pihole in podman container on SELinux, all kinds of issues

Hi :slight_smile:

I'm very much a newbie trying for the first time to get pihole set up on an old laptop running Rocky Linux so I can use it as a network-wide ad blocker. I was able to get pihole running on it before (there were just some DNS settings i had yet to figure out), but the next day it stopped working and I haven't been able to fix it.

It's been driving me crazy, I hope someone will be able to point me in the right direction.

Expected Behaviour:

On Rocky Linux 10.8, after starting the podman 4.9.4 container with the following yml file:

services:
  pihole:
    container_name: pihole
    image: pihole/pihole:latest
    dns: 8.8.8.8
    ports:
      # DNS Ports
      - "53:53/tcp"
      - "53:53/udp"
      # Default HTTP Port
      - "80:80/tcp"
      # Default HTTPs Port. FTL will generate a self-signed certificate
      - "443:443/tcp"
      # Uncomment the below if using Pi-hole as your DHCP Server
      - "67:67/udp"
      # Uncomment the line below if you are using Pi-hole as your NTP server
      #- "123:123/udp"
    environment:
      # Set the appropriate timezone for your location from
      # https://en.wikipedia.org/wiki/List_of_tz_database_time_zones, e.g:
      TZ: 'Europe/Zurich'
      # Set a password to access the web interface. Not setting one will result in a random password being assigned
      # If using Docker's default `bridge` network setting the dns listening mode should be set to 'ALL'
      FTLCONF_dns_listeningMode: 'ALL'
    # Volumes store your data between container upgrades
    volumes:
      # For persisting Pi-hole's databases and common configuration file
      - './etc-pihole:/etc/pihole'
      # Uncomment the below if you have custom dnsmasq config files that you want to persist. Not needed for most starting fresh with Pi-hole v6. If you're upgrading from v5 you and have used this directory before, you should keep it enabled for the first v6 container start to allow for a complete migration. It can be removed afterwards. Needs environment variable FTLCONF_misc_etc_dnsmasq_d: 'true'
      - './etc-dnsmasq.d:/etc/dnsmasq.d'
    cap_add:
      # See https://docs.pi-hole.net/docker/configuration/#note-on-capabilities
      # Required if you are using Pi-hole as your DHCP server, else not needed
      - NET_ADMIN
      # Required if you are using Pi-hole as your NTP client to be able to set the host's system time
      - SYS_TIME
      # Optional, if Pi-hole should get some more processing time
      - SYS_NICE
    restart: unless-stopped

and after confirming that the container is up and running with podman ps I expect to see the pihole web interface when i navigate to http://<ip-address>/admin.

Actual Behaviour:

I am met with the following message on the web interface:

This site can’t be reached
The connection was reset.
Try:

Checking the connection
Checking the proxy and the firewall
ERR_CONNECTION_RESET

Debug Token:

(I had to run pihole -d inside the podman container, so after podman exec -it pihole bash)

https://tricorder.pi-hole.net/Pow09aDa/

Your debug log shows a few different issues.

  • The first one is related to the DNS port (53).
    Port 53 is already used by some service on the host:

    *** [ DIAGNOSING ]: Ports in use
    [βœ—] udp:0.0.0.0:53 is in use by
    [βœ—] udp:*:53 is in use by
    [βœ—] tcp:0.0.0.0:53 is in use by
    [βœ—] tcp:*:53 is in use by 
    

    The debug log can't find the service name (not enough permissions inside the container).

    You need to disable the service that is using this port on the host.

  • Pi-hole can't find many files, probably because there is an issue with permissions and the container can't create the files:

    2026-08-31 19:08:38.004 CEST [9M] INFO: Config file /etc/pihole/pihole.toml not available (r): No such file or directory
    
    ...
    
    2026-08-31 19:18:52.304 CEST [72M] ERROR: SQLite3: os_unix.c:46874: (0) open(/etc/pihole/pihole-FTL.db) -  (14)
    2026-08-31 19:18:52.305 CEST [72M] ERROR: Error while trying to open database: unable to open database file
    
    ...
    
    2026-08-31 19:18:53.016 CEST [72/T74] ERROR: Cannot read gravity database at /etc/pihole/gravity.db - file does not exist or is not readable
    
  • The other issue explains why the web server is not running:

    -rw-r--r-- 1 pihole pihole 165 Aug 31 19:08 /var/log/pihole/webserver.log
       -----head of webserver.log------
       [2026-08-31 19:08:40.881 CEST 72] Initializing HTTP server on ports "80o,443os,[::]:80o,[::]:443os"
       [2026-08-31 19:08:40.959 CEST 72] Error initializing SSL context
    

    There is an issue with the certificate and the HTTPS initialization fails.

    My guess is:
    there is a permission issue and the certificate can't be written to the disk. Without a certificate, the web server doesn't start.

yeah what rdwebdesign said about port 53 and the missing files is probably the main mess. on rocky with selinux though, in my experience the volume mounts also need the :Z (or :z) label or the container just cant write /etc/pihole and then the cert/db stuff fails the same way your log shows.

so maybe something like ./etc-pihole:/etc/pihole:Z and same for dnsmasq.d, then podman unshare chown -R if needed, and free host dns on 53 first. after that the web ui usually comes back.