DISCLAIMER: On my system (which is acting as the lan gateway), this opens port 53 and port 80 to the public despite my firewalld configuration blocking all external connections. Please don't use this configuration in production!
I was able to get pihole running with podman and systemd with the following service unit in /etc/systemd/system/pihole.service:
[Unit]
Description=Podman pihole.service
Documentation=man:podman-generate-systemd(1)
Wants=network.target
After=network-online.target
[Service]
Type=simple
User=root
Environment=PODMAN_SYSTEMD_UNIT=%n
EnvironmentFile=/etc/sysconfig/pihole
ExecStartPre=/bin/rm -f %t/container-pihole.pid %t/container-pihole.ctr-id
ExecStart=/usr/bin/podman run --env-file=/etc/sysconfig/pihole --pull=always --cidfile %t/container-pihole.ctr-id --cgroups=no-conmon --replace --name pihole -p ${PIFACE}:53:53/tcp -p ${PIFACE}:53:53/udp -p ${PIFACE}:80:80 -p ${PIFACE}:443:443 -v /etc/pihole/:/etc/pihole/:z -v /etc/pihole/dnsmasq.d/:/etc/dnsmasq.d/:z --dns=127.0.0.1 --dns=9.9.9.9 --hostname ${HOSTNAME} docker.io/pihole/pihole:latest
TimeoutStartSec=30s
TimeoutStopSec=30s
ExecStopPost=/usr/bin/podman rm --ignore -f --cidfile %t/container-pihole.ctr-id
#CapabilityBoundingSet=SYS_RESOURCE NET_ADMIN # this didn't work for me
[Install]
WantedBy=multi-user.target default.target
And my environment file in /etc/sysconfig/pihole (replace pi.hole with your hostname and change the password ofc):
TZ=America/New_York
WEBPASSWORD=password123
DNS1=8.8.8.8
DNS2=9.9.9.9
DNSSEC=rue
HOSTNAME=pi.hole
VIRTUAL_HOST=pi.hole
PROXY_LOCATION=pi.hole
ServerIP=192.168.1.1
PIFACE=192.168.1.1