these 111 derivations will be built: /nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv /nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv /nix/store/d4vj54sx388dyibi2ja6r7jckm4ra5bl-nginx.conf.drv /nix/store/q04acjz5k41ghz0px4lyprax5iwaddql-system-path.drv /nix/store/jgciai23q360dmqk3m1n4jhzsi77lwif-dbus-1.drv /nix/store/zrgg0w0g2drlxnpy5c5i52sh4b0vj3bi-X-Restart-Triggers-dbus-broker.drv /nix/store/9vhkv3j34lhgg86zz9njs0az7jc6lv2j-unit-dbus-broker.service.drv /nix/store/dw1sannzka5dl33nv6rpf6mwf60qlbck-user-units.drv /nix/store/6z5jc0sp4vjkgzd37icya2gy22sk8q70-nixos-tmpfiles.d.drv /nix/store/79kfpjcg65c0rrnp43qfppivwzfx8yvi-10-acme.conf.drv /nix/store/dxhcs8f88vsb624k3l6b10b549cv921m-tmpfiles.d.drv /nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv /nix/store/55r3xbviq6l3zgziig53rhs351x7xj6l-cacert-extra-certificates-bundle.crt.drv /nix/store/x52vjn5rprsx9n1jd5m287f9yhs1ffqn-cacert-blocklist.txt.drv /nix/store/padyknikkjqgfy4dqzfv3zac5wbypxga-nss-cacert-3.126.drv /nix/store/v3r6klh4wv9zb6hmz7fwb1gyzyil9a5n-unit-40-eth1.network.drv /nix/store/ycl6gbj04ywcaxa7ad5ms35wranp5b1r-X-Reload-Triggers-systemd-networkd.drv /nix/store/2y5dcvasfw9vhxcmcgzy70r1w1bd6jg9-unit-systemd-networkd.service.drv /nix/store/579wix8gpv1kx7q5ilr3pi7y7bsjj2a0-unit-nix-daemon.service.drv /nix/store/7pfy24j8qyd0avkdbzd322wr7x9wb2im-unit-dbus-broker.service.drv /nix/store/9wq3xd2sy586pzs7rnpcsl1857hf2a4x-unit-systemd-journald-.service.drv /nix/store/j3lmyghsa4g7nacl7gf67lvx5m91k2br-unit-script-acme-setup-start.drv /nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv /nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv /nix/store/g2gpd27y6vw63m3l59xsfrqf44l31igf-unit-systemd-sysctl.service.drv /nix/store/g9bfvl6h2n1ags2vhzcymd11bzbp5vsc-unit-systemd-journald.service.drv /nix/store/8v8nx7xkgmlz39rnf6l90mdmzhz8c9yx-unit-script-nginx-pre-start.drv /nix/store/j2jdcyp4233cn5lky6zlsk016msb24sr-unit-nginx.service.drv /nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv /nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv /nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv /nix/store/pz8cs4lg35mq4mi7ck3am5chl70g70yx-firewall-start.drv /nix/store/1h3016b7n1wag10qh4dax4mdvk4hiydh-firewall-reload.drv /nix/store/ra9f6mzgpig8bxfp26sd4f4dhdymamc3-unit-firewall.service.drv /nix/store/y9vs2brijwc8c2b5mh0vxrsz0hh37z6h-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/rmxiym60q7p0pgy3rvrqhgl15ngv7yc5-unit-systemd-tmpfiles-resetup.service.drv /nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv /nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv /nix/store/v0clim1zszqklxri4dwhf4gr45rx79ja-unit-systemd-resolved.service.drv /nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv /nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv /nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv /nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/vdfjiw9h88dv64dagxkcdjqy37kkv4z0-system-units.drv /nix/store/6czdibl19vskfdxh9hq70pb6c08r105h-etc.drv /nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv /nix/store/c9izh4gzjzdwdwmznifpwi7rvmmizhha-activate.drv /nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv /nix/store/7fm2sk8drxwspqnc8fzcqy0h7vaydvnj-nixos-system-server-test.drv /nix/store/056524hdq34x27bigz9shhn4x9zi7y02-run-server-nspawn.drv /nix/store/06xj51r5iv0wg3sry7cb1b5p0arh8amk-ca.json.drv /nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv /nix/store/hzmavrl4zmzhyfz3aihprwcvmq7rw11m-system-path.drv /nix/store/1js2x70k6ddahgqrh28zipsnzxjx7l9j-dbus-1.drv /nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv /nix/store/p58gpq8dlbza3dklkqrzwj7blz2knydv-nginx-recommended-proxy_set_header-headers.conf.drv /nix/store/4xq1axfvdgf49msggmxqrmscqafczgj2-nginx.conf.drv /nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv /nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv /nix/store/468p6xhdg7qyzr7isv227xvrdg6r3730-X-Restart-Triggers-dbus-broker.drv /nix/store/jg7zz8425hqiizgxyn4imlz6ydm0drzd-unit-dbus-broker.service.drv /nix/store/brdiqrza4w6vb0wiccvwq1zh9v5y3jhc-user-units.drv /nix/store/bx9ay666mdpxmqa49l3hw83wkl8bjvvs-user-generators.drv /nix/store/imw2kazzmfl6nlf52psv7h2vlnfpdxn3-system-shutdown.drv /nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv /nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv /nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv /nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv /nix/store/fcigm5lijsg6dwldbhhvb6zm2fwl9145-unit-dbus-broker.service.drv /nix/store/fx7ik3vx6rfz50jgfpv7iqc1npfpfzn6-unit-systemd-networkd.service.drv /nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv /nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv /nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv /nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv /nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv /nix/store/xbxd9w9n98kxv8xai0cwa169x1ac9fha-X-Restart-Triggers-step-ca.drv /nix/store/sjh85fq2x445snq0kd66rdbikr113rds-unit-step-ca.service.drv /nix/store/7xx9in4vzx2fh4a7fz1s4wgqj1qf0nxw-unit-script-nginx-pre-start.drv /nix/store/z2id9fli5k6ymffhg4lic3ipyaiywxp6-unit-nginx.service.drv /nix/store/lysdsl3mpn2ldai2qvgdch0ba2ba174d-system-units.drv /nix/store/rr3k22qcv35qb8krj0p5bp7b2yvqp8ml-system-generators.drv /nix/store/3smgikm1rsrqzim2wc564jvqf3qdqgm1-etc.drv /nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv /nix/store/27y4dswv2kiliqv0a7w0vfm21fvsf99v-activate.drv /nix/store/rv1q9jjrri3jsmjk8gyq8xlk9663a0c7-system-path.drv /nix/store/kcg1sng0r20y32mqjjp9y6zicd68zzqz-dbus-1.drv /nix/store/csjdmrjp08pnh38q2yxmh9yymp46n03q-X-Restart-Triggers-dbus-broker.drv /nix/store/3sd144j30qanf036aasfgnp9592pymf7-unit-dbus-broker.service.drv /nix/store/2xhnv7gmks4yzk39pmw7hzrsaahinmsv-user-units.drv /nix/store/50m6cfa5x1dxaslnp49g6lxj4p7np9bp-unit-systemd-networkd.service.drv /nix/store/3wbzl5zadk20cplik16z31fcvghbrlcz-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/7hgnzq5d0x9pk0i03d6a0ia7i525pzmi-unit-systemd-tmpfiles-resetup.service.drv /nix/store/dbk0qb88nzffrsi192pr72cidhrsvqbh-unit-dbus-broker.service.drv /nix/store/i8g688x99787cjd8jvlsmddvhq71rcv2-unit-firewall.service.drv /nix/store/5pnhj5gqqdyn440bfh8fkd62iqgca2s2-system-units.drv /nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv /nix/store/5kzsnqdp0dvg62mwxh7ibjyx1bsk9mj7-etc.drv /nix/store/5mrdkkv0rkyrgkwxwdj3gbwks10c6i55-users-groups.json.drv /nix/store/hvpdgppc2ph0w7r40a0nla0cl5zy2x1k-dry-activate.drv /nix/store/j91la78fnqvrfxlc2aqsn6kxwcgily6b-activate.drv /nix/store/2d8ibm5r6g0nxc1n2vghw7miq6rlvfbw-nixos-system-client-test.drv /nix/store/f8v8h4aimzs2r0x49h5n8np2cblaq637-run-client-nspawn.drv /nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv /nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv /nix/store/pxcw65jdg877ni8ccmn417r7sqfgg07y-nixos-system-ca-test.drv /nix/store/wwllwaak1qmy3gfrxa4iigaffw9sr9li-run-ca-nspawn.drv /nix/store/bsrwhwygnxcmkyz8n03rkpfimx53g7pl-driverConfiguration.json.drv /nix/store/yvmw8lqkvgkxvmz46pcp4jmjfhp3c5da-nixos-test-driver-certificates.drv /nix/store/hjy2ggir6s6g922jlzfq6wnavs2j0znq-container-test-run-certificates.drv these 16 paths will be fetched (45.5 MiB download, 148.8 MiB unpacked): /nix/store/3japwvq6a40ykrmxjjjvm695q2z6c66c-flock-0.4.0 /nix/store/6nr0a4775j5z9nr71ciasfd9pzz076zs-gixy-0.1.21 /nix/store/p12aczsxidgl3m4jkpc4dl4y7kzf8vck-lego-4.35.2 /nix/store/fqcqw4nlcg6q6n77z3gnxhgg3ll6gjvy-minica-1.1.0 /nix/store/pjqhdi88bpspx4a01qlsw96jn2isl11k-nginx-1.30.4 /nix/store/g59y871mjn55fgjswdn72g51qc62j6wa-nginx-config-formatter-1.4.0 /nix/store/n0hdbypqp52bcmm1b5bhxgha5yl8hjs1-nginx-mod-moreheaders-0.40 /nix/store/zzhdyl8d6l7z4jfl5i36ijwqz2vpja7i-nginx-mod-rtmp-1.2.2 /nix/store/1psq003v8r8611bv7bk74xdwz9z6dgaj-openssl-3.6.3-man /nix/store/06pcrb4pj0c0sk6pa39hgmfddprslv4k-openssl-4.0.1 /nix/store/fkylsp720lag8s97n9cbxcafx78clj31-python3.14-buildcatrust-0.5.1 /nix/store/kjz0wmk9imvcj2nrm6ls5yd4mw8awajj-python3.14-cached-property-2.0.1 /nix/store/pfxx0s91wb2bhph7m1hdmzik1d8r9jn9-python3.14-configargparse-1.7.5 /nix/store/fdr01jdc50hn18dn90hx7q9p2jhkaw6m-python3.14-pyparsing-2.4.7 /nix/store/9zffz42v1gbfs8dwi61v4m09skszgl9x-step-ca-0.30.2 /nix/store/j345y5z7axzdpxivknd0swxi5yccyxq4-zlib-ng-2.3.3 building '/nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v3r6klh4wv9zb6hmz7fwb1gyzyil9a5n-unit-40-eth1.network.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/79kfpjcg65c0rrnp43qfppivwzfx8yvi-10-acme.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p58gpq8dlbza3dklkqrzwj7blz2knydv-nginx-recommended-proxy_set_header-headers.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6z5jc0sp4vjkgzd37icya2gy22sk8q70-nixos-tmpfiles.d.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/pz8cs4lg35mq4mi7ck3am5chl70g70yx-firewall-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/j3lmyghsa4g7nacl7gf67lvx5m91k2br-unit-script-acme-setup-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/06xj51r5iv0wg3sry7cb1b5p0arh8amk-ca.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/x52vjn5rprsx9n1jd5m287f9yhs1ffqn-cacert-blocklist.txt.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/55r3xbviq6l3zgziig53rhs351x7xj6l-cacert-extra-certificates-bundle.crt.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/hzmavrl4zmzhyfz3aihprwcvmq7rw11m-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/q04acjz5k41ghz0px4lyprax5iwaddql-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rv1q9jjrri3jsmjk8gyq8xlk9663a0c7-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rr3k22qcv35qb8krj0p5bp7b2yvqp8ml-system-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/imw2kazzmfl6nlf52psv7h2vlnfpdxn3-system-shutdown.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/bx9ay666mdpxmqa49l3hw83wkl8bjvvs-user-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/d4vj54sx388dyibi2ja6r7jckm4ra5bl-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/79kfpjcg65c0rrnp43qfppivwzfx8yvi-10-acme.conf.drv' building '/nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv' building '/nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv' building '/nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv' building '/nix/store/6z5jc0sp4vjkgzd37icya2gy22sk8q70-nixos-tmpfiles.d.drv' building '/nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv' building '/nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv' unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled building '/nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv' unit-acme-renew-ca.foo.timer> structuredAttrs is enabled building '/nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv' unit-acme-renew-test.foo.timer> structuredAttrs is enabled building '/nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/p58gpq8dlbza3dklkqrzwj7blz2knydv-nginx-recommended-proxy_set_header-headers.conf.drv' building '/nix/store/x52vjn5rprsx9n1jd5m287f9yhs1ffqn-cacert-blocklist.txt.drv' building '/nix/store/v3r6klh4wv9zb6hmz7fwb1gyzyil9a5n-unit-40-eth1.network.drv' unit-40-eth1.network> structuredAttrs is enabled building '/nix/store/55r3xbviq6l3zgziig53rhs351x7xj6l-cacert-extra-certificates-bundle.crt.drv' building '/nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv' building '/nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv' unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled building '/nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/j3lmyghsa4g7nacl7gf67lvx5m91k2br-unit-script-acme-setup-start.drv' building '/nix/store/06xj51r5iv0wg3sry7cb1b5p0arh8amk-ca.json.drv' ca.json> structuredAttrs is enabled building '/nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv' building '/nix/store/padyknikkjqgfy4dqzfv3zac5wbypxga-nss-cacert-3.126.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/xbxd9w9n98kxv8xai0cwa169x1ac9fha-X-Restart-Triggers-step-ca.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/4xq1axfvdgf49msggmxqrmscqafczgj2-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/pz8cs4lg35mq4mi7ck3am5chl70g70yx-firewall-start.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/ycl6gbj04ywcaxa7ad5ms35wranp5b1r-X-Reload-Triggers-systemd-networkd.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv' building '/nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv' building '/nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv' vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully building '/nix/store/dxhcs8f88vsb624k3l6b10b549cv921m-tmpfiles.d.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv' building '/nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/1h3016b7n1wag10qh4dax4mdvk4hiydh-firewall-reload.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv' building '/nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv' building '/nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv' building '/nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv' building '/nix/store/rv1q9jjrri3jsmjk8gyq8xlk9663a0c7-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/hzmavrl4zmzhyfz3aihprwcvmq7rw11m-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv' building '/nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rr3k22qcv35qb8krj0p5bp7b2yvqp8ml-system-generators.drv' building '/nix/store/imw2kazzmfl6nlf52psv7h2vlnfpdxn3-system-shutdown.drv' building '/nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/bx9ay666mdpxmqa49l3hw83wkl8bjvvs-user-generators.drv' building '/nix/store/q04acjz5k41ghz0px4lyprax5iwaddql-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/xbxd9w9n98kxv8xai0cwa169x1ac9fha-X-Restart-Triggers-step-ca.drv' building '/nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv' building '/nix/store/sjh85fq2x445snq0kd66rdbikr113rds-unit-step-ca.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv' building '/nix/store/1js2x70k6ddahgqrh28zipsnzxjx7l9j-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jgciai23q360dmqk3m1n4jhzsi77lwif-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kcg1sng0r20y32mqjjp9y6zicd68zzqz-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv' building '/nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/4xq1axfvdgf49msggmxqrmscqafczgj2-nginx.conf.drv' nginx.conf> structuredAttrs is enabled building '/nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv' building '/nix/store/d4vj54sx388dyibi2ja6r7jckm4ra5bl-nginx.conf.drv' nginx.conf> structuredAttrs is enabled building '/nix/store/ycl6gbj04ywcaxa7ad5ms35wranp5b1r-X-Reload-Triggers-systemd-networkd.drv' building '/nix/store/2y5dcvasfw9vhxcmcgzy70r1w1bd6jg9-unit-systemd-networkd.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/1h3016b7n1wag10qh4dax4mdvk4hiydh-firewall-reload.drv' building '/nix/store/padyknikkjqgfy4dqzfv3zac5wbypxga-nss-cacert-3.126.drv' nss-cacert-3.126> Running phase: unpackPhase nss-cacert-3.126> Running phase: patchPhase nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase building '/nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/ra9f6mzgpig8bxfp26sd4f4dhdymamc3-unit-firewall.service.drv' on 'ssh-ng://builder@build01.clan.lol' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv' unit-acme-ca.foo.service> structuredAttrs is enabled building '/nix/store/8v8nx7xkgmlz39rnf6l90mdmzhz8c9yx-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' nss-cacert-3.126> Running phase: installPhase nss-cacert-3.126> Running phase: fixupPhase nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/ridw8gz0dkhf4vy5c9afxnxknvw961ig-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/ridw8gz0dkhf4vy5c9afxnxknvw961ig-nss-cacert-3.126... nss-cacert-3.126> patching script interpreter paths in /nix/store/ridw8gz0dkhf4vy5c9afxnxknvw961ig-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/dvn31l91l8iqv893xdx8vyw0yvw7h9dj-nss-cacert-3.126-unbundled building '/nix/store/7xx9in4vzx2fh4a7fz1s4wgqj1qf0nxw-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' nss-cacert-3.126> checking for references to /build/ in /nix/store/dvn31l91l8iqv893xdx8vyw0yvw7h9dj-nss-cacert-3.126-unbundled... nss-cacert-3.126> patching script interpreter paths in /nix/store/dvn31l91l8iqv893xdx8vyw0yvw7h9dj-nss-cacert-3.126-unbundled nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/vmk1fn6m29k5nzblx2zykispx7bilw3f-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/vmk1fn6m29k5nzblx2zykispx7bilw3f-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/vmk1fn6m29k5nzblx2zykispx7bilw3f-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/npxlb2shi8hbh65w64clxcsi09sn11lp-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/npxlb2shi8hbh65w64clxcsi09sn11lp-nss-cacert-3.126-hashed... nss-cacert-3.126> patching script interpreter paths in /nix/store/npxlb2shi8hbh65w64clxcsi09sn11lp-nss-cacert-3.126-hashed building '/nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv' unit-acme-test.foo.service> structuredAttrs is enabled building '/nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv' building '/nix/store/dxhcs8f88vsb624k3l6b10b549cv921m-tmpfiles.d.drv' building '/nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv' unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled building '/nix/store/y9vs2brijwc8c2b5mh0vxrsz0hh37z6h-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kcg1sng0r20y32mqjjp9y6zicd68zzqz-dbus-1.drv' building '/nix/store/jgciai23q360dmqk3m1n4jhzsi77lwif-dbus-1.drv' building '/nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv' unit-acme-order-renew-test.foo.service> structuredAttrs is enabled building '/nix/store/csjdmrjp08pnh38q2yxmh9yymp46n03q-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/sjh85fq2x445snq0kd66rdbikr113rds-unit-step-ca.service.drv' unit-step-ca.service> structuredAttrs is enabled building '/nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv' building '/nix/store/579wix8gpv1kx7q5ilr3pi7y7bsjj2a0-unit-nix-daemon.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/1js2x70k6ddahgqrh28zipsnzxjx7l9j-dbus-1.drv' building '/nix/store/zrgg0w0g2drlxnpy5c5i52sh4b0vj3bi-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/468p6xhdg7qyzr7isv227xvrdg6r3730-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/8v8nx7xkgmlz39rnf6l90mdmzhz8c9yx-unit-script-nginx-pre-start.drv' building '/nix/store/2y5dcvasfw9vhxcmcgzy70r1w1bd6jg9-unit-systemd-networkd.service.drv' unit-systemd-networkd.service> structuredAttrs is enabled building '/nix/store/7xx9in4vzx2fh4a7fz1s4wgqj1qf0nxw-unit-script-nginx-pre-start.drv' building '/nix/store/y9vs2brijwc8c2b5mh0vxrsz0hh37z6h-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' building '/nix/store/468p6xhdg7qyzr7isv227xvrdg6r3730-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/zrgg0w0g2drlxnpy5c5i52sh4b0vj3bi-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/ra9f6mzgpig8bxfp26sd4f4dhdymamc3-unit-firewall.service.drv' unit-firewall.service> structuredAttrs is enabled building '/nix/store/rmxiym60q7p0pgy3rvrqhgl15ngv7yc5-unit-systemd-tmpfiles-resetup.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/j2jdcyp4233cn5lky6zlsk016msb24sr-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/csjdmrjp08pnh38q2yxmh9yymp46n03q-X-Restart-Triggers-dbus-broker.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/7pfy24j8qyd0avkdbzd322wr7x9wb2im-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/9vhkv3j34lhgg86zz9njs0az7jc6lv2j-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/j2jdcyp4233cn5lky6zlsk016msb24sr-unit-nginx.service.drv' building '/nix/store/z2id9fli5k6ymffhg4lic3ipyaiywxp6-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' unit-nginx.service> structuredAttrs is enabled building '/nix/store/579wix8gpv1kx7q5ilr3pi7y7bsjj2a0-unit-nix-daemon.service.drv' unit-nix-daemon.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/fcigm5lijsg6dwldbhhvb6zm2fwl9145-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jg7zz8425hqiizgxyn4imlz6ydm0drzd-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3sd144j30qanf036aasfgnp9592pymf7-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dbk0qb88nzffrsi192pr72cidhrsvqbh-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7pfy24j8qyd0avkdbzd322wr7x9wb2im-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/9vhkv3j34lhgg86zz9njs0az7jc6lv2j-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/z2id9fli5k6ymffhg4lic3ipyaiywxp6-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/dw1sannzka5dl33nv6rpf6mwf60qlbck-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/fcigm5lijsg6dwldbhhvb6zm2fwl9145-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/3sd144j30qanf036aasfgnp9592pymf7-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/jg7zz8425hqiizgxyn4imlz6ydm0drzd-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/dw1sannzka5dl33nv6rpf6mwf60qlbck-user-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/brdiqrza4w6vb0wiccvwq1zh9v5y3jhc-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dbk0qb88nzffrsi192pr72cidhrsvqbh-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/rmxiym60q7p0pgy3rvrqhgl15ngv7yc5-unit-systemd-tmpfiles-resetup.service.drv' unit-systemd-tmpfiles-resetup.service> structuredAttrs is enabled building '/nix/store/5pnhj5gqqdyn440bfh8fkd62iqgca2s2-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/5pnhj5gqqdyn440bfh8fkd62iqgca2s2-system-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/brdiqrza4w6vb0wiccvwq1zh9v5y3jhc-user-units.drv' building '/nix/store/2xhnv7gmks4yzk39pmw7hzrsaahinmsv-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/lysdsl3mpn2ldai2qvgdch0ba2ba174d-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/vdfjiw9h88dv64dagxkcdjqy37kkv4z0-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/2xhnv7gmks4yzk39pmw7hzrsaahinmsv-user-units.drv' building '/nix/store/vdfjiw9h88dv64dagxkcdjqy37kkv4z0-system-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/6czdibl19vskfdxh9hq70pb6c08r105h-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/lysdsl3mpn2ldai2qvgdch0ba2ba174d-system-units.drv' building '/nix/store/5kzsnqdp0dvg62mwxh7ibjyx1bsk9mj7-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3smgikm1rsrqzim2wc564jvqf3qdqgm1-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5kzsnqdp0dvg62mwxh7ibjyx1bsk9mj7-etc.drv' building '/nix/store/6czdibl19vskfdxh9hq70pb6c08r105h-etc.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/c9izh4gzjzdwdwmznifpwi7rvmmizhha-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/c9izh4gzjzdwdwmznifpwi7rvmmizhha-activate.drv' building '/nix/store/j91la78fnqvrfxlc2aqsn6kxwcgily6b-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3smgikm1rsrqzim2wc564jvqf3qdqgm1-etc.drv' building '/nix/store/7fm2sk8drxwspqnc8fzcqy0h7vaydvnj-nixos-system-server-test.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/27y4dswv2kiliqv0a7w0vfm21fvsf99v-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/j91la78fnqvrfxlc2aqsn6kxwcgily6b-activate.drv' building '/nix/store/2d8ibm5r6g0nxc1n2vghw7miq6rlvfbw-nixos-system-client-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7fm2sk8drxwspqnc8fzcqy0h7vaydvnj-nixos-system-server-test.drv' nixos-system-server-test> structuredAttrs is enabled building '/nix/store/056524hdq34x27bigz9shhn4x9zi7y02-run-server-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/27y4dswv2kiliqv0a7w0vfm21fvsf99v-activate.drv' building '/nix/store/pxcw65jdg877ni8ccmn417r7sqfgg07y-nixos-system-ca-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/pxcw65jdg877ni8ccmn417r7sqfgg07y-nixos-system-ca-test.drv' nixos-system-ca-test> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/wwllwaak1qmy3gfrxa4iigaffw9sr9li-run-ca-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wwllwaak1qmy3gfrxa4iigaffw9sr9li-run-ca-nspawn.drv' building '/nix/store/056524hdq34x27bigz9shhn4x9zi7y02-run-server-nspawn.drv' building '/nix/store/2d8ibm5r6g0nxc1n2vghw7miq6rlvfbw-nixos-system-client-test.drv' nixos-system-client-test> structuredAttrs is enabled building '/nix/store/f8v8h4aimzs2r0x49h5n8np2cblaq637-run-client-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/f8v8h4aimzs2r0x49h5n8np2cblaq637-run-client-nspawn.drv' building '/nix/store/bsrwhwygnxcmkyz8n03rkpfimx53g7pl-driverConfiguration.json.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/bsrwhwygnxcmkyz8n03rkpfimx53g7pl-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/yvmw8lqkvgkxvmz46pcp4jmjfhp3c5da-nixos-test-driver-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/yvmw8lqkvgkxvmz46pcp4jmjfhp3c5da-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! building '/nix/store/hjy2ggir6s6g922jlzfq6wnavs2j0znq-container-test-run-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/hjy2ggir6s6g922jlzfq6wnavs2j0znq-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> ca: systemd-nspawn running (pid 51) container-test-run-certificates> client: systemd-nspawn running (pid 54) container-test-run-certificates> server: systemd-nspawn running (pid 56) container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.00 seconds) container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> server # [5827223.025163] server systemd-journald[69]: Journal started container-test-run-certificates> server # [5827223.025219] server systemd-journald[69]: Runtime Journal (/run/log/journal/88ea13f087484b088f4675e2139dcdb2) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> server # [5827223.034629] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> server # [5827223.035466] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> server # [5827223.036155] server systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> server # [5827223.045600] server systemd-journald[69]: Time spent on flushing to /var/log/journal/88ea13f087484b088f4675e2139dcdb2 is 1.438ms for 5 entries. container-test-run-certificates> server # [5827223.045600] server systemd-journald[69]: System Journal (/var/log/journal/88ea13f087484b088f4675e2139dcdb2) is 8M, max 4G, 3.9G free. container-test-run-certificates> server # [5827223.048829] server systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> server # [5827223.049471] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> server # [5827223.049591] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> server # [5827223.050450] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> server # [5827223.050496] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [5827223.051424] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [5827223.051462] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [5827223.085646] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [5827223.086568] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> server # [5827223.107894] server systemd-tmpfiles[130]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [5827223.108139] server systemd-tmpfiles[130]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [5827223.108284] server systemd-tmpfiles[130]: fchmod() of /var/log/journal/88ea13f087484b088f4675e2139dcdb2 failed: Operation not permitted container-test-run-certificates> server # [5827223.108517] server systemd-tmpfiles[130]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [5827223.110260] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [5827223.111527] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [5827223.112497] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [5827223.123374] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [5827223.131812] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [5827223.132981] server systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [5827223.143227] server systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [5827223.146258] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [5827223.168353] server systemd[1]: Finished Firewall. container-test-run-certificates> server # [5827223.168498] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> server # [5827223.168702] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [5827223.169710] server systemd[1]: Starting Network Management... container-test-run-certificates> ca # [5827223.024970] ca systemd-journald[78]: Journal started container-test-run-certificates> ca # [5827223.025033] ca systemd-journald[78]: Runtime Journal (/run/log/journal/6d3713baf045460f8f1c432b5dcb2b37) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> ca # [5827223.034532] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [5827223.035374] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [5827223.036094] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [5827223.043544] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/6d3713baf045460f8f1c432b5dcb2b37 is 1.534ms for 5 entries. container-test-run-certificates> ca # [5827223.043544] ca systemd-journald[78]: System Journal (/var/log/journal/6d3713baf045460f8f1c432b5dcb2b37) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [5827223.048837] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [5827223.049476] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> ca # [5827223.049590] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [5827223.050397] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [5827223.050446] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [5827223.051326] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [5827223.051359] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [5827223.083308] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> ca # [5827223.085096] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [5827223.100866] ca systemd-tmpfiles[139]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> ca # [5827223.101044] ca systemd-tmpfiles[139]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> ca # [5827223.101162] ca systemd-tmpfiles[139]: fchmod() of /var/log/journal/6d3713baf045460f8f1c432b5dcb2b37 failed: Operation not permitted container-test-run-certificates> ca # [5827223.101347] ca systemd-tmpfiles[139]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> ca # [5827223.102657] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> ca # [5827223.103701] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> ca # [5827223.104402] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [5827223.115531] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [5827223.122809] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> ca # [5827223.123835] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> ca # [5827223.134023] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> ca # [5827223.146825] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> ca # [5827223.166149] ca systemd[1]: Finished Firewall. container-test-run-certificates> ca # [5827223.166308] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [5827223.029246] client systemd-journald[69]: Journal started container-test-run-certificates> ca # [5827223.166536] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [5827223.029295] client systemd-journald[69]: Runtime Journal (/run/log/journal/e1f6894fc97d47aab3c36715fab75acf) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> ca # [5827223.167629] ca systemd[1]: Starting Network Management... container-test-run-certificates> client # [5827223.034881] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> client # [5827223.043859] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [5827223.044710] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [5827223.045376] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [5827223.052924] client systemd-journald[69]: Time spent on flushing to /var/log/journal/e1f6894fc97d47aab3c36715fab75acf is 1.394ms for 6 entries. container-test-run-certificates> client # [5827223.052924] client systemd-journald[69]: System Journal (/var/log/journal/e1f6894fc97d47aab3c36715fab75acf) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [5827223.060884] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [5827223.061635] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [5827223.061766] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [5827223.062602] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [5827223.062650] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [5827223.063543] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> client # [5827223.063575] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> client # [5827223.084718] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [5827223.086363] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> client # [5827223.100325] client systemd-tmpfiles[121]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [5827223.100499] client systemd-tmpfiles[121]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [5827223.100619] client systemd-tmpfiles[121]: fchmod() of /var/log/journal/e1f6894fc97d47aab3c36715fab75acf failed: Operation not permitted container-test-run-certificates> client # [5827223.100798] client systemd-tmpfiles[121]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [5827223.102101] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> client # [5827223.103185] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> client # [5827223.103939] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> client # [5827223.116871] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> client # [5827223.122585] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> client # [5827223.123683] client systemd[1]: Starting Update is Completed... container-test-run-certificates> client # [5827223.134020] client systemd[1]: Finished Update is Completed. container-test-run-certificates> client # [5827223.146273] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> client # [5827223.174266] client systemd[1]: Finished Firewall. container-test-run-certificates> client # [5827223.174414] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [5827223.174688] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [5827223.175706] client systemd[1]: Starting Network Management... container-test-run-certificates> ca # [5827223.575086] ca systemd-networkd[196]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [5827223.575182] ca systemd-networkd[196]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [5827223.582368] ca systemd-networkd[196]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [5827223.582528] ca systemd-networkd[196]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [5827223.582742] ca systemd-networkd[196]: lo: Link UP container-test-run-certificates> ca # [5827223.582747] ca systemd-networkd[196]: lo: Gained carrier container-test-run-certificates> ca # [5827223.582925] ca systemd-networkd[196]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> ca # [5827223.583334] ca systemd[1]: Started Network Management. container-test-run-certificates> ca # [5827223.583405] ca systemd-networkd[196]: eth1: Link UP container-test-run-certificates> ca # [5827223.583779] ca systemd-networkd[196]: eth1: Gained carrier container-test-run-certificates> ca # [5827223.584411] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [5827223.614195] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> ca # [5827223.766555] ca systemd-resolved[104]: Positive Trust Anchors: container-test-run-certificates> ca # [5827223.766567] ca systemd-resolved[104]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [5827223.766571] ca systemd-resolved[104]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [5827223.766607] ca systemd-resolved[104]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [5827223.788938] ca systemd-resolved[104]: Using system hostname 'ca'. container-test-run-certificates> ca # [5827223.790363] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [5827223.790469] ca systemd[1]: Reached target Network. container-test-run-certificates> ca # [5827223.790542] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [5827223.790600] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [5827223.790866] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> ca # [5827223.790903] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [5827223.790930] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [5827223.790956] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> ca # [5827223.791105] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> ca # [5827223.791238] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [5827223.791388] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [5827223.791417] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [5827223.791463] ca systemd[1]: Reached target Basic System. container-test-run-certificates> ca # [5827223.817302] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> ca # [5827223.818310] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [5827223.818361] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> ca # [5827223.819310] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [5827223.820695] ca systemd[1]: Starting step-ca service... container-test-run-certificates> ca # [5827223.822350] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [5827223.575085] server systemd-networkd[187]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [5827223.575193] server systemd-networkd[187]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [5827223.582472] server systemd-networkd[187]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [5827223.582638] server systemd-networkd[187]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [5827223.582789] server systemd-networkd[187]: lo: Link UP container-test-run-certificates> server # [5827223.582793] server systemd-networkd[187]: lo: Gained carrier container-test-run-certificates> server # [5827223.582964] server systemd-networkd[187]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [5827223.583343] server systemd[1]: Started Network Management. container-test-run-certificates> server # [5827223.583468] server systemd-networkd[187]: eth1: Link UP container-test-run-certificates> server # [5827223.583792] server systemd-networkd[187]: eth1: Gained carrier container-test-run-certificates> server # [5827223.584395] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> server # [5827223.609483] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [5827223.767958] server systemd-resolved[95]: Positive Trust Anchors: container-test-run-certificates> server # [5827223.767969] server systemd-resolved[95]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [5827223.767973] server systemd-resolved[95]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [5827223.768020] server systemd-resolved[95]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [5827223.790057] server systemd-resolved[95]: Using system hostname 'server'. container-test-run-certificates> server # [5827223.791453] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [5827223.791594] server systemd[1]: Reached target Network. container-test-run-certificates> server # [5827223.791689] server systemd[1]: Reached target Network is Online. container-test-run-certificates> server # [5827223.791769] server systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [5827223.792197] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> server # [5827223.792258] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [5827223.792306] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [5827223.792348] server systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [5827223.792573] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [5827223.792764] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [5827223.792993] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [5827223.793041] server systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [5827223.793121] server systemd[1]: Reached target Basic System. container-test-run-certificates> server # [5827223.817645] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> server # [5827223.819034] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [5827223.819103] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> server # [5827223.820491] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [5827223.822620] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> client # [5827223.583444] client systemd-networkd[183]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [5827223.583545] client systemd-networkd[183]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [5827223.594806] client systemd-networkd[183]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [5827223.594971] client systemd-networkd[183]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [5827223.595150] client systemd-networkd[183]: lo: Link UP container-test-run-certificates> client # [5827223.595155] client systemd-networkd[183]: lo: Gained carrier container-test-run-certificates> client # [5827223.595360] client systemd-networkd[183]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [5827223.595726] client systemd[1]: Started Network Management. container-test-run-certificates> client # [5827223.595849] client systemd-networkd[183]: eth1: Link UP container-test-run-certificates> client # [5827223.596126] client systemd-networkd[183]: eth1: Gained carrier container-test-run-certificates> client # [5827223.596722] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> client # [5827223.629932] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> client # [5827223.753138] client systemd-resolved[92]: Positive Trust Anchors: container-test-run-certificates> client # [5827223.753150] client systemd-resolved[92]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> client # [5827223.753154] client systemd-resolved[92]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [5827223.753190] client systemd-resolved[92]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [5827223.776701] client systemd-resolved[92]: Using system hostname 'client'. container-test-run-certificates> client # [5827223.778116] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> client # [5827223.778230] client systemd[1]: Reached target Network. container-test-run-certificates> client # [5827223.778324] client systemd[1]: Reached target System Initialization. container-test-run-certificates> client # [5827223.778410] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [5827223.778455] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> client # [5827223.778485] client systemd[1]: Reached target Timer Units. container-test-run-certificates> client # [5827223.778667] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [5827223.778846] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> client # [5827223.779015] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> client # [5827223.779053] client systemd[1]: Reached target Socket Units. container-test-run-certificates> client # [5827223.779113] client systemd[1]: Reached target Basic System. container-test-run-certificates> client # [5827223.781306] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> client # [5827223.782567] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> client # [5827223.816485] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> client # [5827223.833626] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> client # [5827223.962763] client nsncd[189]: Aug 15 10:04:10.015 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [5827223.962920] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [5827223.963031] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [5827223.963125] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> client # [5827223.985429] client systemd[1]: Starting User Login Management... container-test-run-certificates> client # [5827223.986768] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> client # [5827224.063279] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> client # [5827224.065150] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> client # [5827224.068383] client systemd[1]: Started Console Getty. container-test-run-certificates> client # [5827224.068460] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> client # [5827224.068494] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> client # [5827224.074274] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> client # [5827224.075315] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [5827224.075315] client dbus-broker-launch[190]: Invalid user-name in /nix/store/z18i8gax7zmfr2d22nqb67kfsfgm8wx8-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [5827224.075774] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [5827223.840679] server systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [5827223.946561] server acme-setup-privileged[192]: + set -euo pipefail container-test-run-certificates> server # [5827223.946561] server acme-setup-privileged[192]: + cd /var/lib/acme container-test-run-certificates> server # [5827223.946561] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> server # [5827223.948960] server acme-setup-privileged[192]: + chown -R acme .lego/accounts container-test-run-certificates> server # [5827223.950575] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [5827223.950650] server acme-setup-privileged[192]: + '[' -d test.foo ']' container-test-run-certificates> server # [5827223.950650] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [5827223.950650] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']' container-test-run-certificates> server # [5827223.959450] server nsncd[194]: Aug 15 10:04:10.012 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> server # [5827223.984893] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> server # [5827223.985147] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> server # [5827223.985252] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [5827223.987098] server systemd[1]: Starting User Login Management... container-test-run-certificates> server # [5827223.988211] server systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [5827223.997609] server systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [5827223.998875] server systemd[1]: Started Console Getty. container-test-run-certificates> server # [5827223.998916] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [5827223.998937] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [5827224.019557] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [5827224.080233] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [5827224.081346] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [5827224.081346] server dbus-broker-launch[195]: Invalid user-name in /nix/store/jv9ppm6bn4crwrlhr26v9g05j5n42z3q-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [5827224.081702] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [5827224.090504] server dbus-broker-launch[195]: Ready container-test-run-certificates> ca # [5827223.838844] ca systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> ca # [5827223.929004] ca acme-setup-privileged[201]: + set -euo pipefail container-test-run-certificates> ca # [5827223.929004] ca acme-setup-privileged[201]: + cd /var/lib/acme container-test-run-certificates> ca # [5827223.929004] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> ca # [5827223.930374] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts container-test-run-certificates> ca # [5827223.932060] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [5827223.932060] ca acme-setup-privileged[201]: + '[' -d ca.foo ']' container-test-run-certificates> ca # [5827223.932060] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [5827223.932060] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> ca # [5827223.950564] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [5827223.950689] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [5827223.950787] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [5827223.950843] ca nsncd[203]: Aug 15 10:04:10.003 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [5827223.985156] ca systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [5827223.986793] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [5827224.057138] ca dbus-broker-launch[205]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [5827224.057870] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [5827224.059015] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [5827224.061356] ca dbus-broker-launch[205]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> ca # [5827224.061356] ca dbus-broker-launch[205]: Invalid user-name in /nix/store/vd1mfhapbcl6nngw7x71n7cxgwkrw88b-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> ca # [5827224.062184] ca systemd[1]: Started Console Getty. container-test-run-certificates> ca # [5827224.062238] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> ca # [5827224.062258] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca # [5827224.062396] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [5827224.071240] ca dbus-broker-launch[205]: Ready container-test-run-certificates> client # [5827224.084923] client dbus-broker-launch[190]: Ready container-test-run-certificates> client # [5827224.524376] client systemd-logind[205]: New seat seat0. container-test-run-certificates> client # [5827224.524604] client systemd[1]: Started User Login Management. container-test-run-certificates> client # [5827224.526749] client systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [5827224.565842] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> client # [5827224.566037] client systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [5827224.567174] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> client # [5827224.567391] client systemd[1]: Startup finished in 1.936s. container-test-run-certificates> server # [5827224.520739] server systemd-logind[219]: New seat seat0. container-test-run-certificates> server # [5827224.520921] server systemd[1]: Started User Login Management. container-test-run-certificates> server # [5827224.523336] server systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [5827224.553680] server acme-setup-start[208]: + set -euo pipefail container-test-run-certificates> server # [5827224.553680] server acme-setup-start[208]: + test -e ca/key.pem container-test-run-certificates> server # [5827224.554280] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> server # [5827224.565859] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [5827224.522692] ca systemd-logind[231]: New seat seat0. container-test-run-certificates> server # [5827224.565977] server systemd[1]: Finished linger-users.service. container-test-run-certificates> server # [5827224.577356] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [5827224.522936] ca systemd[1]: Started User Login Management. container-test-run-certificates> server # [5827224.579891] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> ca # [5827224.524854] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [5827224.672163] server systemd-networkd[187]: eth1: Gained IPv6LL container-test-run-certificates> ca # [5827224.564592] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [5827224.564766] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [5827224.582968] ca acme-setup-start[219]: + set -euo pipefail container-test-run-certificates> ca # [5827224.582968] ca acme-setup-start[219]: + test -e ca/key.pem container-test-run-certificates> ca # [5827224.583561] ca acme-setup-start[219]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [5827224.599227] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [5827224.600833] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> ca # [5827224.703414] ca step-ca[204]: badger 2026/08/15 10:04:10 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [5827224.707703] ca step-ca[204]: 2026/08/15 10:04:10 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> ca # [5827224.714411] ca step-ca[204]: 2026/08/15 10:04:10 Starting Smallstep CA/0.30.2 (linux/arm64) container-test-run-certificates> ca # [5827224.714411] ca step-ca[204]: 2026/08/15 10:04:10 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> ca # [5827224.714411] ca step-ca[204]: 2026/08/15 10:04:10 Community Discord: https://u.step.sm/discord container-test-run-certificates> ca # [5827224.714411] ca step-ca[204]: 2026/08/15 10:04:10 Config file: /etc/smallstep/ca.json container-test-run-certificates> ca # [5827224.714411] ca step-ca[204]: 2026/08/15 10:04:10 The primary server URL is https://ca.foo:1443 container-test-run-certificates> ca # [5827224.714411] ca step-ca[204]: 2026/08/15 10:04:10 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [5827224.714411] ca step-ca[204]: 2026/08/15 10:04:10 X.509 Root Fingerprint: f9e7a116c83d2375b63fd0fee2b3f3d2c10fa91e7eb2213ff0482fdebbf2ec31 container-test-run-certificates> ca # [5827224.715040] ca systemd[1]: Started step-ca service. container-test-run-certificates> ca # [5827224.715413] ca step-ca[204]: 2026/08/15 10:04:10 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> client # [5827224.800220] client systemd-networkd[183]: eth1: Gained IPv6LL container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> server # [5827225.064106] server acme-test.foo-start[245]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [5827225.066620] server acme-test.foo-start[245]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [5827225.066620] server acme-test.foo-start[245]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [5827225.081058] server acme-test.foo-start[255]: + cd test.foo container-test-run-certificates> server # [5827225.081058] server acme-test.foo-start[255]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [5827225.082549] server acme-test.foo-start[256]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [5827225.082849] server acme-test.foo-start[255]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [5827225.083778] server acme-test.foo-start[255]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [5827225.083979] server acme-test.foo-start[245]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [5827225.085410] server acme-test.foo-start[245]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [5827225.087114] server acme-test.foo-start[245]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [5827225.088747] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [5827225.088779] server acme-test.foo-start[245]: + '[' -d out ']' container-test-run-certificates> server # [5827225.088779] server acme-test.foo-start[245]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [5827225.090516] server acme-test.foo-start[245]: + chown -R acme:nginx out container-test-run-certificates> server # [5827225.093724] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [5827225.093751] server acme-test.foo-start[245]: + '[' -d certificates ']' container-test-run-certificates> server # [5827225.096974] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [5827225.098386] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> ca # [5827225.082349] ca acme-ca.foo-start[256]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [5827225.085257] ca acme-ca.foo-start[256]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [5827225.085257] ca acme-ca.foo-start[256]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> ca # [5827225.099847] ca acme-ca.foo-start[294]: + cd ca.foo container-test-run-certificates> ca # [5827225.100280] ca acme-ca.foo-start[294]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> ca # [5827225.101692] ca acme-ca.foo-start[295]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [5827225.101975] ca acme-ca.foo-start[294]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> ca # [5827225.103157] ca acme-ca.foo-start[294]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [5827225.103374] ca acme-ca.foo-start[256]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [5827225.105094] ca acme-ca.foo-start[256]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [5827225.106829] ca acme-ca.foo-start[256]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [5827225.108109] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [5827225.108153] ca acme-ca.foo-start[256]: + '[' -d out ']' container-test-run-certificates> ca # [5827225.108153] ca acme-ca.foo-start[256]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [5827225.109517] ca acme-ca.foo-start[256]: + chown -R acme:nginx out container-test-run-certificates> ca # [5827225.113140] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [5827225.113171] ca acme-ca.foo-start[256]: + '[' -d certificates ']' container-test-run-certificates> ca # [5827225.144261] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> ca # [5827225.146470] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> ca # [5827225.220220] ca systemd-networkd[196]: eth1: Gained IPv6LL container-test-run-certificates> server # [5827225.668593] server nginx-pre-start[267]: nginx: the configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf syntax is ok container-test-run-certificates> server # [5827225.669215] server nginx-pre-start[267]: nginx: configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf test is successful container-test-run-certificates> server # [5827225.708581] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [5827225.709410] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [5827225.711718] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> ca # [5827225.683768] ca nginx-pre-start[306]: nginx: the configuration file /nix/store/y0w3rf0mygndzvcgy9cmg2mqb83s730b-nginx.conf syntax is ok container-test-run-certificates> ca # [5827225.684389] ca nginx-pre-start[306]: nginx: configuration file /nix/store/y0w3rf0mygndzvcgy9cmg2mqb83s730b-nginx.conf test is successful container-test-run-certificates> ca # [5827225.708758] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [5827225.709593] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [5827225.711996] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca # [5827226.252889] ca acme-order-renew-ca.foo-start[309]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [5827226.255498] ca acme-order-renew-ca.foo-start[309]: + set -euo pipefail container-test-run-certificates> ca # [5827226.255571] ca acme-order-renew-ca.foo-start[309]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [5827226.255681] ca acme-order-renew-ca.foo-start[309]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [5827226.257192] ca acme-order-renew-ca.foo-start[309]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> ca # [5827226.283227] ca acme-order-renew-ca.foo-start[320]: 2026/08/15 10:04:12 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [5827226.283552] ca acme-order-renew-ca.foo-start[320]: 2026/08/15 10:04:12 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [5827226.306827] ca step-ca[204]: time="2026-08-15T10:04:12Z" level=info duration="155.602µs" duration-ns=155602 fields.time="2026-08-15T10:04:12Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=f8113957-25bc-4712-bbe8-ec8352b6feb4 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5827226.307214] ca acme-order-renew-ca.foo-start[320]: 2026/08/15 10:04:12 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> ca # [5827226.316419] ca step-ca[204]: time="2026-08-15T10:04:12Z" level=info duration=9.083768ms duration-ns=9083768 fields.time="2026-08-15T10:04:12Z" method=HEAD name=ca nonce=STlvZ3lUeXAxdm90UENEa0tXdWNiSTYxdDdzTW5NY2Q path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=d6fee5cf-86c8-4ccf-b93a-2193b23cca07 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5827226.318974] ca step-ca[204]: time="2026-08-15T10:04:12Z" level=info duration=1.604543ms duration-ns=1604543 fields.time="2026-08-15T10:04:12Z" method=POST name=ca nonce=QUxpS2hUTGtlWVpxeXMzTVNJVXY1cWtEYTVQcHdNRDY path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=594ed8f2-1762-457a-9df5-cb2a8bc4ecd3 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/NBX8XSQr7Qf0uLGdO21PAw4pUZqrsHYb/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5827226.319368] ca acme-order-renew-ca.foo-start[320]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [5827226.319368] ca acme-order-renew-ca.foo-start[320]: Your account credentials have been saved in your container-test-run-certificates> ca # [5827226.319368] ca acme-order-renew-ca.foo-start[320]: configuration directory at "accounts". container-test-run-certificates> ca # [5827226.319368] ca acme-order-renew-ca.foo-start[320]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [5827226.319368] ca acme-order-renew-ca.foo-start[320]: configuration directory will also contain private keys container-test-run-certificates> ca # [5827226.319368] ca acme-order-renew-ca.foo-start[320]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [5827226.319368] ca acme-order-renew-ca.foo-start[320]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [5827226.319493] ca acme-order-renew-ca.foo-start[320]: 2026/08/15 10:04:12 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [5827226.323482] ca step-ca[204]: time="2026-08-15T10:04:12Z" level=info duration=3.560731ms duration-ns=3560731 fields.time="2026-08-15T10:04:12Z" method=POST name=ca nonce=enVFd1RTbVZuVlZ0dFhrcnhZOFl4QkhpSHM5bWlMY0M path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=d85bfe27-02e1-45da-b1fe-5cc61c8c479e response="{\"id\":\"UfxTfQO0YUkVjj3goocseskxwMDrCWqr\",\"status\":\"pending\",\"expires\":\"2026-08-16T10:04:12Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-15T10:03:12Z\",\"notAfter\":\"2026-11-13T10:04:12Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/Jnbfakku4kAIRVe3k2aZ953EeqSCBRhG\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/UfxTfQO0YUkVjj3goocseskxwMDrCWqr/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5827226.384541] ca step-ca[204]: time="2026-08-15T10:04:12Z" level=info duration=3.718413ms duration-ns=3718413 fields.time="2026-08-15T10:04:12Z" method=POST name=ca nonce=amtYZ21pbjBWcUNSQnpYMHBENGt2WDB1d082SnVja1Q path=/acme/acme/authz/Jnbfakku4kAIRVe3k2aZ953EeqSCBRhG protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=abdf6855-896c-4027-a028-d2e0f5acd678 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"WhDSaphepov7ryIUak8405521tlI1BMh\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/Jnbfakku4kAIRVe3k2aZ953EeqSCBRhG/7TQMrIfPR0xHuaT4TPxrBd5UDXiF3cSk\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"WhDSaphepov7ryIUak8405521tlI1BMh\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/Jnbfakku4kAIRVe3k2aZ953EeqSCBRhG/SzYZfhOYyYfLs7ArWSCHvvJn3Ssje0Ua\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"WhDSaphepov7ryIUak8405521tlI1BMh\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/Jnbfakku4kAIRVe3k2aZ953EeqSCBRhG/T8MZpgpG7OwK195nT3vb4ogun5Cl53y8\"}],\"wildcard\":false,\"expires\":\"2026-08-16T10:04:12Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5827226.385033] ca acme-order-renew-ca.foo-start[320]: 2026/08/15 10:04:12 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/Jnbfakku4kAIRVe3k2aZ953EeqSCBRhG container-test-run-certificates> ca # [5827226.385033] ca acme-order-renew-ca.foo-start[320]: 2026/08/15 10:04:12 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [5827226.385033] ca acme-order-renew-ca.foo-start[320]: 2026/08/15 10:04:12 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [5827226.385215] ca acme-order-renew-ca.foo-start[320]: 2026/08/15 10:04:12 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> ca # [5827226.391677] ca step-ca[204]: time="2026-08-15T10:04:12Z" level=info duration=5.6896ms duration-ns=5689600 fields.time="2026-08-15T10:04:12Z" method=POST name=ca nonce=T2VORmI2NHlhdlFCUTBMM0tLekR1aGFRYk5ObWc5MUc path=/acme/acme/challenge/Jnbfakku4kAIRVe3k2aZ953EeqSCBRhG/SzYZfhOYyYfLs7ArWSCHvvJn3Ssje0Ua protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=41400ec7-7327-4eb3-b320-d4d68067a6e9 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"WhDSaphepov7ryIUak8405521tlI1BMh\",\"validated\":\"2026-08-15T10:04:12Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/Jnbfakku4kAIRVe3k2aZ953EeqSCBRhG/SzYZfhOYyYfLs7ArWSCHvvJn3Ssje0Ua\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5827226.392117] ca acme-order-renew-ca.foo-start[320]: 2026/08/15 10:04:12 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [5827226.392194] ca acme-order-renew-ca.foo-start[320]: 2026/08/15 10:04:12 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [5827226.402100] ca step-ca[204]: time="2026-08-15T10:04:12Z" level=info duration=8.53004ms duration-ns=8530040 fields.time="2026-08-15T10:04:12Z" method=POST name=ca nonce=NGhmbVJITGs3Um04UVBhOXJrbERNaVJITE1kRTdFR1A path=/acme/acme/order/UfxTfQO0YUkVjj3goocseskxwMDrCWqr/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=74b8f03e-6abf-4f08-aecd-666b1ad5966c response="{\"id\":\"UfxTfQO0YUkVjj3goocseskxwMDrCWqr\",\"status\":\"valid\",\"expires\":\"2026-08-16T10:04:12Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-15T10:03:12Z\",\"notAfter\":\"2026-11-13T10:04:12Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/Jnbfakku4kAIRVe3k2aZ953EeqSCBRhG\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/UfxTfQO0YUkVjj3goocseskxwMDrCWqr/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/FUF7v1QVce24eP7oBCVp8wszCAw8GAfZ\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5827226.404554] ca step-ca[204]: time="2026-08-15T10:04:12Z" level=info certificate=MIIB0zCCAXmgAwIBAgIQWMcNT7sd+pVPHk4ykplKlTAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MTUxMDAzMTJaFw0yNjExMTMxMDA0MTJaMBExDzANBgNVBAMTBmNhLmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABMnWDI1H48vy+4tKZXg9Wjx0GqkksLjpZYodg0Ep2VRL9NIev013mKTgeRP+w1x2i+d5CpEsALqvWmYam+ZYb+GjgaQwgaEwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQU0Jxu8JYr4RD+UU8N7lk1E/Sp7hQwHwYDVR0jBBgwFoAUyrMkoOjEoJ4PmApsZSFe/i6TkO0wEQYDVR0RBAowCIIGY2EuZm9vMB0GDCsGAQQBgqRkxihAAQQNMAsCAQYEBGFjbWUEADAKBggqhkjOPQQDAgNIADBFAiEA/pvoJ+dgV8eVK+f0SEXe5VWs0UooLupJwjXrRsejY9cCIEkGFvCay+MZv92MX+7CjBK+IYlcDVQlkP/Dv9VM2Dil duration=1.523661ms duration-ns=1523661 fields.time="2026-08-15T10:04:12Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=T2x2dEZuZmlQVzRYNzdmR081NTVjdU9Cdk1zaUlJQXY path=/acme/acme/certificate/FUF7v1QVce24eP7oBCVp8wszCAw8GAfZ protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=06f878c9-7a01-49ab-b6b9-cc800aca6578 sans="map[dns:[ca.foo]]" serial=118005600692180652643457787927463545493 size=1340 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-15T10:03:12Z" valid-to="2026-11-13T10:04:12Z" container-test-run-certificates> ca # [5827226.404817] ca acme-order-renew-ca.foo-start[320]: 2026/08/15 10:04:12 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [5827226.409141] ca acme-order-renew-ca.foo-start[309]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [5827226.411073] ca acme-order-renew-ca.foo-start[309]: + touch out/acme-success container-test-run-certificates> ca # [5827226.412970] ca acme-order-renew-ca.foo-start[309]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [5827226.414176] ca acme-order-renew-ca.foo-start[309]: + touch out/renewed container-test-run-certificates> ca # [5827226.415595] ca acme-order-renew-ca.foo-start[309]: + echo Installing new certificate container-test-run-certificates> ca # [5827226.415595] ca acme-order-renew-ca.foo-start[309]: Installing new certificate container-test-run-certificates> ca # [5827226.415595] ca acme-order-renew-ca.foo-start[309]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [5827226.417463] ca acme-order-renew-ca.foo-start[353]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [5827226.417842] ca acme-order-renew-ca.foo-start[309]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [5827226.419066] ca acme-order-renew-ca.foo-start[354]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [5827226.419378] ca acme-order-renew-ca.foo-start[309]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [5827226.420916] ca acme-order-renew-ca.foo-start[355]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [5827226.421229] ca acme-order-renew-ca.foo-start[309]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [5827226.422626] ca acme-order-renew-ca.foo-start[309]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [5827226.424216] ca acme-order-renew-ca.foo-start[309]: + for fixpath in out certificates container-test-run-certificates> ca # [5827226.424216] ca acme-order-renew-ca.foo-start[309]: + '[' -d out ']' container-test-run-certificates> ca # [5827226.424312] ca acme-order-renew-ca.foo-start[309]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [5827226.425645] ca acme-order-renew-ca.foo-start[309]: + chown -R acme:nginx out container-test-run-certificates> ca # [5827226.428744] ca acme-order-renew-ca.foo-start[309]: + for fixpath in out certificates container-test-run-certificates> ca # [5827226.428744] ca acme-order-renew-ca.foo-start[309]: + '[' -d certificates ']' container-test-run-certificates> ca # [5827226.428851] ca acme-order-renew-ca.foo-start[309]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [5827226.430522] ca acme-order-renew-ca.foo-start[309]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [5827226.432631] ca acme-order-renew-ca.foo-start[309]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [5827226.566175] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [5827226.250730] server acme-order-renew-test.foo-start[270]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [5827226.254189] server acme-order-renew-test.foo-start[270]: + set -euo pipefail container-test-run-certificates> server # [5827226.254264] server acme-order-renew-test.foo-start[270]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [5827226.254378] server acme-order-renew-test.foo-start[270]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [5827226.255571] server acme-order-renew-test.foo-start[270]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [5827226.283455] server acme-order-renew-test.foo-start[281]: 2026/08/15 10:04:12 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [5827226.283848] server acme-order-renew-test.foo-start[281]: 2026/08/15 10:04:12 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> server # [5827226.320267] server acme-order-renew-test.foo-start[281]: 2026/08/15 10:04:12 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority container-test-run-certificates> server # [5827226.323500] server acme-order-renew-test.foo-start[270]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [5827226.323500] server acme-order-renew-test.foo-start[270]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [5827226.323500] server acme-order-renew-test.foo-start[270]: + exit 10 container-test-run-certificates> server # [5827226.327246] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a container-test-run-certificates> server # [5827226.327382] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'. container-test-run-certificates> server # [5827226.327663] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [5827226.328154] server systemd[1]: Startup finished in 3.711s. container-test-run-certificates> ca # [5827226.570066] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [5827226.570265] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> ca # [5827227.103808] ca nginx[371]: nginx: the configuration file /nix/store/y0w3rf0mygndzvcgy9cmg2mqb83s730b-nginx.conf syntax is ok container-test-run-certificates> ca # [5827227.104506] ca nginx[371]: nginx: configuration file /nix/store/y0w3rf0mygndzvcgy9cmg2mqb83s730b-nginx.conf test is successful container-test-run-certificates> ca # [5827227.621205] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [5827227.621806] ca systemd[1]: Startup finished in 4.974s. container-test-run-certificates> ca # [5827227.849848] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 3.44 seconds) container-test-run-certificates> ca # [5827228.452688] ca acme-order-renew-ca.foo-start[386]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [5827228.455277] ca acme-order-renew-ca.foo-start[386]: + set -euo pipefail container-test-run-certificates> ca # [5827228.455349] ca acme-order-renew-ca.foo-start[386]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [5827228.455459] ca acme-order-renew-ca.foo-start[386]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [5827228.456688] ca acme-order-renew-ca.foo-start[386]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [5827228.456688] ca acme-order-renew-ca.foo-start[386]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [5827228.457234] ca acme-order-renew-ca.foo-start[394]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [5827228.460370] ca acme-order-renew-ca.foo-start[386]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [5827228.460444] ca acme-order-renew-ca.foo-start[386]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [5827228.505348] ca step-ca[204]: time="2026-08-15T10:04:14Z" level=info duration="63.561µs" duration-ns=63561 fields.time="2026-08-15T10:04:14Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=cc40aa04-b64d-4159-8ca5-31ef5c21ae58 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5827228.505778] ca acme-order-renew-ca.foo-start[395]: 2026/08/15 10:04:14 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [5827228.505778] ca acme-order-renew-ca.foo-start[395]: 2026/08/15 10:04:14 [INFO] [ca.foo] The certificate expires at 2026-11-13T10:04:12Z, the renewal can be performed in 1439h59m37.441081809s: no renewal. container-test-run-certificates> ca # [5827228.506347] ca acme-order-renew-ca.foo-start[386]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [5827228.508402] ca acme-order-renew-ca.foo-start[386]: + touch out/acme-success container-test-run-certificates> ca # [5827228.510222] ca acme-order-renew-ca.foo-start[386]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [5827228.511630] ca acme-order-renew-ca.foo-start[386]: + for fixpath in out certificates container-test-run-certificates> ca # [5827228.511660] ca acme-order-renew-ca.foo-start[386]: + '[' -d out ']' container-test-run-certificates> ca # [5827228.511660] ca acme-order-renew-ca.foo-start[386]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [5827228.512938] ca acme-order-renew-ca.foo-start[386]: + chown -R acme:nginx out container-test-run-certificates> ca # [5827228.516222] ca acme-order-renew-ca.foo-start[386]: + for fixpath in out certificates container-test-run-certificates> ca # [5827228.516222] ca acme-order-renew-ca.foo-start[386]: + '[' -d certificates ']' container-test-run-certificates> ca # [5827228.516283] ca acme-order-renew-ca.foo-start[386]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [5827228.517879] ca acme-order-renew-ca.foo-start[386]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [5827228.520592] ca acme-order-renew-ca.foo-start[386]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [5827228.624910] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [5827228.625273] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server # [5827231.656317] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [5827231.656685] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [5827231.657925] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [5827231.698102] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.55 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1009 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [112 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 15 10:04:11 2026 GMT container-test-run-certificates> * expire date: Sep 14 10:04:11 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 38cde3 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [5827232.157988] server acme-test.foo-start[316]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [5827232.160930] server acme-test.foo-start[316]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [5827232.160930] server acme-test.foo-start[316]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [5827232.175789] server acme-test.foo-start[326]: + cd test.foo container-test-run-certificates> server # [5827232.176102] server acme-test.foo-start[326]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [5827232.177679] server acme-test.foo-start[327]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [5827232.177948] server acme-test.foo-start[326]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [5827232.179401] server acme-test.foo-start[326]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [5827232.179685] server acme-test.foo-start[316]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [5827232.181625] server acme-test.foo-start[316]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [5827232.183248] server acme-test.foo-start[316]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [5827232.185086] server acme-test.foo-start[316]: + for fixpath in out certificates container-test-run-certificates> server # [5827232.185106] server acme-test.foo-start[316]: + '[' -d out ']' container-test-run-certificates> server # [5827232.185106] server acme-test.foo-start[316]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [5827232.186889] server acme-test.foo-start[316]: + chown -R acme:nginx out container-test-run-certificates> server # [5827232.189488] server acme-test.foo-start[316]: + for fixpath in out certificates container-test-run-certificates> server # [5827232.189531] server acme-test.foo-start[316]: + '[' -d certificates ']' container-test-run-certificates> server # [5827232.194034] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [5827232.199149] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> server # [5827232.741730] server acme-order-renew-test.foo-start[334]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [5827232.744517] server acme-order-renew-test.foo-start[334]: + set -euo pipefail container-test-run-certificates> server # [5827232.744587] server acme-order-renew-test.foo-start[334]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [5827232.744706] server acme-order-renew-test.foo-start[334]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [5827232.745929] server acme-order-renew-test.foo-start[334]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [5827232.801003] server acme-order-renew-test.foo-start[342]: 2026/08/15 10:04:18 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [5827232.837464] server acme-order-renew-test.foo-start[342]: !!!! HEADS UP !!!! container-test-run-certificates> server # [5827232.837464] server acme-order-renew-test.foo-start[342]: Your account credentials have been saved in your container-test-run-certificates> server # [5827232.837464] server acme-order-renew-test.foo-start[342]: configuration directory at "accounts". container-test-run-certificates> server # [5827232.837464] server acme-order-renew-test.foo-start[342]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [5827232.837464] server acme-order-renew-test.foo-start[342]: configuration directory will also contain private keys container-test-run-certificates> server # [5827232.837464] server acme-order-renew-test.foo-start[342]: generated by lego and certificates obtained from the ACME container-test-run-certificates> server # [5827232.837464] server acme-order-renew-test.foo-start[342]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [5827232.837464] server acme-order-renew-test.foo-start[342]: 2026/08/15 10:04:18 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> server # [5827232.915357] server acme-order-renew-test.foo-start[342]: 2026/08/15 10:04:18 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/3Yk0tlE9VeDYOHxy9gUSMKCU6jySLBzV container-test-run-certificates> server # [5827232.915357] server acme-order-renew-test.foo-start[342]: 2026/08/15 10:04:18 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [5827232.915357] server acme-order-renew-test.foo-start[342]: 2026/08/15 10:04:18 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [5827232.915357] server acme-order-renew-test.foo-start[342]: 2026/08/15 10:04:18 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [5827232.923776] server acme-order-renew-test.foo-start[342]: 2026/08/15 10:04:18 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [5827232.923878] server acme-order-renew-test.foo-start[342]: 2026/08/15 10:04:18 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [5827232.940795] server acme-order-renew-test.foo-start[342]: 2026/08/15 10:04:18 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [5827232.946399] server acme-order-renew-test.foo-start[334]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [5827232.948280] server acme-order-renew-test.foo-start[334]: + touch out/acme-success container-test-run-certificates> server # [5827232.950047] server acme-order-renew-test.foo-start[334]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [5827232.951282] server acme-order-renew-test.foo-start[334]: + touch out/renewed container-test-run-certificates> server # [5827232.953246] server acme-order-renew-test.foo-start[334]: + echo Installing new certificate container-test-run-certificates> server # [5827232.953246] server acme-order-renew-test.foo-start[334]: Installing new certificate container-test-run-certificates> server # [5827232.953246] server acme-order-renew-test.foo-start[334]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [5827232.955045] server acme-order-renew-test.foo-start[373]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [5827232.955411] server acme-order-renew-test.foo-start[334]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [5827232.957172] server acme-order-renew-test.foo-start[374]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [5827232.957499] server acme-order-renew-test.foo-start[334]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [5827232.958976] server acme-order-renew-test.foo-start[375]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [5827232.959274] server acme-order-renew-test.foo-start[334]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [5827232.960695] server acme-order-renew-test.foo-start[334]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [5827232.962580] server acme-order-renew-test.foo-start[334]: + for fixpath in out certificates container-test-run-certificates> server # [5827232.962580] server acme-order-renew-test.foo-start[334]: + '[' -d out ']' container-test-run-certificates> server # [5827232.962676] server acme-order-renew-test.foo-start[334]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [5827232.964330] server acme-order-renew-test.foo-start[334]: + chown -R acme:nginx out container-test-run-certificates> server # [5827232.967439] server acme-order-renew-test.foo-start[334]: + for fixpath in out certificates container-test-run-certificates> server # [5827232.967439] server acme-order-renew-test.foo-start[334]: + '[' -d certificates ']' container-test-run-certificates> server # [5827232.967548] server acme-order-renew-test.foo-start[334]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [5827232.969312] server acme-order-renew-test.foo-start[334]: + chown -R acme:nginx certificates container-test-run-certificates> server # [5827232.972127] server acme-order-renew-test.foo-start[334]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [5827232.800365] ca step-ca[204]: time="2026-08-15T10:04:18Z" level=info duration="42.44µs" duration-ns=42440 fields.time="2026-08-15T10:04:18Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=0bbf031f-6479-400b-b201-5a19df604797 response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5827232.829579] ca step-ca[204]: time="2026-08-15T10:04:18Z" level=info duration=23.723935ms duration-ns=23723935 fields.time="2026-08-15T10:04:18Z" method=HEAD name=ca nonce=ZGVnNlVyRVpPTUZTeFBoRXdHekw3NUFxc3pIZ2t5Mmw path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=88185ea8-1516-4f6b-95fd-fa9c01413c69 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5827232.836866] ca step-ca[204]: time="2026-08-15T10:04:18Z" level=info duration=3.348727ms duration-ns=3348727 fields.time="2026-08-15T10:04:18Z" method=POST name=ca nonce=Q0JzUUlpNElIWU9SOXpIT05YYldKRjAxYUtLR0NXRms path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=68e1ef79-8632-44e9-bb9e-83aecb8a3853 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/Sd2U8yELQM8bC2U9dI7RO8neXGFCCuX8/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5827232.845979] ca step-ca[204]: time="2026-08-15T10:04:18Z" level=info duration=5.69596ms duration-ns=5695960 fields.time="2026-08-15T10:04:18Z" method=POST name=ca nonce=TEhFWHJkSEljMXV1S05raUFmbkdWRVQxZ0FQVVRVdzg path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=19ce11d4-f436-4803-a4a9-d6399d4ee827 response="{\"id\":\"w6mCOKbov1sGRZBxIj0W04YdtTpMJ82O\",\"status\":\"pending\",\"expires\":\"2026-08-16T10:04:18Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-15T10:03:18Z\",\"notAfter\":\"2026-11-13T10:04:18Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/3Yk0tlE9VeDYOHxy9gUSMKCU6jySLBzV\"],\"finalize\":\"https://ca.foo/acme/acme/order/w6mCOKbov1sGRZBxIj0W04YdtTpMJ82O/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5827232.914861] ca step-ca[204]: time="2026-08-15T10:04:18Z" level=info duration=9.503334ms duration-ns=9503334 fields.time="2026-08-15T10:04:18Z" method=POST name=ca nonce=THg4Uk9jbGlpaHFUdm5zcEdWeFpaV1lnejhLZ0NHYzA path=/acme/acme/authz/3Yk0tlE9VeDYOHxy9gUSMKCU6jySLBzV protocol=HTTP/1.1 referer= remote-address="::1" request-id=6b698188-3474-4cb1-bb9f-f82635d2a510 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"soGHmjoRW9qnxCm6wNuWfTIpo1PRSmdr\",\"url\":\"https://ca.foo/acme/acme/challenge/3Yk0tlE9VeDYOHxy9gUSMKCU6jySLBzV/chahRTIcxdwahm2oNMxpUeXGf8csmSlO\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"soGHmjoRW9qnxCm6wNuWfTIpo1PRSmdr\",\"url\":\"https://ca.foo/acme/acme/challenge/3Yk0tlE9VeDYOHxy9gUSMKCU6jySLBzV/9n2nyICjlDSvUthILhMxscO55WMCgIWi\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"soGHmjoRW9qnxCm6wNuWfTIpo1PRSmdr\",\"url\":\"https://ca.foo/acme/acme/challenge/3Yk0tlE9VeDYOHxy9gUSMKCU6jySLBzV/nW3qWcN6idBngV35RbHCXPxmOcN30K9w\"}],\"wildcard\":false,\"expires\":\"2026-08-16T10:04:18Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5827232.923120] ca step-ca[204]: time="2026-08-15T10:04:18Z" level=info duration=4.609185ms duration-ns=4609185 fields.time="2026-08-15T10:04:18Z" method=POST name=ca nonce=MU0wbjJHTFNvTDgwdXVpUnZlTjFvSmVzREhZQXJPcDk path=/acme/acme/challenge/3Yk0tlE9VeDYOHxy9gUSMKCU6jySLBzV/9n2nyICjlDSvUthILhMxscO55WMCgIWi protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=e8bbd40b-2cb4-41e8-bf01-8978918e80d6 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"soGHmjoRW9qnxCm6wNuWfTIpo1PRSmdr\",\"validated\":\"2026-08-15T10:04:18Z\",\"url\":\"https://ca.foo/acme/acme/challenge/3Yk0tlE9VeDYOHxy9gUSMKCU6jySLBzV/9n2nyICjlDSvUthILhMxscO55WMCgIWi\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5827232.936577] ca step-ca[204]: time="2026-08-15T10:04:18Z" level=info duration=8.281197ms duration-ns=8281197 fields.time="2026-08-15T10:04:18Z" method=POST name=ca nonce=Y2c5c2o3ZFlDeG1qdnBsNkl6MU51cnB0MXFmQUN1emw path=/acme/acme/order/w6mCOKbov1sGRZBxIj0W04YdtTpMJ82O/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=dd0870a9-f989-44b7-a90e-f7287f1952d2 response="{\"id\":\"w6mCOKbov1sGRZBxIj0W04YdtTpMJ82O\",\"status\":\"valid\",\"expires\":\"2026-08-16T10:04:18Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-15T10:03:18Z\",\"notAfter\":\"2026-11-13T10:04:18Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/3Yk0tlE9VeDYOHxy9gUSMKCU6jySLBzV\"],\"finalize\":\"https://ca.foo/acme/acme/order/w6mCOKbov1sGRZBxIj0W04YdtTpMJ82O/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/4iBC7ylBUgNg00CX0ATtN75EWCbw5nQp\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5827232.940304] ca step-ca[204]: time="2026-08-15T10:04:18Z" level=info certificate=MIIB2TCCAX6gAwIBAgIRAODc+wEXiuOtNagnY92nOCswCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwODE1MTAwMzE4WhcNMjYxMTEzMTAwNDE4WjATMREwDwYDVQQDEwh0ZXN0LmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABBAFEgfnf/C/mV7dO8BGRdglmeZ7NM2JD1mzUQl7WkYvmEZdEHQHel1Dycr5JpaQ6UUbe7VqohO1Dc2NYZPofrmjgaYwgaMwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUzA3XLnwgcUQljOZ8CE4HK7BiSfowHwYDVR0jBBgwFoAUyrMkoOjEoJ4PmApsZSFe/i6TkO0wEwYDVR0RBAwwCoIIdGVzdC5mb28wHQYMKwYBBAGCpGTGKEABBA0wCwIBBgQEYWNtZQQAMAoGCCqGSM49BAMCA0kAMEYCIQC/Z7kF5OwHqZAlbDF3DCkOY0nycVUmetLZNpTOAcx7vwIhAIPpdD2BUw2IOu5Ll8u5igNGE031cUmihbDFO3CuVxuj duration=1.260058ms duration-ns=1260058 fields.time="2026-08-15T10:04:18Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=NTIyRm94WGViNlhmM0pRV3loMTU3V3p2VHRnbGtIRnM path=/acme/acme/certificate/4iBC7ylBUgNg00CX0ATtN75EWCbw5nQp protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=a665affc-c26a-4dff-8a43-748f668c23f2 sans="map[dns:[test.foo]]" serial=298894467336023558853612714206809241643 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-15T10:03:18Z" valid-to="2026-11-13T10:04:18Z" container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1009 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 15 10:04:11 2026 GMT container-test-run-certificates> * expire date: Sep 14 10:04:11 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 38cde3 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [5827233.105540] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [5827233.109321] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [5827233.109497] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [5827233.609750] server nginx[391]: nginx: the configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf syntax is ok container-test-run-certificates> server # [5827233.610069] server nginx[391]: nginx: configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf test is successful container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [931 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [79 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 15 10:03:18 2026 GMT container-test-run-certificates> * expire date: Nov 13 10:04:18 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 39264 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 789 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 2.14 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> e0:dc:fb:01:17:8a:e3:ad:35:a8:27:63:dd:a7:38:2b container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Aug 15 10:03:18 2026 GMT container-test-run-certificates> Not After : Nov 13 10:04:18 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:10:05:12:07:e7:7f:f0:bf:99:5e:dd:3b:c0:46: container-test-run-certificates> 45:d8:25:99:e6:7b:34:cd:89:0f:59:b3:51:09:7b: container-test-run-certificates> 5a:46:2f:98:46:5d:10:74:07:7a:5d:43:c9:ca:f9: container-test-run-certificates> 26:96:90:e9:45:1b:7b:b5:6a:a2:13:b5:0d:cd:8d: container-test-run-certificates> 61:93:e8:7e:b9 container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> CC:0D:D7:2E:7C:20:71:44:25:8C:E6:7C:08:4E:07:2B:B0:62:49:FA container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> CA:B3:24:A0:E8:C4:A0:9E:0F:98:0A:6C:65:21:5E:FE:2E:93:90:ED container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:46:02:21:00:bf:67:b9:05:e4:ec:07:a9:90:25:6c:31:77: container-test-run-certificates> 0c:29:0e:63:49:f2:71:55:26:7a:d2:d9:36:94:ce:01:cc:7b: container-test-run-certificates> bf:02:21:00:83:e9:74:3d:81:53:0d:88:3a:ee:4b:97:cb:b9: container-test-run-certificates> 8a:03:46:13:4d:f5:71:49:a2:85:b0:c5:3b:70:ae:57:1b:a3 container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.04 seconds) container-test-run-certificates> (finished: run the VM test script, in 12.18 seconds) container-test-run-certificates> server # [5827234.116324] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> test script finished in 12.36s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 51) container-test-run-certificates> kill NspawnMachine (pid 54) container-test-run-certificates> kill NspawnMachine (pid 56) container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> Container server terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.49 seconds) post-build step Upload to niks3: ok time=2026-08-15T10:04:22.221Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-08-15T10:04:23.629Z level=INFO msg="Uploading 1 narinfos" time=2026-08-15T10:04:24.087Z level=INFO msg="Upload complete. (1.929s)"