General Error Assistance

Expected Behaviour:

Errors during debug, unsure of cause or solutions. My understanding of Docker and pihole are both rather limited, as I’m not very knowledgeable in networking. Decided to run a debug because the admin panel shows “Warning in NTP client:” from about a week ago.

Run on stock Pi5 running Bookworm v.12.

Docker version is 28.5.1. build e180ab8

Docker-compose.yml:

services:
  pihole:
    container_name: pihole
    image: pihole/pihole:latest
    ports:
      # DNS Ports
      - "53:53/tcp"
      - "53:53/udp"
      # Default HTTP Port
      - "80:80/tcp"
      # Default HTTPs Port. FTL will generate a self-signed certificate
      - "443:443/tcp"
      # Uncomment the below if using Pi-hole as your DHCP Server
      #- "67:67/udp"
      # Uncomment the line below if you are using Pi-hole as your NTP server
      #- "123:123/udp"
    environment:
      # Set the appropriate timezone for your location from
      # https://en.wikipedia.org/wiki/List_of_tz_database_time_zones, e.g:
      TZ: 'America/New_York'
      # Set a password to access the web interface. Not setting one will result in a random password being assigned
      FTLCONF_webserver_api_password:
      # If using Docker's default `bridge` network setting the dns listening mode should be set to 'all'
      FTLCONF_dns_listeningMode: 'all'
      # Volumes store your data between container upgrades
    volumes:
      # For persisting Pi-hole's databases and common configuration file
      - './etc-pihole:/etc/pihole'
      # Uncomment the below if you have custom dnsmasq config files that you want to persist. Not needed for most starting fresh with Pi-hole v6. If you're upgrading from v5 you and have used this directory before, you should keep it enabled for the first v6 container start to allow for a complete migration. It can be removed afterwards. Needs environment variable FTLCONF_misc_etc_dnsmasq_d: 'true'
      #- './etc-dnsmasq.d:/etc/dnsmasq.d'
    cap_add:
      # See https://github.com/pi-hole/docker-pi-hole#note-on-capabilities
      # Required if you are using Pi-hole as your DHCP server, else not needed
      - NET_ADMIN
      # Required if you are using Pi-hole as your NTP client to be able to set the host's system time
      - SYS_TIME
      # Optional, if Pi-hole should get some more processing time
      - SYS_NICE
    restart: unless-stopped

Actual Behaviour:

Unsure if related, but I have noticed a lot of ads getting through where this has not been a previous issue. Could be just a coincidence or my own lack of awareness, but I’m not experiencing any major deviations from expected behavior.

Debug Token:

https://tricorder.pi-hole.net/y2M4706Q/

As the host and the Docker containers share the same clock, you can safely disable time syncing in the container:

Pi-hole Settings > System > flip Basic to Expert > All settings > Network Time Sync > ntp.sync.active

Just as long as the Docker host itself is able to sync time.
Plus I'm pretty sure the container is unable to set/sync date/time for the host machine.

EDIT: Oops I was wrong with above.
With the right caps it can:

But still, you dont need two time keepers.