;RV There Yet? hero image&#34;)](https://store.steampowered.com/app/3949040/RV_There_Yet/)

Friendslop is a new word for me. It&#39;s meant to define the low-stakes co-op games that are sold at low prices so that everyone in the group can afford to play them.

I don&#39;t know how true that definition is, I&#39;ve only ever played it with one person, who I can safely say is not qualified to drive an RV, whilst drinking a beer, smoking a cigarette, cooking burgers, being chased by a bear.

I almost put [Peak](https://peak-game.com/) here, but so far I&#39;ve had more fun in RV There Yet?.

This game gets the last [Platinum](https://www.protondb.com/app/3949040) rating on ProtonDB for games released in 2025, because this is the last of that list.

[Steam](https://store.steampowered.com/app/3949040/RV_There_Yet/)

## Not released in 2025

These weren&#39;t released this year; they made the list anyway.

### The Beginner&#39;s Guide

&gt; Single-player narrative-exploration-art.

[![The Beginner&#39;s Guide hero image](https://shared.fastly.steamstatic.com/store_item_assets/steam/apps/303210/header.jpg?t=1765833998 &#34;The Beginner&#39;s Guide hero image&#34;)](https://store.steampowered.com/app/303210/The_Beginners_Guide/)

The Beginner&#39;s Guide took me a decade to play, and I&#39;m glad I finally did. It came out in 2015 and I got it this year as a Christmas present (thank you!). I played and finished it that same day.

It&#39;s made by the same developer as [The Stanley Parable](https://www.stanleyparable.com/), which I really enjoyed, and it was a very different experience for this one. Whereas TSP was an interesting game, I&#39;d describe TBG as art. It doesn&#39;t involve much gameplay, and instead uses the medium of video games to do interactive storytelling.

Despite the rest of my list, I think you might need to view video games as an art-form, not just zombie-killing-space-laser-shooting-explosion-simulators, to really appreciate this one.

It gets a [Platinum](https://www.protondb.com/app/303210) rating on ProtonDB and was natively released on Linux. I had to [change a setting](https://micro.paultibbetts.uk/2025/12/31/how-to-play-the-beginners.html) to make it playable.

[Steam](https://store.steampowered.com/app/303210/The_Beginners_Guide/)

### Ministry of Broadcast

&gt; Single-player platformer

[![Ministry of Broadcast hero image](https://images.igdb.com/igdb/image/upload/t_1080p/ardda.webp &#34;Ministry of Broadcast hero image&#34;)](https://store.steampowered.com/app/874040/Ministry_of_Broadcast/)

Another Christmas present I&#39;m really enjoying. It&#39;s perfectly suited for the Steam Deck, so it also works well with a controller, and is the only game on this list where I get to lean back in my chair instead of forward.

It&#39;s inspired by George Orwell&#39;s 1984, which might be why I&#39;m liking it so much. Though I don&#39;t remember Winston falling off as many buildings as I have.

[Platinum](https://www.protondb.com/app/874040) rated on ProtonDB.

[Steam](https://store.steampowered.com/app/874040/Ministry_of_Broadcast/)

### Baldur&#39;s Gate 3

&gt; Single-player / online co-op party-based RPG

[![Baldur&#39;s Gate 3 hero image](https://shared.fastly.steamstatic.com/store_item_assets/steam/apps/1086940/48a2fcbda8565bb45025e98fd8ebde8a7203f6a0/header.jpg?t=1765505948 &#34;Baldur&#39;s Gate 3 hero image&#34;)](https://store.steampowered.com/app/1086940/Baldurs_Gate_3/)

I am still playing Baldur&#39;s Gate 3. I am still in Act 1. I know.

This is such a good game that I can&#39;t just turn it on mindlessly for 20 minutes. I need to settle in for an afternoon and play for a few hours at a time - to get into the right mind-frame and settle into being a powerful sorcerer.

Or whatever I am, I don&#39;t know, I&#39;ve never played D&amp;D before. My character keeps wanting to kill things, and I am happy to oblige.

I am sorry bard, I don&#39;t know what came over me.

[Gold](https://www.protondb.com/app/1086940) rated on ProtonDB, which is weird because it has a [native Linux build](https://larian.com/support/faqs/steam-deck-native-version_121).

[Steam](https://store.steampowered.com/app/1086940/Baldurs_Gate_3/)
</source:markdown></item><item>
      <title>Pangolin on a Pi</title>
      <link>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/12/30/pangolin-on-a-pi/</link>
      <pubDate>Tue, 30 Dec 2025 15:10:00 +0000</pubDate>
      <guid>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/12/30/pangolin-on-a-pi/</guid>
      <category>homelab</category>
      <category>IPv6</category>
      <category>Pangolin</category>
      <category>Raspberry Pi</category>
      <description>This post is not a step-by-step guide. It’s a record of what I tried and what I learned getting Pangolin to run on a Raspberry Pi with NFS storage in an IPv6-only environment.
TLDR: if you want to run Pangolin hassle-free, use a VPS with local SSD storage on an IPv4 network.</description>
      <content:encoded><![CDATA[<p>This post is not a step-by-step guide. It&rsquo;s a record of what I tried and what I learned getting Pangolin to run on a Raspberry Pi with NFS storage in an IPv6-only environment.</p>
<p><strong>TLDR</strong>: if you want to run Pangolin hassle-free, use a VPS with local SSD storage on an IPv4 network.</p>
<h2 id="pangolin">Pangolin</h2>
<p><a href="https://digpangolin.com/">Pangolin</a>
 is a &ldquo;secure access platform&rdquo; for safely exposing internal services. I&rsquo;m using it to let friends and family reach a few apps in my homelab without giving them the keys to everything.</p>
<p>It&rsquo;s a free, open-source alternative to <a href="https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/">Cloudflare Tunnel</a>
 for those who like independence from Cloudflare, want to self-host the stack themselves, or prefer not to rely on a third-party network for media streaming, which is not its intended use-case.</p>
<p>If none of those things bother you then you&rsquo;ll be fine using Cloudflare Tunnel or one of the alternatives. Read the terms and conditions first, media streaming is a bit of a grey area, I am not a lawyer and that wasn&rsquo;t legal advice.</p>
<h2 id="alternatives">Alternatives</h2>
<p>I already use <a href="https://www.wireguard.com/">Wireguard</a>
 as a VPN, and I still use it myself to get into my home network. VPNs work, but they&rsquo;re not fun to manage for friends and family and I wanted the ability to lock them down to certain apps.</p>
<p>There&rsquo;s also <a href="https://tailscale.com/">Tailscale</a>
, <a href="https://netbird.io/">Netbird</a>
, and <a href="https://www.zerotier.com/">ZeroTier</a>
, which use Wireguard to make a mesh network, but that&rsquo;s more of the same VPN solution. I&rsquo;d need to set up profiles and install clients on devices, and I wanted something easier. Tailscale now has its own <a href="https://tailscale.com/kb/1223/funnel">Funnel</a>
 project, but by the time I&rsquo;d seen it I was already setting up Pangolin.</p>
<p>The last alternative to mention is that you can achieve a similar result by renting a server, adding it to your VPN, and setting up a reverse proxy on it. But then you&rsquo;d need something else to make it secure, and you end up back at Pangolin.</p>
<h2 id="hosting">Hosting</h2>
<p>Pangolin needs to be hosted outside your network, so I needed to rent a server. It doesn&rsquo;t need to be a big one, Pangolin can work with 1 vCPU and 1GB of RAM, but ideally it would be close to your internal network and the users that want to get into it.</p>
<p>I live in the UK, so my options were UK, Ireland or Europe. UK-based hosting turned out to be expensive, with Krystal charging <a href="https://krystal.io/cloud-vps">£12 per month</a>
, whereas Hetzner, based in Germany, offers the same specs for <a href="https://www.hetzner.com/cloud">£3.97</a>
.</p>
<p>I should have gone with Hetzner. The extra latency would likely have been ~20ms and for Pangolin&rsquo;s use case - web apps and media streaming - that wouldn&rsquo;t have been noticeable.</p>
<p>But at the time I wanted my server to be based in the UK, so I carried on looking, until I found <a href="https://www.mythic-beasts.com/">Mythic Beasts</a>
. Not only had they recently <a href="https://www.mythic-beasts.com/blog/2025/02/25/supporting-the-open-rights-group/">donated to the Open Rights Group</a>
, an organisation I also support, but they have a cluster of Raspberry Pis you can use.</p>
<p>My search was over. I wanted Pangolin on a Pi. I did some initial testing, and the early signs were good, so I signed up for a year.</p>
<h2 id="raspberry-pi">Raspberry Pi</h2>
<p>The Mythic Beasts Pis come with two obstacles to running Pangolin. The first is that they are IPv6 only, and the second is the storage they use. One of these involves a little workaround and the other makes it a bad choice for hosting Pangolin.</p>
<h3 id="nfs-storage">NFS Storage</h3>
<p>Pangolin is actually more of a stack, with Pangolin as the control plane, Traefik doing reverse proxying, Gerbil running the tunnel and a thing called Badger to do the middleware that checks for authentication. The easiest way to run it all is with Docker Compose, and this is the first hurdle to running Pangolin on a Mythic Beasts Pi.</p>
<p>The Pis only have network storage available, and Docker doesn&rsquo;t like that because NFS doesn&rsquo;t provide the kind of guarantees Docker wants from a filesystem. Docker <em>can</em> work with NFS, but only using the <code>vfs</code> storage driver. Unlike the default <code>overlay2</code> driver, which uses a layered filesystem, <code>vfs</code> doesn&rsquo;t share layers, so every image consumes more space than it should.</p>
<p>So not only does NFS end up being slow, copying over lots of small files, it means the Docker images can&rsquo;t do any of the space saving that would normally happen. I have 50GB of storage and it&rsquo;s at 70% usage, even though the final images only take up 2GB, all because of the way <code>vfs</code> does its layering.</p>
<p>Did I mention that it&rsquo;s slow? Starting up the containers takes about 15 minutes. Turning them off isn&rsquo;t fast either. And upgrades? You won&rsquo;t have room for the new images, so you&rsquo;ll have to turn everything off to remove the old ones before you can start downloading the new ones. This means upgrades can take about an hour, with Pangolin down the entire time.</p>
<h3 id="ipv6">IPv6</h3>
<p>The internet&rsquo;s ran out of IPv4 addresses, by the way, so the Pis are IPv6 only. This means you have to do a bit of extra work to make Pangolin available for everyone.</p>
<p>IPv6 is the future but support for it is still mixed, so Mythic Beasts have an IPv4 to IPv6 proxy to allow users stuck on IPv4-only networks to get to your server. To use it you configure the proxy to forward requests to your domain on to the IPv6 address of the Pi.</p>
<p>The other end of the tunnel, the one in your home network, is managed by a service called Newt. It needs to speak to Gerbil on the Pi, and I was not successful getting it to run with the default <code>pangolin.example.com</code> address I was using.</p>
<p>Newt is configured by pointing it at Pangolin, which advertises the Gerbil endpoint it should connect to. Maybe it was Pangolin, or the proxy, or even something else; I could not get it to work. To make some progress I changed the <code>base_endpoint</code> in <code>config/config.yml</code>. First I tried the IPv6 address of the Pi, but that still didn&rsquo;t work, so I created an AAAA record for Gerbil and pointed it at the Pi. This would do the same thing as the CNAME I&rsquo;d used for Pangolin, except that went through the proxy and maybe that was messing things up. This time, it worked.</p>
<p>Mythic Beasts <a href="https://www.mythic-beasts.com/support/topics/proxy">state their proxy</a>
:</p>
<blockquote>
<p>will relay traffic for common services, such as HTTP and HTTPS</p>
</blockquote>
<p>and I have a suspicion that Wireguard doesn&rsquo;t count as a &ldquo;common service&rdquo;.</p>
<h2 id="home-network">Home network</h2>
<p>The final hurdle to getting this setup to work was my own network. Since the proxy doesn&rsquo;t seem to forward Wireguard traffic, and I have to connect directly to the Pi with IPv6, my network needs to let me do that.</p>
<p>This means I need at least IPv6 egress. That doesn&rsquo;t mean full IPv6 support everywhere, just enough to have a usable outbound path. I tried a bunch of different things to get it to work, and some of my changes actually made things worse, so what follows is what worked for me, in case your setup is similar, most likely it isn&rsquo;t.</p>
<h3 id="isp-router">ISP router</h3>
<p>I&rsquo;m still using the router my ISP gave me, which has very basic IPv6 support. I&rsquo;m with Vodafone and it&rsquo;s the standard &ldquo;WiFi hub&rdquo; they gave out several years ago.</p>
<p>The right combination of buttons to press is under <code>Settings -&gt; Local Network</code> and you want:</p>
<p><code>IPv6</code> <strong>Enabled</strong></p>
<p><code>IPv6 ULA</code> <strong>Disabled</strong></p>
<p>The <code>IPv6</code> toggle enables Router Advertisements (RA) from the router and this gives hosts a global IPv6 address, and also tells them what the default route for IPv6 traffic is, which is through this router.</p>
<p>The <code>IPv6 ULA</code> toggle disables Unique Local Addresses, which is a private IPv6 space used for hosts to speak to each other over IPv6, and is not necessary for Newt to reach Gerbil, so it can be disabled.</p>
<h3 id="mesh-router">Mesh router</h3>
<p>I&rsquo;ve also got a pair of mesh devices I use as a wireless bridge between floors, since I&rsquo;m not able to run an ethernet cable.</p>
<p>They&rsquo;re definitely in bridge mode. However, in the admin panel under <code>Settings -&gt; Network -&gt; Advanced</code>, IPv6 was set to &ldquo;Auto Configuration&rdquo;, meaning they were also doing SLAAC and DHCPv6. This added to the confusion, not just for myself but for my devices, so I changed that to &ldquo;Local Connectivity Only&rdquo; to simplify things.</p>
<h3 id="dhcp">DHCP</h3>
<p>My ISP router sucks, it even crashed when I double checked the settings I mentioned above, so I&rsquo;ve moved DHCP off of it and instead do that with Pi-hole. It&rsquo;s way more stable and lets me view the admin panel without crashing.</p>
<p>An extra benefit of this is that when Pi-hole tells a device what its address is it will also tell them to use it as the DNS server, which makes it an automatic setup. The device now gets ad-blocking and can see the custom DNS records I&rsquo;ve set in Pi-hole without me doing anything.</p>
<h3 id="rdnss">RDNSS</h3>
<p>Except now that my ISP router is doing IPv6, it&rsquo;s also doing <abbr title="Recursive DNS Server">RDNSS</abbr>, which is DNS for IPv6, and I can&rsquo;t turn it off. This means it does the same thing that Pi-hole is doing but for IPv6 instead of 4. Since IPv6 is the future, every device on the network now prefers going to the router for DNS, instead of Pi-hole, so they lose the ad-blocking and custom DNS records I&rsquo;ve set.</p>
<p>If I had a better router that let me turn on IPv6 and either disable RDNSS, or advertise Pi-hole as the IPv6 DNS server, then this wouldn&rsquo;t be a problem. With my ISP router not letting me do that I could manually set every device to use Pi-hole for DNS, which is fine, unless you want to do it on Android.</p>
<h3 id="android">Android</h3>
<p>Most of the mobile devices in this house run iOS, which lets you manually set the DNS server, and allows you to enter an IPv4 address, which is fine for Pi-hole.</p>
<p>Android does it differently. It lets you set an IPv4 address, but if it sees RDNSS then it ignores your manual setting and uses that instead, which for me is the ISP router. So no ad-blocking or custom DNS records for Android devices.</p>
<p>This means if you&rsquo;re in the kitchen and want to check Mealie to see the recipe for tonight&rsquo;s meal you have to go out over the internet to come back and reach the server in the other room.</p>
<p>I don&rsquo;t personally use Android, but as the architect of the setup it still feels bad.</p>
<h3 id="router-dns">Router DNS</h3>
<p>There is a fix, although it&rsquo;s not ideal, and that&rsquo;s to set my router&rsquo;s DNS to use Pi-hole. I had initially forgotten about doing this, because I thought it was already setup, but it turns out I&rsquo;d turned it off for good reason.</p>
<p>Whilst it works, and the Android devices can now see apps in my homelab, all the traffic goes to Pi-hole through the router, so you can&rsquo;t distinguish where it came from. I don&rsquo;t really need this, but I remember now why I preferred Pi-hole handing out its own address as the DNS server.</p>
<h2 id="what-i-could-do-to-improve-it">What I could do to improve it</h2>
<p>This project has made me question, well a lot of things. The ability to update my RSS feeds without toggling my VPN on and off is kinda nice, and I can share limited access to my homelab with my friends and family, so for now it can stay.</p>
<p>Here&rsquo;s what would make it better:</p>
<h3 id="use-a-vps-with-ssd-storage-on-an-ipv4-network">Use a VPS with SSD storage on an IPv4 network</h3>
<p>This is the most obvious improvement to the setup.</p>
<p>The NFS storage on the Pi makes it a bad choice to run Docker Compose setups like the Pangolin stack. It works, but startup and even shutdown take too long and so upgrades have far more downtime than they should. NFS is fine for storage for the containers, but it&rsquo;s not suitable for running the containers themselves.</p>
<p>The IPv4 to IPv6 proxy that I&rsquo;m using doesn&rsquo;t forward Wireguard traffic, so I&rsquo;ve had to set up IPv6 in my network, which has caused some manual work I wasn&rsquo;t expecting.</p>
<p>To be clear, the Pi itself is not to blame for any of this, it&rsquo;s more than capable of handling the Pangolin stack. It&rsquo;s the fact it only has NFS storage that lets it down. The proxy not forwarding Wireguard can be worked around, and both are completely understandable tradeoffs that Mythic Beasts have made to make Raspberry PI hosting available in the first place.</p>
<p>The improvement would be to use a VPS, or even another Pi if I could find one, that uses fast local storage and is on an IPv4 network, or has a proxy available that also forwards Wireguard traffic.</p>
<p>If I hadn&rsquo;t already committed to a 12 month contract for the Pi I would have already done this. If I can find an alternative use for it maybe I&rsquo;ll move before the contract runs out.</p>
<p>Until then, I&rsquo;m not doing this.</p>
<h3 id="host-pangolin-without-docker">Host Pangolin without Docker</h3>
<p>This is entirely possible, but goes against the point of using Pangolin. I wanted an easy to use system, and as soon as I start deploying each part of it myself and connecting all the parts together it&rsquo;s no longer simple or easy to use.</p>
<p>The same goes for installing Wireguard manually on the Pi and reverse proxying through it into my homelab. I&rsquo;ve already got a Wireguard server up and running, so that&rsquo;s half the job already done, but then I&rsquo;d need to setup something to secure access into that tunnel, and that&rsquo;s what Pangolin&rsquo;s for.</p>
<h3 id="bluegreen-deployments">Blue/Green deployments</h3>
<p>NFS means the Pi takes a while to run upgrades, so there&rsquo;s about an hour of downtime.</p>
<p>I could get around this by spinning up a second Pi, installing the upgraded software, somehow sync the configs, and then switch the DNS to point to the upgraded Pi.</p>
<p>This wouldn&rsquo;t solve any of the problems except the downtime, and it would cost me more money to do so. I&rsquo;m not doing that. My friends and family will have to put up with the downtime.</p>
<p>They could chip in to cover the costs, but that turns the whole thing into a business arrangement and I don&rsquo;t want to go down that road.</p>
<h3 id="get-a-better-router">Get a better router</h3>
<p>This is more of a homelab quality-of-life improvement than a Pangolin-specific fix.</p>
<p>Getting rid of the ISP router and replacing it with something better would mean I can stop using Pi-hole for DHCP and only use it for its original intended purpose, DNS.</p>
<p>It only needs the ability to change the RDNSS setting to advertise Pi-hole as the DNS server to be better than my ISP router. Forwarding DNS through the router works, but advertising Pi-hole directly would preserve the per-device visibility in Pi-hole that I originally had for all devices.</p>
<p>This may need to happen anyway, but I wasn&rsquo;t looking to do this right now, so for now it isn&rsquo;t a priority. When I do upgrade, OpenWRT, OPNsense and pfSense would all allow me to use Pi-hole for RDNSS.</p>
<h3 id="host-my-own-ipv4-to-ipv6-proxy">Host my own IPv4 to IPv6 proxy</h3>
<p>I could technically go back to IPv4 only in my network if the proxy I use to connect to the Pi also forwarded Wireguard connections. Since the current one doesn&rsquo;t, the only options are to setup IPv6 in my home network or host my own proxy that can.</p>
<p>I picked the Pi because it was the cheapest UK-based hosting I could find, and this doubles the cost, so it isn&rsquo;t really an option.</p>
<p>Also I don&rsquo;t want to host a tunnel for my tunnel. That&rsquo;s too many tunnels.</p>
<h2 id="would-i-do-this-again">Would I do this again?</h2>
<p>Absolutely not.</p>
<h3 id="am-i-glad-i-tried-it">Am I glad I tried it?</h3>
<p>Yes. That&rsquo;s the point of a homelab.</p>]]></content:encoded><source:markdown>
This post is not a step-by-step guide. It&#39;s a record of what I tried and what I learned getting Pangolin to run on a Raspberry Pi with NFS storage in an IPv6-only environment.

**TLDR**: if you want to run Pangolin hassle-free, use a VPS with local SSD storage on an IPv4 network.

&lt;!--more--&gt;

## Pangolin

[Pangolin](https://digpangolin.com/) is a &#34;secure access platform&#34; for safely exposing internal services. I&#39;m using it to let friends and family reach a few apps in my homelab without giving them the keys to everything.

It&#39;s a free, open-source alternative to [Cloudflare Tunnel](https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/) for those who like independence from Cloudflare, want to self-host the stack themselves, or prefer not to rely on a third-party network for media streaming, which is not its intended use-case.

If none of those things bother you then you&#39;ll be fine using Cloudflare Tunnel or one of the alternatives. Read the terms and conditions first, media streaming is a bit of a grey area, I am not a lawyer and that wasn&#39;t legal advice.

## Alternatives

I already use [Wireguard](https://www.wireguard.com/) as a VPN, and I still use it myself to get into my home network. VPNs work, but they&#39;re not fun to manage for friends and family and I wanted the ability to lock them down to certain apps.

There&#39;s also [Tailscale](https://tailscale.com/), [Netbird](https://netbird.io/), and [ZeroTier](https://www.zerotier.com/), which use Wireguard to make a mesh network, but that&#39;s more of the same VPN solution. I&#39;d need to set up profiles and install clients on devices, and I wanted something easier. Tailscale now has its own [Funnel](https://tailscale.com/kb/1223/funnel) project, but by the time I&#39;d seen it I was already setting up Pangolin.

The last alternative to mention is that you can achieve a similar result by renting a server, adding it to your VPN, and setting up a reverse proxy on it. But then you&#39;d need something else to make it secure, and you end up back at Pangolin.

## Hosting

Pangolin needs to be hosted outside your network, so I needed to rent a server. It doesn&#39;t need to be a big one, Pangolin can work with 1 vCPU and 1GB of RAM, but ideally it would be close to your internal network and the users that want to get into it.

I live in the UK, so my options were UK, Ireland or Europe. UK-based hosting turned out to be expensive, with Krystal charging [£12 per month](https://krystal.io/cloud-vps), whereas Hetzner, based in Germany, offers the same specs for [£3.97](https://www.hetzner.com/cloud).

I should have gone with Hetzner. The extra latency would likely have been ~20ms and for Pangolin&#39;s use case - web apps and media streaming - that wouldn&#39;t have been noticeable.

But at the time I wanted my server to be based in the UK, so I carried on looking, until I found [Mythic Beasts](https://www.mythic-beasts.com/). Not only had they recently [donated to the Open Rights Group](https://www.mythic-beasts.com/blog/2025/02/25/supporting-the-open-rights-group/), an organisation I also support, but they have a cluster of Raspberry Pis you can use.

My search was over. I wanted Pangolin on a Pi. I did some initial testing, and the early signs were good, so I signed up for a year.

## Raspberry Pi

The Mythic Beasts Pis come with two obstacles to running Pangolin. The first is that they are IPv6 only, and the second is the storage they use. One of these involves a little workaround and the other makes it a bad choice for hosting Pangolin.

### NFS Storage

Pangolin is actually more of a stack, with Pangolin as the control plane, Traefik doing reverse proxying, Gerbil running the tunnel and a thing called Badger to do the middleware that checks for authentication. The easiest way to run it all is with Docker Compose, and this is the first hurdle to running Pangolin on a Mythic Beasts Pi.

The Pis only have network storage available, and Docker doesn&#39;t like that because NFS doesn&#39;t provide the kind of guarantees Docker wants from a filesystem. Docker _can_ work with NFS, but only using the `vfs` storage driver. Unlike the default `overlay2` driver, which uses a layered filesystem, `vfs` doesn&#39;t share layers, so every image consumes more space than it should.

So not only does NFS end up being slow, copying over lots of small files, it means the Docker images can&#39;t do any of the space saving that would normally happen. I have 50GB of storage and it&#39;s at 70% usage, even though the final images only take up 2GB, all because of the way `vfs` does its layering.

Did I mention that it&#39;s slow? Starting up the containers takes about 15 minutes. Turning them off isn&#39;t fast either. And upgrades? You won&#39;t have room for the new images, so you&#39;ll have to turn everything off to remove the old ones before you can start downloading the new ones. This means upgrades can take about an hour, with Pangolin down the entire time.

### IPv6

The internet&#39;s ran out of IPv4 addresses, by the way, so the Pis are IPv6 only. This means you have to do a bit of extra work to make Pangolin available for everyone.

IPv6 is the future but support for it is still mixed, so Mythic Beasts have an IPv4 to IPv6 proxy to allow users stuck on IPv4-only networks to get to your server. To use it you configure the proxy to forward requests to your domain on to the IPv6 address of the Pi.

The other end of the tunnel, the one in your home network, is managed by a service called Newt. It needs to speak to Gerbil on the Pi, and I was not successful getting it to run with the default `pangolin.example.com` address I was using.

Newt is configured by pointing it at Pangolin, which advertises the Gerbil endpoint it should connect to. Maybe it was Pangolin, or the proxy, or even something else; I could not get it to work. To make some progress I changed the `base_endpoint` in `config/config.yml`. First I tried the IPv6 address of the Pi, but that still didn&#39;t work, so I created an AAAA record for Gerbil and pointed it at the Pi. This would do the same thing as the CNAME I&#39;d used for Pangolin, except that went through the proxy and maybe that was messing things up. This time, it worked.

Mythic Beasts [state their proxy](https://www.mythic-beasts.com/support/topics/proxy):

&gt; will relay traffic for common services, such as HTTP and HTTPS

and I have a suspicion that Wireguard doesn&#39;t count as a &#34;common service&#34;.

## Home network

The final hurdle to getting this setup to work was my own network. Since the proxy doesn&#39;t seem to forward Wireguard traffic, and I have to connect directly to the Pi with IPv6, my network needs to let me do that.

This means I need at least IPv6 egress. That doesn&#39;t mean full IPv6 support everywhere, just enough to have a usable outbound path. I tried a bunch of different things to get it to work, and some of my changes actually made things worse, so what follows is what worked for me, in case your setup is similar, most likely it isn&#39;t.

### ISP router

I&#39;m still using the router my ISP gave me, which has very basic IPv6 support. I&#39;m with Vodafone and it&#39;s the standard &#34;WiFi hub&#34; they gave out several years ago.

The right combination of buttons to press is under `Settings -&gt; Local Network` and you want:

`IPv6` **Enabled**

`IPv6 ULA` **Disabled**

The `IPv6` toggle enables Router Advertisements (RA) from the router and this gives hosts a global IPv6 address, and also tells them what the default route for IPv6 traffic is, which is through this router.

The `IPv6 ULA` toggle disables Unique Local Addresses, which is a private IPv6 space used for hosts to speak to each other over IPv6, and is not necessary for Newt to reach Gerbil, so it can be disabled.

### Mesh router

I&#39;ve also got a pair of mesh devices I use as a wireless bridge between floors, since I&#39;m not able to run an ethernet cable.

They&#39;re definitely in bridge mode. However, in the admin panel under `Settings -&gt; Network -&gt; Advanced`, IPv6 was set to &#34;Auto Configuration&#34;, meaning they were also doing SLAAC and DHCPv6. This added to the confusion, not just for myself but for my devices, so I changed that to &#34;Local Connectivity Only&#34; to simplify things.

### DHCP

My ISP router sucks, it even crashed when I double checked the settings I mentioned above, so I&#39;ve moved DHCP off of it and instead do that with Pi-hole. It&#39;s way more stable and lets me view the admin panel without crashing.

An extra benefit of this is that when Pi-hole tells a device what its address is it will also tell them to use it as the DNS server, which makes it an automatic setup. The device now gets ad-blocking and can see the custom DNS records I&#39;ve set in Pi-hole without me doing anything.

### RDNSS

Except now that my ISP router is doing IPv6, it&#39;s also doing &lt;abbr title=&#34;Recursive DNS Server&#34;&gt;RDNSS&lt;/abbr&gt;, which is DNS for IPv6, and I can&#39;t turn it off. This means it does the same thing that Pi-hole is doing but for IPv6 instead of 4. Since IPv6 is the future, every device on the network now prefers going to the router for DNS, instead of Pi-hole, so they lose the ad-blocking and custom DNS records I&#39;ve set.

If I had a better router that let me turn on IPv6 and either disable RDNSS, or advertise Pi-hole as the IPv6 DNS server, then this wouldn&#39;t be a problem. With my ISP router not letting me do that I could manually set every device to use Pi-hole for DNS, which is fine, unless you want to do it on Android.

### Android

Most of the mobile devices in this house run iOS, which lets you manually set the DNS server, and allows you to enter an IPv4 address, which is fine for Pi-hole.

Android does it differently. It lets you set an IPv4 address, but if it sees RDNSS then it ignores your manual setting and uses that instead, which for me is the ISP router. So no ad-blocking or custom DNS records for Android devices.

This means if you&#39;re in the kitchen and want to check Mealie to see the recipe for tonight&#39;s meal you have to go out over the internet to come back and reach the server in the other room.

I don&#39;t personally use Android, but as the architect of the setup it still feels bad.

### Router DNS

There is a fix, although it&#39;s not ideal, and that&#39;s to set my router&#39;s DNS to use Pi-hole. I had initially forgotten about doing this, because I thought it was already setup, but it turns out I&#39;d turned it off for good reason.

Whilst it works, and the Android devices can now see apps in my homelab, all the traffic goes to Pi-hole through the router, so you can&#39;t distinguish where it came from. I don&#39;t really need this, but I remember now why I preferred Pi-hole handing out its own address as the DNS server.

## What I could do to improve it

This project has made me question, well a lot of things. The ability to update my RSS feeds without toggling my VPN on and off is kinda nice, and I can share limited access to my homelab with my friends and family, so for now it can stay.

Here&#39;s what would make it better:

### Use a VPS with SSD storage on an IPv4 network

This is the most obvious improvement to the setup.

The NFS storage on the Pi makes it a bad choice to run Docker Compose setups like the Pangolin stack. It works, but startup and even shutdown take too long and so upgrades have far more downtime than they should. NFS is fine for storage for the containers, but it&#39;s not suitable for running the containers themselves.

The IPv4 to IPv6 proxy that I&#39;m using doesn&#39;t forward Wireguard traffic, so I&#39;ve had to set up IPv6 in my network, which has caused some manual work I wasn&#39;t expecting.

To be clear, the Pi itself is not to blame for any of this, it&#39;s more than capable of handling the Pangolin stack. It&#39;s the fact it only has NFS storage that lets it down. The proxy not forwarding Wireguard can be worked around, and both are completely understandable tradeoffs that Mythic Beasts have made to make Raspberry PI hosting available in the first place.

The improvement would be to use a VPS, or even another Pi if I could find one, that uses fast local storage and is on an IPv4 network, or has a proxy available that also forwards Wireguard traffic.

If I hadn&#39;t already committed to a 12 month contract for the Pi I would have already done this. If I can find an alternative use for it maybe I&#39;ll move before the contract runs out.

Until then, I&#39;m not doing this.

### Host Pangolin without Docker

This is entirely possible, but goes against the point of using Pangolin. I wanted an easy to use system, and as soon as I start deploying each part of it myself and connecting all the parts together it&#39;s no longer simple or easy to use.

The same goes for installing Wireguard manually on the Pi and reverse proxying through it into my homelab. I&#39;ve already got a Wireguard server up and running, so that&#39;s half the job already done, but then I&#39;d need to setup something to secure access into that tunnel, and that&#39;s what Pangolin&#39;s for.

### Blue/Green deployments

NFS means the Pi takes a while to run upgrades, so there&#39;s about an hour of downtime.

I could get around this by spinning up a second Pi, installing the upgraded software, somehow sync the configs, and then switch the DNS to point to the upgraded Pi.

This wouldn&#39;t solve any of the problems except the downtime, and it would cost me more money to do so. I&#39;m not doing that. My friends and family will have to put up with the downtime.

They could chip in to cover the costs, but that turns the whole thing into a business arrangement and I don&#39;t want to go down that road.

### Get a better router

This is more of a homelab quality-of-life improvement than a Pangolin-specific fix.

Getting rid of the ISP router and replacing it with something better would mean I can stop using Pi-hole for DHCP and only use it for its original intended purpose, DNS.

It only needs the ability to change the RDNSS setting to advertise Pi-hole as the DNS server to be better than my ISP router. Forwarding DNS through the router works, but advertising Pi-hole directly would preserve the per-device visibility in Pi-hole that I originally had for all devices.

This may need to happen anyway, but I wasn&#39;t looking to do this right now, so for now it isn&#39;t a priority. When I do upgrade, OpenWRT, OPNsense and pfSense would all allow me to use Pi-hole for RDNSS.

### Host my own IPv4 to IPv6 proxy

I could technically go back to IPv4 only in my network if the proxy I use to connect to the Pi also forwarded Wireguard connections. Since the current one doesn&#39;t, the only options are to setup IPv6 in my home network or host my own proxy that can.

I picked the Pi because it was the cheapest UK-based hosting I could find, and this doubles the cost, so it isn&#39;t really an option.

Also I don&#39;t want to host a tunnel for my tunnel. That&#39;s too many tunnels.

## Would I do this again?

Absolutely not.

### Am I glad I tried it?

Yes. That&#39;s the point of a homelab.
</source:markdown></item>
  </channel>
</rss>
