these 108 derivations will be built: /nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv /nix/store/hzmavrl4zmzhyfz3aihprwcvmq7rw11m-system-path.drv /nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv /nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv /nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv /nix/store/1js2x70k6ddahgqrh28zipsnzxjx7l9j-dbus-1.drv /nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv /nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv /nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv /nix/store/468p6xhdg7qyzr7isv227xvrdg6r3730-X-Restart-Triggers-dbus-broker.drv /nix/store/jg7zz8425hqiizgxyn4imlz6ydm0drzd-unit-dbus-broker.service.drv /nix/store/brdiqrza4w6vb0wiccvwq1zh9v5y3jhc-user-units.drv /nix/store/bx9ay666mdpxmqa49l3hw83wkl8bjvvs-user-generators.drv /nix/store/cryvp3wr06ihxdxd2wq9xjchsc3h0ff2-ca.json.drv /nix/store/55r3xbviq6l3zgziig53rhs351x7xj6l-cacert-extra-certificates-bundle.crt.drv /nix/store/x52vjn5rprsx9n1jd5m287f9yhs1ffqn-cacert-blocklist.txt.drv /nix/store/cs32wl4yihymfh2v0x861qmhpxcvyi1c-nss-cacert-3.126.drv /nix/store/6z5jc0sp4vjkgzd37icya2gy22sk8q70-nixos-tmpfiles.d.drv /nix/store/79kfpjcg65c0rrnp43qfppivwzfx8yvi-10-acme.conf.drv /nix/store/dxhcs8f88vsb624k3l6b10b549cv921m-tmpfiles.d.drv /nix/store/imw2kazzmfl6nlf52psv7h2vlnfpdxn3-system-shutdown.drv /nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv /nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv /nix/store/p58gpq8dlbza3dklkqrzwj7blz2knydv-nginx-recommended-proxy_set_header-headers.conf.drv /nix/store/m37gigycmrnkpgagwmnz3b0qr30ylvff-nginx.conf.drv /nix/store/rr3k22qcv35qb8krj0p5bp7b2yvqp8ml-system-generators.drv /nix/store/3rr9fv8hypdi85kskd7jfm3i9k9kfrr5-unit-nix-daemon.service.drv /nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv /nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv /nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv /nix/store/fcigm5lijsg6dwldbhhvb6zm2fwl9145-unit-dbus-broker.service.drv /nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/dm4jdfhdpwka7rxqgmnqik2ijlpyp0g4-X-Restart-Triggers-step-ca.drv /nix/store/mbhvcgl77bl4ss63kidvg5xm82wkp39f-unit-step-ca.service.drv /nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv /nix/store/j3lmyghsa4g7nacl7gf67lvx5m91k2br-unit-script-acme-setup-start.drv /nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv /nix/store/pz8cs4lg35mq4mi7ck3am5chl70g70yx-firewall-start.drv /nix/store/1h3016b7n1wag10qh4dax4mdvk4hiydh-firewall-reload.drv /nix/store/ra9f6mzgpig8bxfp26sd4f4dhdymamc3-unit-firewall.service.drv /nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv /nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv /nix/store/y9vs2brijwc8c2b5mh0vxrsz0hh37z6h-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/rmxiym60q7p0pgy3rvrqhgl15ngv7yc5-unit-systemd-tmpfiles-resetup.service.drv /nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv /nix/store/v0clim1zszqklxri4dwhf4gr45rx79ja-unit-systemd-resolved.service.drv /nix/store/frbj3kw64q4znlk75j58890sk1gqv653-unit-script-nginx-pre-start.drv /nix/store/zffj7h0r2w4jykj0qiqhl4id0spx8g45-unit-nginx.service.drv /nix/store/yb8h1znw1pvvp84asdq6dbi07nb4dyfr-system-units.drv /nix/store/z36ldxpd4hhcidwmmbh37dcp6hg9s16v-etc.drv /nix/store/s57yr4zh2lbgzl679ll6v4l4s7r5d8f1-activate.drv /nix/store/0yvf5xjxk8469qc9cfyxggw7yh481fyx-nixos-system-ca-test.drv /nix/store/0r46c1l364l5ig25nnv6phfpwdb7nx3p-run-ca-nspawn.drv /nix/store/7bm5w0wpz1gk6ma416c9i77kslkzgm9m-decrypt-age-secrets.drv /nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv /nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv /nix/store/d4vj54sx388dyibi2ja6r7jckm4ra5bl-nginx.conf.drv /nix/store/q04acjz5k41ghz0px4lyprax5iwaddql-system-path.drv /nix/store/jgciai23q360dmqk3m1n4jhzsi77lwif-dbus-1.drv /nix/store/zrgg0w0g2drlxnpy5c5i52sh4b0vj3bi-X-Restart-Triggers-dbus-broker.drv /nix/store/9vhkv3j34lhgg86zz9njs0az7jc6lv2j-unit-dbus-broker.service.drv /nix/store/dw1sannzka5dl33nv6rpf6mwf60qlbck-user-units.drv /nix/store/v3r6klh4wv9zb6hmz7fwb1gyzyil9a5n-unit-40-eth1.network.drv /nix/store/ycl6gbj04ywcaxa7ad5ms35wranp5b1r-X-Reload-Triggers-systemd-networkd.drv /nix/store/2y5dcvasfw9vhxcmcgzy70r1w1bd6jg9-unit-systemd-networkd.service.drv /nix/store/7pfy24j8qyd0avkdbzd322wr7x9wb2im-unit-dbus-broker.service.drv /nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv /nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv /nix/store/8v8nx7xkgmlz39rnf6l90mdmzhz8c9yx-unit-script-nginx-pre-start.drv /nix/store/j2jdcyp4233cn5lky6zlsk016msb24sr-unit-nginx.service.drv /nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv /nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv /nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv /nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv /nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv /nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv /nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv /nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv /nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/l0qp5ayg5cr133jndv1pmxsfp5vv3wzz-system-units.drv /nix/store/gxyrv48ipgri59d6khxd83fm0bmpcfz3-etc.drv /nix/store/13bc7ip7079nqnf4xd0hykclz7jgwcm7-activate.drv /nix/store/5mrdkkv0rkyrgkwxwdj3gbwks10c6i55-users-groups.json.drv /nix/store/hvpdgppc2ph0w7r40a0nla0cl5zy2x1k-dry-activate.drv /nix/store/rv1q9jjrri3jsmjk8gyq8xlk9663a0c7-system-path.drv /nix/store/kcg1sng0r20y32mqjjp9y6zicd68zzqz-dbus-1.drv /nix/store/csjdmrjp08pnh38q2yxmh9yymp46n03q-X-Restart-Triggers-dbus-broker.drv /nix/store/3sd144j30qanf036aasfgnp9592pymf7-unit-dbus-broker.service.drv /nix/store/2xhnv7gmks4yzk39pmw7hzrsaahinmsv-user-units.drv /nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv /nix/store/3wbzl5zadk20cplik16z31fcvghbrlcz-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/7hgnzq5d0x9pk0i03d6a0ia7i525pzmi-unit-systemd-tmpfiles-resetup.service.drv /nix/store/dbk0qb88nzffrsi192pr72cidhrsvqbh-unit-dbus-broker.service.drv /nix/store/i8g688x99787cjd8jvlsmddvhq71rcv2-unit-firewall.service.drv /nix/store/i93x66p04sf34kl79hz7aaqa7mcxyc64-system-units.drv /nix/store/sjl5biaqkb12ir3lmc9crzajxbrfz10h-etc.drv /nix/store/x05w7h7wpg52psqvxfxw8m971cmv0agp-activate.drv /nix/store/aj842vp40j4xn3m27cwv5m2wi1gkc9pb-nixos-system-client-test.drv /nix/store/2j378qwcdzm3i4p61jfv5yfkllmm1rsr-run-client-nspawn.drv /nix/store/5k59m3qhfcaxaxyz5kkrpzsj2v6c4j3s-nixos-test-driver-1.1.drv /nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv /nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv /nix/store/d4mq0y98hhfnpgnl2ig42fvrm7jsklij-nixos-system-server-test.drv /nix/store/va353zbqnmhwnl4srpqv13y9ajb04vri-run-server-nspawn.drv /nix/store/riwqzpi81lw6s4k1vx76ygb2jakz17pw-driverConfiguration.json.drv /nix/store/3r6n5js4ghahx5yl4jb64a5cak14xcif-nixos-test-driver-certificates.drv /nix/store/7r92j0zq4v1wx649g3zifshnrvxk68n5-container-test-run-certificates.drv these 17 paths will be fetched (45.8 MiB download, 150.1 MiB unpacked): /nix/store/rfjs1fcacfd1xysy7cmvxsrb9znz6iln-certdata.txt /nix/store/3japwvq6a40ykrmxjjjvm695q2z6c66c-flock-0.4.0 /nix/store/6nr0a4775j5z9nr71ciasfd9pzz076zs-gixy-0.1.21 /nix/store/p12aczsxidgl3m4jkpc4dl4y7kzf8vck-lego-4.35.2 /nix/store/fqcqw4nlcg6q6n77z3gnxhgg3ll6gjvy-minica-1.1.0 /nix/store/pjqhdi88bpspx4a01qlsw96jn2isl11k-nginx-1.30.4 /nix/store/g59y871mjn55fgjswdn72g51qc62j6wa-nginx-config-formatter-1.4.0 /nix/store/n0hdbypqp52bcmm1b5bhxgha5yl8hjs1-nginx-mod-moreheaders-0.40 /nix/store/zzhdyl8d6l7z4jfl5i36ijwqz2vpja7i-nginx-mod-rtmp-1.2.2 /nix/store/1psq003v8r8611bv7bk74xdwz9z6dgaj-openssl-3.6.3-man /nix/store/06pcrb4pj0c0sk6pa39hgmfddprslv4k-openssl-4.0.1 /nix/store/fkylsp720lag8s97n9cbxcafx78clj31-python3.14-buildcatrust-0.5.1 /nix/store/kjz0wmk9imvcj2nrm6ls5yd4mw8awajj-python3.14-cached-property-2.0.1 /nix/store/pfxx0s91wb2bhph7m1hdmzik1d8r9jn9-python3.14-configargparse-1.7.5 /nix/store/fdr01jdc50hn18dn90hx7q9p2jhkaw6m-python3.14-pyparsing-2.4.7 /nix/store/9zffz42v1gbfs8dwi61v4m09skszgl9x-step-ca-0.30.2 /nix/store/j345y5z7axzdpxivknd0swxi5yccyxq4-zlib-ng-2.3.3 building '/nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v3r6klh4wv9zb6hmz7fwb1gyzyil9a5n-unit-40-eth1.network.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/79kfpjcg65c0rrnp43qfppivwzfx8yvi-10-acme.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p58gpq8dlbza3dklkqrzwj7blz2knydv-nginx-recommended-proxy_set_header-headers.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6z5jc0sp4vjkgzd37icya2gy22sk8q70-nixos-tmpfiles.d.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/pz8cs4lg35mq4mi7ck3am5chl70g70yx-firewall-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/j3lmyghsa4g7nacl7gf67lvx5m91k2br-unit-script-acme-setup-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/cryvp3wr06ihxdxd2wq9xjchsc3h0ff2-ca.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/x52vjn5rprsx9n1jd5m287f9yhs1ffqn-cacert-blocklist.txt.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/55r3xbviq6l3zgziig53rhs351x7xj6l-cacert-extra-certificates-bundle.crt.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/hzmavrl4zmzhyfz3aihprwcvmq7rw11m-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/q04acjz5k41ghz0px4lyprax5iwaddql-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rv1q9jjrri3jsmjk8gyq8xlk9663a0c7-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rr3k22qcv35qb8krj0p5bp7b2yvqp8ml-system-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/imw2kazzmfl6nlf52psv7h2vlnfpdxn3-system-shutdown.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/bx9ay666mdpxmqa49l3hw83wkl8bjvvs-user-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/d4vj54sx388dyibi2ja6r7jckm4ra5bl-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p58gpq8dlbza3dklkqrzwj7blz2knydv-nginx-recommended-proxy_set_header-headers.conf.drv' building '/nix/store/v3r6klh4wv9zb6hmz7fwb1gyzyil9a5n-unit-40-eth1.network.drv' unit-40-eth1.network> structuredAttrs is enabled building '/nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv' building '/nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv' building '/nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv' building '/nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv' unit-acme-renew-test.foo.timer> structuredAttrs is enabled building '/nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv' unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/m37gigycmrnkpgagwmnz3b0qr30ylvff-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/79kfpjcg65c0rrnp43qfppivwzfx8yvi-10-acme.conf.drv' building '/nix/store/x52vjn5rprsx9n1jd5m287f9yhs1ffqn-cacert-blocklist.txt.drv' building '/nix/store/55r3xbviq6l3zgziig53rhs351x7xj6l-cacert-extra-certificates-bundle.crt.drv' building '/nix/store/pz8cs4lg35mq4mi7ck3am5chl70g70yx-firewall-start.drv' building '/nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv' unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled building '/nix/store/j3lmyghsa4g7nacl7gf67lvx5m91k2br-unit-script-acme-setup-start.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/1h3016b7n1wag10qh4dax4mdvk4hiydh-firewall-reload.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6z5jc0sp4vjkgzd37icya2gy22sk8q70-nixos-tmpfiles.d.drv' building '/nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv' building '/nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv' unit-acme-renew-ca.foo.timer> structuredAttrs is enabled building '/nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv' building '/nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv' vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully building '/nix/store/cs32wl4yihymfh2v0x861qmhpxcvyi1c-nss-cacert-3.126.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv' building '/nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv' building '/nix/store/ycl6gbj04ywcaxa7ad5ms35wranp5b1r-X-Reload-Triggers-systemd-networkd.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv' building '/nix/store/cryvp3wr06ihxdxd2wq9xjchsc3h0ff2-ca.json.drv' ca.json> structuredAttrs is enabled building '/nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv' building '/nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv' building '/nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dm4jdfhdpwka7rxqgmnqik2ijlpyp0g4-X-Restart-Triggers-step-ca.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dxhcs8f88vsb624k3l6b10b549cv921m-tmpfiles.d.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv' building '/nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv' building '/nix/store/q04acjz5k41ghz0px4lyprax5iwaddql-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/rv1q9jjrri3jsmjk8gyq8xlk9663a0c7-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/hzmavrl4zmzhyfz3aihprwcvmq7rw11m-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv' building '/nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv' building '/nix/store/imw2kazzmfl6nlf52psv7h2vlnfpdxn3-system-shutdown.drv' building '/nix/store/bx9ay666mdpxmqa49l3hw83wkl8bjvvs-user-generators.drv' building '/nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rr3k22qcv35qb8krj0p5bp7b2yvqp8ml-system-generators.drv' building '/nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv' building '/nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv' building '/nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv' building '/nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kcg1sng0r20y32mqjjp9y6zicd68zzqz-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/d4vj54sx388dyibi2ja6r7jckm4ra5bl-nginx.conf.drv' nginx.conf> structuredAttrs is enabled building '/nix/store/1js2x70k6ddahgqrh28zipsnzxjx7l9j-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jgciai23q360dmqk3m1n4jhzsi77lwif-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/m37gigycmrnkpgagwmnz3b0qr30ylvff-nginx.conf.drv' nginx.conf> structuredAttrs is enabled building '/nix/store/8v8nx7xkgmlz39rnf6l90mdmzhz8c9yx-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/frbj3kw64q4znlk75j58890sk1gqv653-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/1h3016b7n1wag10qh4dax4mdvk4hiydh-firewall-reload.drv' building '/nix/store/ra9f6mzgpig8bxfp26sd4f4dhdymamc3-unit-firewall.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/cs32wl4yihymfh2v0x861qmhpxcvyi1c-nss-cacert-3.126.drv' nss-cacert-3.126> Running phase: unpackPhase nss-cacert-3.126> Running phase: patchPhase nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase nss-cacert-3.126> Running phase: installPhase building '/nix/store/ycl6gbj04ywcaxa7ad5ms35wranp5b1r-X-Reload-Triggers-systemd-networkd.drv' nss-cacert-3.126> Running phase: fixupPhase nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/gafhg7l0kwd6wb183j6vhjxgjpp5ghnf-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/gafhg7l0kwd6wb183j6vhjxgjpp5ghnf-nss-cacert-3.126... nss-cacert-3.126> patching script interpreter paths in /nix/store/gafhg7l0kwd6wb183j6vhjxgjpp5ghnf-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/zkrpdyg17jv200wpj3vd41caw9zysf4k-nss-cacert-3.126-unbundled nss-cacert-3.126> checking for references to /build/ in /nix/store/zkrpdyg17jv200wpj3vd41caw9zysf4k-nss-cacert-3.126-unbundled... nss-cacert-3.126> patching script interpreter paths in /nix/store/zkrpdyg17jv200wpj3vd41caw9zysf4k-nss-cacert-3.126-unbundled nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/1nhrgrgga0alx1g11vsagslydb01rpz9-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/1nhrgrgga0alx1g11vsagslydb01rpz9-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/1nhrgrgga0alx1g11vsagslydb01rpz9-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/6ilxw28v6ifmqci0xwx23pfcr8g8fsz4-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/6ilxw28v6ifmqci0xwx23pfcr8g8fsz4-nss-cacert-3.126-hashed... nss-cacert-3.126> patching script interpreter paths in /nix/store/6ilxw28v6ifmqci0xwx23pfcr8g8fsz4-nss-cacert-3.126-hashed building '/nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv' building '/nix/store/dm4jdfhdpwka7rxqgmnqik2ijlpyp0g4-X-Restart-Triggers-step-ca.drv' building '/nix/store/2y5dcvasfw9vhxcmcgzy70r1w1bd6jg9-unit-systemd-networkd.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv' building '/nix/store/mbhvcgl77bl4ss63kidvg5xm82wkp39f-unit-step-ca.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dxhcs8f88vsb624k3l6b10b549cv921m-tmpfiles.d.drv' building '/nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/y9vs2brijwc8c2b5mh0vxrsz0hh37z6h-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3rr9fv8hypdi85kskd7jfm3i9k9kfrr5-unit-nix-daemon.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/8v8nx7xkgmlz39rnf6l90mdmzhz8c9yx-unit-script-nginx-pre-start.drv' building '/nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv' building '/nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv' unit-acme-ca.foo.service> structuredAttrs is enabled building '/nix/store/kcg1sng0r20y32mqjjp9y6zicd68zzqz-dbus-1.drv' building '/nix/store/csjdmrjp08pnh38q2yxmh9yymp46n03q-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/frbj3kw64q4znlk75j58890sk1gqv653-unit-script-nginx-pre-start.drv' building '/nix/store/1js2x70k6ddahgqrh28zipsnzxjx7l9j-dbus-1.drv' building '/nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv' unit-acme-test.foo.service> structuredAttrs is enabled building '/nix/store/zffj7h0r2w4jykj0qiqhl4id0spx8g45-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/jgciai23q360dmqk3m1n4jhzsi77lwif-dbus-1.drv' building '/nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv' unit-acme-order-renew-test.foo.service> structuredAttrs is enabled building '/nix/store/zrgg0w0g2drlxnpy5c5i52sh4b0vj3bi-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv' unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled building '/nix/store/ra9f6mzgpig8bxfp26sd4f4dhdymamc3-unit-firewall.service.drv' unit-firewall.service> structuredAttrs is enabled building '/nix/store/468p6xhdg7qyzr7isv227xvrdg6r3730-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/j2jdcyp4233cn5lky6zlsk016msb24sr-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/y9vs2brijwc8c2b5mh0vxrsz0hh37z6h-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' building '/nix/store/3rr9fv8hypdi85kskd7jfm3i9k9kfrr5-unit-nix-daemon.service.drv' unit-nix-daemon.service> structuredAttrs is enabled building '/nix/store/mbhvcgl77bl4ss63kidvg5xm82wkp39f-unit-step-ca.service.drv' unit-step-ca.service> structuredAttrs is enabled building '/nix/store/2y5dcvasfw9vhxcmcgzy70r1w1bd6jg9-unit-systemd-networkd.service.drv' unit-systemd-networkd.service> structuredAttrs is enabled building '/nix/store/rmxiym60q7p0pgy3rvrqhgl15ngv7yc5-unit-systemd-tmpfiles-resetup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/csjdmrjp08pnh38q2yxmh9yymp46n03q-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/zffj7h0r2w4jykj0qiqhl4id0spx8g45-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/468p6xhdg7qyzr7isv227xvrdg6r3730-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/fcigm5lijsg6dwldbhhvb6zm2fwl9145-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jg7zz8425hqiizgxyn4imlz6ydm0drzd-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/zrgg0w0g2drlxnpy5c5i52sh4b0vj3bi-X-Restart-Triggers-dbus-broker.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/j2jdcyp4233cn5lky6zlsk016msb24sr-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/rmxiym60q7p0pgy3rvrqhgl15ngv7yc5-unit-systemd-tmpfiles-resetup.service.drv' unit-systemd-tmpfiles-resetup.service> structuredAttrs is enabled building '/nix/store/fcigm5lijsg6dwldbhhvb6zm2fwl9145-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/yb8h1znw1pvvp84asdq6dbi07nb4dyfr-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/jg7zz8425hqiizgxyn4imlz6ydm0drzd-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/brdiqrza4w6vb0wiccvwq1zh9v5y3jhc-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3sd144j30qanf036aasfgnp9592pymf7-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7pfy24j8qyd0avkdbzd322wr7x9wb2im-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/9vhkv3j34lhgg86zz9njs0az7jc6lv2j-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/yb8h1znw1pvvp84asdq6dbi07nb4dyfr-system-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/7pfy24j8qyd0avkdbzd322wr7x9wb2im-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/3sd144j30qanf036aasfgnp9592pymf7-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/brdiqrza4w6vb0wiccvwq1zh9v5y3jhc-user-units.drv' building '/nix/store/z36ldxpd4hhcidwmmbh37dcp6hg9s16v-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dbk0qb88nzffrsi192pr72cidhrsvqbh-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/2xhnv7gmks4yzk39pmw7hzrsaahinmsv-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/9vhkv3j34lhgg86zz9njs0az7jc6lv2j-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/l0qp5ayg5cr133jndv1pmxsfp5vv3wzz-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dw1sannzka5dl33nv6rpf6mwf60qlbck-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/z36ldxpd4hhcidwmmbh37dcp6hg9s16v-etc.drv' building '/nix/store/s57yr4zh2lbgzl679ll6v4l4s7r5d8f1-activate.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/l0qp5ayg5cr133jndv1pmxsfp5vv3wzz-system-units.drv' building '/nix/store/2xhnv7gmks4yzk39pmw7hzrsaahinmsv-user-units.drv' building '/nix/store/dbk0qb88nzffrsi192pr72cidhrsvqbh-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/dw1sannzka5dl33nv6rpf6mwf60qlbck-user-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/gxyrv48ipgri59d6khxd83fm0bmpcfz3-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/s57yr4zh2lbgzl679ll6v4l4s7r5d8f1-activate.drv' building '/nix/store/i93x66p04sf34kl79hz7aaqa7mcxyc64-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0yvf5xjxk8469qc9cfyxggw7yh481fyx-nixos-system-ca-test.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/gxyrv48ipgri59d6khxd83fm0bmpcfz3-etc.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/0yvf5xjxk8469qc9cfyxggw7yh481fyx-nixos-system-ca-test.drv' nixos-system-ca-test> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/i93x66p04sf34kl79hz7aaqa7mcxyc64-system-units.drv' building '/nix/store/0r46c1l364l5ig25nnv6phfpwdb7nx3p-run-ca-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/sjl5biaqkb12ir3lmc9crzajxbrfz10h-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/13bc7ip7079nqnf4xd0hykclz7jgwcm7-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0r46c1l364l5ig25nnv6phfpwdb7nx3p-run-ca-nspawn.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/13bc7ip7079nqnf4xd0hykclz7jgwcm7-activate.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/d4mq0y98hhfnpgnl2ig42fvrm7jsklij-nixos-system-server-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/sjl5biaqkb12ir3lmc9crzajxbrfz10h-etc.drv' building '/nix/store/d4mq0y98hhfnpgnl2ig42fvrm7jsklij-nixos-system-server-test.drv' nixos-system-server-test> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/x05w7h7wpg52psqvxfxw8m971cmv0agp-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/va353zbqnmhwnl4srpqv13y9ajb04vri-run-server-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/va353zbqnmhwnl4srpqv13y9ajb04vri-run-server-nspawn.drv' building '/nix/store/x05w7h7wpg52psqvxfxw8m971cmv0agp-activate.drv' building '/nix/store/aj842vp40j4xn3m27cwv5m2wi1gkc9pb-nixos-system-client-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/aj842vp40j4xn3m27cwv5m2wi1gkc9pb-nixos-system-client-test.drv' nixos-system-client-test> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/2j378qwcdzm3i4p61jfv5yfkllmm1rsr-run-client-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/2j378qwcdzm3i4p61jfv5yfkllmm1rsr-run-client-nspawn.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/riwqzpi81lw6s4k1vx76ygb2jakz17pw-driverConfiguration.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/riwqzpi81lw6s4k1vx76ygb2jakz17pw-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/3r6n5js4ghahx5yl4jb64a5cak14xcif-nixos-test-driver-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3r6n5js4ghahx5yl4jb64a5cak14xcif-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! building '/nix/store/7r92j0zq4v1wx649g3zifshnrvxk68n5-container-test-run-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7r92j0zq4v1wx649g3zifshnrvxk68n5-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> ca: systemd-nspawn running (pid 52) container-test-run-certificates> server: systemd-nspawn running (pid 56) container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> client: systemd-nspawn running (pid 55) container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.00 seconds) container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> server # [5740882.610233] server systemd-journald[69]: Journal started container-test-run-certificates> server # [5740882.610281] server systemd-journald[69]: Runtime Journal (/run/log/journal/b83edb7c2808493c86067facdce134cd) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> server # [5740882.613033] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> server # [5740882.621457] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> server # [5740882.622196] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> server # [5740882.622803] server systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> server # [5740882.631126] server systemd-journald[69]: Time spent on flushing to /var/log/journal/b83edb7c2808493c86067facdce134cd is 1.479ms for 6 entries. container-test-run-certificates> server # [5740882.631126] server systemd-journald[69]: System Journal (/var/log/journal/b83edb7c2808493c86067facdce134cd) is 8M, max 4G, 3.9G free. container-test-run-certificates> server # [5740882.640460] server systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> server # [5740882.641123] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> server # [5740882.641239] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> server # [5740882.642033] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> server # [5740882.642076] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [5740882.642883] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [5740882.642917] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [5740882.680234] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [5740882.681675] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> server # [5740882.701814] server systemd-tmpfiles[134]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [5740882.702201] server systemd-tmpfiles[134]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [5740882.702332] server systemd-tmpfiles[134]: fchmod() of /var/log/journal/b83edb7c2808493c86067facdce134cd failed: Operation not permitted container-test-run-certificates> server # [5740882.702516] server systemd-tmpfiles[134]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [5740882.704032] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [5740882.705291] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [5740882.706161] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [5740882.717573] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [5740882.723891] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [5740882.724954] server systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [5740882.734778] server systemd[1]: Finished Update is Completed. container-test-run-certificates> client # [5740882.601424] client systemd-journald[69]: Journal started container-test-run-certificates> server # [5740882.758510] server systemd[1]: Finished Firewall. container-test-run-certificates> client # [5740882.601477] client systemd-journald[69]: Runtime Journal (/run/log/journal/53cf3f1db2a34a8ea6e697a76049360a) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> server # [5740882.758657] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [5740882.606268] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> server # [5740882.758869] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> ca # [5740882.667048] ca systemd-journald[78]: Journal started container-test-run-certificates> server # [5740882.759844] server systemd[1]: Starting Network Management... container-test-run-certificates> client # [5740882.614578] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [5740882.667098] ca systemd-journald[78]: Runtime Journal (/run/log/journal/22278df8060b4468bb4e5a9c4544b635) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> client # [5740882.615347] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [5740882.672602] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> client # [5740882.615972] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [5740882.681081] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [5740882.624431] client systemd-journald[69]: Time spent on flushing to /var/log/journal/53cf3f1db2a34a8ea6e697a76049360a is 1.977ms for 6 entries. container-test-run-certificates> ca # [5740882.681851] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [5740882.624431] client systemd-journald[69]: System Journal (/var/log/journal/53cf3f1db2a34a8ea6e697a76049360a) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [5740882.682525] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [5740882.627975] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [5740882.689904] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/22278df8060b4468bb4e5a9c4544b635 is 1.653ms for 6 entries. container-test-run-certificates> client # [5740882.628208] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> ca # [5740882.689904] ca systemd-journald[78]: System Journal (/var/log/journal/22278df8060b4468bb4e5a9c4544b635) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [5740882.628290] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [5740882.694715] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [5740882.629001] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [5740882.695333] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [5740882.629042] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [5740882.695444] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [5740882.629861] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [5740882.696236] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [5740882.629895] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [5740882.696283] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [5740882.690562] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> ca # [5740882.697056] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> client # [5740882.691660] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [5740882.697090] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> client # [5740882.707318] client systemd-tmpfiles[143]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> ca # [5740882.715326] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [5740882.707510] client systemd-tmpfiles[143]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> ca # [5740882.716929] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> client # [5740882.707642] client systemd-tmpfiles[143]: fchmod() of /var/log/journal/53cf3f1db2a34a8ea6e697a76049360a failed: Operation not permitted container-test-run-certificates> ca # [5740882.735726] ca systemd-tmpfiles[130]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [5740882.707847] client systemd-tmpfiles[143]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> ca # [5740882.735928] ca systemd-tmpfiles[130]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [5740882.709751] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> ca # [5740882.736087] ca systemd-tmpfiles[130]: fchmod() of /var/log/journal/22278df8060b4468bb4e5a9c4544b635 failed: Operation not permitted container-test-run-certificates> client # [5740882.710791] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> ca # [5740882.736687] ca systemd-tmpfiles[130]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [5740882.711524] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [5740882.738181] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> client # [5740882.723912] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [5740882.739294] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> client # [5740882.730063] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> ca # [5740882.740052] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> client # [5740882.731104] client systemd[1]: Starting Update is Completed... container-test-run-certificates> ca # [5740882.752532] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> client # [5740882.740707] client systemd[1]: Finished Update is Completed. container-test-run-certificates> ca # [5740882.757795] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> client # [5740882.744446] client systemd[1]: Finished Firewall. container-test-run-certificates> ca # [5740882.758938] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> client # [5740882.744593] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [5740882.744796] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [5740882.745882] client systemd[1]: Starting Network Management... container-test-run-certificates> ca # [5740882.768271] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> ca # [5740882.810564] ca systemd[1]: Finished Firewall. container-test-run-certificates> ca # [5740882.810707] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [5740882.810919] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> ca # [5740882.811944] ca systemd[1]: Starting Network Management... container-test-run-certificates> ca # [5740882.923432] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> client # [5740882.923498] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [5740882.923915] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [5740883.183360] server systemd-networkd[186]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [5740883.183444] server systemd-networkd[186]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [5740883.190926] server systemd-networkd[186]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [5740883.191085] server systemd-networkd[186]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [5740883.191228] server systemd-networkd[186]: lo: Link UP container-test-run-certificates> server # [5740883.191233] server systemd-networkd[186]: lo: Gained carrier container-test-run-certificates> server # [5740883.191398] server systemd-networkd[186]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [5740883.191817] server systemd[1]: Started Network Management. container-test-run-certificates> server # [5740883.244340] server systemd-networkd[186]: eth1: Link UP container-test-run-certificates> server # [5740883.244435] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> server # [5740883.244718] server systemd-networkd[186]: eth1: Gained carrier container-test-run-certificates> server # [5740883.289757] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [5740883.320324] server systemd-resolved[94]: Positive Trust Anchors: container-test-run-certificates> server # [5740883.320336] server systemd-resolved[94]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [5740883.320339] server systemd-resolved[94]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [5740883.320373] server systemd-resolved[94]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [5740883.342452] server systemd-resolved[94]: Using system hostname 'server'. container-test-run-certificates> server # [5740883.343711] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [5740883.343780] server systemd[1]: Reached target Network. container-test-run-certificates> server # [5740883.343833] server systemd[1]: Reached target Network is Online. container-test-run-certificates> server # [5740883.343873] server systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [5740883.344073] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> server # [5740883.344104] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [5740883.344127] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [5740883.344145] server systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [5740883.344253] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [5740883.344349] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [5740883.344452] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [5740883.344472] server systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [5740883.344514] server systemd[1]: Reached target Basic System. container-test-run-certificates> server # [5740883.345838] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> server # [5740883.346769] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [5740883.346803] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> server # [5740883.347651] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [5740883.348877] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [5740883.366388] server systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [5740883.482907] server acme-setup-privileged[192]: + set -euo pipefail container-test-run-certificates> server # [5740883.482907] server acme-setup-privileged[192]: + cd /var/lib/acme container-test-run-certificates> server # [5740883.482907] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> client # [5740883.174427] client systemd-networkd[182]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [5740883.174516] client systemd-networkd[182]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [5740883.181506] client systemd-networkd[182]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [5740883.181671] client systemd-networkd[182]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [5740883.181816] client systemd-networkd[182]: lo: Link UP container-test-run-certificates> client # [5740883.181820] client systemd-networkd[182]: lo: Gained carrier container-test-run-certificates> client # [5740883.182011] client systemd-networkd[182]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [5740883.182402] client systemd[1]: Started Network Management. container-test-run-certificates> client # [5740883.182458] client systemd-networkd[182]: eth1: Link UP container-test-run-certificates> client # [5740883.182851] client systemd-networkd[182]: eth1: Gained carrier container-test-run-certificates> client # [5740883.183640] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> client # [5740883.253777] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> client # [5740883.330608] client systemd-resolved[95]: Positive Trust Anchors: container-test-run-certificates> client # [5740883.330619] client systemd-resolved[95]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> client # [5740883.330623] client systemd-resolved[95]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [5740883.330658] client systemd-resolved[95]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [5740883.352561] client systemd-resolved[95]: Using system hostname 'client'. container-test-run-certificates> client # [5740883.353940] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> client # [5740883.354030] client systemd[1]: Reached target Network. container-test-run-certificates> client # [5740883.354105] client systemd[1]: Reached target System Initialization. container-test-run-certificates> client # [5740883.354166] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [5740883.354204] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> client # [5740883.354227] client systemd[1]: Reached target Timer Units. container-test-run-certificates> client # [5740883.354458] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [5740883.354611] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> client # [5740883.354760] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> client # [5740883.354786] client systemd[1]: Reached target Socket Units. container-test-run-certificates> client # [5740883.354838] client systemd[1]: Reached target Basic System. container-test-run-certificates> client # [5740883.356086] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> client # [5740883.357125] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> client # [5740883.358636] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> client # [5740883.375713] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> client # [5740883.505110] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [5740883.505277] client nsncd[189]: Aug 14 10:05:09.558 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [5740883.505176] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [5740883.505242] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [5740883.290019] ca systemd-networkd[195]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [5740883.290127] ca systemd-networkd[195]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [5740883.296638] ca systemd-networkd[195]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [5740883.296798] ca systemd-networkd[195]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [5740883.296943] ca systemd-networkd[195]: lo: Link UP container-test-run-certificates> ca # [5740883.296946] ca systemd-networkd[195]: lo: Gained carrier container-test-run-certificates> ca # [5740883.297130] ca systemd-networkd[195]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> ca # [5740883.297465] ca systemd[1]: Started Network Management. container-test-run-certificates> ca # [5740883.297548] ca systemd-networkd[195]: eth1: Link UP container-test-run-certificates> ca # [5740883.297754] ca systemd-networkd[195]: eth1: Gained carrier container-test-run-certificates> ca # [5740883.298659] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [5740883.341913] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> ca # [5740883.400347] ca systemd-resolved[103]: Positive Trust Anchors: container-test-run-certificates> ca # [5740883.400358] ca systemd-resolved[103]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [5740883.400363] ca systemd-resolved[103]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [5740883.400398] ca systemd-resolved[103]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [5740883.422710] ca systemd-resolved[103]: Using system hostname 'ca'. container-test-run-certificates> ca # [5740883.424215] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [5740883.424302] ca systemd[1]: Reached target Network. container-test-run-certificates> ca # [5740883.424370] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [5740883.424424] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [5740883.424642] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> ca # [5740883.424688] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [5740883.424712] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [5740883.424734] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> ca # [5740883.424878] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> ca # [5740883.425002] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [5740883.425134] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [5740883.425164] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [5740883.425207] ca systemd[1]: Reached target Basic System. container-test-run-certificates> ca # [5740883.426624] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> ca # [5740883.427655] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [5740883.427700] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> ca # [5740883.428572] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [5740883.429670] ca systemd[1]: Starting step-ca service... container-test-run-certificates> ca # [5740883.431078] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> ca # [5740883.447725] ca systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> ca # [5740883.558903] ca acme-setup-privileged[201]: + set -euo pipefail container-test-run-certificates> ca # [5740883.558903] ca acme-setup-privileged[201]: + cd /var/lib/acme container-test-run-certificates> ca # [5740883.558903] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> server # [5740883.484568] server acme-setup-privileged[192]: + chown -R acme .lego/accounts container-test-run-certificates> server # [5740883.486434] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> client # [5740883.506645] client systemd[1]: Starting User Login Management... container-test-run-certificates> server # [5740883.486464] server acme-setup-privileged[192]: + '[' -d test.foo ']' container-test-run-certificates> server # [5740883.486464] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [5740883.486503] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']' container-test-run-certificates> server # [5740883.516807] server nsncd[194]: Aug 14 10:05:09.569 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> server # [5740883.516868] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> server # [5740883.516946] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> server # [5740883.517015] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> client # [5740883.507703] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [5740883.518273] server systemd[1]: Starting User Login Management... container-test-run-certificates> client # [5740883.518831] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [5740883.518872] server systemd[1]: systemd-user-sessions.service: Failed to spawn executor: No such file or directory container-test-run-certificates> client # [5740883.520369] client systemd[1]: Started Console Getty. container-test-run-certificates> server # [5740883.518898] server systemd[1]: systemd-user-sessions.service: Failed to spawn 'start' task: No such file or directory container-test-run-certificates> client # [5740883.520443] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [5740883.518936] server systemd[1]: systemd-user-sessions.service: Failed with result 'resources'. container-test-run-certificates> client # [5740883.520496] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [5740883.519041] server systemd[1]: Failed to start Permit User Sessions. container-test-run-certificates> client # [5740883.592780] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [5740883.520016] server systemd[1]: Started Console Getty. container-test-run-certificates> client # [5740883.627093] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [5740883.520073] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> client # [5740883.627998] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [5740883.520100] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> client # [5740883.627998] client dbus-broker-launch[190]: Invalid user-name in /nix/store/z18i8gax7zmfr2d22nqb67kfsfgm8wx8-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [5740883.599465] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> client # [5740883.628435] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [5740883.648399] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> client # [5740883.636138] client dbus-broker-launch[190]: Ready container-test-run-certificates> server # [5740883.649208] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [5740883.649208] server dbus-broker-launch[195]: Invalid user-name in /nix/store/jv9ppm6bn4crwrlhr26v9g05j5n42z3q-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [5740883.649553] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [5740883.656966] server dbus-broker-launch[195]: Ready container-test-run-certificates> ca # [5740883.560350] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts container-test-run-certificates> ca # [5740883.562091] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [5740883.562120] ca acme-setup-privileged[201]: + '[' -d ca.foo ']' container-test-run-certificates> ca # [5740883.562120] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [5740883.562120] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> ca # [5740883.576169] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [5740883.576259] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [5740883.576546] ca nsncd[203]: Aug 14 10:05:09.629 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [5740883.576350] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [5740883.577778] ca systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [5740883.578747] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [5740883.589967] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [5740883.590896] ca systemd[1]: Started Console Getty. container-test-run-certificates> ca # [5740883.590937] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> ca # [5740883.590958] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca # [5740883.658063] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [5740883.675129] ca dbus-broker-launch[205]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [5740883.675908] ca dbus-broker-launch[205]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> ca # [5740883.675908] ca dbus-broker-launch[205]: Invalid user-name in /nix/store/vd1mfhapbcl6nngw7x71n7cxgwkrw88b-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> ca # [5740883.676320] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [5740883.683267] ca dbus-broker-launch[205]: Ready container-test-run-certificates> client # [5740884.041938] client systemd-logind[205]: New seat seat0. container-test-run-certificates> client # [5740884.042139] client systemd[1]: Started User Login Management. container-test-run-certificates> client # [5740884.044388] client systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [5740884.104766] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> client # [5740884.104923] client systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [5740884.105459] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> client # [5740884.105754] client systemd[1]: Startup finished in 1.924s. container-test-run-certificates> client # [5740884.288250] client systemd-networkd[182]: eth1: Gained IPv6LL container-test-run-certificates> server # [5740884.039296] server systemd-logind[223]: New seat seat0. container-test-run-certificates> server # [5740884.044103] server systemd[1]: Started User Login Management. container-test-run-certificates> server # [5740884.045552] server systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [5740884.077594] server acme-setup-start[208]: + set -euo pipefail container-test-run-certificates> server # [5740884.077594] server acme-setup-start[208]: + test -e ca/key.pem container-test-run-certificates> server # [5740884.077944] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> server # [5740884.101261] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> server # [5740884.102808] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server # [5740884.109218] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> server # [5740884.109333] server systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [5740884.073745] ca systemd-logind[235]: New seat seat0. container-test-run-certificates> ca # [5740884.073940] ca systemd[1]: Started User Login Management. container-test-run-certificates> ca # [5740884.096785] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> ca # [5740884.110498] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [5740884.110638] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [5740884.117809] ca acme-setup-start[219]: + set -euo pipefail container-test-run-certificates> ca # [5740884.118111] ca acme-setup-start[219]: + test -e ca/key.pem container-test-run-certificates> ca # [5740884.118111] ca acme-setup-start[219]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [5740884.139145] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [5740884.141891] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> ca # [5740884.285489] ca step-ca[204]: badger 2026/08/14 10:05:10 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [5740884.290441] ca step-ca[204]: 2026/08/14 10:05:10 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> ca # [5740884.295518] ca step-ca[204]: 2026/08/14 10:05:10 Starting Smallstep CA/0.30.2 (linux/arm64) container-test-run-certificates> ca # [5740884.295518] ca step-ca[204]: 2026/08/14 10:05:10 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> ca # [5740884.295518] ca step-ca[204]: 2026/08/14 10:05:10 Community Discord: https://u.step.sm/discord container-test-run-certificates> ca # [5740884.295518] ca step-ca[204]: 2026/08/14 10:05:10 Config file: /etc/smallstep/ca.json container-test-run-certificates> ca # [5740884.295518] ca step-ca[204]: 2026/08/14 10:05:10 The primary server URL is https://ca.foo:1443 container-test-run-certificates> ca # [5740884.295518] ca step-ca[204]: 2026/08/14 10:05:10 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [5740884.295679] ca step-ca[204]: 2026/08/14 10:05:10 X.509 Root Fingerprint: c1911077b4f2d9872aae3851e0f048672b07db04673b7a04d166b3f5d4607c7c container-test-run-certificates> ca # [5740884.296250] ca systemd[1]: Started step-ca service. container-test-run-certificates> ca # [5740884.296465] ca step-ca[204]: 2026/08/14 10:05:10 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> ca # [5740884.420149] ca systemd-networkd[195]: eth1: Gained IPv6LL container-test-run-certificates> ca # [5740884.623289] ca acme-ca.foo-start[256]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [5740884.626037] ca acme-ca.foo-start[256]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [5740884.626083] ca acme-ca.foo-start[256]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> ca # [5740884.637112] ca acme-ca.foo-start[293]: + cd ca.foo container-test-run-certificates> ca # [5740884.637318] ca acme-ca.foo-start[293]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> ca # [5740884.638612] ca acme-ca.foo-start[294]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [5740884.638823] ca acme-ca.foo-start[293]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> ca # [5740884.640255] ca acme-ca.foo-start[293]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [5740884.640495] ca acme-ca.foo-start[256]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [5740884.641963] ca acme-ca.foo-start[256]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [5740884.643540] ca acme-ca.foo-start[256]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [5740884.645341] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [5740884.645375] ca acme-ca.foo-start[256]: + '[' -d out ']' container-test-run-certificates> ca # [5740884.645375] ca acme-ca.foo-start[256]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [5740884.647053] ca acme-ca.foo-start[256]: + chown -R acme:nginx out container-test-run-certificates> ca # [5740884.649384] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [5740884.649409] ca acme-ca.foo-start[256]: + '[' -d certificates ']' container-test-run-certificates> ca # [5740884.652579] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> ca # [5740884.654210] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> server # [5740884.576142] server systemd-networkd[186]: eth1: Gained IPv6LL container-test-run-certificates> server # [5740884.579331] server acme-test.foo-start[242]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [5740884.582306] server acme-test.foo-start[242]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [5740884.582306] server acme-test.foo-start[242]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [5740884.593070] server acme-test.foo-start[253]: + cd test.foo container-test-run-certificates> server # [5740884.593665] server acme-test.foo-start[253]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [5740884.594835] server acme-test.foo-start[254]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [5740884.595174] server acme-test.foo-start[253]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [5740884.596454] server acme-test.foo-start[253]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [5740884.596719] server acme-test.foo-start[242]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [5740884.598227] server acme-test.foo-start[242]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [5740884.600286] server acme-test.foo-start[242]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [5740884.602177] server acme-test.foo-start[242]: + for fixpath in out certificates container-test-run-certificates> server # [5740884.602177] server acme-test.foo-start[242]: + '[' -d out ']' container-test-run-certificates> server # [5740884.602274] server acme-test.foo-start[242]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [5740884.604266] server acme-test.foo-start[242]: + chown -R acme:nginx out container-test-run-certificates> server # [5740884.607228] server acme-test.foo-start[242]: + for fixpath in out certificates container-test-run-certificates> server # [5740884.607261] server acme-test.foo-start[242]: + '[' -d certificates ']' container-test-run-certificates> server # [5740884.610949] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [5740884.612340] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> ca # [5740885.210049] ca nginx-pre-start[305]: nginx: the configuration file /nix/store/bhwbsbxslpqmc38qj1yb11qhx7gnm7kr-nginx.conf syntax is ok container-test-run-certificates> server # [5740885.165001] server nginx-pre-start[265]: nginx: the configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf syntax is ok container-test-run-certificates> ca # [5740885.210375] ca nginx-pre-start[305]: nginx: configuration file /nix/store/bhwbsbxslpqmc38qj1yb11qhx7gnm7kr-nginx.conf test is successful container-test-run-certificates> server # [5740885.165334] server nginx-pre-start[265]: nginx: configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf test is successful container-test-run-certificates> ca # [5740885.216688] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [5740885.170735] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [5740885.217479] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [5740885.171518] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [5740885.219724] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> server # [5740885.173836] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> server # [5740885.714625] server acme-order-renew-test.foo-start[268]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [5740885.718002] server acme-order-renew-test.foo-start[268]: + set -euo pipefail container-test-run-certificates> server # [5740885.718078] server acme-order-renew-test.foo-start[268]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [5740885.718191] server acme-order-renew-test.foo-start[268]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [5740885.719613] server acme-order-renew-test.foo-start[268]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> ca # [5740885.764798] ca acme-order-renew-ca.foo-start[308]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [5740885.768303] ca acme-order-renew-ca.foo-start[308]: + set -euo pipefail container-test-run-certificates> ca # [5740885.768380] ca acme-order-renew-ca.foo-start[308]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> server # [5740885.751868] server acme-order-renew-test.foo-start[280]: 2026/08/14 10:05:11 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [5740885.752355] server acme-order-renew-test.foo-start[280]: 2026/08/14 10:05:11 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [5740885.768497] ca acme-order-renew-ca.foo-start[308]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [5740885.769931] ca acme-order-renew-ca.foo-start[308]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> ca # [5740885.787762] ca acme-order-renew-ca.foo-start[320]: 2026/08/14 10:05:11 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [5740885.788167] ca acme-order-renew-ca.foo-start[320]: 2026/08/14 10:05:11 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [5740885.814842] ca step-ca[204]: time="2026-08-14T10:05:11Z" level=info duration="148.202µs" duration-ns=148202 fields.time="2026-08-14T10:05:11Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=f7d5438e-fce8-4ef7-a53c-e2de7e6bf8aa response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5740885.815179] ca acme-order-renew-ca.foo-start[320]: 2026/08/14 10:05:11 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> ca # [5740885.849969] ca step-ca[204]: time="2026-08-14T10:05:11Z" level=info duration=34.468396ms duration-ns=34468396 fields.time="2026-08-14T10:05:11Z" method=HEAD name=ca nonce=YVRlRjMxTmF4M20zNTNWOE9vUWRuRkRNbk1CS3p5YkE path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=694047c6-ea44-4e82-a6c7-f926951119fe size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5740885.854436] ca step-ca[204]: time="2026-08-14T10:05:11Z" level=info duration=3.226284ms duration-ns=3226284 fields.time="2026-08-14T10:05:11Z" method=POST name=ca nonce=bWRZS1ZYbVNuVUJScmJFemd0eGNuSjc0ZXpDbGNnODU path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=6f4e1949-9534-476e-82be-7a90f2e3dc0b response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/w75ECmfGGFLzzaFhxVbIPguBuKjwAjGw/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5740885.854940] ca acme-order-renew-ca.foo-start[320]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [5740885.854940] ca acme-order-renew-ca.foo-start[320]: Your account credentials have been saved in your container-test-run-certificates> ca # [5740885.854940] ca acme-order-renew-ca.foo-start[320]: configuration directory at "accounts". container-test-run-certificates> ca # [5740885.854940] ca acme-order-renew-ca.foo-start[320]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [5740885.854940] ca acme-order-renew-ca.foo-start[320]: configuration directory will also contain private keys container-test-run-certificates> ca # [5740885.854940] ca acme-order-renew-ca.foo-start[320]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [5740885.854940] ca acme-order-renew-ca.foo-start[320]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [5740885.855064] ca acme-order-renew-ca.foo-start[320]: 2026/08/14 10:05:11 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [5740885.858501] ca step-ca[204]: time="2026-08-14T10:05:11Z" level=info duration=3.031202ms duration-ns=3031202 fields.time="2026-08-14T10:05:11Z" method=POST name=ca nonce=ZW85MWZWMDJQYXhPMGZnZ1BJbTRHaGhndjB1NlZlcTE path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=d079f8ae-5618-46ba-b1a9-3aee893a5190 response="{\"id\":\"kZJJVYJAGjhFLBLM1ghzgl61uNGiNTYS\",\"status\":\"pending\",\"expires\":\"2026-08-15T10:05:11Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-14T10:04:11Z\",\"notAfter\":\"2026-11-12T10:05:11Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/EaSOiY7u2q9Y9tjgPcmpWKT3lPl116nk\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/kZJJVYJAGjhFLBLM1ghzgl61uNGiNTYS/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5740885.927550] ca step-ca[204]: time="2026-08-14T10:05:11Z" level=info duration=11.795723ms duration-ns=11795723 fields.time="2026-08-14T10:05:11Z" method=POST name=ca nonce=elNYc3oxNHphRWJXRFRiUXo1UndBMDFqcDZ2cWRzbVI path=/acme/acme/authz/EaSOiY7u2q9Y9tjgPcmpWKT3lPl116nk protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=7996b043-7db6-46d8-b956-6fdbb0087792 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"LsJi41FEkDdLiRk2h9s4TciHJzJdAm9c\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/EaSOiY7u2q9Y9tjgPcmpWKT3lPl116nk/Ss4AMciiO7cCHMDqk3tIHdun6nsAIXbq\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"LsJi41FEkDdLiRk2h9s4TciHJzJdAm9c\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/EaSOiY7u2q9Y9tjgPcmpWKT3lPl116nk/IuxQ16esTmnUMbEyMG2tBXroNEoNeNPx\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"LsJi41FEkDdLiRk2h9s4TciHJzJdAm9c\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/EaSOiY7u2q9Y9tjgPcmpWKT3lPl116nk/bv7Pt4aJrNev5RJmUr5ES5lhNDpEc25t\"}],\"wildcard\":false,\"expires\":\"2026-08-15T10:05:11Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5740885.927905] ca acme-order-renew-ca.foo-start[320]: 2026/08/14 10:05:11 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/EaSOiY7u2q9Y9tjgPcmpWKT3lPl116nk container-test-run-certificates> ca # [5740885.927905] ca acme-order-renew-ca.foo-start[320]: 2026/08/14 10:05:11 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [5740885.927905] ca acme-order-renew-ca.foo-start[320]: 2026/08/14 10:05:11 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [5740885.927905] ca acme-order-renew-ca.foo-start[320]: 2026/08/14 10:05:11 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> ca # [5740885.932347] ca step-ca[204]: time="2026-08-14T10:05:11Z" level=info duration=3.841373ms duration-ns=3841373 fields.time="2026-08-14T10:05:11Z" method=POST name=ca nonce=QmZFUFZWWGt2N2JPWWRaeHVxanlQQnZvSFd1bXRIU0U path=/acme/acme/challenge/EaSOiY7u2q9Y9tjgPcmpWKT3lPl116nk/IuxQ16esTmnUMbEyMG2tBXroNEoNeNPx protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=ba99dee2-636a-4e92-bad7-48d6e9803d5d response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"LsJi41FEkDdLiRk2h9s4TciHJzJdAm9c\",\"validated\":\"2026-08-14T10:05:11Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/EaSOiY7u2q9Y9tjgPcmpWKT3lPl116nk/IuxQ16esTmnUMbEyMG2tBXroNEoNeNPx\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5740885.932635] ca acme-order-renew-ca.foo-start[320]: 2026/08/14 10:05:11 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [5740885.932713] ca acme-order-renew-ca.foo-start[320]: 2026/08/14 10:05:11 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [5740885.938646] ca step-ca[204]: time="2026-08-14T10:05:11Z" level=info duration=4.892108ms duration-ns=4892108 fields.time="2026-08-14T10:05:11Z" method=POST name=ca nonce=RDliaU1mNDdXbGFRMm4zN0RRSHA0M2pXemQ1YjlUanA path=/acme/acme/order/kZJJVYJAGjhFLBLM1ghzgl61uNGiNTYS/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=9a50fcf0-049a-4d19-9430-d4750ac8f512 response="{\"id\":\"kZJJVYJAGjhFLBLM1ghzgl61uNGiNTYS\",\"status\":\"valid\",\"expires\":\"2026-08-15T10:05:11Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-14T10:04:11Z\",\"notAfter\":\"2026-11-12T10:05:11Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/EaSOiY7u2q9Y9tjgPcmpWKT3lPl116nk\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/kZJJVYJAGjhFLBLM1ghzgl61uNGiNTYS/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/jhDB8ElHl7IrmPGG1XTmvr9zcbqNwRsP\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5740885.940049] ca step-ca[204]: time="2026-08-14T10:05:11Z" level=info certificate="MIIB1DCCAXmgAwIBAgIQETatHooTGmjiUdqq+1lL4DAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MTQxMDA0MTFaFw0yNjExMTIxMDA1MTFaMBExDzANBgNVBAMTBmNhLmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABFpHsD9Uf2khDHmMQ5f1guJ2zLNKaAr7Zh6UblKpfJ4IOYv+nuO3XXJr+VxSqm2eJwHgsaPqLicebpYBHJ0OXvqjgaQwgaEwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQU2+8clocifCkpTtSmkK8phD8sc/kwHwYDVR0jBBgwFoAUFdSLKtRX3IG+4ZGzQ/tALRpRAFIwEQYDVR0RBAowCIIGY2EuZm9vMB0GDCsGAQQBgqRkxihAAQQNMAsCAQYEBGFjbWUEADAKBggqhkjOPQQDAgNJADBGAiEA4XLRGok1bRXjv0sphEWnVXHt0ExU1Gn2HBQjRLeXgSoCIQDl9HVR2bPi2lVcy61s//ZqW1EYKBXvIw9mfFeJvWBw7Q==" duration="895.733µs" duration-ns=895733 fields.time="2026-08-14T10:05:11Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=dTBnUDdxeHZ1ZFRyUkVVcDJFa3FENERYOFB0MFBrZjk path=/acme/acme/certificate/jhDB8ElHl7IrmPGG1XTmvr9zcbqNwRsP protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=d97f6e2b-a53a-4c2b-a293-60a7641aa951 sans="map[dns:[ca.foo]]" serial=22880771235142783360435129375824366560 size=1344 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-14T10:04:11Z" valid-to="2026-11-12T10:05:11Z" container-test-run-certificates> ca # [5740885.940210] ca acme-order-renew-ca.foo-start[320]: 2026/08/14 10:05:11 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [5740885.945365] ca acme-order-renew-ca.foo-start[308]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [5740885.946902] ca acme-order-renew-ca.foo-start[308]: + touch out/acme-success container-test-run-certificates> ca # [5740885.948391] ca acme-order-renew-ca.foo-start[308]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [5740885.949580] ca acme-order-renew-ca.foo-start[308]: + touch out/renewed container-test-run-certificates> ca # [5740885.951273] ca acme-order-renew-ca.foo-start[308]: + echo Installing new certificate container-test-run-certificates> ca # [5740885.951273] ca acme-order-renew-ca.foo-start[308]: Installing new certificate container-test-run-certificates> ca # [5740885.951345] ca acme-order-renew-ca.foo-start[308]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [5740885.952697] ca acme-order-renew-ca.foo-start[350]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [5740885.952938] ca acme-order-renew-ca.foo-start[308]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [5740885.954082] ca acme-order-renew-ca.foo-start[351]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [5740885.954263] ca acme-order-renew-ca.foo-start[308]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [5740885.955770] ca acme-order-renew-ca.foo-start[352]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [5740885.956005] ca acme-order-renew-ca.foo-start[308]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [5740885.957395] ca acme-order-renew-ca.foo-start[308]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [5740885.958913] ca acme-order-renew-ca.foo-start[308]: + for fixpath in out certificates container-test-run-certificates> ca # [5740885.958944] ca acme-order-renew-ca.foo-start[308]: + '[' -d out ']' container-test-run-certificates> ca # [5740885.958944] ca acme-order-renew-ca.foo-start[308]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [5740885.960294] ca acme-order-renew-ca.foo-start[308]: + chown -R acme:nginx out container-test-run-certificates> ca # [5740885.962514] ca acme-order-renew-ca.foo-start[308]: + for fixpath in out certificates container-test-run-certificates> ca # [5740885.962514] ca acme-order-renew-ca.foo-start[308]: + '[' -d certificates ']' container-test-run-certificates> ca # [5740885.962621] ca acme-order-renew-ca.foo-start[308]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [5740885.963820] ca acme-order-renew-ca.foo-start[308]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [5740885.965865] ca acme-order-renew-ca.foo-start[308]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [5740886.065965] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> ca # [5740886.069766] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [5740886.069942] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> ca # [5740886.620950] ca nginx[368]: nginx: the configuration file /nix/store/bhwbsbxslpqmc38qj1yb11qhx7gnm7kr-nginx.conf syntax is ok container-test-run-certificates> ca # [5740886.621267] ca nginx[368]: nginx: configuration file /nix/store/bhwbsbxslpqmc38qj1yb11qhx7gnm7kr-nginx.conf test is successful container-test-run-certificates> server # [5740886.787023] server acme-order-renew-test.foo-start[280]: 2026/08/14 10:05:12 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 2 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority container-test-run-certificates> server # [5740886.791734] server acme-order-renew-test.foo-start[268]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [5740886.791734] server acme-order-renew-test.foo-start[268]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [5740886.791734] server acme-order-renew-test.foo-start[268]: + exit 10 container-test-run-certificates> server # [5740886.795227] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a container-test-run-certificates> server # [5740886.795346] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'. container-test-run-certificates> server # [5740886.824183] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [5740886.824588] server systemd[1]: Startup finished in 4.629s. container-test-run-certificates> ca # [5740887.116615] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [5740887.117102] ca systemd[1]: Startup finished in 4.910s. container-test-run-certificates> ca # [5740887.416877] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 3.44 seconds) container-test-run-certificates> ca # [5740888.031470] ca acme-order-renew-ca.foo-start[383]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [5740888.033838] ca acme-order-renew-ca.foo-start[383]: + set -euo pipefail container-test-run-certificates> ca # [5740888.033908] ca acme-order-renew-ca.foo-start[383]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [5740888.034015] ca acme-order-renew-ca.foo-start[383]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [5740888.034958] ca acme-order-renew-ca.foo-start[383]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [5740888.034958] ca acme-order-renew-ca.foo-start[383]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [5740888.035304] ca acme-order-renew-ca.foo-start[391]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [5740888.038082] ca acme-order-renew-ca.foo-start[383]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [5740888.038131] ca acme-order-renew-ca.foo-start[383]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [5740888.076905] ca step-ca[204]: time="2026-08-14T10:05:14Z" level=info duration="49.4µs" duration-ns=49400 fields.time="2026-08-14T10:05:14Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=58d88fb6-25f8-4380-947f-b6e57ed7d554 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5740888.077361] ca acme-order-renew-ca.foo-start[392]: 2026/08/14 10:05:14 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [5740888.077361] ca acme-order-renew-ca.foo-start[392]: 2026/08/14 10:05:14 [INFO] [ca.foo] The certificate expires at 2026-11-12T10:05:11Z, the renewal can be performed in 1439h59m36.869485382s: no renewal. container-test-run-certificates> ca # [5740888.077868] ca acme-order-renew-ca.foo-start[383]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [5740888.079512] ca acme-order-renew-ca.foo-start[383]: + touch out/acme-success container-test-run-certificates> ca # [5740888.081217] ca acme-order-renew-ca.foo-start[383]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [5740888.082261] ca acme-order-renew-ca.foo-start[383]: + for fixpath in out certificates container-test-run-certificates> ca # [5740888.082282] ca acme-order-renew-ca.foo-start[383]: + '[' -d out ']' container-test-run-certificates> ca # [5740888.082299] ca acme-order-renew-ca.foo-start[383]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [5740888.084153] ca acme-order-renew-ca.foo-start[383]: + chown -R acme:nginx out container-test-run-certificates> ca # [5740888.086399] ca acme-order-renew-ca.foo-start[383]: + for fixpath in out certificates container-test-run-certificates> ca # [5740888.086421] ca acme-order-renew-ca.foo-start[383]: + '[' -d certificates ']' container-test-run-certificates> ca # [5740888.086438] ca acme-order-renew-ca.foo-start[383]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [5740888.087870] ca acme-order-renew-ca.foo-start[383]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [5740888.090800] ca acme-order-renew-ca.foo-start[383]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [5740888.192756] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [5740888.192945] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server # [5740891.208998] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [5740891.209155] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [5740891.209991] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [5740891.211387] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.66 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1008 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 14 10:05:10 2026 GMT container-test-run-certificates> * expire date: Sep 13 10:05:10 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 31591e container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [5740891.801280] server acme-test.foo-start[314]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [5740891.804646] server acme-test.foo-start[314]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [5740891.804646] server acme-test.foo-start[314]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [5740891.815431] server acme-test.foo-start[325]: + cd test.foo container-test-run-certificates> server # [5740891.815657] server acme-test.foo-start[325]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [5740891.817202] server acme-test.foo-start[326]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [5740891.817475] server acme-test.foo-start[325]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [5740891.818836] server acme-test.foo-start[325]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [5740891.819107] server acme-test.foo-start[314]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [5740891.821030] server acme-test.foo-start[314]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [5740891.823047] server acme-test.foo-start[314]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [5740891.824640] server acme-test.foo-start[314]: + for fixpath in out certificates container-test-run-certificates> server # [5740891.824669] server acme-test.foo-start[314]: + '[' -d out ']' container-test-run-certificates> server # [5740891.824669] server acme-test.foo-start[314]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [5740891.826442] server acme-test.foo-start[314]: + chown -R acme:nginx out container-test-run-certificates> server # [5740891.829624] server acme-test.foo-start[314]: + for fixpath in out certificates container-test-run-certificates> server # [5740891.829624] server acme-test.foo-start[314]: + '[' -d certificates ']' container-test-run-certificates> server # [5740891.856425] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [5740891.858884] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> server # [5740892.598782] server acme-order-renew-test.foo-start[333]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [5740892.602235] server acme-order-renew-test.foo-start[333]: + set -euo pipefail container-test-run-certificates> server # [5740892.602352] server acme-order-renew-test.foo-start[333]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [5740892.602437] server acme-order-renew-test.foo-start[333]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [5740892.603868] server acme-order-renew-test.foo-start[333]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [5740892.650737] server acme-order-renew-test.foo-start[341]: 2026/08/14 10:05:18 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [5740892.714370] server acme-order-renew-test.foo-start[341]: !!!! HEADS UP !!!! container-test-run-certificates> server # [5740892.714370] server acme-order-renew-test.foo-start[341]: Your account credentials have been saved in your container-test-run-certificates> server # [5740892.714370] server acme-order-renew-test.foo-start[341]: configuration directory at "accounts". container-test-run-certificates> server # [5740892.714370] server acme-order-renew-test.foo-start[341]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [5740892.714370] server acme-order-renew-test.foo-start[341]: configuration directory will also contain private keys container-test-run-certificates> server # [5740892.714370] server acme-order-renew-test.foo-start[341]: generated by lego and certificates obtained from the ACME container-test-run-certificates> server # [5740892.714370] server acme-order-renew-test.foo-start[341]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [5740892.714582] server acme-order-renew-test.foo-start[341]: 2026/08/14 10:05:18 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> server # [5740892.794466] server acme-order-renew-test.foo-start[341]: 2026/08/14 10:05:18 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/DHyqMNQx4y2Ap9yuMXiKsJlD3efHffIl container-test-run-certificates> server # [5740892.794466] server acme-order-renew-test.foo-start[341]: 2026/08/14 10:05:18 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [5740892.794466] server acme-order-renew-test.foo-start[341]: 2026/08/14 10:05:18 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [5740892.794466] server acme-order-renew-test.foo-start[341]: 2026/08/14 10:05:18 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [5740892.802026] server acme-order-renew-test.foo-start[341]: 2026/08/14 10:05:18 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [5740892.802135] server acme-order-renew-test.foo-start[341]: 2026/08/14 10:05:18 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [5740892.814344] server acme-order-renew-test.foo-start[341]: 2026/08/14 10:05:18 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [5740892.824229] server acme-order-renew-test.foo-start[333]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [5740892.825768] server acme-order-renew-test.foo-start[333]: + touch out/acme-success container-test-run-certificates> server # [5740892.827124] server acme-order-renew-test.foo-start[333]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [5740892.828195] server acme-order-renew-test.foo-start[333]: + touch out/renewed container-test-run-certificates> server # [5740892.829628] server acme-order-renew-test.foo-start[333]: + echo Installing new certificate container-test-run-certificates> server # [5740892.829628] server acme-order-renew-test.foo-start[333]: Installing new certificate container-test-run-certificates> server # [5740892.829678] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [5740892.831105] server acme-order-renew-test.foo-start[373]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [5740892.831348] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [5740892.833427] server acme-order-renew-test.foo-start[374]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [5740892.833732] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [5740892.835013] server acme-order-renew-test.foo-start[375]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [5740892.835218] server acme-order-renew-test.foo-start[333]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [5740892.836754] server acme-order-renew-test.foo-start[333]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [5740892.838265] server acme-order-renew-test.foo-start[333]: + for fixpath in out certificates container-test-run-certificates> server # [5740892.838293] server acme-order-renew-test.foo-start[333]: + '[' -d out ']' container-test-run-certificates> server # [5740892.838293] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [5740892.839706] server acme-order-renew-test.foo-start[333]: + chown -R acme:nginx out container-test-run-certificates> server # [5740892.841957] server acme-order-renew-test.foo-start[333]: + for fixpath in out certificates container-test-run-certificates> server # [5740892.841985] server acme-order-renew-test.foo-start[333]: + '[' -d certificates ']' container-test-run-certificates> server # [5740892.841985] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [5740892.843373] server acme-order-renew-test.foo-start[333]: + chown -R acme:nginx certificates container-test-run-certificates> server # [5740892.845483] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [5740892.650303] ca step-ca[204]: time="2026-08-14T10:05:18Z" level=info duration="40.601µs" duration-ns=40601 fields.time="2026-08-14T10:05:18Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=4ea96889-9c41-44ae-bcb3-6167c8a87de2 response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5740892.709537] ca step-ca[204]: time="2026-08-14T10:05:18Z" level=info duration=56.781945ms duration-ns=56781945 fields.time="2026-08-14T10:05:18Z" method=HEAD name=ca nonce=NnBQWXRFMzg2MDVENGpRSUVqb1FwTkI5dkhBRGdjbWo path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=89d1a54e-3673-4155-bae8-1c581ba76032 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5740892.713828] ca step-ca[204]: time="2026-08-14T10:05:18Z" level=info duration=2.085029ms duration-ns=2085029 fields.time="2026-08-14T10:05:18Z" method=POST name=ca nonce=elNSM2hmM29TQUFnMkZaUWNXTVRyNkNkbkN6eWZwbUY path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=b5cc2852-a80d-4905-8272-f99628d9abbd response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/jySRiqS9AjLZFkK5Z9by8tJop30VqvT8/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5740892.719617] ca step-ca[204]: time="2026-08-14T10:05:18Z" level=info duration=3.394527ms duration-ns=3394527 fields.time="2026-08-14T10:05:18Z" method=POST name=ca nonce=VUJiQVZ1bUNkVHY2ODJiY2gyUWZYYXhXdUE2Mzc3WFI path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=62ae2371-4e78-437b-8dc2-bb3f1039e351 response="{\"id\":\"DtvCam0HiIdrvFRsrBra4pQLCkUN63Lz\",\"status\":\"pending\",\"expires\":\"2026-08-15T10:05:18Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-14T10:04:18Z\",\"notAfter\":\"2026-11-12T10:05:18Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/DHyqMNQx4y2Ap9yuMXiKsJlD3efHffIl\"],\"finalize\":\"https://ca.foo/acme/acme/order/DtvCam0HiIdrvFRsrBra4pQLCkUN63Lz/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5740892.793939] ca step-ca[204]: time="2026-08-14T10:05:18Z" level=info duration=15.436134ms duration-ns=15436134 fields.time="2026-08-14T10:05:18Z" method=POST name=ca nonce=RG15N2VlUEpFOVo5OENqS01xdXA2NWFXaFZTV043eUE path=/acme/acme/authz/DHyqMNQx4y2Ap9yuMXiKsJlD3efHffIl protocol=HTTP/1.1 referer= remote-address="::1" request-id=579fc266-6bce-4ce0-b5d8-8881d1f72281 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"AYCKujsNtYDocbxLpfOayUdNA38XS3tY\",\"url\":\"https://ca.foo/acme/acme/challenge/DHyqMNQx4y2Ap9yuMXiKsJlD3efHffIl/iRJKNgvlfOShDmda20LDNqnjjqn8x1o9\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"AYCKujsNtYDocbxLpfOayUdNA38XS3tY\",\"url\":\"https://ca.foo/acme/acme/challenge/DHyqMNQx4y2Ap9yuMXiKsJlD3efHffIl/2r2lAMRcWH9aIaJu82C1FVkx6VRbTasZ\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"AYCKujsNtYDocbxLpfOayUdNA38XS3tY\",\"url\":\"https://ca.foo/acme/acme/challenge/DHyqMNQx4y2Ap9yuMXiKsJlD3efHffIl/IMccY9fnem0laPt5gGTA1vvc0JVMWK2j\"}],\"wildcard\":false,\"expires\":\"2026-08-15T10:05:18Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5740892.801614] ca step-ca[204]: time="2026-08-14T10:05:18Z" level=info duration=5.165792ms duration-ns=5165792 fields.time="2026-08-14T10:05:18Z" method=POST name=ca nonce=WTZ1eTc5eERSVkhkcTgyT3h2dXV2enNTbVprb3NDeUs path=/acme/acme/challenge/DHyqMNQx4y2Ap9yuMXiKsJlD3efHffIl/2r2lAMRcWH9aIaJu82C1FVkx6VRbTasZ protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=bbef4022-d909-47cc-8b57-738ea902bd87 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"AYCKujsNtYDocbxLpfOayUdNA38XS3tY\",\"validated\":\"2026-08-14T10:05:18Z\",\"url\":\"https://ca.foo/acme/acme/challenge/DHyqMNQx4y2Ap9yuMXiKsJlD3efHffIl/2r2lAMRcWH9aIaJu82C1FVkx6VRbTasZ\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5740892.810621] ca step-ca[204]: time="2026-08-14T10:05:18Z" level=info duration=6.472929ms duration-ns=6472929 fields.time="2026-08-14T10:05:18Z" method=POST name=ca nonce=eGthTFNmbmdVemVOTUJSU3h0U2tMWmRoYVk1V29mS04 path=/acme/acme/order/DtvCam0HiIdrvFRsrBra4pQLCkUN63Lz/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=1bcf2676-0d3b-48fa-ab4d-ce4d2e02fcbb response="{\"id\":\"DtvCam0HiIdrvFRsrBra4pQLCkUN63Lz\",\"status\":\"valid\",\"expires\":\"2026-08-15T10:05:18Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-14T10:04:18Z\",\"notAfter\":\"2026-11-12T10:05:18Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/DHyqMNQx4y2Ap9yuMXiKsJlD3efHffIl\"],\"finalize\":\"https://ca.foo/acme/acme/order/DtvCam0HiIdrvFRsrBra4pQLCkUN63Lz/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/7ApMGpAGfekQHzA5lggjlpePf1ncv1F2\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5740892.814024] ca step-ca[204]: time="2026-08-14T10:05:18Z" level=info certificate="MIIB2DCCAX6gAwIBAgIRANOKkFQ8epU5+mvGqjPH6MwwCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwODE0MTAwNDE4WhcNMjYxMTEyMTAwNTE4WjATMREwDwYDVQQDEwh0ZXN0LmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABI05MGtKYGG2vWckxr/+giA/maIVVLZIluXu/HnrCNuPJK9F5ilyGImsBBW6/spaKz7qlEmBXmzx1UkRYSvVOIyjgaYwgaMwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQU1odb/ewsGfSP12s2GcYVQdbByykwHwYDVR0jBBgwFoAUFdSLKtRX3IG+4ZGzQ/tALRpRAFIwEwYDVR0RBAwwCoIIdGVzdC5mb28wHQYMKwYBBAGCpGTGKEABBA0wCwIBBgQEYWNtZQQAMAoGCCqGSM49BAMCA0gAMEUCIBYcrk7G2YmZbrOtKYhd9ndyqAHrvMoWNheDeLBVxYkEAiEAiF7hME2zfhM14qG0sX7NVapad3k3NlPP8NlR+t11OAQ=" duration=1.381979ms duration-ns=1381979 fields.time="2026-08-14T10:05:18Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=cE5yajROWDFmVEZ4ZEg4bFhoNGxuN3pjOHZ1ajFEOXY path=/acme/acme/certificate/7ApMGpAGfekQHzA5lggjlpePf1ncv1F2 protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=cdcb1ce0-b892-4a28-9a07-530e53d1c0da sans="map[dns:[test.foo]]" serial=281186571417960926675574687902149896396 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-14T10:04:18Z" valid-to="2026-11-12T10:05:18Z" container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1008 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [112 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 14 10:05:10 2026 GMT container-test-run-certificates> * expire date: Sep 13 10:05:10 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 31591e container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [5740892.940036] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [5740892.943940] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [5740892.944137] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [5740893.529320] server nginx[391]: nginx: the configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf syntax is ok container-test-run-certificates> server # [5740893.529632] server nginx[391]: nginx: configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf test is successful container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1008 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [110 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 14 10:05:10 2026 GMT container-test-run-certificates> * expire date: Sep 13 10:05:10 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 31591e container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [5740894.173098] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [931 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [79 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 14 10:04:18 2026 GMT container-test-run-certificates> * expire date: Nov 12 10:05:18 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 33072 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 797 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 3.17 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> d3:8a:90:54:3c:7a:95:39:fa:6b:c6:aa:33:c7:e8:cc container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Aug 14 10:04:18 2026 GMT container-test-run-certificates> Not After : Nov 12 10:05:18 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:8d:39:30:6b:4a:60:61:b6:bd:67:24:c6:bf:fe: container-test-run-certificates> 82:20:3f:99:a2:15:54:b6:48:96:e5:ee:fc:79:eb: container-test-run-certificates> 08:db:8f:24:af:45:e6:29:72:18:89:ac:04:15:ba: container-test-run-certificates> fe:ca:5a:2b:3e:ea:94:49:81:5e:6c:f1:d5:49:11: container-test-run-certificates> 61:2b:d5:38:8c container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> D6:87:5B:FD:EC:2C:19:F4:8F:D7:6B:36:19:C6:15:41:D6:C1:CB:29 container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> 15:D4:8B:2A:D4:57:DC:81:BE:E1:91:B3:43:FB:40:2D:1A:51:00:52 container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:45:02:20:16:1c:ae:4e:c6:d9:89:99:6e:b3:ad:29:88:5d: container-test-run-certificates> f6:77:72:a8:01:eb:bc:ca:16:36:17:83:78:b0:55:c5:89:04: container-test-run-certificates> 02:21:00:88:5e:e1:30:4d:b3:7e:13:35:e2:a1:b4:b1:7e:cd: container-test-run-certificates> 55:aa:5a:77:79:37:36:53:cf:f0:d9:51:fa:dd:75:38:04 container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.05 seconds) container-test-run-certificates> (finished: run the VM test script, in 13.32 seconds) container-test-run-certificates> test script finished in 14.38s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 52) container-test-run-certificates> kill NspawnMachine (pid 55) container-test-run-certificates> kill NspawnMachine (pid 56) container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> Container server terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.54 seconds) post-build step Upload to niks3: ok time=2026-08-14T10:05:23.327Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-08-14T10:05:24.351Z level=INFO msg="Uploading 1 narinfos" time=2026-08-14T10:05:24.941Z level=INFO msg="Upload complete. (1.666s)"