these 89 derivations will be built: /nix/store/06xj51r5iv0wg3sry7cb1b5p0arh8amk-ca.json.drv /nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv /nix/store/l4s3hilg46786l91xxnck8qrd5zk5c39-system-path.drv /nix/store/53gz0xpb6hi1n7f8k9iaf0j65rb177yi-dbus-1.drv /nix/store/3yyv0623ddraws79zmjfk1qcwpy46j4w-X-Restart-Triggers-dbus-broker.drv /nix/store/3f4j3in4icr0w7mmf5azp7wrbb87lvrd-unit-dbus-broker.service.drv /nix/store/2afbh3vl9b4wqmi7rhmal5s3lqq5d2di-user-units.drv /nix/store/v3r6klh4wv9zb6hmz7fwb1gyzyil9a5n-unit-40-eth1.network.drv /nix/store/ycl6gbj04ywcaxa7ad5ms35wranp5b1r-X-Reload-Triggers-systemd-networkd.drv /nix/store/2y5dcvasfw9vhxcmcgzy70r1w1bd6jg9-unit-systemd-networkd.service.drv /nix/store/r83pgfxcw1n2v781qbslkwagg3w0p541-system-path.drv /nix/store/hfdp8pwsxxzhasg8ndcg2w197prj0nxb-dbus-1.drv /nix/store/pkyvq9bzv5p1p73rgk7y09vkimippi4r-X-Restart-Triggers-dbus-broker.drv /nix/store/gibl8vf5nh7rz7km47zqnhslnk5xdf1d-unit-dbus-broker.service.drv /nix/store/36cy4w2pi2w6k7jg152rzzpm1plchm8z-user-units.drv /nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv /nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv /nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv /nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv /nix/store/d4vj54sx388dyibi2ja6r7jckm4ra5bl-nginx.conf.drv /nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv /nix/store/padyknikkjqgfy4dqzfv3zac5wbypxga-nss-cacert-3.126.drv /nix/store/579wix8gpv1kx7q5ilr3pi7y7bsjj2a0-unit-nix-daemon.service.drv /nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv /nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv /nix/store/8v8nx7xkgmlz39rnf6l90mdmzhz8c9yx-unit-script-nginx-pre-start.drv /nix/store/j2jdcyp4233cn5lky6zlsk016msb24sr-unit-nginx.service.drv /nix/store/kx6mamh3kwimxnppg229zxy58cb8bgpr-unit-dbus-broker.service.drv /nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv /nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv /nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv /nix/store/rmxiym60q7p0pgy3rvrqhgl15ngv7yc5-unit-systemd-tmpfiles-resetup.service.drv /nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv /nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv /nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv /nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv /nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv /nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/wx0c1mhy9cbnqqslsbcyafy4qi30k2qn-system-units.drv /nix/store/xq7rs5kk8qzzspi7crlj4fjby5v1h3a4-etc.drv /nix/store/m5hnp0n89z3fry2sd74x37lxlpdkhms1-activate.drv /nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv /nix/store/3wjrp864wrm3nkhzym5nlprr6cl8zr2l-nixos-system-server-test.drv /nix/store/qxhrn5k10q3b7l2q99pvdzmkpi020xl6-system-path.drv /nix/store/am9qkfk9c09a47pkjf3vp7w6d4pqkk2b-dbus-1.drv /nix/store/qrrxsdc2h8nzpxn9dc9msx5xy2588qwx-X-Restart-Triggers-dbus-broker.drv /nix/store/4b2qclyk27xay6ar619c5acmkskacj4y-unit-dbus-broker.service.drv /nix/store/4xq1axfvdgf49msggmxqrmscqafczgj2-nginx.conf.drv /nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv /nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv /nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv /nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv /nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv /nix/store/7xx9in4vzx2fh4a7fz1s4wgqj1qf0nxw-unit-script-nginx-pre-start.drv /nix/store/hylqa47xmlzklb4mr8hi3kb4bvj1bb5f-unit-dbus-broker.service.drv /nix/store/9q0gkwrspfnwfq2gnbnj6cz4ndh94ifb-system-units.drv /nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv /nix/store/mk9inacviys80vn7la8kwlk9rjxkxmp3-etc.drv /nix/store/9iha09fcbpkp47qrr572viqsnl1z67kk-activate.drv /nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv /nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv /nix/store/bx9ay666mdpxmqa49l3hw83wkl8bjvvs-user-generators.drv /nix/store/wwlslfgw81qzfz9qlyr94hwf26df1iah-unit-dbus-broker.service.drv /nix/store/d7kgyvbw6k4b3qpsbhrgp60hg0dd7df9-user-units.drv /nix/store/imw2kazzmfl6nlf52psv7h2vlnfpdxn3-system-shutdown.drv /nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv /nix/store/rr3k22qcv35qb8krj0p5bp7b2yvqp8ml-system-generators.drv /nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv /nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv /nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv /nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv /nix/store/xbxd9w9n98kxv8xai0cwa169x1ac9fha-X-Restart-Triggers-step-ca.drv /nix/store/sjh85fq2x445snq0kd66rdbikr113rds-unit-step-ca.service.drv /nix/store/z2id9fli5k6ymffhg4lic3ipyaiywxp6-unit-nginx.service.drv /nix/store/wyqpfdgrs9ji9kxpc1p945bag0dnj687-system-units.drv /nix/store/bf5n3ragmhhadmqs84ciw80v6qj94w8x-etc.drv /nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv /nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv /nix/store/v1d98r0hiplay94cmz0ddapw7z0jmfs0-activate.drv /nix/store/pbfa0b8z7hvk46yrh6ag4x0q1ajjkwi4-nixos-system-ca-test.drv /nix/store/slals3rggzrm99il5qp6c1a7br5vxn7h-run-ca-nspawn.drv /nix/store/zx764c5w94ipds67d03kpph8bj35gqjb-nixos-system-client-test.drv /nix/store/ym3y1xnf0n1n5xdh66hc3qddzrq7qk6n-run-client-nspawn.drv /nix/store/z82g04vwvwgw132mscgh14hrr1pldmp5-run-server-nspawn.drv /nix/store/p22hyyagw7riy2qi3jqzbn8ax3a1n98f-driverConfiguration.json.drv /nix/store/9spzxar43sa82ydhq7wly755hypcxghm-nixos-test-driver-certificates.drv /nix/store/vw8crry78da5f1958wkdswp2rh5kgi9c-container-test-run-certificates.drv this path will be fetched (19.5 MiB download, 67.0 MiB unpacked): /nix/store/9zffz42v1gbfs8dwi61v4m09skszgl9x-step-ca-0.30.2 building '/nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/l4s3hilg46786l91xxnck8qrd5zk5c39-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qxhrn5k10q3b7l2q99pvdzmkpi020xl6-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/r83pgfxcw1n2v781qbslkwagg3w0p541-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/4xq1axfvdgf49msggmxqrmscqafczgj2-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/d4vj54sx388dyibi2ja6r7jckm4ra5bl-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/06xj51r5iv0wg3sry7cb1b5p0arh8amk-ca.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/padyknikkjqgfy4dqzfv3zac5wbypxga-nss-cacert-3.126.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rr3k22qcv35qb8krj0p5bp7b2yvqp8ml-system-generators.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv' building '/nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv' building '/nix/store/qxhrn5k10q3b7l2q99pvdzmkpi020xl6-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/4xq1axfvdgf49msggmxqrmscqafczgj2-nginx.conf.drv' nginx.conf> structuredAttrs is enabled building '/nix/store/l4s3hilg46786l91xxnck8qrd5zk5c39-system-path.drv' system-path> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy system-path> created 1718 symlinks in user environment building '/nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/imw2kazzmfl6nlf52psv7h2vlnfpdxn3-system-shutdown.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/06xj51r5iv0wg3sry7cb1b5p0arh8amk-ca.json.drv' ca.json> structuredAttrs is enabled building '/nix/store/d4vj54sx388dyibi2ja6r7jckm4ra5bl-nginx.conf.drv' nginx.conf> structuredAttrs is enabled nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv' building '/nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv' vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully building '/nix/store/xbxd9w9n98kxv8xai0cwa169x1ac9fha-X-Restart-Triggers-step-ca.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/8v8nx7xkgmlz39rnf6l90mdmzhz8c9yx-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/padyknikkjqgfy4dqzfv3zac5wbypxga-nss-cacert-3.126.drv' nss-cacert-3.126> Running phase: unpackPhase nss-cacert-3.126> Running phase: patchPhase nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase nss-cacert-3.126> Running phase: installPhase nss-cacert-3.126> Running phase: fixupPhase nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/ridw8gz0dkhf4vy5c9afxnxknvw961ig-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/ridw8gz0dkhf4vy5c9afxnxknvw961ig-nss-cacert-3.126... nss-cacert-3.126> patching script interpreter paths in /nix/store/ridw8gz0dkhf4vy5c9afxnxknvw961ig-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/dvn31l91l8iqv893xdx8vyw0yvw7h9dj-nss-cacert-3.126-unbundled nss-cacert-3.126> checking for references to /build/ in /nix/store/dvn31l91l8iqv893xdx8vyw0yvw7h9dj-nss-cacert-3.126-unbundled... nss-cacert-3.126> patching script interpreter paths in /nix/store/dvn31l91l8iqv893xdx8vyw0yvw7h9dj-nss-cacert-3.126-unbundled nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/vmk1fn6m29k5nzblx2zykispx7bilw3f-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/vmk1fn6m29k5nzblx2zykispx7bilw3f-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/vmk1fn6m29k5nzblx2zykispx7bilw3f-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/npxlb2shi8hbh65w64clxcsi09sn11lp-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/npxlb2shi8hbh65w64clxcsi09sn11lp-nss-cacert-3.126-hashed... nss-cacert-3.126> patching script interpreter paths in /nix/store/npxlb2shi8hbh65w64clxcsi09sn11lp-nss-cacert-3.126-hashed building '/nix/store/r83pgfxcw1n2v781qbslkwagg3w0p541-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv' building '/nix/store/579wix8gpv1kx7q5ilr3pi7y7bsjj2a0-unit-nix-daemon.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/rr3k22qcv35qb8krj0p5bp7b2yvqp8ml-system-generators.drv' building '/nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/am9qkfk9c09a47pkjf3vp7w6d4pqkk2b-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/53gz0xpb6hi1n7f8k9iaf0j65rb177yi-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/hfdp8pwsxxzhasg8ndcg2w197prj0nxb-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv' building '/nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv' building '/nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv' building '/nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv' building '/nix/store/8v8nx7xkgmlz39rnf6l90mdmzhz8c9yx-unit-script-nginx-pre-start.drv' building '/nix/store/j2jdcyp4233cn5lky6zlsk016msb24sr-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7xx9in4vzx2fh4a7fz1s4wgqj1qf0nxw-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/bx9ay666mdpxmqa49l3hw83wkl8bjvvs-user-generators.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv' unit-acme-renew-ca.foo.timer> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/53gz0xpb6hi1n7f8k9iaf0j65rb177yi-dbus-1.drv' building '/nix/store/am9qkfk9c09a47pkjf3vp7w6d4pqkk2b-dbus-1.drv' building '/nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv' building '/nix/store/7xx9in4vzx2fh4a7fz1s4wgqj1qf0nxw-unit-script-nginx-pre-start.drv' building '/nix/store/3yyv0623ddraws79zmjfk1qcwpy46j4w-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv' unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled building '/nix/store/hfdp8pwsxxzhasg8ndcg2w197prj0nxb-dbus-1.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/579wix8gpv1kx7q5ilr3pi7y7bsjj2a0-unit-nix-daemon.service.drv' unit-nix-daemon.service> structuredAttrs is enabled building '/nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv' building '/nix/store/bx9ay666mdpxmqa49l3hw83wkl8bjvvs-user-generators.drv' building '/nix/store/qrrxsdc2h8nzpxn9dc9msx5xy2588qwx-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/j2jdcyp4233cn5lky6zlsk016msb24sr-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv' unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled building '/nix/store/pkyvq9bzv5p1p73rgk7y09vkimippi4r-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/xbxd9w9n98kxv8xai0cwa169x1ac9fha-X-Restart-Triggers-step-ca.drv' building '/nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/imw2kazzmfl6nlf52psv7h2vlnfpdxn3-system-shutdown.drv' building '/nix/store/sjh85fq2x445snq0kd66rdbikr113rds-unit-step-ca.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv' unit-acme-renew-test.foo.timer> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv' building '/nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv' unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv' building '/nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv' building '/nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv' unit-acme-order-renew-test.foo.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/z2id9fli5k6ymffhg4lic3ipyaiywxp6-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qrrxsdc2h8nzpxn9dc9msx5xy2588qwx-X-Restart-Triggers-dbus-broker.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv' building '/nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/4b2qclyk27xay6ar619c5acmkskacj4y-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wwlslfgw81qzfz9qlyr94hwf26df1iah-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3yyv0623ddraws79zmjfk1qcwpy46j4w-X-Restart-Triggers-dbus-broker.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/pkyvq9bzv5p1p73rgk7y09vkimippi4r-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/gibl8vf5nh7rz7km47zqnhslnk5xdf1d-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/hylqa47xmlzklb4mr8hi3kb4bvj1bb5f-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/sjh85fq2x445snq0kd66rdbikr113rds-unit-step-ca.service.drv' unit-step-ca.service> structuredAttrs is enabled building '/nix/store/z2id9fli5k6ymffhg4lic3ipyaiywxp6-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv' unit-acme-ca.foo.service> structuredAttrs is enabled building '/nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv' unit-acme-test.foo.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/3f4j3in4icr0w7mmf5azp7wrbb87lvrd-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kx6mamh3kwimxnppg229zxy58cb8bgpr-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/gibl8vf5nh7rz7km47zqnhslnk5xdf1d-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/hylqa47xmlzklb4mr8hi3kb4bvj1bb5f-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/wwlslfgw81qzfz9qlyr94hwf26df1iah-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/d7kgyvbw6k4b3qpsbhrgp60hg0dd7df9-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/4b2qclyk27xay6ar619c5acmkskacj4y-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/wyqpfdgrs9ji9kxpc1p945bag0dnj687-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kx6mamh3kwimxnppg229zxy58cb8bgpr-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/3f4j3in4icr0w7mmf5azp7wrbb87lvrd-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/wx0c1mhy9cbnqqslsbcyafy4qi30k2qn-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/d7kgyvbw6k4b3qpsbhrgp60hg0dd7df9-user-units.drv' building '/nix/store/2afbh3vl9b4wqmi7rhmal5s3lqq5d2di-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/wyqpfdgrs9ji9kxpc1p945bag0dnj687-system-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/2afbh3vl9b4wqmi7rhmal5s3lqq5d2di-user-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/wx0c1mhy9cbnqqslsbcyafy4qi30k2qn-system-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/xq7rs5kk8qzzspi7crlj4fjby5v1h3a4-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/bf5n3ragmhhadmqs84ciw80v6qj94w8x-etc.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/bf5n3ragmhhadmqs84ciw80v6qj94w8x-etc.drv' building '/nix/store/9q0gkwrspfnwfq2gnbnj6cz4ndh94ifb-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/36cy4w2pi2w6k7jg152rzzpm1plchm8z-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/xq7rs5kk8qzzspi7crlj4fjby5v1h3a4-etc.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/m5hnp0n89z3fry2sd74x37lxlpdkhms1-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/36cy4w2pi2w6k7jg152rzzpm1plchm8z-user-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/9q0gkwrspfnwfq2gnbnj6cz4ndh94ifb-system-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/mk9inacviys80vn7la8kwlk9rjxkxmp3-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/m5hnp0n89z3fry2sd74x37lxlpdkhms1-activate.drv' building '/nix/store/3wjrp864wrm3nkhzym5nlprr6cl8zr2l-nixos-system-server-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v1d98r0hiplay94cmz0ddapw7z0jmfs0-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3wjrp864wrm3nkhzym5nlprr6cl8zr2l-nixos-system-server-test.drv' nixos-system-server-test> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/mk9inacviys80vn7la8kwlk9rjxkxmp3-etc.drv' building '/nix/store/z82g04vwvwgw132mscgh14hrr1pldmp5-run-server-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/9iha09fcbpkp47qrr572viqsnl1z67kk-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v1d98r0hiplay94cmz0ddapw7z0jmfs0-activate.drv' building '/nix/store/pbfa0b8z7hvk46yrh6ag4x0q1ajjkwi4-nixos-system-ca-test.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/z82g04vwvwgw132mscgh14hrr1pldmp5-run-server-nspawn.drv' building '/nix/store/9iha09fcbpkp47qrr572viqsnl1z67kk-activate.drv' building '/nix/store/zx764c5w94ipds67d03kpph8bj35gqjb-nixos-system-client-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/pbfa0b8z7hvk46yrh6ag4x0q1ajjkwi4-nixos-system-ca-test.drv' nixos-system-ca-test> structuredAttrs is enabled building '/nix/store/slals3rggzrm99il5qp6c1a7br5vxn7h-run-ca-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/zx764c5w94ipds67d03kpph8bj35gqjb-nixos-system-client-test.drv' nixos-system-client-test> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/slals3rggzrm99il5qp6c1a7br5vxn7h-run-ca-nspawn.drv' building '/nix/store/ym3y1xnf0n1n5xdh66hc3qddzrq7qk6n-run-client-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/ym3y1xnf0n1n5xdh66hc3qddzrq7qk6n-run-client-nspawn.drv' building '/nix/store/p22hyyagw7riy2qi3jqzbn8ax3a1n98f-driverConfiguration.json.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/p22hyyagw7riy2qi3jqzbn8ax3a1n98f-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/9spzxar43sa82ydhq7wly755hypcxghm-nixos-test-driver-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/9spzxar43sa82ydhq7wly755hypcxghm-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! building '/nix/store/vw8crry78da5f1958wkdswp2rh5kgi9c-container-test-run-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/vw8crry78da5f1958wkdswp2rh5kgi9c-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> ca: systemd-nspawn running (pid 53) container-test-run-certificates> client: systemd-nspawn running (pid 54) container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> server: systemd-nspawn running (pid 57) container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.00 seconds) container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> ca # [6018449.685220] ca systemd-journald[78]: Journal started container-test-run-certificates> ca # [6018449.685270] ca systemd-journald[78]: Runtime Journal (/run/log/journal/0c00c0b60f55456e9a56573482876220) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> ca # [6018449.691351] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> ca # [6018449.700639] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [6018449.684997] client systemd-journald[69]: Journal started container-test-run-certificates> ca # [6018449.701633] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [6018449.685053] client systemd-journald[69]: Runtime Journal (/run/log/journal/34488fb0b15a4686b12fc7ffa5c0e7f2) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> ca # [6018449.702364] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [6018449.691378] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> ca # [6018449.710312] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/0c00c0b60f55456e9a56573482876220 is 1.506ms for 6 entries. container-test-run-certificates> client # [6018449.700715] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [6018449.710312] ca systemd-journald[78]: System Journal (/var/log/journal/0c00c0b60f55456e9a56573482876220) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [6018449.701608] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [6018449.719729] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [6018449.702349] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [6018449.719974] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [6018449.710307] client systemd-journald[69]: Time spent on flushing to /var/log/journal/34488fb0b15a4686b12fc7ffa5c0e7f2 is 1.446ms for 6 entries. container-test-run-certificates> ca # [6018449.720071] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [6018449.720811] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [6018449.720860] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [6018449.710307] client systemd-journald[69]: System Journal (/var/log/journal/34488fb0b15a4686b12fc7ffa5c0e7f2) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [6018449.721745] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> client # [6018449.716695] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [6018449.721780] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> client # [6018449.716979] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> ca # [6018449.747203] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [6018449.717066] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [6018449.749178] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> client # [6018449.717804] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [6018449.766014] ca systemd-tmpfiles[139]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [6018449.717843] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [6018449.766229] ca systemd-tmpfiles[139]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [6018449.685364] server systemd-journald[69]: Journal started container-test-run-certificates> client # [6018449.718706] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [6018449.685419] server systemd-journald[69]: Runtime Journal (/run/log/journal/540c6d0dc03647e08e21ffb1bc9863fd) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> ca # [6018449.766372] ca systemd-tmpfiles[139]: fchmod() of /var/log/journal/0c00c0b60f55456e9a56573482876220 failed: Operation not permitted container-test-run-certificates> server # [6018449.693117] server systemd[1]: Finished Apply Kernel Variables. container-test-run-certificates> client # [6018449.718744] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> client # [6018449.746373] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [6018449.748314] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> client # [6018449.763512] client systemd-tmpfiles[129]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [6018449.763728] client systemd-tmpfiles[129]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [6018449.763872] client systemd-tmpfiles[129]: fchmod() of /var/log/journal/34488fb0b15a4686b12fc7ffa5c0e7f2 failed: Operation not permitted container-test-run-certificates> client # [6018449.764120] client systemd-tmpfiles[129]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [6018449.765656] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> client # [6018449.766867] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> client # [6018449.767799] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> client # [6018449.779497] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> client # [6018449.787434] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> client # [6018449.789515] client systemd[1]: Starting Update is Completed... container-test-run-certificates> client # [6018449.804454] client systemd[1]: Finished Update is Completed. container-test-run-certificates> client # [6018449.824465] client systemd[1]: Finished Firewall. container-test-run-certificates> client # [6018449.824617] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [6018449.824834] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [6018449.825888] client systemd[1]: Starting Network Management... container-test-run-certificates> ca # [6018449.766652] ca systemd-tmpfiles[139]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [6018449.702922] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> ca # [6018449.768283] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [6018449.715648] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [6018449.769411] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [6018449.716644] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [6018449.770159] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [6018449.781691] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [6018449.717144] server systemd[1]: systemd-tmpfiles-setup-dev.service: Failed to spawn executor: No such file or directory container-test-run-certificates> ca # [6018449.787637] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [6018449.717170] server systemd[1]: systemd-tmpfiles-setup-dev.service: Failed to spawn 'start' task: No such file or directory container-test-run-certificates> ca # [6018449.788652] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [6018449.717206] server systemd[1]: systemd-tmpfiles-setup-dev.service: Failed with result 'resources'. container-test-run-certificates> ca # [6018449.798903] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [6018449.717258] server systemd[1]: Failed to start Create Static Device Nodes in /dev. container-test-run-certificates> server # [6018449.717405] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> server # [6018449.717499] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> server # [6018449.718412] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> server # [6018449.718458] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6018449.719168] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [6018449.719202] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [6018449.725040] server systemd-journald[69]: Time spent on flushing to /var/log/journal/540c6d0dc03647e08e21ffb1bc9863fd is 1.834ms for 16 entries. container-test-run-certificates> server # [6018449.725040] server systemd-journald[69]: System Journal (/var/log/journal/540c6d0dc03647e08e21ffb1bc9863fd) is 8M, max 4G, 3.9G free. container-test-run-certificates> server # [6018449.747507] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [6018449.749467] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> server # [6018449.764382] server systemd-tmpfiles[127]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [6018449.764606] server systemd-tmpfiles[127]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [6018449.764758] server systemd-tmpfiles[127]: fchmod() of /var/log/journal/540c6d0dc03647e08e21ffb1bc9863fd failed: Operation not permitted container-test-run-certificates> server # [6018449.765000] server systemd-tmpfiles[127]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [6018449.767275] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [6018449.768519] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [6018449.769254] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [6018449.780490] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [6018449.787422] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [6018449.788629] server systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [6018449.802802] server systemd[1]: Finished Update is Completed. container-test-run-certificates> ca # [6018449.880237] ca systemd[1]: Finished Firewall. container-test-run-certificates> ca # [6018449.880873] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [6018449.881351] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> ca # [6018449.882371] ca systemd[1]: Starting Network Management... container-test-run-certificates> ca # [6018449.958691] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> client # [6018449.956510] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [6018449.880268] server systemd[1]: Finished Firewall. container-test-run-certificates> server # [6018449.880461] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> server # [6018449.880681] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [6018449.881766] server systemd[1]: Starting Network Management... container-test-run-certificates> server # [6018449.958693] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> client # [6018450.382114] client systemd-networkd[182]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6018450.382232] client systemd-networkd[182]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6018450.389137] client systemd-networkd[182]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [6018450.389304] client systemd-networkd[182]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [6018450.389560] client systemd-networkd[182]: lo: Link UP container-test-run-certificates> client # [6018450.389564] client systemd-networkd[182]: lo: Gained carrier container-test-run-certificates> client # [6018450.389743] client systemd-networkd[182]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [6018450.390105] client systemd[1]: Started Network Management. container-test-run-certificates> client # [6018450.390200] client systemd-networkd[182]: eth1: Link UP container-test-run-certificates> client # [6018450.390564] client systemd-networkd[182]: eth1: Gained carrier container-test-run-certificates> client # [6018450.391168] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> client # [6018450.446730] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> client # [6018450.557694] client systemd-resolved[96]: Positive Trust Anchors: container-test-run-certificates> client # [6018450.557707] client systemd-resolved[96]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> client # [6018450.557710] client systemd-resolved[96]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [6018450.557745] client systemd-resolved[96]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [6018450.580199] client systemd-resolved[96]: Using system hostname 'client'. container-test-run-certificates> client # [6018450.581557] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> client # [6018450.581640] client systemd[1]: Reached target Network. container-test-run-certificates> client # [6018450.581705] client systemd[1]: Reached target System Initialization. container-test-run-certificates> client # [6018450.581758] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [6018450.581787] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> client # [6018450.581806] client systemd[1]: Reached target Timer Units. container-test-run-certificates> client # [6018450.581941] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [6018450.582063] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> client # [6018450.582162] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> client # [6018450.582186] client systemd[1]: Reached target Socket Units. container-test-run-certificates> client # [6018450.582221] client systemd[1]: Reached target Basic System. container-test-run-certificates> client # [6018450.583315] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> client # [6018450.584254] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> client # [6018450.585528] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> client # [6018450.635260] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> ca # [6018450.382115] ca systemd-networkd[195]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [6018450.382212] ca systemd-networkd[195]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [6018450.389133] ca systemd-networkd[195]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [6018450.389305] ca systemd-networkd[195]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [6018450.389521] ca systemd-networkd[195]: lo: Link UP container-test-run-certificates> ca # [6018450.389525] ca systemd-networkd[195]: lo: Gained carrier container-test-run-certificates> ca # [6018450.389737] ca systemd-networkd[195]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> ca # [6018450.390166] ca systemd[1]: Started Network Management. container-test-run-certificates> ca # [6018450.390267] ca systemd-networkd[195]: eth1: Link UP container-test-run-certificates> ca # [6018450.390582] ca systemd-networkd[195]: eth1: Gained carrier container-test-run-certificates> ca # [6018450.391728] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [6018450.446807] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> ca # [6018450.565318] ca systemd-resolved[106]: Positive Trust Anchors: container-test-run-certificates> ca # [6018450.565329] ca systemd-resolved[106]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [6018450.565333] ca systemd-resolved[106]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [6018450.565368] ca systemd-resolved[106]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [6018450.588968] ca systemd-resolved[106]: Using system hostname 'ca'. container-test-run-certificates> ca # [6018450.590339] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [6018450.590420] ca systemd[1]: Reached target Network. container-test-run-certificates> ca # [6018450.590482] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [6018450.590521] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [6018450.590710] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> ca # [6018450.590741] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [6018450.590763] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [6018450.590779] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> ca # [6018450.590889] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> ca # [6018450.590992] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [6018450.591096] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [6018450.591114] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [6018450.591146] ca systemd[1]: Reached target Basic System. container-test-run-certificates> ca # [6018450.621054] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> ca # [6018450.621938] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [6018450.621985] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> ca # [6018450.622908] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [6018450.623968] ca systemd[1]: Starting step-ca service... container-test-run-certificates> ca # [6018450.625314] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [6018450.386565] server systemd-networkd[184]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [6018450.386658] server systemd-networkd[184]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [6018450.393505] server systemd-networkd[184]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [6018450.393672] server systemd-networkd[184]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [6018450.393842] server systemd-networkd[184]: lo: Link UP container-test-run-certificates> server # [6018450.393847] server systemd-networkd[184]: lo: Gained carrier container-test-run-certificates> server # [6018450.394059] server systemd-networkd[184]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [6018450.394473] server systemd[1]: Started Network Management. container-test-run-certificates> server # [6018450.394533] server systemd-networkd[184]: eth1: Link UP container-test-run-certificates> server # [6018450.394773] server systemd-networkd[184]: eth1: Gained carrier container-test-run-certificates> server # [6018450.436956] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> server # [6018450.448739] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [6018450.565690] server systemd-resolved[103]: Positive Trust Anchors: container-test-run-certificates> server # [6018450.565700] server systemd-resolved[103]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [6018450.565704] server systemd-resolved[103]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [6018450.565739] server systemd-resolved[103]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [6018450.588693] server systemd-resolved[103]: Using system hostname 'server'. container-test-run-certificates> server # [6018450.590130] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [6018450.590214] server systemd[1]: Reached target Network. container-test-run-certificates> server # [6018450.590279] server systemd[1]: Reached target Network is Online. container-test-run-certificates> server # [6018450.590324] server systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [6018450.590532] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> server # [6018450.590572] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6018450.590593] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [6018450.590610] server systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [6018450.590741] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [6018450.590850] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [6018450.590953] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [6018450.590973] server systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [6018450.591006] server systemd[1]: Reached target Basic System. container-test-run-certificates> server # [6018450.621054] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> server # [6018450.623108] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [6018450.623157] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> server # [6018450.624046] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [6018450.626857] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [6018450.642235] server systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> client # [6018450.674098] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [6018450.641102] ca systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> client # [6018450.770640] client nsncd[189]: Aug 17 15:11:16.823 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [6018450.674321] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [6018450.674653] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [6018450.730006] ca acme-setup-privileged[201]: + set -euo pipefail container-test-run-certificates> server # [6018450.720644] server acme-setup-privileged[190]: + set -euo pipefail container-test-run-certificates> ca # [6018450.730006] ca acme-setup-privileged[201]: + cd /var/lib/acme container-test-run-certificates> server # [6018450.720644] server acme-setup-privileged[190]: + cd /var/lib/acme container-test-run-certificates> ca # [6018450.730389] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> server # [6018450.721031] server acme-setup-privileged[190]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> ca # [6018450.731444] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts container-test-run-certificates> server # [6018450.722024] server acme-setup-privileged[190]: + chown -R acme .lego/accounts container-test-run-certificates> ca # [6018450.732972] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> client # [6018450.770823] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [6018450.733009] ca acme-setup-privileged[201]: + '[' -d ca.foo ']' container-test-run-certificates> client # [6018450.770878] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [6018450.733009] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> server # [6018450.723553] server acme-setup-privileged[190]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> ca # [6018450.733009] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> server # [6018450.723587] server acme-setup-privileged[190]: + '[' -d test.foo ']' container-test-run-certificates> ca # [6018450.755813] ca nsncd[203]: Aug 17 15:11:16.808 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> server # [6018450.723587] server acme-setup-privileged[190]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> ca # [6018450.780523] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> server # [6018450.723587] server acme-setup-privileged[190]: + '[' -d .lego/test.foo ']' container-test-run-certificates> ca # [6018450.780675] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [6018450.770938] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [6018450.780743] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [6018450.747388] server nsncd[192]: Aug 17 15:11:16.800 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [6018450.781441] client systemd[1]: Starting User Login Management... container-test-run-certificates> server # [6018450.747465] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [6018450.782583] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [6018450.747533] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [6018450.792303] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [6018450.782467] ca systemd[1]: Starting User Login Management... container-test-run-certificates> client # [6018450.793472] client systemd[1]: Started Console Getty. container-test-run-certificates> server # [6018450.747592] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> client # [6018450.793515] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> ca # [6018450.783412] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> client # [6018450.793534] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [6018450.781062] server systemd[1]: Starting User Login Management... container-test-run-certificates> server # [6018450.781999] server systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [6018450.792075] server systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [6018450.792895] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [6018450.793228] server systemd[1]: Started Console Getty. container-test-run-certificates> ca # [6018450.793995] ca systemd[1]: Started Console Getty. container-test-run-certificates> server # [6018450.793266] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [6018450.793286] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca # [6018450.794041] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> ca # [6018450.794059] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [6018450.903116] server dbus-broker-launch[193]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [6018450.903958] server dbus-broker-launch[193]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [6018450.903958] server dbus-broker-launch[193]: Invalid user-name in /nix/store/lxnlg1wvz5bx4xfzc75k21l11ngxkyck-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [6018450.904384] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [6018450.911476] server dbus-broker-launch[193]: Ready container-test-run-certificates> ca # [6018450.911413] ca dbus-broker-launch[205]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [6018450.912606] ca dbus-broker-launch[205]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> ca # [6018450.912606] ca dbus-broker-launch[205]: Invalid user-name in /nix/store/mfvkn1zwby5692v4kx3ynjdz34b2lkq3-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> ca # [6018450.913040] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [6018450.920288] ca dbus-broker-launch[205]: Ready container-test-run-certificates> client # [6018451.000333] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> client # [6018451.001139] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [6018451.001139] client dbus-broker-launch[190]: Invalid user-name in /nix/store/s0a40wv0lnwiz13r43fk318ri3wv536k-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [6018451.001522] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> client # [6018451.008375] client dbus-broker-launch[190]: Ready container-test-run-certificates> ca # [6018451.456334] ca systemd-networkd[195]: eth1: Gained IPv6LL container-test-run-certificates> ca # [6018451.466466] ca systemd-logind[230]: New seat seat0. container-test-run-certificates> ca # [6018451.466675] ca systemd[1]: Started User Login Management. container-test-run-certificates> ca # [6018451.532513] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> ca # [6018451.535534] ca acme-setup-start[219]: + set -euo pipefail container-test-run-certificates> ca # [6018451.535804] ca acme-setup-start[219]: + test -e ca/key.pem container-test-run-certificates> ca # [6018451.535804] ca acme-setup-start[219]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [6018451.545619] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [6018451.545747] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [6018451.556109] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [6018451.557684] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> client # [6018451.456210] client systemd-logind[205]: New seat seat0. container-test-run-certificates> client # [6018451.456446] client systemd[1]: Started User Login Management. container-test-run-certificates> client # [6018451.458011] client systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [6018451.542230] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> client # [6018451.542404] client systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [6018451.542852] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> client # [6018451.543052] client systemd[1]: Startup finished in 2.298s. container-test-run-certificates> server # [6018451.460516] server systemd-logind[218]: New seat seat0. container-test-run-certificates> server # [6018451.461098] server systemd[1]: Started User Login Management. container-test-run-certificates> server # [6018451.532513] server systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [6018451.533769] server acme-setup-start[206]: + set -euo pipefail container-test-run-certificates> server # [6018451.533769] server acme-setup-start[206]: + test -e ca/key.pem container-test-run-certificates> server # [6018451.534143] server acme-setup-start[206]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> server # [6018451.547357] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> server # [6018451.547437] server systemd[1]: Finished linger-users.service. container-test-run-certificates> server # [6018451.553905] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> server # [6018451.555940] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> server # [6018451.840204] server systemd-networkd[184]: eth1: Gained IPv6LL container-test-run-certificates> ca # [6018451.897314] ca step-ca[204]: badger 2026/08/17 15:11:17 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [6018451.908085] ca step-ca[204]: 2026/08/17 15:11:17 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> ca # [6018451.917215] ca step-ca[204]: 2026/08/17 15:11:17 Starting Smallstep CA/0.30.2 (linux/arm64) container-test-run-certificates> ca # [6018451.917215] ca step-ca[204]: 2026/08/17 15:11:17 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> ca # [6018451.917215] ca step-ca[204]: 2026/08/17 15:11:17 Community Discord: https://u.step.sm/discord container-test-run-certificates> ca # [6018451.917215] ca step-ca[204]: 2026/08/17 15:11:17 Config file: /etc/smallstep/ca.json container-test-run-certificates> ca # [6018451.917215] ca step-ca[204]: 2026/08/17 15:11:17 The primary server URL is https://ca.foo:1443 container-test-run-certificates> ca # [6018451.917215] ca step-ca[204]: 2026/08/17 15:11:17 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [6018451.917354] ca step-ca[204]: 2026/08/17 15:11:17 X.509 Root Fingerprint: f9e7a116c83d2375b63fd0fee2b3f3d2c10fa91e7eb2213ff0482fdebbf2ec31 container-test-run-certificates> ca # [6018451.917856] ca systemd[1]: Started step-ca service. container-test-run-certificates> ca # [6018451.918134] ca step-ca[204]: 2026/08/17 15:11:17 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> server # [6018452.153175] server acme-test.foo-start[243]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6018452.155902] server acme-test.foo-start[243]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [6018452.155995] server acme-test.foo-start[243]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [6018452.166623] server acme-test.foo-start[253]: + cd test.foo container-test-run-certificates> server # [6018452.167017] server acme-test.foo-start[253]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [6018452.167986] server acme-test.foo-start[254]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [6018452.168310] server acme-test.foo-start[253]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [6018452.169423] server acme-test.foo-start[253]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [6018452.169655] server acme-test.foo-start[243]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [6018452.171376] server acme-test.foo-start[243]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [6018452.173064] server acme-test.foo-start[243]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6018452.174598] server acme-test.foo-start[243]: + for fixpath in out certificates container-test-run-certificates> server # [6018452.174598] server acme-test.foo-start[243]: + '[' -d out ']' container-test-run-certificates> server # [6018452.174671] server acme-test.foo-start[243]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6018452.176142] server acme-test.foo-start[243]: + chown -R acme:nginx out container-test-run-certificates> server # [6018452.178647] server acme-test.foo-start[243]: + for fixpath in out certificates container-test-run-certificates> server # [6018452.178685] server acme-test.foo-start[243]: + '[' -d certificates ']' container-test-run-certificates> server # [6018452.181783] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [6018452.183282] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> ca # [6018452.209734] ca acme-ca.foo-start[256]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6018452.212233] ca acme-ca.foo-start[256]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [6018452.212350] ca acme-ca.foo-start[256]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> ca # [6018452.222927] ca acme-ca.foo-start[292]: + cd ca.foo container-test-run-certificates> ca # [6018452.223319] ca acme-ca.foo-start[292]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> ca # [6018452.224389] ca acme-ca.foo-start[293]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [6018452.224621] ca acme-ca.foo-start[292]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> ca # [6018452.225805] ca acme-ca.foo-start[292]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [6018452.226046] ca acme-ca.foo-start[256]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [6018452.227473] ca acme-ca.foo-start[256]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [6018452.229582] ca acme-ca.foo-start[256]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [6018452.230375] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [6018452.230375] ca acme-ca.foo-start[256]: + '[' -d out ']' container-test-run-certificates> ca # [6018452.230469] ca acme-ca.foo-start[256]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6018452.231860] ca acme-ca.foo-start[256]: + chown -R acme:nginx out container-test-run-certificates> ca # [6018452.234351] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [6018452.234351] ca acme-ca.foo-start[256]: + '[' -d certificates ']' container-test-run-certificates> ca # [6018452.238856] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> ca # [6018452.240357] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> client # [6018452.256142] client systemd-networkd[182]: eth1: Gained IPv6LL container-test-run-certificates> server # [6018452.818795] server nginx-pre-start[265]: nginx: the configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf syntax is ok container-test-run-certificates> server # [6018452.819159] server nginx-pre-start[265]: nginx: configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf test is successful container-test-run-certificates> server # [6018452.823796] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [6018452.824201] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [6018452.825523] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> ca # [6018452.844971] ca nginx-pre-start[304]: nginx: the configuration file /nix/store/y0w3rf0mygndzvcgy9cmg2mqb83s730b-nginx.conf syntax is ok container-test-run-certificates> ca # [6018452.845414] ca nginx-pre-start[304]: nginx: configuration file /nix/store/y0w3rf0mygndzvcgy9cmg2mqb83s730b-nginx.conf test is successful container-test-run-certificates> ca # [6018452.855195] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [6018452.855587] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [6018452.857267] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca # [6018453.519817] ca acme-order-renew-ca.foo-start[307]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6018453.522508] ca acme-order-renew-ca.foo-start[307]: + set -euo pipefail container-test-run-certificates> ca # [6018453.522587] ca acme-order-renew-ca.foo-start[307]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [6018453.522702] ca acme-order-renew-ca.foo-start[307]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [6018453.523780] ca acme-order-renew-ca.foo-start[307]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> ca # [6018453.539355] ca acme-order-renew-ca.foo-start[319]: 2026/08/17 15:11:19 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [6018453.539745] ca acme-order-renew-ca.foo-start[319]: 2026/08/17 15:11:19 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [6018453.564661] ca step-ca[204]: time="2026-08-17T15:11:19Z" level=info duration="115.362µs" duration-ns=115362 fields.time="2026-08-17T15:11:19Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=07d1bdb6-3420-40da-bb73-f24fb2962b39 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6018453.565109] ca acme-order-renew-ca.foo-start[319]: 2026/08/17 15:11:19 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [6018453.499002] server acme-order-renew-test.foo-start[268]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6018453.501739] server acme-order-renew-test.foo-start[268]: + set -euo pipefail container-test-run-certificates> server # [6018453.501819] server acme-order-renew-test.foo-start[268]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [6018453.501935] server acme-order-renew-test.foo-start[268]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [6018453.503168] server acme-order-renew-test.foo-start[268]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [6018453.518981] server acme-order-renew-test.foo-start[279]: 2026/08/17 15:11:19 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [6018453.519484] server acme-order-renew-test.foo-start[279]: 2026/08/17 15:11:19 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> server # [6018453.548931] server acme-order-renew-test.foo-start[279]: 2026/08/17 15:11:19 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority container-test-run-certificates> server # [6018453.552427] server acme-order-renew-test.foo-start[268]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [6018453.552427] server acme-order-renew-test.foo-start[268]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [6018453.552427] server acme-order-renew-test.foo-start[268]: + exit 10 container-test-run-certificates> server # [6018453.555568] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a container-test-run-certificates> server # [6018453.555677] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'. container-test-run-certificates> server # [6018453.555952] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [6018453.556263] server systemd[1]: Startup finished in 4.294s. container-test-run-certificates> ca # [6018453.807658] ca step-ca[204]: time="2026-08-17T15:11:19Z" level=info duration=242.3725ms duration-ns=242372500 fields.time="2026-08-17T15:11:19Z" method=HEAD name=ca nonce=eFhSdERBY2pIR1VzaTZnS0g2N3U5MmFkZjF0RWcxdWo path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=856b120b-b8de-48fa-9e8b-37a3e178890c size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6018453.824430] ca step-ca[204]: time="2026-08-17T15:11:19Z" level=info duration=15.95838ms duration-ns=15958380 fields.time="2026-08-17T15:11:19Z" method=POST name=ca nonce=bzhkelV3ZUxWSXlSUlJ1YXAwR091WDJWbzA2S2ZlMks path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=79b0ca4b-e79b-47cd-8e5d-b110b640fab3 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/mrHSHzOj2eI6q0KfSsHNsXv7JDucKUdE/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6018453.824791] ca acme-order-renew-ca.foo-start[319]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [6018453.824791] ca acme-order-renew-ca.foo-start[319]: Your account credentials have been saved in your container-test-run-certificates> ca # [6018453.824791] ca acme-order-renew-ca.foo-start[319]: configuration directory at "accounts". container-test-run-certificates> ca # [6018453.824791] ca acme-order-renew-ca.foo-start[319]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [6018453.824791] ca acme-order-renew-ca.foo-start[319]: configuration directory will also contain private keys container-test-run-certificates> ca # [6018453.824791] ca acme-order-renew-ca.foo-start[319]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [6018453.824791] ca acme-order-renew-ca.foo-start[319]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [6018453.824928] ca acme-order-renew-ca.foo-start[319]: 2026/08/17 15:11:19 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [6018453.831062] ca step-ca[204]: time="2026-08-17T15:11:19Z" level=info duration=5.708439ms duration-ns=5708439 fields.time="2026-08-17T15:11:19Z" method=POST name=ca nonce=QTRyUm5BUEhnRTJ6Q2NoMWcyM3JKbmM2ckpmOVY2Wkg path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=2dfabd68-428b-4f60-91e4-b7844c7a13d3 response="{\"id\":\"9rkczlUdigqtkHZfmG1heQoQHdk2BS6E\",\"status\":\"pending\",\"expires\":\"2026-08-18T15:11:19Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-17T15:10:19Z\",\"notAfter\":\"2026-11-15T15:11:19Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/plDfpSPNTyFF6hHo2TvliwW3HSqxXK9f\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/9rkczlUdigqtkHZfmG1heQoQHdk2BS6E/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6018453.891518] ca step-ca[204]: time="2026-08-17T15:11:19Z" level=info duration=3.482608ms duration-ns=3482608 fields.time="2026-08-17T15:11:19Z" method=POST name=ca nonce=SkJnR2dJOVNGMXVDWldFSEwyamxFb2xIWXozT25Balk path=/acme/acme/authz/plDfpSPNTyFF6hHo2TvliwW3HSqxXK9f protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=0d4771aa-b2b1-4061-abd8-4e6397203368 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"9RShoRvfpwkKtcWvagWdWVNjZ2JKqXr8\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/plDfpSPNTyFF6hHo2TvliwW3HSqxXK9f/tqWUxpeJm03mHaB7JGkhnsAzN7pxMPIM\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"9RShoRvfpwkKtcWvagWdWVNjZ2JKqXr8\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/plDfpSPNTyFF6hHo2TvliwW3HSqxXK9f/oEKoABisY8mIEq6PYfwxvF3WKHkNbIIY\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"9RShoRvfpwkKtcWvagWdWVNjZ2JKqXr8\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/plDfpSPNTyFF6hHo2TvliwW3HSqxXK9f/sWs8vCPqPd781dW0J0XQgaIl4zWHgo4b\"}],\"wildcard\":false,\"expires\":\"2026-08-18T15:11:19Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6018453.891868] ca acme-order-renew-ca.foo-start[319]: 2026/08/17 15:11:19 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/plDfpSPNTyFF6hHo2TvliwW3HSqxXK9f container-test-run-certificates> ca # [6018453.891868] ca acme-order-renew-ca.foo-start[319]: 2026/08/17 15:11:19 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [6018453.891868] ca acme-order-renew-ca.foo-start[319]: 2026/08/17 15:11:19 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [6018453.891868] ca acme-order-renew-ca.foo-start[319]: 2026/08/17 15:11:19 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> ca # [6018453.896051] ca step-ca[204]: time="2026-08-17T15:11:19Z" level=info duration=3.583049ms duration-ns=3583049 fields.time="2026-08-17T15:11:19Z" method=POST name=ca nonce=WkpJWGhJcUNtbUphYmh0bUpiVXdPUFo4RFhXSjhPTTU path=/acme/acme/challenge/plDfpSPNTyFF6hHo2TvliwW3HSqxXK9f/oEKoABisY8mIEq6PYfwxvF3WKHkNbIIY protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=b82da9b3-3679-4fd8-9a67-b9646050864c response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"9RShoRvfpwkKtcWvagWdWVNjZ2JKqXr8\",\"validated\":\"2026-08-17T15:11:19Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/plDfpSPNTyFF6hHo2TvliwW3HSqxXK9f/oEKoABisY8mIEq6PYfwxvF3WKHkNbIIY\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6018453.896297] ca acme-order-renew-ca.foo-start[319]: 2026/08/17 15:11:19 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [6018453.896406] ca acme-order-renew-ca.foo-start[319]: 2026/08/17 15:11:19 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [6018453.906916] ca step-ca[204]: time="2026-08-17T15:11:19Z" level=info duration=9.588372ms duration-ns=9588372 fields.time="2026-08-17T15:11:19Z" method=POST name=ca nonce=WlRDWGxiU1NCM0dTSmo3dUpLcDJyOXFJOE1na3VmTDM path=/acme/acme/order/9rkczlUdigqtkHZfmG1heQoQHdk2BS6E/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=850f1255-1842-46da-98c9-9b4aaa182625 response="{\"id\":\"9rkczlUdigqtkHZfmG1heQoQHdk2BS6E\",\"status\":\"valid\",\"expires\":\"2026-08-18T15:11:19Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-17T15:10:19Z\",\"notAfter\":\"2026-11-15T15:11:19Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/plDfpSPNTyFF6hHo2TvliwW3HSqxXK9f\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/9rkczlUdigqtkHZfmG1heQoQHdk2BS6E/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/MrWKjNIT4ZA9j0SMhRjHHpM0ORgA0eww\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6018453.909349] ca step-ca[204]: time="2026-08-17T15:11:19Z" level=info certificate="MIIB1DCCAXmgAwIBAgIQc+teFoUxEg6BkArufgawGDAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MTcxNTEwMTlaFw0yNjExMTUxNTExMTlaMBExDzANBgNVBAMTBmNhLmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABLJaZE5k7xSexo1/n+hS+9U2njXUv2bTX26eqh6E6WjR/OZNlFnl94YS7s0/1BqUCb1MykGfwbx6KZDPjgM1+qGjgaQwgaEwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUSni/sIKBNdDM2ryewPSED7QI14kwHwYDVR0jBBgwFoAUyrMkoOjEoJ4PmApsZSFe/i6TkO0wEQYDVR0RBAowCIIGY2EuZm9vMB0GDCsGAQQBgqRkxihAAQQNMAsCAQYEBGFjbWUEADAKBggqhkjOPQQDAgNJADBGAiEAsoJ9LgdnJ2362MgN0gQY1BytWQUDTdzv1l2uR2QRGU4CIQDjtzKw09cWLsjKV+5TL8o5qemALc71riisFnxRwvX52Q==" duration=1.585502ms duration-ns=1585502 fields.time="2026-08-17T15:11:19Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=TDNCbFBVTnM5VXBMdEx3VlZnekFHNEJlWGF3YUlLSmU path=/acme/acme/certificate/MrWKjNIT4ZA9j0SMhRjHHpM0ORgA0eww protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=4ff9f41d-1bf1-4e60-9aa2-0d559dedfef1 sans="map[dns:[ca.foo]]" serial=154083317607764157389064850371670093848 size=1344 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-17T15:10:19Z" valid-to="2026-11-15T15:11:19Z" container-test-run-certificates> ca # [6018453.909597] ca acme-order-renew-ca.foo-start[319]: 2026/08/17 15:11:19 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [6018453.915365] ca acme-order-renew-ca.foo-start[307]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [6018453.917337] ca acme-order-renew-ca.foo-start[307]: + touch out/acme-success container-test-run-certificates> ca # [6018453.918938] ca acme-order-renew-ca.foo-start[307]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6018453.919915] ca acme-order-renew-ca.foo-start[307]: + touch out/renewed container-test-run-certificates> ca # [6018453.921416] ca acme-order-renew-ca.foo-start[307]: + echo Installing new certificate container-test-run-certificates> ca # [6018453.921416] ca acme-order-renew-ca.foo-start[307]: Installing new certificate container-test-run-certificates> ca # [6018453.921475] ca acme-order-renew-ca.foo-start[307]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6018453.923798] ca acme-order-renew-ca.foo-start[350]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [6018453.924255] ca acme-order-renew-ca.foo-start[307]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [6018453.925721] ca acme-order-renew-ca.foo-start[351]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [6018453.925982] ca acme-order-renew-ca.foo-start[307]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [6018453.927542] ca acme-order-renew-ca.foo-start[352]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [6018453.927762] ca acme-order-renew-ca.foo-start[307]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [6018453.929324] ca acme-order-renew-ca.foo-start[307]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [6018453.930892] ca acme-order-renew-ca.foo-start[307]: + for fixpath in out certificates container-test-run-certificates> ca # [6018453.930892] ca acme-order-renew-ca.foo-start[307]: + '[' -d out ']' container-test-run-certificates> ca # [6018453.930960] ca acme-order-renew-ca.foo-start[307]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6018453.932504] ca acme-order-renew-ca.foo-start[307]: + chown -R acme:nginx out container-test-run-certificates> ca # [6018453.935240] ca acme-order-renew-ca.foo-start[307]: + for fixpath in out certificates container-test-run-certificates> ca # [6018453.935240] ca acme-order-renew-ca.foo-start[307]: + '[' -d certificates ']' container-test-run-certificates> ca # [6018453.935329] ca acme-order-renew-ca.foo-start[307]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [6018453.936648] ca acme-order-renew-ca.foo-start[307]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [6018453.939391] ca acme-order-renew-ca.foo-start[307]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6018454.087980] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> ca # [6018454.095580] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [6018454.136297] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> ca # [6018454.869087] ca nginx[368]: nginx: the configuration file /nix/store/y0w3rf0mygndzvcgy9cmg2mqb83s730b-nginx.conf syntax is ok container-test-run-certificates> ca # [6018454.869417] ca nginx[368]: nginx: configuration file /nix/store/y0w3rf0mygndzvcgy9cmg2mqb83s730b-nginx.conf test is successful container-test-run-certificates> ca # [6018457.002254] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [6018457.002549] ca systemd[1]: Startup finished in 7.728s. container-test-run-certificates> ca # [6018457.496416] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 7.20 seconds) container-test-run-certificates> ca # [6018458.818954] ca acme-order-renew-ca.foo-start[383]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6018458.822309] ca acme-order-renew-ca.foo-start[383]: + set -euo pipefail container-test-run-certificates> ca # [6018458.822387] ca acme-order-renew-ca.foo-start[383]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [6018458.822503] ca acme-order-renew-ca.foo-start[383]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [6018458.823531] ca acme-order-renew-ca.foo-start[383]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [6018458.823562] ca acme-order-renew-ca.foo-start[383]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [6018458.823974] ca acme-order-renew-ca.foo-start[391]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [6018458.826187] ca acme-order-renew-ca.foo-start[383]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [6018458.826224] ca acme-order-renew-ca.foo-start[383]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [6018458.864145] ca step-ca[204]: time="2026-08-17T15:11:24Z" level=info duration="49.64µs" duration-ns=49640 fields.time="2026-08-17T15:11:24Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=ae403cb7-a276-4343-b2a5-5dc0e57f97b9 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6018458.864568] ca acme-order-renew-ca.foo-start[392]: 2026/08/17 15:11:24 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [6018458.864568] ca acme-order-renew-ca.foo-start[392]: 2026/08/17 15:11:24 [INFO] [ca.foo] The certificate expires at 2026-11-15T15:11:19Z, the renewal can be performed in 1439h59m34.082346401s: no renewal. container-test-run-certificates> ca # [6018458.864994] ca acme-order-renew-ca.foo-start[383]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [6018458.866664] ca acme-order-renew-ca.foo-start[383]: + touch out/acme-success container-test-run-certificates> ca # [6018458.868063] ca acme-order-renew-ca.foo-start[383]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6018458.869163] ca acme-order-renew-ca.foo-start[383]: + for fixpath in out certificates container-test-run-certificates> ca # [6018458.869190] ca acme-order-renew-ca.foo-start[383]: + '[' -d out ']' container-test-run-certificates> ca # [6018458.869190] ca acme-order-renew-ca.foo-start[383]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6018458.870610] ca acme-order-renew-ca.foo-start[383]: + chown -R acme:nginx out container-test-run-certificates> ca # [6018458.873797] ca acme-order-renew-ca.foo-start[383]: + for fixpath in out certificates container-test-run-certificates> ca # [6018458.873818] ca acme-order-renew-ca.foo-start[383]: + '[' -d certificates ']' container-test-run-certificates> ca # [6018458.873835] ca acme-order-renew-ca.foo-start[383]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [6018458.875264] ca acme-order-renew-ca.foo-start[383]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [6018458.877240] ca acme-order-renew-ca.foo-start[383]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6018459.027620] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [6018459.027826] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server # [6018462.054316] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [6018462.054476] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [6018462.055496] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [6018462.056892] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.99 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1008 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 17 15:11:18 2026 GMT container-test-run-certificates> * expire date: Sep 16 15:11:18 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 113551 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6018463.002169] server acme-test.foo-start[313]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6018463.004744] server acme-test.foo-start[313]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [6018463.004787] server acme-test.foo-start[313]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [6018463.015267] server acme-test.foo-start[323]: + cd test.foo container-test-run-certificates> server # [6018463.015622] server acme-test.foo-start[323]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [6018463.016875] server acme-test.foo-start[324]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [6018463.017092] server acme-test.foo-start[323]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [6018463.018250] server acme-test.foo-start[323]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [6018463.018462] server acme-test.foo-start[313]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [6018463.020303] server acme-test.foo-start[313]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [6018463.021737] server acme-test.foo-start[313]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6018463.023208] server acme-test.foo-start[313]: + for fixpath in out certificates container-test-run-certificates> server # [6018463.023230] server acme-test.foo-start[313]: + '[' -d out ']' container-test-run-certificates> server # [6018463.023247] server acme-test.foo-start[313]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6018463.024609] server acme-test.foo-start[313]: + chown -R acme:nginx out container-test-run-certificates> server # [6018463.026989] server acme-test.foo-start[313]: + for fixpath in out certificates container-test-run-certificates> server # [6018463.027034] server acme-test.foo-start[313]: + '[' -d certificates ']' container-test-run-certificates> server # [6018463.030167] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [6018463.032614] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1008 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [112 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 17 15:11:18 2026 GMT container-test-run-certificates> * expire date: Sep 16 15:11:18 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 113551 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6018463.908422] server acme-order-renew-test.foo-start[331]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6018463.910773] server acme-order-renew-test.foo-start[331]: + set -euo pipefail container-test-run-certificates> server # [6018463.910850] server acme-order-renew-test.foo-start[331]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [6018463.910964] server acme-order-renew-test.foo-start[331]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [6018463.912402] server acme-order-renew-test.foo-start[331]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [6018463.956197] server acme-order-renew-test.foo-start[339]: 2026/08/17 15:11:30 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [6018464.039826] server acme-order-renew-test.foo-start[339]: !!!! HEADS UP !!!! container-test-run-certificates> server # [6018464.039826] server acme-order-renew-test.foo-start[339]: Your account credentials have been saved in your container-test-run-certificates> server # [6018464.039826] server acme-order-renew-test.foo-start[339]: configuration directory at "accounts". container-test-run-certificates> server # [6018464.039826] server acme-order-renew-test.foo-start[339]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [6018464.039826] server acme-order-renew-test.foo-start[339]: configuration directory will also contain private keys container-test-run-certificates> server # [6018464.039826] server acme-order-renew-test.foo-start[339]: generated by lego and certificates obtained from the ACME container-test-run-certificates> server # [6018464.039826] server acme-order-renew-test.foo-start[339]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [6018464.040287] server acme-order-renew-test.foo-start[339]: 2026/08/17 15:11:30 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> server # [6018464.110042] server acme-order-renew-test.foo-start[339]: 2026/08/17 15:11:30 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/j4NIYOLGQC6W4MT7uFMSqCO0ySVCVQbm container-test-run-certificates> server # [6018464.110042] server acme-order-renew-test.foo-start[339]: 2026/08/17 15:11:30 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [6018464.110042] server acme-order-renew-test.foo-start[339]: 2026/08/17 15:11:30 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [6018464.110042] server acme-order-renew-test.foo-start[339]: 2026/08/17 15:11:30 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [6018464.118019] server acme-order-renew-test.foo-start[339]: 2026/08/17 15:11:30 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [6018464.118133] server acme-order-renew-test.foo-start[339]: 2026/08/17 15:11:30 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [6018464.135089] server acme-order-renew-test.foo-start[339]: 2026/08/17 15:11:30 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [6018464.140965] server acme-order-renew-test.foo-start[331]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [6018464.143060] server acme-order-renew-test.foo-start[331]: + touch out/acme-success container-test-run-certificates> server # [6018464.144707] server acme-order-renew-test.foo-start[331]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [6018464.145870] server acme-order-renew-test.foo-start[331]: + touch out/renewed container-test-run-certificates> server # [6018464.147431] server acme-order-renew-test.foo-start[331]: + echo Installing new certificate container-test-run-certificates> server # [6018464.147431] server acme-order-renew-test.foo-start[331]: Installing new certificate container-test-run-certificates> server # [6018464.147431] server acme-order-renew-test.foo-start[331]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [6018464.148804] server acme-order-renew-test.foo-start[371]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [6018464.149126] server acme-order-renew-test.foo-start[331]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [6018464.150565] server acme-order-renew-test.foo-start[372]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [6018464.150835] server acme-order-renew-test.foo-start[331]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [6018464.153165] server acme-order-renew-test.foo-start[373]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [6018464.153480] server acme-order-renew-test.foo-start[331]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [6018464.155942] server acme-order-renew-test.foo-start[331]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6018464.157517] server acme-order-renew-test.foo-start[331]: + for fixpath in out certificates container-test-run-certificates> server # [6018464.157517] server acme-order-renew-test.foo-start[331]: + '[' -d out ']' container-test-run-certificates> server # [6018464.157599] server acme-order-renew-test.foo-start[331]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6018464.158970] server acme-order-renew-test.foo-start[331]: + chown -R acme:nginx out container-test-run-certificates> ca # [6018463.955690] ca step-ca[204]: time="2026-08-17T15:11:30Z" level=info duration="47.961µs" duration-ns=47961 fields.time="2026-08-17T15:11:30Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=0c694dc0-7b5c-4722-9222-c522c2be6ffd response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6018464.032539] ca step-ca[204]: time="2026-08-17T15:11:30Z" level=info duration=74.180942ms duration-ns=74180942 fields.time="2026-08-17T15:11:30Z" method=HEAD name=ca nonce=azQ2SkhYTW83S21RdHpoQmhPQkZyRUFhMVJGYU1lck0 path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=96515ed3-e29d-43fc-9897-d5f5d867bd64 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6018464.039116] ca step-ca[204]: time="2026-08-17T15:11:30Z" level=info duration=3.235325ms duration-ns=3235325 fields.time="2026-08-17T15:11:30Z" method=POST name=ca nonce=Nzc2bG15amlSUmNBbklKRUFsbzRBNDBUTDVnQktMcGQ path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=17717c9e-7e97-41e9-9cc4-c2236fe34db7 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/1XyedUjwFTFAoUev7vkYbUYQIffWXjH3/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6018464.047308] ca step-ca[204]: time="2026-08-17T15:11:30Z" level=info duration=4.205818ms duration-ns=4205818 fields.time="2026-08-17T15:11:30Z" method=POST name=ca nonce=dlZZQjFkQlN6aGdFSEZ5alZsWUxaanBoNHQ2SVRCZGo path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=7e5e192b-57cc-450b-a9e2-3c62449fecc8 response="{\"id\":\"8xIQ7oGedjdwvDBeLA2PsJ0ad1i1u1Hi\",\"status\":\"pending\",\"expires\":\"2026-08-18T15:11:30Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-17T15:10:30Z\",\"notAfter\":\"2026-11-15T15:11:30Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/j4NIYOLGQC6W4MT7uFMSqCO0ySVCVQbm\"],\"finalize\":\"https://ca.foo/acme/acme/order/8xIQ7oGedjdwvDBeLA2PsJ0ad1i1u1Hi/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6018464.109387] ca step-ca[204]: time="2026-08-17T15:11:30Z" level=info duration=2.305592ms duration-ns=2305592 fields.time="2026-08-17T15:11:30Z" method=POST name=ca nonce=WGF1eXpYTUtJVzNRcGt6b0FtbXNvdnVzUW5qelY0Ulo path=/acme/acme/authz/j4NIYOLGQC6W4MT7uFMSqCO0ySVCVQbm protocol=HTTP/1.1 referer= remote-address="::1" request-id=01add973-c190-43be-acd8-89be5dea4263 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"xgqz8WbrEBz7KRerTUMJimBshHfCeD7w\",\"url\":\"https://ca.foo/acme/acme/challenge/j4NIYOLGQC6W4MT7uFMSqCO0ySVCVQbm/qOWVX2F7dLu6nx5GteUIiuaGRWS6kOEE\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"xgqz8WbrEBz7KRerTUMJimBshHfCeD7w\",\"url\":\"https://ca.foo/acme/acme/challenge/j4NIYOLGQC6W4MT7uFMSqCO0ySVCVQbm/yQbDF4AqYKYOypS1A71W0c3peB4S1ZvB\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"xgqz8WbrEBz7KRerTUMJimBshHfCeD7w\",\"url\":\"https://ca.foo/acme/acme/challenge/j4NIYOLGQC6W4MT7uFMSqCO0ySVCVQbm/gsex4fZFYJpiXPIEMWeiQ93ohMgjnFYT\"}],\"wildcard\":false,\"expires\":\"2026-08-18T15:11:30Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6018464.117579] ca step-ca[204]: time="2026-08-17T15:11:30Z" level=info duration=4.074576ms duration-ns=4074576 fields.time="2026-08-17T15:11:30Z" method=POST name=ca nonce=UXpnb0VFWkE3WEZGTTFsa1BUeXo4RzlzR0U0cVJ2SDk path=/acme/acme/challenge/j4NIYOLGQC6W4MT7uFMSqCO0ySVCVQbm/yQbDF4AqYKYOypS1A71W0c3peB4S1ZvB protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=e450a18d-1a30-4e38-92ea-68d726b04ef0 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"xgqz8WbrEBz7KRerTUMJimBshHfCeD7w\",\"validated\":\"2026-08-17T15:11:30Z\",\"url\":\"https://ca.foo/acme/acme/challenge/j4NIYOLGQC6W4MT7uFMSqCO0ySVCVQbm/yQbDF4AqYKYOypS1A71W0c3peB4S1ZvB\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6018464.129239] ca step-ca[204]: time="2026-08-17T15:11:30Z" level=info duration=7.817307ms duration-ns=7817307 fields.time="2026-08-17T15:11:30Z" method=POST name=ca nonce=VmRqMDJScTJ1Y1NoSDNSUnVwNUV0aFNzQ3E5RXBzMGY path=/acme/acme/order/8xIQ7oGedjdwvDBeLA2PsJ0ad1i1u1Hi/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=7b6239a7-428c-493a-bf16-d683b4b5d687 response="{\"id\":\"8xIQ7oGedjdwvDBeLA2PsJ0ad1i1u1Hi\",\"status\":\"valid\",\"expires\":\"2026-08-18T15:11:30Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-17T15:10:30Z\",\"notAfter\":\"2026-11-15T15:11:30Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/j4NIYOLGQC6W4MT7uFMSqCO0ySVCVQbm\"],\"finalize\":\"https://ca.foo/acme/acme/order/8xIQ7oGedjdwvDBeLA2PsJ0ad1i1u1Hi/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/UR0FqcFT4ioErPgaXtejTEnfW7yiv4it\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6018464.134619] ca step-ca[204]: time="2026-08-17T15:11:30Z" level=info certificate=MIIB2TCCAX6gAwIBAgIRALKZo0DnNND4QFAOSy0+yLkwCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwODE3MTUxMDMwWhcNMjYxMTE1MTUxMTMwWjATMREwDwYDVQQDEwh0ZXN0LmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABBjkrQsomOf3wpwWNxLQceIeGrwP5DSIToYLMElF2UiTbXKx2HREPj1XXyN8VN/R4PXrY39wfinAF08KsjTqruCjgaYwgaMwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUlCGtzyikyv2bCIc68C68QAUYKUowHwYDVR0jBBgwFoAUyrMkoOjEoJ4PmApsZSFe/i6TkO0wEwYDVR0RBAwwCoIIdGVzdC5mb28wHQYMKwYBBAGCpGTGKEABBA0wCwIBBgQEYWNtZQQAMAoGCCqGSM49BAMCA0kAMEYCIQC+B89/xWiiZpprV+qfgJRwNTmODmT75yjLTy/UD11FfwIhAKkhnP/0P/LYwPVxj+1uKInf0BmmDOo9L1MpkGOeEYvl duration=2.087868ms duration-ns=2087868 fields.time="2026-08-17T15:11:30Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=R0xkRHZDR2lNbFFyOXJQZllzUFpRVkVIMTZTdGVPWWs path=/acme/acme/certificate/UR0FqcFT4ioErPgaXtejTEnfW7yiv4it protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=4aae9898-e220-4c04-9239-33862b1440c0 sans="map[dns:[test.foo]]" serial=237400315843993538382245390548335511737 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-17T15:10:30Z" valid-to="2026-11-15T15:11:30Z" container-test-run-certificates> server # [6018464.161527] server acme-order-renew-test.foo-start[331]: + for fixpath in out certificates container-test-run-certificates> server # [6018464.161527] server acme-order-renew-test.foo-start[331]: + '[' -d certificates ']' container-test-run-certificates> server # [6018464.161527] server acme-order-renew-test.foo-start[331]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [6018464.162901] server acme-order-renew-test.foo-start[331]: + chown -R acme:nginx certificates container-test-run-certificates> server # [6018464.165685] server acme-order-renew-test.foo-start[331]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> server # [6018464.305748] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [6018464.309493] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [6018464.309702] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1008 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [110 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 17 15:11:18 2026 GMT container-test-run-certificates> * expire date: Sep 16 15:11:18 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 113551 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6018465.133014] server nginx[389]: nginx: the configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf syntax is ok container-test-run-certificates> server # [6018465.133374] server nginx[389]: nginx: configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf test is successful container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1008 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 17 15:11:18 2026 GMT container-test-run-certificates> * expire date: Sep 16 15:11:18 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 113551 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6018466.843826] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [931 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [79 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 17 15:10:30 2026 GMT container-test-run-certificates> * expire date: Nov 15 15:11:30 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 36210 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 848 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 4.21 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> b2:99:a3:40:e7:34:d0:f8:40:50:0e:4b:2d:3e:c8:b9 container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Aug 17 15:10:30 2026 GMT container-test-run-certificates> Not After : Nov 15 15:11:30 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:18:e4:ad:0b:28:98:e7:f7:c2:9c:16:37:12:d0: container-test-run-certificates> 71:e2:1e:1a:bc:0f:e4:34:88:4e:86:0b:30:49:45: container-test-run-certificates> d9:48:93:6d:72:b1:d8:74:44:3e:3d:57:5f:23:7c: container-test-run-certificates> 54:df:d1:e0:f5:eb:63:7f:70:7e:29:c0:17:4f:0a: container-test-run-certificates> b2:34:ea:ae:e0 container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> 94:21:AD:CF:28:A4:CA:FD:9B:08:87:3A:F0:2E:BC:40:05:18:29:4A container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> CA:B3:24:A0:E8:C4:A0:9E:0F:98:0A:6C:65:21:5E:FE:2E:93:90:ED container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:46:02:21:00:be:07:cf:7f:c5:68:a2:66:9a:6b:57:ea:9f: container-test-run-certificates> 80:94:70:35:39:8e:0e:64:fb:e7:28:cb:4f:2f:d4:0f:5d:45: container-test-run-certificates> 7f:02:21:00:a9:21:9c:ff:f4:3f:f2:d8:c0:f5:71:8f:ed:6e: container-test-run-certificates> 28:89:df:d0:19:a6:0c:ea:3d:2f:53:29:90:63:9e:11:8b:e5 container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.04 seconds) container-test-run-certificates> (finished: run the VM test script, in 18.44 seconds) container-test-run-certificates> test script finished in 18.57s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 53) container-test-run-certificates> kill NspawnMachine (pid 54) container-test-run-certificates> kill NspawnMachine (pid 57) container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.44 seconds) container-test-run-certificates> Container server terminated by signal KILL. post-build step Upload to niks3: ok time=2026-08-17T15:11:35.138Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-08-17T15:11:40.478Z level=WARN msg="Request returned retryable status, retrying" attempt=1 max_attempts=6 backoff=100ms status=500 url="https://s3.eu-central-003.backblazeb2.com/clan-cache-geninf/ksw2b7lqbgaf2wmz15mbmh3gyny1y0wx.ls?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=003eaae730241090000000009%2F20260817%2Feu-central-003%2Fs3%2Faws4_request&X-Amz-Date=20260817T151135Z&X-Amz-Expires=18000&X-Amz-SignedHeaders=host&X-Amz-Signature=4ed5a6d2d5cc33e72fad852372ef981062484fee8a4fddc1e2593f2c8c67e0d1" time=2026-08-17T15:11:40.840Z level=INFO msg="Uploading 1 narinfos" time=2026-08-17T15:11:41.278Z level=INFO msg="Upload complete. (6.191s)"