these 48 derivations will be built: /nix/store/07pghvsywprcxk5n9dzbmmplw3dp2ani-unit-acme-account-7998a3b359822a28de2d.target.drv /nix/store/120lxjzl7ba414yfkkzf5gadv2x51gp9-acme-postrun.drv /nix/store/6kdyayv2wsdwgkaisn7vlfjqidvm23s6-sshd.conf-settings.drv /nix/store/17n2jn6khp1s9j248qcam5x9c218rn3d-sshd.conf-final.drv /nix/store/26118y1gvhi62gj5xzlzcxr2qglmrxry-unit-acme-account-77910265d11d16c51f22.target.drv /nix/store/4bl9m348ybnfc9psqlhqc2r1rdmimfz7-unit-oauth2-proxy.service.drv /nix/store/gmpy9ya9999i19schqnjzf1slk4mqz6z-acme-postrun.drv /nix/store/4h2yxbfnim3al69g0h9fiqp3a72b2yc2-unit-acme-order-renew-idm.mulatta.io.service.drv /nix/store/n9nkrcd2za8dq7i04s8f50r09f09rvbi-unit-script-acme-order-renew-mulatta.io-start.drv /nix/store/5qy5hmgzncy02hys5j9b3nc6f9c11p5p-unit-acme-order-renew-mulatta.io.service.drv /nix/store/5vpvb0dwa17m6zdg5ja42c80afxa57x7-unit-nginx-config-reload.service.drv /nix/store/6j6hvkljj51ljpy7a8kwp4pzb1iysrb8-acme-setup-privileged.drv /nix/store/6dzwgw09pviv8l3vmmkhjdq1zxdcd3l6-unit-acme-setup.service.drv /nix/store/6sx45fcqlf2qg4ppaf3ymk1j8sck2y0p-unit-acme-renew-mail.mulatta.io.timer.drv /nix/store/8fm6yc5i25kx303s7jjcigzmay0c0i94-unit-oauth2-proxy-restate.service.drv /nix/store/adyq7v6cmhbx282gy8f2pyq7sr491b8b-nginx.conf.drv /nix/store/viifb5mhhmjjk161sdm76yh7acv33ds0-unit-script-nginx-pre-start.drv /nix/store/8n7hxsqbk0lxsc8lkldlxda0mjc32qwh-unit-nginx.service.drv /nix/store/90f0jcs56mw0nxraxj8nx3qpcxa7jy9w-unit-acme-renew-ca.x.timer.drv /nix/store/hc3xrv2n7w49s9cj6adyz7mpjsl23yrh-unit-script-acme-mulatta.io-start.drv /nix/store/q5f55fl2pbn1n9479ab74p5lacgr1pvw-X-Restart-Triggers-acme-mulatta.io.drv /nix/store/9fcin9hsfcgdbkqhyq7hcr1kv1lf2y3y-unit-acme-mulatta.io.service.drv /nix/store/8i84rw2vmvki71q72p90h0dpbxqay9ai-jail.local.drv /nix/store/rss5jggy7idsik18pn8pgg13mp7gfky8-extra-jail.local.drv /nix/store/8bh0q8skizlw4jbmxfwspkn2qd8zyimn-jail.local.drv /nix/store/kvln35a4gh104wphz4fhbqd7iz86z8bq-X-Restart-Triggers-fail2ban.drv /nix/store/bb5ixmy1sl8mzx154k08fv33agy2mpzc-unit-fail2ban.service.drv /nix/store/gdnnwmb684fwx6w2wgw00cq7m1bbvwh6-X-Restart-Triggers-acme-mail.mulatta.io.drv /nix/store/ggiwks0l08mjkgp6np9yk106mvrr46fh-unit-script-acme-mail.mulatta.io-start.drv /nix/store/fpbivcd28kdywghs2zcfc2snlz21wkpc-unit-acme-mail.mulatta.io.service.drv /nix/store/cprwvwzyna1f8mx1z5zmz8r7pap8c637-extra-hosts.drv /nix/store/jmv17ibr5f1d20rja58av3hvvm11iap7-string-hosts.drv /nix/store/jqsq0cibyl3fx1bxr42pyqczsh7vxvwq-localhost-hosts.drv /nix/store/b71mjmn8gzvip721p5acid57q8d846hb-hosts.drv /nix/store/bdi83gc78ym3gl2ljdh1kvkngi1033iv-nftables-rules.drv /nix/store/ismc5vb6sdgd96h217j426vwhjs11zg2-unit-nftables.service.drv /nix/store/jf1zqd6b2bdsh18f92zm3rkz853y354f-unit-acme-renew-mulatta.io.timer.drv /nix/store/nlzgqsy55y36qd7zp9rvc5rwfqwn3ssf-X-Restart-Triggers-sshd.drv /nix/store/kvvpghbrvi4qfnsmbznlm7xh9j7n1w4f-unit-sshd.service.drv /nix/store/3h813rlyd2zqqjh9i3ywavkf5ya4yhqg-acme-postrun.drv /nix/store/fhr94l83f7njxcdwh7spb9w6ic9naj0w-unit-script-acme-order-renew-mail.mulatta.io-start.drv /nix/store/mj6j467gf5yws0mg5z5h6fcf3dk1k0nz-unit-acme-order-renew-mail.mulatta.io.service.drv /nix/store/sq9xlw7jj3c8q7nkh5wc0m7kl4s1qk7f-unit-acme-renew-idm.mulatta.io.timer.drv /nix/store/7rm7mipqmnfd8siij8bl0cm7qvds2b5z-system-units.drv /nix/store/bdycvp50vfpnkpmni4cwwsyl1h6fp8q8-etc.drv /nix/store/2p5rz7y9ik5dcgp6czr1z1qvz1188c3b-activate.drv /nix/store/bcbkhy67xd93h5d18qj16a1a513qy5mz-check-sshd-config.drv /nix/store/bnmlwnsby32w6m5br5jqgc8chj50sz91-nixos-system-cask-26.11.20260727.fc72407.drv these 2 paths will be fetched (18.1 MiB download, 52.2 MiB unpacked): /nix/store/82jr976666scpdcp1i82awcaa7y4y5g0-libredirect-0 /nix/store/9fah46rsmy98m0knlxv936rds741d2nk-lkl-2025-11-13-lib building '/nix/store/adyq7v6cmhbx282gy8f2pyq7sr491b8b-nginx.conf.drv' building '/nix/store/cprwvwzyna1f8mx1z5zmz8r7pap8c637-extra-hosts.drv' building '/nix/store/rss5jggy7idsik18pn8pgg13mp7gfky8-extra-jail.local.drv' building '/nix/store/8i84rw2vmvki71q72p90h0dpbxqay9ai-jail.local.drv' building '/nix/store/jqsq0cibyl3fx1bxr42pyqczsh7vxvwq-localhost-hosts.drv' building '/nix/store/jmv17ibr5f1d20rja58av3hvvm11iap7-string-hosts.drv' building '/nix/store/26118y1gvhi62gj5xzlzcxr2qglmrxry-unit-acme-account-77910265d11d16c51f22.target.drv' building '/nix/store/07pghvsywprcxk5n9dzbmmplw3dp2ani-unit-acme-account-7998a3b359822a28de2d.target.drv' building '/nix/store/90f0jcs56mw0nxraxj8nx3qpcxa7jy9w-unit-acme-renew-ca.x.timer.drv' building '/nix/store/sq9xlw7jj3c8q7nkh5wc0m7kl4s1qk7f-unit-acme-renew-idm.mulatta.io.timer.drv' building '/nix/store/6sx45fcqlf2qg4ppaf3ymk1j8sck2y0p-unit-acme-renew-mail.mulatta.io.timer.drv' building '/nix/store/jf1zqd6b2bdsh18f92zm3rkz853y354f-unit-acme-renew-mulatta.io.timer.drv' building '/nix/store/5vpvb0dwa17m6zdg5ja42c80afxa57x7-unit-nginx-config-reload.service.drv' building '/nix/store/8fm6yc5i25kx303s7jjcigzmay0c0i94-unit-oauth2-proxy-restate.service.drv' building '/nix/store/4bl9m348ybnfc9psqlhqc2r1rdmimfz7-unit-oauth2-proxy.service.drv' building '/nix/store/gdnnwmb684fwx6w2wgw00cq7m1bbvwh6-X-Restart-Triggers-acme-mail.mulatta.io.drv' building '/nix/store/q5f55fl2pbn1n9479ab74p5lacgr1pvw-X-Restart-Triggers-acme-mulatta.io.drv' building '/nix/store/120lxjzl7ba414yfkkzf5gadv2x51gp9-acme-postrun.drv' building '/nix/store/3h813rlyd2zqqjh9i3ywavkf5ya4yhqg-acme-postrun.drv' building '/nix/store/gmpy9ya9999i19schqnjzf1slk4mqz6z-acme-postrun.drv' building '/nix/store/6j6hvkljj51ljpy7a8kwp4pzb1iysrb8-acme-setup-privileged.drv' building '/nix/store/ggiwks0l08mjkgp6np9yk106mvrr46fh-unit-script-acme-mail.mulatta.io-start.drv' building '/nix/store/hc3xrv2n7w49s9cj6adyz7mpjsl23yrh-unit-script-acme-mulatta.io-start.drv' building '/nix/store/fhr94l83f7njxcdwh7spb9w6ic9naj0w-unit-script-acme-order-renew-mail.mulatta.io-start.drv' building '/nix/store/n9nkrcd2za8dq7i04s8f50r09f09rvbi-unit-script-acme-order-renew-mulatta.io-start.drv' nginx.conf> structuredAttrs is enabled unit-acme-account-77910265d11d16c51f22.target> structuredAttrs is enabled unit-acme-account-7998a3b359822a28de2d.target> structuredAttrs is enabled unit-acme-renew-ca.x.timer> structuredAttrs is enabled unit-acme-renew-idm.mulatta.io.timer> structuredAttrs is enabled unit-acme-renew-mail.mulatta.io.timer> structuredAttrs is enabled unit-acme-renew-mulatta.io.timer> structuredAttrs is enabled unit-nginx-config-reload.service> structuredAttrs is enabled unit-oauth2-proxy-restate.service> structuredAttrs is enabled unit-oauth2-proxy.service> structuredAttrs is enabled building '/nix/store/b71mjmn8gzvip721p5acid57q8d846hb-hosts.drv' building '/nix/store/8bh0q8skizlw4jbmxfwspkn2qd8zyimn-jail.local.drv' building '/nix/store/fpbivcd28kdywghs2zcfc2snlz21wkpc-unit-acme-mail.mulatta.io.service.drv' building '/nix/store/4h2yxbfnim3al69g0h9fiqp3a72b2yc2-unit-acme-order-renew-idm.mulatta.io.service.drv' building '/nix/store/6dzwgw09pviv8l3vmmkhjdq1zxdcd3l6-unit-acme-setup.service.drv' unit-acme-mail.mulatta.io.service> structuredAttrs is enabled unit-acme-order-renew-idm.mulatta.io.service> structuredAttrs is enabled building '/nix/store/kvln35a4gh104wphz4fhbqd7iz86z8bq-X-Restart-Triggers-fail2ban.drv' building '/nix/store/9fcin9hsfcgdbkqhyq7hcr1kv1lf2y3y-unit-acme-mulatta.io.service.drv' building '/nix/store/mj6j467gf5yws0mg5z5h6fcf3dk1k0nz-unit-acme-order-renew-mail.mulatta.io.service.drv' building '/nix/store/5qy5hmgzncy02hys5j9b3nc6f9c11p5p-unit-acme-order-renew-mulatta.io.service.drv' nginx.conf> [context] INFO Can't find variable 'user' nginx.conf> [context] INFO Can't find variable 'email' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> nginx.conf> >> Problem: [add_header_redefinition] Nested "add_header" drops parent headers. nginx.conf> Description: "add_header" replaces ALL parent headers. See documentation: http://nginx.org/en/docs/http/ngx_http_headers_module.html#add_header nginx.conf> Additional info: https://github.com/yandex/gixy/blob/master/docs/en/plugins/addheaderredefinition.md nginx.conf> Reason: Parent headers "x-frame-options", "x-content-type-options" was dropped in current level nginx.conf> Pseudo config: nginx.conf> nginx.conf> server { nginx.conf> server_name rad.mulatta.io; nginx.conf> nginx.conf> location / { nginx.conf> add_header Cache-Control public, max-age=3600; nginx.conf> } nginx.conf> add_header X-Frame-Options DENY always; nginx.conf> add_header X-Content-Type-Options nosniff always; nginx.conf> add_header Referrer-Policy strict-origin-when-cross-origin always; nginx.conf> } nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 1 nginx.conf> High: 0 nginx.conf> nginx.conf> \n\nThis can be caused by combining multiple incompatible services on the same hostname.\n\nFull merged config:\n\n nginx.conf> pid /run/nginx/nginx.pid; nginx.conf> error_log stderr; nginx.conf> daemon off; nginx.conf> events { nginx.conf> } nginx.conf> http { nginx.conf> # Load mime types and configure maximum size of the types hash tables. nginx.conf> include /nix/store/bqb4ja5w47g587b5j2hkl4993sw5mykd-mailcap-2.1.54/etc/nginx/mime.types; nginx.conf> types_hash_max_size 2688; nginx.conf> include /nix/store/ixc951srcxa7p68hpbnzzdimqi4ivlvk-nginx-1.30.4/conf/fastcgi.conf; nginx.conf> include /nix/store/ixc951srcxa7p68hpbnzzdimqi4ivlvk-nginx-1.30.4/conf/uwsgi_params; nginx.conf> default_type application/octet-stream; nginx.conf> resolver [fd28:387a:8e:7600::1] 1.1.1.1 8.8.8.8; nginx.conf> # optimisation nginx.conf> sendfile on; nginx.conf> tcp_nopush on; nginx.conf> tcp_nodelay on; nginx.conf> keepalive_timeout 65; nginx.conf> ssl_protocols TLSv1.2 TLSv1.3; nginx.conf> ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305; nginx.conf> # Consider https://ssl-config.mozilla.org/#server=nginx&config=intermediate as the lower bound nginx.conf> ssl_conf_command Groups "X25519MLKEM768:X25519:P-256:P-384"; nginx.conf> ssl_session_timeout 1d; nginx.conf> ssl_session_cache shared:SSL:10m; nginx.conf> # Breaks forward secrecy: https://github.com/mozilla/server-side-tls/issues/135 nginx.conf> ssl_session_tickets off; nginx.conf> # We don't enable insecure ciphers by default, so this allows nginx.conf> # clients to pick the most performant, per https://github.com/mozilla/server-side-tls/issues/260 nginx.conf> ssl_prefer_server_ciphers off; nginx.conf> brotli on; nginx.conf> brotli_static on; nginx.conf> brotli_comp_level 5; nginx.conf> brotli_window 512k; nginx.conf> brotli_min_length 256; nginx.conf> brotli_types application/atom+xml application/geo+json application/javascript application/json application/ld+json application/manifest+json application/rdf+xml application/vnd.ms-fontobject application/wasm application/x-rss+xml application/x-web-app-manifest+json application/xhtml+xml application/xliff+xml application/xml font/collection font/otf font/ttf image/bmp image/svg+xml image/vnd.microsoft.icon text/cache-manifest text/calendar text/css text/csv text/javascript text/markdown text/plain text/vcard text/vnd.rim.location.xloc text/vtt text/x-component text/xml; nginx.conf> gzip on; nginx.conf> gzip_static on; nginx.conf> gzip_vary on; nginx.conf> gzip_comp_level 5; nginx.conf> gzip_min_length 256; nginx.conf> gzip_proxied expired no-cache no-store private auth; nginx.conf> gzip_types application/atom+xml application/geo+json application/javascript application/json application/ld+json application/manifest+json application/rdf+xml application/vnd.ms-fontobject application/wasm application/x-rss+xml application/x-web-app-manifest+json application/xhtml+xml application/xliff+xml application/xml font/collection font/otf font/ttf image/bmp image/svg+xml image/vnd.microsoft.icon text/cache-manifest text/calendar text/css text/csv text/javascript text/markdown text/plain text/vcard text/vnd.rim.location.xloc text/vtt text/x-component text/xml; nginx.conf> proxy_redirect off; nginx.conf> proxy_connect_timeout 3600s; nginx.conf> proxy_send_timeout 3600s; nginx.conf> proxy_read_timeout 3600s; nginx.conf> proxy_http_version 1.1; unit-acme-mulatta.io.service> structuredAttrs is enabled unit-acme-order-renew-mail.mulatta.io.service> structuredAttrs is enabled unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/bb5ixmy1sl8mzx154k08fv33agy2mpzc-unit-fail2ban.service.drv' nginx.conf> # don't let clients close the keep-alive connection to upstream. See the nginx blog for details: nginx.conf> # https://www.nginx.com/blog/avoiding-top-10-nginx-configuration-mistakes/#no-keepalives nginx.conf> proxy_set_header "Connection" ""; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> # $connection_upgrade is used for websocket proxying nginx.conf> map $http_upgrade $connection_upgrade { nginx.conf> default upgrade; nginx.conf> '' close; nginx.conf> } nginx.conf> client_max_body_size 10m; nginx.conf> server_tokens off; nginx.conf> add_header Strict-Transport-Security 'max-age=31536000; includeSubDomains; preload' always; nginx.conf> access_log syslog:server=unix:/dev/log; nginx.conf> server { nginx.conf> listen [::1]:443 quic default_server; nginx.conf> listen [::1]:443 ssl default_server; nginx.conf> listen 10.208.0.9:80 default_server; nginx.conf> listen 10.208.0.9:443 quic default_server; nginx.conf> listen 10.208.0.9:443 ssl default_server; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80 default_server; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic default_server; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl default_server; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80 default_server; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic default_server; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl default_server; nginx.conf> listen 0.0.0.0:80 default_server; nginx.conf> listen 0.0.0.0:443 quic default_server; nginx.conf> listen 0.0.0.0:443 ssl default_server; nginx.conf> server_name _; nginx.conf> ssl_reject_handshake on; nginx.conf> location / { nginx.conf> return 444; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name atuin.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name atuin.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> proxy_pass http://127.0.0.1:8888; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name blossom.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; unit-acme-order-renew-mulatta.io.service> structuredAttrs is enabled building '/nix/store/6kdyayv2wsdwgkaisn7vlfjqidvm23s6-sshd.conf-settings.drv' nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name blossom.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> proxy_pass http://127.0.0.1:8396; nginx.conf> client_max_body_size 100m; nginx.conf> proxy_request_buffering on; nginx.conf> proxy_read_timeout 300s; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> location ~ ^/(upload|media|nip96|api/upload) { nginx.conf> proxy_pass http://127.0.0.1:8396; nginx.conf> limit_req zone=blossom_upload burst=4 nodelay; nginx.conf> limit_conn blossom_conn 2; nginx.conf> client_max_body_size 100m; nginx.conf> proxy_request_buffering on; nginx.conf> proxy_read_timeout 300s; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:80; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:80; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name ca.x; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/ca.x/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/ca.x/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/ca.x/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> proxy_pass https://localhost:1443; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> location = /ca.crt { nginx.conf> alias /nix/store/3jr13xmgmflr1vbv4fyv8cpln8hbrbmf-per-machine-cask-step-intermediate-cert_intermediate.crt; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name cache.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name cache.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { unit-fail2ban.service> structuredAttrs is enabled nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> proxy_pass http://127.0.0.1:5751; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name chat.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name chat.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> root /nix/store/29y1klykqx42lfny0ixxhzj01b3iprl0-glowing-bear-0.9.0; nginx.conf> } nginx.conf> location /oauth2/ { nginx.conf> proxy_pass http://127.0.0.1:4183; nginx.conf> auth_request off; nginx.conf> proxy_set_header X-Scheme $scheme; nginx.conf> proxy_set_header X-Auth-Request-Redirect $scheme://$host$request_uri; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> location = /oauth2/auth { nginx.conf> proxy_pass http://127.0.0.1:4183/oauth2/auth; nginx.conf> auth_request off; nginx.conf> proxy_set_header X-Scheme $scheme; nginx.conf> proxy_set_header Content-Length ""; nginx.conf> proxy_pass_request_body off; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> location @redirectToOauth2ProxyLogin { nginx.conf> return 307 https://chat.mulatta.io/oauth2/start?rd=$scheme://$host$request_uri; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location ^~ /weechat { nginx.conf> proxy_pass http://malt.n:4242; nginx.conf> proxy_http_version 1.1; nginx.conf> proxy_set_header Upgrade $http_upgrade; nginx.conf> proxy_set_header Connection $connection_upgrade; nginx.conf> proxy_set_header X-User $user; nginx.conf> proxy_set_header X-Email $email; nginx.conf> proxy_read_timeout 3600s; nginx.conf> proxy_send_timeout 3600s; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> add_header X-Frame-Options "DENY" always; nginx.conf> add_header X-Content-Type-Options "nosniff" always; nginx.conf> add_header Referrer-Policy "strict-origin-when-cross-origin" always; nginx.conf> auth_request /oauth2/auth; nginx.conf> error_page 401 = @redirectToOauth2ProxyLogin; nginx.conf> auth_request_set $user $upstream_http_x_auth_request_user; nginx.conf> auth_request_set $email $upstream_http_x_auth_request_email; nginx.conf> auth_request_set $auth_cookie $upstream_http_set_cookie; nginx.conf> add_header Set-Cookie $auth_cookie; nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name cloud.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name cloud.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> proxy_pass http://malt.n:80; nginx.conf> proxy_http_version 1.1; nginx.conf> proxy_set_header Upgrade $http_upgrade; nginx.conf> proxy_set_header Connection $connection_upgrade; nginx.conf> proxy_buffering off; nginx.conf> proxy_request_buffering off; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> location = /.well-known/caldav { nginx.conf> return 301 $scheme://$host/remote.php/dav; nginx.conf> } nginx.conf> location = /.well-known/carddav { nginx.conf> return 301 $scheme://$host/remote.php/dav; nginx.conf> } nginx.conf> location = /.well-known/nodeinfo { nginx.conf> return 301 $scheme://$host/index.php/.well-known/nodeinfo; nginx.conf> } nginx.conf> location = /.well-known/webfinger { nginx.conf> return 301 $scheme://$host/index.php/.well-known/webfinger; nginx.conf> } nginx.conf> client_max_body_size 16G; nginx.conf> client_body_timeout 3600s; nginx.conf> proxy_connect_timeout 3600s; nginx.conf> proxy_send_timeout 3600s; nginx.conf> proxy_read_timeout 3600s; nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name headscale.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name headscale.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> proxy_pass http://127.0.0.1:8089; nginx.conf> proxy_http_version 1.1; nginx.conf> proxy_set_header Upgrade $http_upgrade; nginx.conf> proxy_set_header Connection $connection_upgrade; nginx.conf> proxy_buffering off; nginx.conf> proxy_request_buffering off; nginx.conf> proxy_read_timeout 3600s; nginx.conf> proxy_send_timeout 3600s; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name home.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name home.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> proxy_pass http://malt.n:8123; nginx.conf> proxy_http_version 1.1; nginx.conf> proxy_set_header Upgrade $http_upgrade; nginx.conf> proxy_set_header Connection $connection_upgrade; nginx.conf> proxy_buffering off; nginx.conf> proxy_read_timeout 3600s; nginx.conf> proxy_send_timeout 3600s; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> location = /.well-known/security.txt { nginx.conf> return 308 https://mulatta.io/.well-known/security.txt; nginx.conf> } nginx.conf> location ~ ^/.well-known/ { nginx.conf> return 404; nginx.conf> } nginx.conf> add_header X-Frame-Options "DENY" always; nginx.conf> add_header X-Content-Type-Options "nosniff" always; nginx.conf> add_header Referrer-Policy "strict-origin-when-cross-origin" always; nginx.conf> if ($block_dotted) { nginx.conf> return 404; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name idm.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name idm.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> proxy_pass https://127.0.0.1:8443; nginx.conf> proxy_http_version 1.1; nginx.conf> proxy_set_header Upgrade $http_upgrade; nginx.conf> proxy_set_header Connection $connection_upgrade; nginx.conf> proxy_ssl_verify off; nginx.conf> proxy_set_header Host $host; nginx.conf> proxy_set_header X-Real-IP $remote_addr; nginx.conf> proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; nginx.conf> proxy_set_header X-Forwarded-Proto $scheme; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name links.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name links.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> proxy_pass http://malt.n:3000; nginx.conf> proxy_http_version 1.1; nginx.conf> proxy_set_header Upgrade $http_upgrade; nginx.conf> proxy_set_header Connection $connection_upgrade; nginx.conf> proxy_read_timeout 300s; nginx.conf> proxy_send_timeout 300s; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> add_header X-Frame-Options "DENY" always; nginx.conf> add_header X-Content-Type-Options "nosniff" always; nginx.conf> add_header Referrer-Policy "strict-origin-when-cross-origin" always; nginx.conf> if ($block_dotted) { nginx.conf> return 404; nginx.conf> } nginx.conf> client_max_body_size 100M; nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:80; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:80; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name localhost 127.0.0.1 [::1]; nginx.conf> location /nginx_status { nginx.conf> stub_status on; nginx.conf> access_log off; nginx.conf> allow 127.0.0.1; nginx.conf> allow ::1; nginx.conf> deny all; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name mail.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name mail.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> proxy_pass http://127.0.0.1:3000; nginx.conf> proxy_http_version 1.1; nginx.conf> proxy_set_header Upgrade $http_upgrade; nginx.conf> proxy_set_header Connection $connection_upgrade; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> location /dav/ { nginx.conf> proxy_pass http://127.0.0.1:8080; nginx.conf> proxy_set_header Host stalwart.mulatta.io; nginx.conf> proxy_set_header X-Real-IP $remote_addr; nginx.conf> proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; nginx.conf> proxy_set_header X-Forwarded-Proto $scheme; nginx.conf> } nginx.conf> location /jmap/ { nginx.conf> proxy_pass http://127.0.0.1:8080; nginx.conf> proxy_http_version 1.1; nginx.conf> proxy_set_header Upgrade $http_upgrade; nginx.conf> proxy_set_header Connection $connection_upgrade; nginx.conf> proxy_set_header Host stalwart.mulatta.io; nginx.conf> proxy_set_header X-Real-IP $remote_addr; nginx.conf> proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; nginx.conf> proxy_set_header X-Forwarded-Proto $scheme; nginx.conf> client_max_body_size 50M; nginx.conf> proxy_read_timeout 3600s; nginx.conf> proxy_send_timeout 3600s; nginx.conf> } nginx.conf> location = /.well-known/caldav { nginx.conf> proxy_pass http://127.0.0.1:8080; nginx.conf> proxy_set_header Host stalwart.mulatta.io; nginx.conf> proxy_set_header X-Real-IP $remote_addr; nginx.conf> proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; nginx.conf> proxy_set_header X-Forwarded-Proto $scheme; nginx.conf> } nginx.conf> location = /.well-known/carddav { nginx.conf> proxy_pass http://127.0.0.1:8080; nginx.conf> proxy_set_header Host stalwart.mulatta.io; nginx.conf> proxy_set_header X-Real-IP $remote_addr; nginx.conf> proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; nginx.conf> proxy_set_header X-Forwarded-Proto $scheme; nginx.conf> } nginx.conf> location = /.well-known/jmap { nginx.conf> proxy_pass http://127.0.0.1:8080/jmap/session; nginx.conf> proxy_set_header Host stalwart.mulatta.io; nginx.conf> proxy_set_header X-Real-IP $remote_addr; nginx.conf> proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; nginx.conf> proxy_set_header X-Forwarded-Proto $scheme; nginx.conf> proxy_set_header Accept-Encoding ""; nginx.conf> sub_filter "https://stalwart.mulatta.io/" "https://mail.mulatta.io/"; nginx.conf> sub_filter_once off; nginx.conf> sub_filter_types application/json; nginx.conf> } nginx.conf> location = /.well-known/oauth-authorization-server { nginx.conf> proxy_pass http://127.0.0.1:8080; nginx.conf> proxy_set_header Host stalwart.mulatta.io; nginx.conf> proxy_set_header X-Real-IP $remote_addr; nginx.conf> proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; nginx.conf> proxy_set_header X-Forwarded-Proto $scheme; nginx.conf> } nginx.conf> location = /.well-known/openid-configuration { nginx.conf> proxy_pass http://127.0.0.1:8080; nginx.conf> proxy_set_header Host stalwart.mulatta.io; nginx.conf> proxy_set_header X-Real-IP $remote_addr; nginx.conf> proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; nginx.conf> proxy_set_header X-Forwarded-Proto $scheme; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name mq.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name mq.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> proxy_pass http://127.0.0.1:18980; nginx.conf> proxy_set_header Host $host; nginx.conf> proxy_set_header X-Real-IP $remote_addr; nginx.conf> proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; nginx.conf> proxy_set_header X-Forwarded-Proto $scheme; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name mta-sts.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name mta-sts.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location =/.well-known/mta-sts.txt { nginx.conf> alias /nix/store/l3967zi6vf1mx48qldwfyzaklmycj6l0-mta-sts.txt; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> return 404; nginx.conf> } nginx.conf> location = /.well-known/nostr.json { nginx.conf> alias /nix/store/hcp5r1cjnxif7afz86wb2xkd17jp9pd4-nostr.json; nginx.conf> add_header Access-Control-Allow-Origin "*" always; nginx.conf> add_header Cache-Control "public, max-age=3600"; nginx.conf> default_type application/json; nginx.conf> } nginx.conf> location = /.well-known/security.txt { nginx.conf> alias /nix/store/si5gb1xwag27pbfagpw946nnbc7fwgfy-security.txt; nginx.conf> default_type "text/plain; charset=utf-8"; nginx.conf> } nginx.conf> location ^~ /.well-known/openpgpkey/ { nginx.conf> alias /nix/store/dn4aksj980bfb15b1jaxsijqzzzg36vp-openpgpkey/; nginx.conf> default_type "application/octet-stream"; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name n8n-api.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name n8n-api.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> return 404; nginx.conf> } nginx.conf> location ~ ^/(webhook(-test)?|healthz) { nginx.conf> proxy_pass http://malt.n:5678; nginx.conf> proxy_http_version 1.1; nginx.conf> proxy_set_header Upgrade $http_upgrade; nginx.conf> proxy_set_header Connection $connection_upgrade; nginx.conf> # SECURITY: Prevent header injection - clear all auth headers nginx.conf> proxy_set_header X-Email ""; nginx.conf> proxy_set_header X-Auth-Request-Email ""; nginx.conf> proxy_set_header X-Auth-Request-User ""; nginx.conf> proxy_set_header X-Access-Token ""; nginx.conf> client_max_body_size 50M; nginx.conf> proxy_read_timeout 3600s; nginx.conf> proxy_send_timeout 3600s; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> add_header X-Frame-Options "DENY" always; nginx.conf> add_header X-Content-Type-Options "nosniff" always; nginx.conf> add_header Referrer-Policy "strict-origin-when-cross-origin" always; nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name n8n.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name n8n.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> proxy_pass http://127.0.0.1:4180; nginx.conf> proxy_http_version 1.1; nginx.conf> proxy_set_header Upgrade $http_upgrade; nginx.conf> proxy_set_header Connection $connection_upgrade; nginx.conf> client_max_body_size 50M; nginx.conf> proxy_read_timeout 3600s; nginx.conf> proxy_send_timeout 3600s; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> add_header X-Frame-Options "DENY" always; nginx.conf> add_header X-Content-Type-Options "nosniff" always; nginx.conf> add_header Referrer-Policy "strict-origin-when-cross-origin" always; nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name niks3.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name niks3.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> proxy_pass http://127.0.0.1:5751; nginx.conf> proxy_connect_timeout 300s; nginx.conf> proxy_send_timeout 300s; nginx.conf> proxy_read_timeout 300s; nginx.conf> proxy_buffering off; nginx.conf> proxy_request_buffering off; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name ntfy.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name ntfy.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> proxy_pass http://127.0.0.1:2586; nginx.conf> proxy_http_version 1.1; nginx.conf> proxy_set_header Upgrade $http_upgrade; nginx.conf> proxy_set_header Connection $connection_upgrade; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> add_header X-Frame-Options "DENY" always; nginx.conf> add_header X-Content-Type-Options "nosniff" always; nginx.conf> add_header Referrer-Policy "strict-origin-when-cross-origin" always; nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name paperless-api.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name paperless-api.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> return 404; nginx.conf> } nginx.conf> location ~ ^/api/ { nginx.conf> proxy_pass http://malt.n:28981; nginx.conf> proxy_http_version 1.1; nginx.conf> proxy_set_header Upgrade $http_upgrade; nginx.conf> proxy_set_header Connection $connection_upgrade; nginx.conf> # SECURITY: prevent auth header injection from sibling SSO setups. nginx.conf> proxy_set_header X-Email ""; nginx.conf> proxy_set_header X-Auth-Request-Email ""; nginx.conf> proxy_set_header X-Auth-Request-User ""; nginx.conf> proxy_set_header X-Access-Token ""; nginx.conf> proxy_set_header Remote-User ""; nginx.conf> proxy_set_header Remote-Email ""; nginx.conf> proxy_read_timeout 3600s; nginx.conf> proxy_send_timeout 3600s; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> add_header X-Frame-Options "DENY" always; nginx.conf> add_header X-Content-Type-Options "nosniff" always; nginx.conf> add_header Referrer-Policy "strict-origin-when-cross-origin" always; nginx.conf> if ($block_dotted) { nginx.conf> return 404; nginx.conf> } nginx.conf> client_max_body_size 256M; nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name paperless.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name paperless.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> proxy_pass http://malt.n:28981; nginx.conf> proxy_http_version 1.1; nginx.conf> proxy_set_header Upgrade $http_upgrade; nginx.conf> proxy_set_header Connection $connection_upgrade; nginx.conf> proxy_read_timeout 3600s; nginx.conf> proxy_send_timeout 3600s; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> add_header X-Frame-Options "DENY" always; nginx.conf> add_header X-Content-Type-Options "nosniff" always; nginx.conf> add_header Referrer-Policy "strict-origin-when-cross-origin" always; nginx.conf> if ($block_dotted) { nginx.conf> return 404; nginx.conf> } nginx.conf> client_max_body_size 256M; nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name rad.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name rad.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> root /nix/store/cfzffj5cyx581g4c8jrpkd5jyhns9xjs-radicle-explorer-0-unstable-2026-07-21; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> try_files $uri $uri/ /index.html; nginx.conf> add_header Cache-Control "public, max-age=3600"; nginx.conf> } nginx.conf> location /api/ { nginx.conf> proxy_pass http://127.0.0.1:8889; nginx.conf> proxy_http_version 1.1; nginx.conf> proxy_set_header Upgrade $http_upgrade; nginx.conf> proxy_set_header Connection $connection_upgrade; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> add_header X-Frame-Options "DENY" always; nginx.conf> add_header X-Content-Type-Options "nosniff" always; nginx.conf> add_header Referrer-Policy "strict-origin-when-cross-origin" always; nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name radicle-mirror.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name radicle-mirror.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> return 404; nginx.conf> } nginx.conf> location = /github { nginx.conf> proxy_pass http://127.0.0.1:4128; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name relay.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name relay.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> proxy_pass http://127.0.0.1:7777; nginx.conf> proxy_http_version 1.1; nginx.conf> proxy_set_header Upgrade $http_upgrade; nginx.conf> proxy_set_header Connection $connection_upgrade; nginx.conf> proxy_set_header Host $host; nginx.conf> proxy_set_header X-Real-IP $remote_addr; nginx.conf> proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; nginx.conf> proxy_set_header X-Forwarded-Proto $scheme; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> location = /.well-known/security.txt { nginx.conf> return 308 https://mulatta.io/.well-known/security.txt; nginx.conf> } nginx.conf> location ~ ^/.well-known/ { nginx.conf> return 404; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name restate-api.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name restate-api.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> return 404; nginx.conf> } nginx.conf> add_header X-Frame-Options "DENY" always; nginx.conf> add_header X-Content-Type-Options "nosniff" always; nginx.conf> add_header Referrer-Policy "strict-origin-when-cross-origin" always; nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name restate.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name restate.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> proxy_pass http://127.0.0.1:4181; nginx.conf> proxy_http_version 1.1; nginx.conf> proxy_set_header Upgrade $http_upgrade; nginx.conf> proxy_set_header Connection $connection_upgrade; nginx.conf> client_max_body_size 50M; nginx.conf> proxy_read_timeout 3600s; nginx.conf> proxy_send_timeout 3600s; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> add_header X-Frame-Options "DENY" always; nginx.conf> add_header X-Content-Type-Options "nosniff" always; nginx.conf> add_header Referrer-Policy "strict-origin-when-cross-origin" always; nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name rss.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name rss.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> proxy_pass http://malt.n:8080; nginx.conf> proxy_http_version 1.1; nginx.conf> proxy_set_header Upgrade $http_upgrade; nginx.conf> proxy_set_header Connection $connection_upgrade; nginx.conf> proxy_hide_header Strict-Transport-Security; nginx.conf> proxy_read_timeout 300s; nginx.conf> proxy_send_timeout 300s; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> if ($block_dotted) { nginx.conf> return 404; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name stalwart.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name stalwart.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> proxy_pass http://127.0.0.1:8080; nginx.conf> proxy_http_version 1.1; nginx.conf> proxy_set_header Upgrade $http_upgrade; nginx.conf> proxy_set_header Connection $connection_upgrade; nginx.conf> proxy_set_header Host $host; nginx.conf> proxy_set_header X-Real-IP $remote_addr; nginx.conf> proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; nginx.conf> proxy_set_header X-Forwarded-Proto $scheme; nginx.conf> client_max_body_size 50M; nginx.conf> proxy_read_timeout 3600s; nginx.conf> proxy_send_timeout 3600s; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> add_header X-Frame-Options "DENY" always; nginx.conf> add_header X-Content-Type-Options "nosniff" always; nginx.conf> add_header Referrer-Policy "strict-origin-when-cross-origin" always; nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name tasks.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name tasks.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> proxy_pass http://malt.n:3456; nginx.conf> proxy_http_version 1.1; nginx.conf> proxy_set_header Upgrade $http_upgrade; nginx.conf> proxy_set_header Connection $connection_upgrade; nginx.conf> client_max_body_size 50M; nginx.conf> proxy_read_timeout 120s; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> location = /.well-known/caldav { nginx.conf> return 301 $scheme://$host/dav; nginx.conf> } nginx.conf> location = /.well-known/security.txt { nginx.conf> return 308 https://mulatta.io/.well-known/security.txt; nginx.conf> } nginx.conf> location ~ ^/.well-known/ { nginx.conf> return 404; nginx.conf> } nginx.conf> add_header X-Frame-Options "DENY" always; nginx.conf> add_header X-Content-Type-Options "nosniff" always; nginx.conf> add_header Referrer-Policy "strict-origin-when-cross-origin" always; nginx.conf> if ($block_dotted) { nginx.conf> return 404; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name upterm.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name upterm.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> root /nix/store/abmi6mhjzj206kcby0a4z4sqbw2s2vs2-uptermd; nginx.conf> } nginx.conf> add_header X-Frame-Options "DENY" always; nginx.conf> add_header X-Content-Type-Options "nosniff" always; nginx.conf> add_header Referrer-Policy "strict-origin-when-cross-origin" always; nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name vaultwarden.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name vaultwarden.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> proxy_pass http://127.0.0.1:8222; nginx.conf> proxy_http_version 1.1; nginx.conf> proxy_set_header Upgrade $http_upgrade; nginx.conf> proxy_set_header Connection $connection_upgrade; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> client_max_body_size 128M; nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name video.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name video.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> proxy_pass http://malt.n:8096; nginx.conf> proxy_http_version 1.1; nginx.conf> proxy_set_header Upgrade $http_upgrade; nginx.conf> proxy_set_header Connection $connection_upgrade; nginx.conf> proxy_buffering off; nginx.conf> proxy_request_buffering off; nginx.conf> proxy_read_timeout 3600s; nginx.conf> proxy_send_timeout 3600s; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> add_header X-Frame-Options "SAMEORIGIN" always; nginx.conf> add_header X-Content-Type-Options "nosniff" always; nginx.conf> add_header Referrer-Policy "strict-origin-when-cross-origin" always; nginx.conf> if ($block_dotted) { nginx.conf> return 404; nginx.conf> } nginx.conf> client_max_body_size 20G; nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name webmail.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name webmail.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location / { nginx.conf> return 301 https://mail.mulatta.io$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name www.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name www.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location / { nginx.conf> return 301 https://mulatta.io$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen 10.208.0.9:80; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:80; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:80; nginx.conf> listen 0.0.0.0:80; nginx.conf> server_name zotero.mulatta.io; nginx.conf> location / { nginx.conf> return 301 https://$host$request_uri; nginx.conf> } nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> } nginx.conf> server { nginx.conf> listen [::1]:443 quic; nginx.conf> listen [::1]:443 ssl; nginx.conf> listen 10.208.0.9:443 quic; nginx.conf> listen 10.208.0.9:443 ssl; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 quic; nginx.conf> listen [fdec:ca5f:90ad:6fdd:8e76:62fc:c0f7:297d]:443 ssl; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 quic; nginx.conf> listen [2401:c080:1c01:382:5400:6ff:fe9c:ad9d]:443 ssl; nginx.conf> listen 0.0.0.0:443 quic; nginx.conf> listen 0.0.0.0:443 ssl; nginx.conf> server_name zotero.mulatta.io; nginx.conf> http2 on; nginx.conf> http3 on; nginx.conf> http3_hq off; nginx.conf> ssl_certificate /var/lib/acme/mulatta.io/fullchain.pem; nginx.conf> ssl_certificate_key /var/lib/acme/mulatta.io/key.pem; nginx.conf> ssl_trusted_certificate /var/lib/acme/mulatta.io/chain.pem; nginx.conf> location ^~ /.well-known/acme-challenge/ { nginx.conf> root /var/lib/acme/acme-challenge; nginx.conf> auth_basic off; nginx.conf> auth_request off; nginx.conf> } nginx.conf> location / { nginx.conf> proxy_pass http://127.0.0.1:8189; nginx.conf> proxy_http_version 1.1; nginx.conf> proxy_set_header Upgrade $http_upgrade; nginx.conf> proxy_set_header Connection $connection_upgrade; nginx.conf> client_max_body_size 512M; nginx.conf> proxy_request_buffering off; nginx.conf> proxy_read_timeout 3600s; nginx.conf> proxy_send_timeout 3600s; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> location /login { nginx.conf> proxy_pass http://127.0.0.1:4182; nginx.conf> proxy_http_version 1.1; nginx.conf> proxy_set_header Upgrade $http_upgrade; nginx.conf> proxy_set_header Connection $connection_upgrade; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> location /oauth2/ { nginx.conf> proxy_pass http://127.0.0.1:4182; nginx.conf> include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; nginx.conf> } nginx.conf> add_header X-Frame-Options "DENY" always; nginx.conf> add_header X-Content-Type-Options "nosniff" always; nginx.conf> add_header Referrer-Policy "strict-origin-when-cross-origin" always; nginx.conf> } nginx.conf> proxy_headers_hash_max_size 1024; nginx.conf> proxy_headers_hash_bucket_size 128; nginx.conf> map $request_uri $block_dotted { nginx.conf> default 0; nginx.conf> "~^/\.well-known/" 0; nginx.conf> "~^/\." 1; nginx.conf> } nginx.conf> limit_req_zone $binary_remote_addr zone=blossom_upload:10m rate=2r/m; nginx.conf> limit_conn_zone $binary_remote_addr zone=blossom_conn:10m; nginx.conf> } error: Cannot build '/nix/store/adyq7v6cmhbx282gy8f2pyq7sr491b8b-nginx.conf.drv'. Reason: builder failed with exit code 1. Output paths: /nix/store/qls8igqpr6mb5mj03xd6jvvf9kwi1rf3-nginx.conf Last 25 log lines: > location /login { > proxy_pass http://127.0.0.1:4182; > proxy_http_version 1.1; > proxy_set_header Upgrade $http_upgrade; > proxy_set_header Connection $connection_upgrade; > include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; > } > location /oauth2/ { > proxy_pass http://127.0.0.1:4182; > include /nix/store/dc8b1rp3ckwly51jgjyj3hx3avvmzy2k-nginx-recommended-proxy_set_header-headers.conf; > } > add_header X-Frame-Options "DENY" always; > add_header X-Content-Type-Options "nosniff" always; > add_header Referrer-Policy "strict-origin-when-cross-origin" always; > } > proxy_headers_hash_max_size 1024; > proxy_headers_hash_bucket_size 128; > map $request_uri $block_dotted { > default 0; > "~^/\.well-known/" 0; > "~^/\." 1; > } > limit_req_zone $binary_remote_addr zone=blossom_upload:10m rate=2r/m; > limit_conn_zone $binary_remote_addr zone=blossom_conn:10m; > } For full logs, run: nix log /nix/store/adyq7v6cmhbx282gy8f2pyq7sr491b8b-nginx.conf.drv error: Cannot build '/nix/store/viifb5mhhmjjk161sdm76yh7acv33ds0-unit-script-nginx-pre-start.drv'. Reason: 1 dependency failed. Output paths: /nix/store/4qysl8369dxg8sbhs2mhb2jqyf445nl1-unit-script-nginx-pre-start error: Cannot build '/nix/store/8n7hxsqbk0lxsc8lkldlxda0mjc32qwh-unit-nginx.service.drv'. Reason: 2 dependencies failed. Output paths: /nix/store/9gzjq3by2k9l6icvk744vl9fixcdband-unit-nginx.service building '/nix/store/17n2jn6khp1s9j248qcam5x9c218rn3d-sshd.conf-final.drv' building '/nix/store/bdi83gc78ym3gl2ljdh1kvkngi1033iv-nftables-rules.drv' building '/nix/store/nlzgqsy55y36qd7zp9rvc5rwfqwn3ssf-X-Restart-Triggers-sshd.drv' building '/nix/store/bcbkhy67xd93h5d18qj16a1a513qy5mz-check-sshd-config.drv' building '/nix/store/kvvpghbrvi4qfnsmbznlm7xh9j7n1w4f-unit-sshd.service.drv' unit-sshd.service> structuredAttrs is enabled building '/nix/store/ismc5vb6sdgd96h217j426vwhjs11zg2-unit-nftables.service.drv' unit-nftables.service> structuredAttrs is enabled error: Cannot build '/nix/store/7rm7mipqmnfd8siij8bl0cm7qvds2b5z-system-units.drv'. Reason: 1 dependency failed. Output paths: /nix/store/bzhp6nxbkjp578ajm6c0xxjpslnrfk00-system-units error: Cannot build '/nix/store/bdycvp50vfpnkpmni4cwwsyl1h6fp8q8-etc.drv'. Reason: 2 dependencies failed. Output paths: /nix/store/74288na56q57kmsvpmx4gmrn072kf3vk-etc error: Cannot build '/nix/store/2p5rz7y9ik5dcgp6czr1z1qvz1188c3b-activate.drv'. Reason: 1 dependency failed. Output paths: /nix/store/db4j1mlhp3rck4f8kyxrqybd0xlnbidr-activate error: Cannot build '/nix/store/bnmlwnsby32w6m5br5jqgc8chj50sz91-nixos-system-cask-26.11.20260727.fc72407.drv'. Reason: 2 dependencies failed. Output paths: /nix/store/n8qamgyg27hmiqg8mgja95x4xds7xwkz-nixos-system-cask-26.11.20260727.fc72407