these 146 derivations will be built: /nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv /nix/store/0wkvjp33zch55ahkr14b0gxwxzcbhdnx-unit-40-eth1.network.drv /nix/store/pz8cs4lg35mq4mi7ck3am5chl70g70yx-firewall-start.drv /nix/store/1h3016b7n1wag10qh4dax4mdvk4hiydh-firewall-reload.drv /nix/store/9m1li3fnxbh19xrfnk3narki8pqdh1ng-stage-2-init.sh.drv /nix/store/f9px5y0wjxrrp2xg3knkl5mzxb7y0sqb-nixos-version.drv /nix/store/l4s3hilg46786l91xxnck8qrd5zk5c39-system-path.drv /nix/store/53gz0xpb6hi1n7f8k9iaf0j65rb177yi-dbus-1.drv /nix/store/3yyv0623ddraws79zmjfk1qcwpy46j4w-X-Restart-Triggers-dbus-broker.drv /nix/store/3f4j3in4icr0w7mmf5azp7wrbb87lvrd-unit-dbus-broker.service.drv /nix/store/2afbh3vl9b4wqmi7rhmal5s3lqq5d2di-user-units.drv /nix/store/3lgdmxj6pllvdi3fds0d4giazm0pcbak-set-environment.drv /nix/store/qwadgx0fzqh4waw8pyhn0kkbgszg7yld-string-hosts.drv /nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv /nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv /nix/store/d4vj54sx388dyibi2ja6r7jckm4ra5bl-nginx.conf.drv /nix/store/6z5jc0sp4vjkgzd37icya2gy22sk8q70-nixos-tmpfiles.d.drv /nix/store/79kfpjcg65c0rrnp43qfppivwzfx8yvi-10-acme.conf.drv /nix/store/dxhcs8f88vsb624k3l6b10b549cv921m-tmpfiles.d.drv /nix/store/55r3xbviq6l3zgziig53rhs351x7xj6l-cacert-extra-certificates-bundle.crt.drv /nix/store/x52vjn5rprsx9n1jd5m287f9yhs1ffqn-cacert-blocklist.txt.drv /nix/store/k5phpbqvva59rzp4cx71phpv7ckmrncv-nss-cacert-3.126.drv /nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv /nix/store/lpjl8rih1zhwsnb1ax1s0p7xh89429kd-etc-profile.drv /nix/store/gp8c99h6mwblqzf2pmx80ax2d7hxjli1-unit-script-nix-gc-start.drv /nix/store/2xj8ma1f4q37pw3g0ias2wvisyf6jsbi-unit-nix-gc.service.drv /nix/store/v3r6klh4wv9zb6hmz7fwb1gyzyil9a5n-unit-40-eth1.network.drv /nix/store/ycl6gbj04ywcaxa7ad5ms35wranp5b1r-X-Reload-Triggers-systemd-networkd.drv /nix/store/2y5dcvasfw9vhxcmcgzy70r1w1bd6jg9-unit-systemd-networkd.service.drv /nix/store/36093jr86bnmgl2w5hi8pb61ly2bfymc-unit-suid-sgid-wrappers.service-disabled.drv /nix/store/5i5ljy0lrq3hs6yxvfinp7v1sppz2a2l-unit-console-getty.service.drv /nix/store/6nk1kbn566ha71hwg69frczrm91sl8ns-unit-systemd-fsck-.service.drv /nix/store/863zw10ii54bs6wmi9c48cjaihd3ln1p-unit-resolvconf.service-disabled.drv /nix/store/9p97s7cydrakaiixbbgrnrcw0551rpyd-unit-nix-optimise.service.drv /nix/store/lnv6cx72zjrnd730hh73gzcfxyinbn9f-X-Restart-Triggers-systemd-journald-.drv /nix/store/9wq3xd2sy586pzs7rnpcsl1857hf2a4x-unit-systemd-journald-.service.drv /nix/store/dc4gn73n2m072ck0rm5jx5npg9winm6c-unit-serial-getty-hvc0.service-disabled.drv /nix/store/j3lmyghsa4g7nacl7gf67lvx5m91k2br-unit-script-acme-setup-start.drv /nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv /nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv /nix/store/p32ifkb9jkjlhm1m1m17jg1nbmqc4zbl-X-Restart-Triggers-systemd-sysctl.drv /nix/store/g2gpd27y6vw63m3l59xsfrqf44l31igf-unit-systemd-sysctl.service.drv /nix/store/yqc4sp989230vvc36w6kxmg7f2bzl9yf-X-Restart-Triggers-systemd-journald.drv /nix/store/g9bfvl6h2n1ags2vhzcymd11bzbp5vsc-unit-systemd-journald.service.drv /nix/store/86yd1gg4qy3vym7mkcyzmf44vgn39nzk-X-Restart-Triggers-nix-daemon.drv /nix/store/i1h54lwmdgn5pwg52jwhmfs61pny4iw3-unit-nix-daemon.service.drv /nix/store/iwak2s8vxh0gknl39krmkycm8k27lbyw-unit-serial-getty-ttyAMA0.service-disabled.drv /nix/store/8v8nx7xkgmlz39rnf6l90mdmzhz8c9yx-unit-script-nginx-pre-start.drv /nix/store/j2jdcyp4233cn5lky6zlsk016msb24sr-unit-nginx.service.drv /nix/store/kx6mamh3kwimxnppg229zxy58cb8bgpr-unit-dbus-broker.service.drv /nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv /nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv /nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv /nix/store/ra9f6mzgpig8bxfp26sd4f4dhdymamc3-unit-firewall.service.drv /nix/store/y9vs2brijwc8c2b5mh0vxrsz0hh37z6h-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/rmxiym60q7p0pgy3rvrqhgl15ngv7yc5-unit-systemd-tmpfiles-resetup.service.drv /nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv /nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv /nix/store/prkpxrpnbg00wkvx2dnkna3y29skgvjg-X-Reload-Triggers-systemd-resolved.drv /nix/store/v0clim1zszqklxri4dwhf4gr45rx79ja-unit-systemd-resolved.service.drv /nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv /nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv /nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv /nix/store/611br14m45zhx3dfhz4q47a5y9248n9n-shutdown-ramfs-contents.json.drv /nix/store/v75n6iibh1hdrjkqg7cig45jy07dhyfa-unit-generate-shutdown-ramfs.service.drv /nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/wsyfklsm3q5s0r921ifrnvrf8vpa818w-unit-systemd-timedated.service.drv /nix/store/y09qxnkg7kkpr443p6k4smg9pspqdbih-unit-serial-getty-.service.drv /nix/store/zysgb31jhg6syi6xkv3ap6lrd4pb7yhm-unit-systemd-makefs-.service.drv /nix/store/rldmhkn4fqpwqrzkv2gi3pvijlp4lzhb-system-units.drv /nix/store/y0qm0gmasb5ln3m9mr5yknii9n5irzgh-useradd.drv /nix/store/ay4c0mq6qaksy643am2xkp47xfr5fg6p-etc.drv /nix/store/7bm5w0wpz1gk6ma416c9i77kslkzgm9m-decrypt-age-secrets.drv /nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv /nix/store/dhkkxdlbls1rv4qwamqi53wvvb50c0xy-activate.drv /nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv /nix/store/ayr5nmixqh47gmapbxx43n6lq4v9004y-nixos-system-server-test.drv /nix/store/7dyjmbnhy0753bz08j222y00v2hhnb3i-run-server-nspawn.drv /nix/store/5mrdkkv0rkyrgkwxwdj3gbwks10c6i55-users-groups.json.drv /nix/store/hvpdgppc2ph0w7r40a0nla0cl5zy2x1k-dry-activate.drv /nix/store/r83pgfxcw1n2v781qbslkwagg3w0p541-system-path.drv /nix/store/hfdp8pwsxxzhasg8ndcg2w197prj0nxb-dbus-1.drv /nix/store/pkyvq9bzv5p1p73rgk7y09vkimippi4r-X-Restart-Triggers-dbus-broker.drv /nix/store/gibl8vf5nh7rz7km47zqnhslnk5xdf1d-unit-dbus-broker.service.drv /nix/store/36cy4w2pi2w6k7jg152rzzpm1plchm8z-user-units.drv /nix/store/ph9gl1f92ahhv1bxxsrky4lgc2k7nwbf-X-Reload-Triggers-systemd-networkd.drv /nix/store/50m6cfa5x1dxaslnp49g6lxj4p7np9bp-unit-systemd-networkd.service.drv /nix/store/wj2j3bqp278r6dp9463nky9mp3lkkhwj-nixos-tmpfiles.d.drv /nix/store/n8sp574dsmhbggqmf9hb0wmrri9l2qq3-tmpfiles.d.drv /nix/store/3wbzl5zadk20cplik16z31fcvghbrlcz-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/7hgnzq5d0x9pk0i03d6a0ia7i525pzmi-unit-systemd-tmpfiles-resetup.service.drv /nix/store/hylqa47xmlzklb4mr8hi3kb4bvj1bb5f-unit-dbus-broker.service.drv /nix/store/wk7m48i09fl5440y04scqvbjjx6v5blg-firewall-reload.drv /nix/store/i8g688x99787cjd8jvlsmddvhq71rcv2-unit-firewall.service.drv /nix/store/65zpxz0y484lp2m2g1xy4gn27l9zgm3w-system-units.drv /nix/store/jznfxppghphx23z7wdkqfnrqnbgbm9q6-string-hosts.drv /nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv /nix/store/vg0gc9drwn9mwr5wwfr1bc6zxjb90g44-etc.drv /nix/store/l3m99y9dhv5nzj8gfrb3vv92hmxa2yjf-activate.drv /nix/store/y8skg0i6c76girw5sbrnxvks7242d5c2-nixos-system-client-test.drv /nix/store/lmmih59av1bbaxr2yf4qgd0a3idkdcnd-run-client-nspawn.drv /nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv /nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv /nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv /nix/store/33cqcqqvm72xwbvp5zvp2vhpz17g33cm-ca.json.drv /nix/store/qxhrn5k10q3b7l2q99pvdzmkpi020xl6-system-path.drv /nix/store/am9qkfk9c09a47pkjf3vp7w6d4pqkk2b-dbus-1.drv /nix/store/qrrxsdc2h8nzpxn9dc9msx5xy2588qwx-X-Restart-Triggers-dbus-broker.drv /nix/store/4b2qclyk27xay6ar619c5acmkskacj4y-unit-dbus-broker.service.drv /nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv /nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv /nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv /nix/store/g4lprx9wmm1d2wsmkpxiksv270j1rgi0-X-Restart-Triggers-step-ca.drv /nix/store/fpz2bqfgazq73k7ga6j1vl77vhp3vjzs-unit-step-ca.service.drv /nix/store/njsvc1nkjyh72y3xif3d6ssg8w9gfklm-unit-40-eth1.network.drv /nix/store/bzcf79ahfynhd1n624f5ggjw3hi1r0cz-X-Reload-Triggers-systemd-networkd.drv /nix/store/fx7ik3vx6rfz50jgfpv7iqc1npfpfzn6-unit-systemd-networkd.service.drv /nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv /nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv /nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv /nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv /nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv /nix/store/p58gpq8dlbza3dklkqrzwj7blz2knydv-nginx-recommended-proxy_set_header-headers.conf.drv /nix/store/b1wakvsznndfrig5xjpba9fwk6lpwkw3-nginx.conf.drv /nix/store/5m1cfc1nmb9cbzniv4dpgdv38ivj0qsz-unit-script-nginx-pre-start.drv /nix/store/skf8nz991czh5gpm41hbaqakj5f7hf0c-unit-nginx.service.drv /nix/store/47h254qhqagyk25s8z4js2c2kga9xsd6-system-units.drv /nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv /nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv /nix/store/bx9ay666mdpxmqa49l3hw83wkl8bjvvs-user-generators.drv /nix/store/wwlslfgw81qzfz9qlyr94hwf26df1iah-unit-dbus-broker.service.drv /nix/store/d7kgyvbw6k4b3qpsbhrgp60hg0dd7df9-user-units.drv /nix/store/imw2kazzmfl6nlf52psv7h2vlnfpdxn3-system-shutdown.drv /nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv /nix/store/rr3k22qcv35qb8krj0p5bp7b2yvqp8ml-system-generators.drv /nix/store/zavgpaf9h8976wj49m95kjd6gc4psk8b-etc.drv /nix/store/f6sz49xdxddn3j4rj98qx3a4xaj1b911-activate.drv /nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv /nix/store/zc4sc0l4a1zlg10hyam6bxymxb6y1kv6-nixos-system-ca-test.drv /nix/store/rr4facpzjyyaz9nfhs8mhfs4kycc38km-run-ca-nspawn.drv /nix/store/1ig9gn83y2k9r9kmdpk62my8zbsl0vdw-driverConfiguration.json.drv /nix/store/5k59m3qhfcaxaxyz5kkrpzsj2v6c4j3s-nixos-test-driver-1.1.drv /nix/store/1qcl83b9sjj9cp2zx2sq1xf8visciqzq-nixos-test-driver-certificates.drv /nix/store/209v17izv4wi9h2qqny6brs83ba9vibz-container-test-run-certificates.drv these 17 paths will be fetched (45.8 MiB download, 150.1 MiB unpacked): /nix/store/rfjs1fcacfd1xysy7cmvxsrb9znz6iln-certdata.txt /nix/store/3japwvq6a40ykrmxjjjvm695q2z6c66c-flock-0.4.0 /nix/store/6nr0a4775j5z9nr71ciasfd9pzz076zs-gixy-0.1.21 /nix/store/p12aczsxidgl3m4jkpc4dl4y7kzf8vck-lego-4.35.2 /nix/store/fqcqw4nlcg6q6n77z3gnxhgg3ll6gjvy-minica-1.1.0 /nix/store/pjqhdi88bpspx4a01qlsw96jn2isl11k-nginx-1.30.4 /nix/store/g59y871mjn55fgjswdn72g51qc62j6wa-nginx-config-formatter-1.4.0 /nix/store/n0hdbypqp52bcmm1b5bhxgha5yl8hjs1-nginx-mod-moreheaders-0.40 /nix/store/zzhdyl8d6l7z4jfl5i36ijwqz2vpja7i-nginx-mod-rtmp-1.2.2 /nix/store/1psq003v8r8611bv7bk74xdwz9z6dgaj-openssl-3.6.3-man /nix/store/06pcrb4pj0c0sk6pa39hgmfddprslv4k-openssl-4.0.1 /nix/store/fkylsp720lag8s97n9cbxcafx78clj31-python3.14-buildcatrust-0.5.1 /nix/store/kjz0wmk9imvcj2nrm6ls5yd4mw8awajj-python3.14-cached-property-2.0.1 /nix/store/pfxx0s91wb2bhph7m1hdmzik1d8r9jn9-python3.14-configargparse-1.7.5 /nix/store/fdr01jdc50hn18dn90hx7q9p2jhkaw6m-python3.14-pyparsing-2.4.7 /nix/store/9zffz42v1gbfs8dwi61v4m09skszgl9x-step-ca-0.30.2 /nix/store/j345y5z7axzdpxivknd0swxi5yccyxq4-zlib-ng-2.3.3 building '/nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v3r6klh4wv9zb6hmz7fwb1gyzyil9a5n-unit-40-eth1.network.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/79kfpjcg65c0rrnp43qfppivwzfx8yvi-10-acme.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p58gpq8dlbza3dklkqrzwj7blz2knydv-nginx-recommended-proxy_set_header-headers.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6z5jc0sp4vjkgzd37icya2gy22sk8q70-nixos-tmpfiles.d.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/pz8cs4lg35mq4mi7ck3am5chl70g70yx-firewall-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v3r6klh4wv9zb6hmz7fwb1gyzyil9a5n-unit-40-eth1.network.drv' unit-40-eth1.network> structuredAttrs is enabled building '/nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv' building '/nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv' building '/nix/store/ycl6gbj04ywcaxa7ad5ms35wranp5b1r-X-Reload-Triggers-systemd-networkd.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/79kfpjcg65c0rrnp43qfppivwzfx8yvi-10-acme.conf.drv' building '/nix/store/6z5jc0sp4vjkgzd37icya2gy22sk8q70-nixos-tmpfiles.d.drv' building '/nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv' building '/nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv' building '/nix/store/p58gpq8dlbza3dklkqrzwj7blz2knydv-nginx-recommended-proxy_set_header-headers.conf.drv' building '/nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv' building '/nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled building '/nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv' building '/nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv' building '/nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv' unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled building '/nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv' unit-acme-renew-ca.foo.timer> structuredAttrs is enabled building '/nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv' unit-acme-renew-test.foo.timer> structuredAttrs is enabled building '/nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/b1wakvsznndfrig5xjpba9fwk6lpwkw3-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv' building '/nix/store/dxhcs8f88vsb624k3l6b10b549cv921m-tmpfiles.d.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/33cqcqqvm72xwbvp5zvp2vhpz17g33cm-ca.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/x52vjn5rprsx9n1jd5m287f9yhs1ffqn-cacert-blocklist.txt.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/55r3xbviq6l3zgziig53rhs351x7xj6l-cacert-extra-certificates-bundle.crt.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/d4vj54sx388dyibi2ja6r7jckm4ra5bl-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rr3k22qcv35qb8krj0p5bp7b2yvqp8ml-system-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/l4s3hilg46786l91xxnck8qrd5zk5c39-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qxhrn5k10q3b7l2q99pvdzmkpi020xl6-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/r83pgfxcw1n2v781qbslkwagg3w0p541-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/imw2kazzmfl6nlf52psv7h2vlnfpdxn3-system-shutdown.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/j3lmyghsa4g7nacl7gf67lvx5m91k2br-unit-script-acme-setup-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/bx9ay666mdpxmqa49l3hw83wkl8bjvvs-user-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv' building '/nix/store/pz8cs4lg35mq4mi7ck3am5chl70g70yx-firewall-start.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/ycl6gbj04ywcaxa7ad5ms35wranp5b1r-X-Reload-Triggers-systemd-networkd.drv' building '/nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv' building '/nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv' building '/nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv' building '/nix/store/1h3016b7n1wag10qh4dax4mdvk4hiydh-firewall-reload.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/2y5dcvasfw9vhxcmcgzy70r1w1bd6jg9-unit-systemd-networkd.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dxhcs8f88vsb624k3l6b10b549cv921m-tmpfiles.d.drv' building '/nix/store/b1wakvsznndfrig5xjpba9fwk6lpwkw3-nginx.conf.drv' nginx.conf> structuredAttrs is enabled building '/nix/store/y9vs2brijwc8c2b5mh0vxrsz0hh37z6h-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' on 'ssh-ng://builder@build01.clan.lol' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/5m1cfc1nmb9cbzniv4dpgdv38ivj0qsz-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv' building '/nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv' building '/nix/store/55r3xbviq6l3zgziig53rhs351x7xj6l-cacert-extra-certificates-bundle.crt.drv' building '/nix/store/x52vjn5rprsx9n1jd5m287f9yhs1ffqn-cacert-blocklist.txt.drv' building '/nix/store/k5phpbqvva59rzp4cx71phpv7ckmrncv-nss-cacert-3.126.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/d4vj54sx388dyibi2ja6r7jckm4ra5bl-nginx.conf.drv' nginx.conf> structuredAttrs is enabled building '/nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/8v8nx7xkgmlz39rnf6l90mdmzhz8c9yx-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/33cqcqqvm72xwbvp5zvp2vhpz17g33cm-ca.json.drv' ca.json> structuredAttrs is enabled building '/nix/store/g4lprx9wmm1d2wsmkpxiksv270j1rgi0-X-Restart-Triggers-step-ca.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rr3k22qcv35qb8krj0p5bp7b2yvqp8ml-system-generators.drv' building '/nix/store/r83pgfxcw1n2v781qbslkwagg3w0p541-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/qxhrn5k10q3b7l2q99pvdzmkpi020xl6-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv' building '/nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv' building '/nix/store/hfdp8pwsxxzhasg8ndcg2w197prj0nxb-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/2y5dcvasfw9vhxcmcgzy70r1w1bd6jg9-unit-systemd-networkd.service.drv' unit-systemd-networkd.service> structuredAttrs is enabled building '/nix/store/1h3016b7n1wag10qh4dax4mdvk4hiydh-firewall-reload.drv' building '/nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/j3lmyghsa4g7nacl7gf67lvx5m91k2br-unit-script-acme-setup-start.drv' building '/nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv' building '/nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv' vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully building '/nix/store/l4s3hilg46786l91xxnck8qrd5zk5c39-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/imw2kazzmfl6nlf52psv7h2vlnfpdxn3-system-shutdown.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/y9vs2brijwc8c2b5mh0vxrsz0hh37z6h-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' building '/nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rmxiym60q7p0pgy3rvrqhgl15ngv7yc5-unit-systemd-tmpfiles-resetup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv' building '/nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv' building '/nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv' building '/nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ra9f6mzgpig8bxfp26sd4f4dhdymamc3-unit-firewall.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/bx9ay666mdpxmqa49l3hw83wkl8bjvvs-user-generators.drv' building '/nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/g4lprx9wmm1d2wsmkpxiksv270j1rgi0-X-Restart-Triggers-step-ca.drv' building '/nix/store/5m1cfc1nmb9cbzniv4dpgdv38ivj0qsz-unit-script-nginx-pre-start.drv' building '/nix/store/fpz2bqfgazq73k7ga6j1vl77vhp3vjzs-unit-step-ca.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/8v8nx7xkgmlz39rnf6l90mdmzhz8c9yx-unit-script-nginx-pre-start.drv' building '/nix/store/j2jdcyp4233cn5lky6zlsk016msb24sr-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/skf8nz991czh5gpm41hbaqakj5f7hf0c-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/k5phpbqvva59rzp4cx71phpv7ckmrncv-nss-cacert-3.126.drv' nss-cacert-3.126> Running phase: unpackPhase nss-cacert-3.126> Running phase: patchPhase nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase building '/nix/store/53gz0xpb6hi1n7f8k9iaf0j65rb177yi-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' nss-cacert-3.126> Running phase: installPhase nss-cacert-3.126> Running phase: fixupPhase nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/0xkhp1jyiww6v4dp6inpsvhj8ms1wmi6-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/0xkhp1jyiww6v4dp6inpsvhj8ms1wmi6-nss-cacert-3.126... nss-cacert-3.126> patching script interpreter paths in /nix/store/0xkhp1jyiww6v4dp6inpsvhj8ms1wmi6-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/1fr2a3iklngc5j6bsfymlk844vkxgahb-nss-cacert-3.126-unbundled nss-cacert-3.126> checking for references to /build/ in /nix/store/1fr2a3iklngc5j6bsfymlk844vkxgahb-nss-cacert-3.126-unbundled... building '/nix/store/am9qkfk9c09a47pkjf3vp7w6d4pqkk2b-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' nss-cacert-3.126> patching script interpreter paths in /nix/store/1fr2a3iklngc5j6bsfymlk844vkxgahb-nss-cacert-3.126-unbundled nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/b2f8gd0bxmgn7746nk6g2bxg8b73shsh-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/b2f8gd0bxmgn7746nk6g2bxg8b73shsh-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/b2f8gd0bxmgn7746nk6g2bxg8b73shsh-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/5iyqm7jlnc3pa4rc1ajgcjfpi8wxmif3-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/5iyqm7jlnc3pa4rc1ajgcjfpi8wxmif3-nss-cacert-3.126-hashed... nss-cacert-3.126> patching script interpreter paths in /nix/store/5iyqm7jlnc3pa4rc1ajgcjfpi8wxmif3-nss-cacert-3.126-hashed building '/nix/store/hfdp8pwsxxzhasg8ndcg2w197prj0nxb-dbus-1.drv' building '/nix/store/pkyvq9bzv5p1p73rgk7y09vkimippi4r-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv' unit-acme-order-renew-test.foo.service> structuredAttrs is enabled building '/nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv' building '/nix/store/i1h54lwmdgn5pwg52jwhmfs61pny4iw3-unit-nix-daemon.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv' unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled building '/nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv' unit-acme-ca.foo.service> structuredAttrs is enabled building '/nix/store/j2jdcyp4233cn5lky6zlsk016msb24sr-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/ra9f6mzgpig8bxfp26sd4f4dhdymamc3-unit-firewall.service.drv' unit-firewall.service> structuredAttrs is enabled building '/nix/store/skf8nz991czh5gpm41hbaqakj5f7hf0c-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/am9qkfk9c09a47pkjf3vp7w6d4pqkk2b-dbus-1.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/fpz2bqfgazq73k7ga6j1vl77vhp3vjzs-unit-step-ca.service.drv' unit-step-ca.service> structuredAttrs is enabled building '/nix/store/pkyvq9bzv5p1p73rgk7y09vkimippi4r-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/gibl8vf5nh7rz7km47zqnhslnk5xdf1d-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/hylqa47xmlzklb4mr8hi3kb4bvj1bb5f-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/rmxiym60q7p0pgy3rvrqhgl15ngv7yc5-unit-systemd-tmpfiles-resetup.service.drv' unit-systemd-tmpfiles-resetup.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv' building '/nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv' building '/nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv' unit-acme-test.foo.service> structuredAttrs is enabled unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/qrrxsdc2h8nzpxn9dc9msx5xy2588qwx-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/53gz0xpb6hi1n7f8k9iaf0j65rb177yi-dbus-1.drv' building '/nix/store/3yyv0623ddraws79zmjfk1qcwpy46j4w-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/i1h54lwmdgn5pwg52jwhmfs61pny4iw3-unit-nix-daemon.service.drv' unit-nix-daemon.service> structuredAttrs is enabled building '/nix/store/hylqa47xmlzklb4mr8hi3kb4bvj1bb5f-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/gibl8vf5nh7rz7km47zqnhslnk5xdf1d-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/36cy4w2pi2w6k7jg152rzzpm1plchm8z-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/65zpxz0y484lp2m2g1xy4gn27l9zgm3w-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qrrxsdc2h8nzpxn9dc9msx5xy2588qwx-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/4b2qclyk27xay6ar619c5acmkskacj4y-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wwlslfgw81qzfz9qlyr94hwf26df1iah-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3yyv0623ddraws79zmjfk1qcwpy46j4w-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/3f4j3in4icr0w7mmf5azp7wrbb87lvrd-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kx6mamh3kwimxnppg229zxy58cb8bgpr-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/36cy4w2pi2w6k7jg152rzzpm1plchm8z-user-units.drv' building '/nix/store/65zpxz0y484lp2m2g1xy4gn27l9zgm3w-system-units.drv' building '/nix/store/wwlslfgw81qzfz9qlyr94hwf26df1iah-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/d7kgyvbw6k4b3qpsbhrgp60hg0dd7df9-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3f4j3in4icr0w7mmf5azp7wrbb87lvrd-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/vg0gc9drwn9mwr5wwfr1bc6zxjb90g44-etc.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/2afbh3vl9b4wqmi7rhmal5s3lqq5d2di-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/4b2qclyk27xay6ar619c5acmkskacj4y-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/2afbh3vl9b4wqmi7rhmal5s3lqq5d2di-user-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/47h254qhqagyk25s8z4js2c2kga9xsd6-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kx6mamh3kwimxnppg229zxy58cb8bgpr-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/d7kgyvbw6k4b3qpsbhrgp60hg0dd7df9-user-units.drv' building '/nix/store/47h254qhqagyk25s8z4js2c2kga9xsd6-system-units.drv' building '/nix/store/rldmhkn4fqpwqrzkv2gi3pvijlp4lzhb-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/vg0gc9drwn9mwr5wwfr1bc6zxjb90g44-etc.drv' building '/nix/store/zavgpaf9h8976wj49m95kjd6gc4psk8b-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/l3m99y9dhv5nzj8gfrb3vv92hmxa2yjf-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rldmhkn4fqpwqrzkv2gi3pvijlp4lzhb-system-units.drv' building '/nix/store/l3m99y9dhv5nzj8gfrb3vv92hmxa2yjf-activate.drv' building '/nix/store/zavgpaf9h8976wj49m95kjd6gc4psk8b-etc.drv' building '/nix/store/ay4c0mq6qaksy643am2xkp47xfr5fg6p-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/y8skg0i6c76girw5sbrnxvks7242d5c2-nixos-system-client-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/f6sz49xdxddn3j4rj98qx3a4xaj1b911-activate.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/ay4c0mq6qaksy643am2xkp47xfr5fg6p-etc.drv' building '/nix/store/y8skg0i6c76girw5sbrnxvks7242d5c2-nixos-system-client-test.drv' nixos-system-client-test> structuredAttrs is enabled building '/nix/store/f6sz49xdxddn3j4rj98qx3a4xaj1b911-activate.drv' building '/nix/store/lmmih59av1bbaxr2yf4qgd0a3idkdcnd-run-client-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/zc4sc0l4a1zlg10hyam6bxymxb6y1kv6-nixos-system-ca-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dhkkxdlbls1rv4qwamqi53wvvb50c0xy-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/lmmih59av1bbaxr2yf4qgd0a3idkdcnd-run-client-nspawn.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/dhkkxdlbls1rv4qwamqi53wvvb50c0xy-activate.drv' building '/nix/store/zc4sc0l4a1zlg10hyam6bxymxb6y1kv6-nixos-system-ca-test.drv' nixos-system-ca-test> structuredAttrs is enabled building '/nix/store/rr4facpzjyyaz9nfhs8mhfs4kycc38km-run-ca-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/rr4facpzjyyaz9nfhs8mhfs4kycc38km-run-ca-nspawn.drv' building '/nix/store/ayr5nmixqh47gmapbxx43n6lq4v9004y-nixos-system-server-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ayr5nmixqh47gmapbxx43n6lq4v9004y-nixos-system-server-test.drv' nixos-system-server-test> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/7dyjmbnhy0753bz08j222y00v2hhnb3i-run-server-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/7dyjmbnhy0753bz08j222y00v2hhnb3i-run-server-nspawn.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/1ig9gn83y2k9r9kmdpk62my8zbsl0vdw-driverConfiguration.json.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/1ig9gn83y2k9r9kmdpk62my8zbsl0vdw-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/1qcl83b9sjj9cp2zx2sq1xf8visciqzq-nixos-test-driver-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/1qcl83b9sjj9cp2zx2sq1xf8visciqzq-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/209v17izv4wi9h2qqny6brs83ba9vibz-container-test-run-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/209v17izv4wi9h2qqny6brs83ba9vibz-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> server: systemd-nspawn running (pid 54) container-test-run-certificates> ca: systemd-nspawn running (pid 53) container-test-run-certificates> client: systemd-nspawn running (pid 55) container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.00 seconds) container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> server # No journal boot entry found for the specified boot (+0). container-test-run-certificates> client # No journal boot entry found for the specified boot (+0). container-test-run-certificates> ca # No journal boot entry found for the specified boot (+0). container-test-run-certificates> server # [6080382.545262] server systemd-journald[69]: Journal started container-test-run-certificates> ca # [6080382.557049] ca systemd-journald[78]: Journal started container-test-run-certificates> server # [6080382.545317] server systemd-journald[69]: Runtime Journal (/run/log/journal/2685418501c84214b452c2968e64de86) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> ca # [6080382.557101] ca systemd-journald[78]: Runtime Journal (/run/log/journal/9633dc39b4bd4992aa24de7183a32b34) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> client # [6080382.552625] client systemd-journald[69]: Journal started container-test-run-certificates> ca # [6080382.573051] ca systemd[1]: Finished Apply Kernel Variables. container-test-run-certificates> client # [6080382.552688] client systemd-journald[69]: Runtime Journal (/run/log/journal/41781df4e9dc4503877605d0254dbb65) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> ca # [6080382.584639] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> client # [6080382.575929] client systemd[1]: Finished Apply Kernel Variables. container-test-run-certificates> ca # [6080382.593379] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [6080382.583740] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> ca # [6080382.594154] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [6080382.592741] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [6080382.594785] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [6080382.593531] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [6080382.602002] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/9633dc39b4bd4992aa24de7183a32b34 is 1.901ms for 7 entries. container-test-run-certificates> client # [6080382.594173] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> server # [6080382.566863] server systemd[1]: Finished Apply Kernel Variables. container-test-run-certificates> ca # [6080382.602002] ca systemd-journald[78]: System Journal (/var/log/journal/9633dc39b4bd4992aa24de7183a32b34) is 8M, max 4G, 3.9G free. container-test-run-certificates> server # [6080382.581331] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> client # [6080382.601557] client systemd-journald[69]: Time spent on flushing to /var/log/journal/41781df4e9dc4503877605d0254dbb65 is 1.720ms for 7 entries. container-test-run-certificates> ca # [6080382.617518] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [6080382.601557] client systemd-journald[69]: System Journal (/var/log/journal/41781df4e9dc4503877605d0254dbb65) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [6080382.618229] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [6080382.617192] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [6080382.618337] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [6080382.617929] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> server # [6080382.590291] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [6080382.618054] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [6080382.619169] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [6080382.618882] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [6080382.619223] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [6080382.618927] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [6080382.620296] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [6080382.591149] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [6080382.620014] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [6080382.591849] server systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [6080382.620056] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [6080382.602121] server systemd-journald[69]: Time spent on flushing to /var/log/journal/2685418501c84214b452c2968e64de86 is 1.702ms for 7 entries. container-test-run-certificates> client # [6080382.661131] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> ca # [6080382.620331] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [6080382.602121] server systemd-journald[69]: System Journal (/var/log/journal/2685418501c84214b452c2968e64de86) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [6080382.663039] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [6080382.662899] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [6080382.664058] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> client # [6080382.677292] client systemd-tmpfiles[162]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [6080382.614030] server systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [6080382.680263] ca systemd-tmpfiles[164]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [6080382.677470] client systemd-tmpfiles[162]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [6080382.614736] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> ca # [6080382.680502] ca systemd-tmpfiles[164]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [6080382.677596] client systemd-tmpfiles[162]: fchmod() of /var/log/journal/41781df4e9dc4503877605d0254dbb65 failed: Operation not permitted container-test-run-certificates> server # [6080382.614859] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [6080382.680639] ca systemd-tmpfiles[164]: fchmod() of /var/log/journal/9633dc39b4bd4992aa24de7183a32b34 failed: Operation not permitted container-test-run-certificates> server # [6080382.615658] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [6080382.680853] ca systemd-tmpfiles[164]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [6080382.677823] client systemd-tmpfiles[162]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [6080382.615702] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [6080382.680784] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [6080382.616600] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [6080382.682634] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [6080382.616632] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [6080382.683720] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [6080382.662618] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> ca # [6080382.684596] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [6080382.663734] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> client # [6080382.681991] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> ca # [6080382.698279] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> client # [6080382.682736] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [6080382.678550] server systemd-tmpfiles[161]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [6080382.682970] client systemd[1]: Finished Firewall. container-test-run-certificates> ca # [6080382.701760] ca systemd[1]: Finished Firewall. container-test-run-certificates> server # [6080382.678737] server systemd-tmpfiles[161]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [6080382.678856] server systemd-tmpfiles[161]: fchmod() of /var/log/journal/2685418501c84214b452c2968e64de86 failed: Operation not permitted container-test-run-certificates> client # [6080382.683489] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [6080382.702237] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> server # [6080382.679040] server systemd-tmpfiles[161]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [6080382.680992] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> ca # [6080382.702524] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [6080382.683804] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [6080382.684841] client systemd[1]: Starting Network Management... container-test-run-certificates> server # [6080382.682831] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> ca # [6080382.703566] ca systemd[1]: Starting Network Management... container-test-run-certificates> ca # [6080382.703796] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> ca # [6080382.705367] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> ca # [6080382.715183] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> ca # [6080382.879041] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> ca # [6080383.552071] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> client # [6080382.694057] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> client # [6080382.702937] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> client # [6080382.704028] client systemd[1]: Starting Update is Completed... container-test-run-certificates> client # [6080382.714120] client systemd[1]: Finished Update is Completed. container-test-run-certificates> client # [6080382.880523] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> client # [6080383.534471] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [6080382.683637] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [6080382.691073] server systemd[1]: Finished Firewall. container-test-run-certificates> server # [6080382.691239] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> server # [6080382.691470] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [6080382.692532] server systemd[1]: Starting Network Management... container-test-run-certificates> server # [6080382.695136] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [6080382.702843] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [6080382.704022] server systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [6080382.714124] server systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [6080382.882913] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [6080383.535290] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [6080383.784478] server systemd-networkd[182]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [6080383.784576] server systemd-networkd[182]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [6080383.824336] server systemd-networkd[182]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [6080383.824502] server systemd-networkd[182]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [6080383.824660] server systemd-networkd[182]: lo: Link UP container-test-run-certificates> server # [6080383.824667] server systemd-networkd[182]: lo: Gained carrier container-test-run-certificates> server # [6080383.824868] server systemd-networkd[182]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [6080383.825281] server systemd[1]: Started Network Management. container-test-run-certificates> server # [6080383.840423] server systemd-networkd[182]: eth1: Link UP container-test-run-certificates> server # [6080383.840765] server systemd-networkd[182]: eth1: Gained carrier container-test-run-certificates> server # [6080383.841245] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> server # [6080383.858989] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> client # [6080383.803797] client systemd-networkd[178]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6080383.803893] client systemd-networkd[178]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6080383.827571] client systemd-networkd[178]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [6080383.827741] client systemd-networkd[178]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [6080383.827914] client systemd-networkd[178]: lo: Link UP container-test-run-certificates> client # [6080383.827918] client systemd-networkd[178]: lo: Gained carrier container-test-run-certificates> client # [6080383.828138] client systemd-networkd[178]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [6080383.828485] client systemd[1]: Started Network Management. container-test-run-certificates> client # [6080383.840731] client systemd-networkd[178]: eth1: Link UP container-test-run-certificates> client # [6080383.841065] client systemd-networkd[178]: eth1: Gained carrier container-test-run-certificates> client # [6080383.841836] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> client # [6080383.902008] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> ca # [6080383.811594] ca systemd-networkd[192]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [6080383.811687] ca systemd-networkd[192]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [6080383.827589] ca systemd-networkd[192]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [6080383.827760] ca systemd-networkd[192]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [6080383.827958] ca systemd-networkd[192]: lo: Link UP container-test-run-certificates> ca # [6080383.827962] ca systemd-networkd[192]: lo: Gained carrier container-test-run-certificates> ca # [6080383.828168] ca systemd-networkd[192]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> ca # [6080383.828533] ca systemd[1]: Started Network Management. container-test-run-certificates> ca # [6080383.840850] ca systemd-networkd[192]: eth1: Link UP container-test-run-certificates> ca # [6080383.841167] ca systemd-networkd[192]: eth1: Gained carrier container-test-run-certificates> ca # [6080383.841958] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [6080383.902199] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [6080384.250208] server systemd-resolved[114]: Positive Trust Anchors: container-test-run-certificates> server # [6080384.250219] server systemd-resolved[114]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [6080384.250222] server systemd-resolved[114]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [6080384.250258] server systemd-resolved[114]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [6080384.272746] server systemd-resolved[114]: Using system hostname 'server'. container-test-run-certificates> server # [6080384.274137] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [6080384.274223] server systemd[1]: Reached target Network. container-test-run-certificates> server # [6080384.274281] server systemd[1]: Reached target Network is Online. container-test-run-certificates> server # [6080384.274326] server systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [6080384.274776] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> server # [6080384.274812] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6080384.274836] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> client # [6080384.257654] client systemd-resolved[117]: Positive Trust Anchors: container-test-run-certificates> server # [6080384.274855] server systemd[1]: Reached target Timer Units. container-test-run-certificates> client # [6080384.257666] client systemd-resolved[117]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [6080384.275192] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [6080384.257670] client systemd-resolved[117]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [6080384.275295] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> client # [6080384.257706] client systemd-resolved[117]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [6080384.280014] client systemd-resolved[117]: Using system hostname 'client'. container-test-run-certificates> server # [6080384.275506] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> client # [6080384.281360] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [6080384.275531] server systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [6080384.275579] server systemd[1]: Reached target Basic System. container-test-run-certificates> client # [6080384.281459] client systemd[1]: Reached target Network. container-test-run-certificates> server # [6080384.277052] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> client # [6080384.281535] client systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [6080384.277795] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> client # [6080384.281603] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6080384.277832] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> client # [6080384.281637] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [6080384.278772] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> client # [6080384.281658] client systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [6080384.280072] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> client # [6080384.281812] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [6080384.343312] server systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> client # [6080384.281963] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [6080384.420755] server acme-setup-privileged[192]: + set -euo pipefail container-test-run-certificates> client # [6080384.282096] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [6080384.420755] server acme-setup-privileged[192]: + cd /var/lib/acme container-test-run-certificates> server # [6080384.421158] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> client # [6080384.282123] client systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [6080384.422257] server acme-setup-privileged[192]: + chown -R acme .lego/accounts container-test-run-certificates> client # [6080384.282169] client systemd[1]: Reached target Basic System. container-test-run-certificates> server # [6080384.423831] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> client # [6080384.328493] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [6080384.423858] server acme-setup-privileged[192]: + '[' -d test.foo ']' container-test-run-certificates> client # [6080384.329618] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [6080384.423858] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [6080384.423900] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']' container-test-run-certificates> client # [6080384.331152] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [6080384.459273] server nsncd[194]: Aug 18 08:23:30.512 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [6080384.346119] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [6080384.459337] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [6080384.446520] client nsncd[189]: Aug 18 08:23:30.499 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> server # [6080384.459405] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [6080384.446717] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> server # [6080384.459469] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> client # [6080384.446784] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> server # [6080384.477022] server systemd[1]: Starting User Login Management... container-test-run-certificates> client # [6080384.446833] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [6080384.478013] server systemd[1]: Starting Permit User Sessions... container-test-run-certificates> client # [6080384.477048] client systemd[1]: Starting User Login Management... container-test-run-certificates> server # [6080384.487429] server systemd[1]: Finished Permit User Sessions. container-test-run-certificates> client # [6080384.478055] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [6080384.488522] server systemd[1]: Started Console Getty. container-test-run-certificates> client # [6080384.487408] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [6080384.488562] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> client # [6080384.488485] client systemd[1]: Started Console Getty. container-test-run-certificates> server # [6080384.488580] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> client # [6080384.488528] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [6080384.555651] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [6080384.556361] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [6080384.488545] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [6080384.556361] server dbus-broker-launch[195]: Invalid user-name in /nix/store/lxnlg1wvz5bx4xfzc75k21l11ngxkyck-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [6080384.555980] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [6080384.264934] ca systemd-resolved[119]: Positive Trust Anchors: container-test-run-certificates> ca # [6080384.264946] ca systemd-resolved[119]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [6080384.264950] ca systemd-resolved[119]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [6080384.264986] ca systemd-resolved[119]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [6080384.287349] ca systemd-resolved[119]: Using system hostname 'ca'. container-test-run-certificates> ca # [6080384.288751] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [6080384.288838] ca systemd[1]: Reached target Network. container-test-run-certificates> ca # [6080384.288898] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [6080384.288941] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [6080384.289141] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> ca # [6080384.289171] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [6080384.289194] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [6080384.289209] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> ca # [6080384.289335] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> ca # [6080384.289431] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [6080384.289529] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [6080384.289547] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [6080384.289582] ca systemd[1]: Reached target Basic System. container-test-run-certificates> ca # [6080384.328607] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> ca # [6080384.329480] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [6080384.329522] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> ca # [6080384.330479] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [6080384.331606] ca systemd[1]: Starting step-ca service... container-test-run-certificates> ca # [6080384.333028] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> ca # [6080384.346138] ca systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> ca # [6080384.434785] ca acme-setup-privileged[201]: + set -euo pipefail container-test-run-certificates> ca # [6080384.434785] ca acme-setup-privileged[201]: + cd /var/lib/acme container-test-run-certificates> ca # [6080384.434785] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> ca # [6080384.436263] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts container-test-run-certificates> ca # [6080384.437714] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [6080384.437746] ca acme-setup-privileged[201]: + '[' -d ca.foo ']' container-test-run-certificates> ca # [6080384.437746] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [6080384.437746] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> ca # [6080384.456515] ca nsncd[203]: Aug 18 08:23:30.509 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [6080384.476548] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [6080384.476694] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [6080384.476817] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [6080384.477963] ca systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [6080384.478886] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [6080384.487387] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [6080384.489157] ca systemd[1]: Started Console Getty. container-test-run-certificates> ca # [6080384.489194] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> ca # [6080384.489212] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> client # [6080384.556638] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [6080384.556638] client dbus-broker-launch[190]: Invalid user-name in /nix/store/s0a40wv0lnwiz13r43fk318ri3wv536k-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [6080384.557069] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> client # [6080384.564248] client dbus-broker-launch[190]: Ready container-test-run-certificates> ca # [6080384.567997] ca dbus-broker-launch[205]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [6080384.556780] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [6080384.568526] ca dbus-broker-launch[205]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [6080384.564181] server dbus-broker-launch[195]: Ready container-test-run-certificates> ca # [6080384.568526] ca dbus-broker-launch[205]: Invalid user-name in /nix/store/mfvkn1zwby5692v4kx3ynjdz34b2lkq3-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> ca # [6080384.568895] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [6080384.575777] ca dbus-broker-launch[205]: Ready container-test-run-certificates> server # [6080384.964118] server systemd-networkd[182]: eth1: Gained IPv6LL container-test-run-certificates> server # [6080385.034239] server systemd-logind[220]: New seat seat0. container-test-run-certificates> server # [6080385.034503] server systemd[1]: Started User Login Management. container-test-run-certificates> server # [6080385.035844] server systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [6080385.091358] server acme-setup-start[208]: + set -euo pipefail container-test-run-certificates> server # [6080385.091358] server acme-setup-start[208]: + test -e ca/key.pem container-test-run-certificates> server # [6080385.091635] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> server # [6080385.100388] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> server # [6080385.100548] server systemd[1]: Finished linger-users.service. container-test-run-certificates> server # [6080385.108469] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> server # [6080385.109940] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> ca # [6080385.042943] ca systemd-logind[230]: New seat seat0. container-test-run-certificates> ca # [6080385.043131] ca systemd[1]: Started User Login Management. container-test-run-certificates> client # [6080385.024168] client systemd-networkd[178]: eth1: Gained IPv6LL container-test-run-certificates> ca # [6080385.093167] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [6080385.034238] client systemd-logind[205]: New seat seat0. container-test-run-certificates> ca # [6080385.105188] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> client # [6080385.034483] client systemd[1]: Started User Login Management. container-test-run-certificates> ca # [6080385.105258] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [6080385.035897] client systemd[1]: Starting linger-users.service... container-test-run-certificates> ca # [6080385.105415] ca acme-setup-start[219]: + set -euo pipefail container-test-run-certificates> client # [6080385.100414] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [6080385.105415] ca acme-setup-start[219]: + test -e ca/key.pem container-test-run-certificates> client # [6080385.100568] client systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [6080385.105415] ca acme-setup-start[219]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [6080385.121812] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [6080385.123276] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> ca # [6080385.268879] ca step-ca[204]: badger 2026/08/18 08:23:31 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [6080385.272774] ca step-ca[204]: 2026/08/18 08:23:31 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> ca # [6080385.278790] ca step-ca[204]: 2026/08/18 08:23:31 Starting Smallstep CA/0.30.2 (linux/arm64) container-test-run-certificates> ca # [6080385.278790] ca step-ca[204]: 2026/08/18 08:23:31 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> client # [6080385.101063] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [6080385.278790] ca step-ca[204]: 2026/08/18 08:23:31 Community Discord: https://u.step.sm/discord container-test-run-certificates> ca # [6080385.278790] ca step-ca[204]: 2026/08/18 08:23:31 Config file: /etc/smallstep/ca.json container-test-run-certificates> client # [6080385.101319] client systemd[1]: Startup finished in 3.014s. container-test-run-certificates> ca # [6080385.278790] ca step-ca[204]: 2026/08/18 08:23:31 The primary server URL is https://ca.foo:1443 container-test-run-certificates> ca # [6080385.278790] ca step-ca[204]: 2026/08/18 08:23:31 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [6080385.278922] ca step-ca[204]: 2026/08/18 08:23:31 X.509 Root Fingerprint: e826ba1017ed9c6d1e80bbc83d56e54b4763fd0cf6f59c398a4f0b383416ea71 container-test-run-certificates> ca # [6080385.279358] ca systemd[1]: Started step-ca service. container-test-run-certificates> ca # [6080385.279651] ca step-ca[204]: 2026/08/18 08:23:31 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> ca # [6080385.572179] ca systemd-networkd[192]: eth1: Gained IPv6LL container-test-run-certificates> ca # [6080385.725412] ca acme-ca.foo-start[256]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6080385.727911] ca acme-ca.foo-start[256]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [6080385.728034] ca acme-ca.foo-start[256]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> ca # [6080385.743226] ca acme-ca.foo-start[294]: + cd ca.foo container-test-run-certificates> ca # [6080385.743778] ca acme-ca.foo-start[294]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> ca # [6080385.744910] ca acme-ca.foo-start[295]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [6080385.745135] ca acme-ca.foo-start[294]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> ca # [6080385.746600] ca acme-ca.foo-start[294]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [6080385.746812] ca acme-ca.foo-start[256]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [6080385.748684] ca acme-ca.foo-start[256]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [6080385.750432] ca acme-ca.foo-start[256]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [6080385.751941] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [6080385.751973] ca acme-ca.foo-start[256]: + '[' -d out ']' container-test-run-certificates> ca # [6080385.751973] ca acme-ca.foo-start[256]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6080385.753601] ca acme-ca.foo-start[256]: + chown -R acme:nginx out container-test-run-certificates> ca # [6080385.756142] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [6080385.756142] ca acme-ca.foo-start[256]: + '[' -d certificates ']' container-test-run-certificates> ca # [6080385.780404] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> ca # [6080385.782967] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> server # [6080385.700040] server acme-test.foo-start[245]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6080385.703028] server acme-test.foo-start[245]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [6080385.703111] server acme-test.foo-start[245]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [6080385.718910] server acme-test.foo-start[255]: + cd test.foo container-test-run-certificates> server # [6080385.719483] server acme-test.foo-start[255]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [6080385.720395] server acme-test.foo-start[256]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [6080385.720724] server acme-test.foo-start[255]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [6080385.721749] server acme-test.foo-start[255]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [6080385.721983] server acme-test.foo-start[245]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [6080385.723623] server acme-test.foo-start[245]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [6080385.725390] server acme-test.foo-start[245]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6080385.727223] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [6080385.727223] server acme-test.foo-start[245]: + '[' -d out ']' container-test-run-certificates> server # [6080385.727335] server acme-test.foo-start[245]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6080385.729330] server acme-test.foo-start[245]: + chown -R acme:nginx out container-test-run-certificates> server # [6080385.732138] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [6080385.732138] server acme-test.foo-start[245]: + '[' -d certificates ']' container-test-run-certificates> server # [6080385.736469] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [6080385.738993] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> server # [6080386.421306] server nginx-pre-start[267]: nginx: the configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf syntax is ok container-test-run-certificates> server # [6080386.421653] server nginx-pre-start[267]: nginx: configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf test is successful container-test-run-certificates> server # [6080386.425870] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [6080386.426268] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [6080386.427493] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> ca # [6080386.431297] ca nginx-pre-start[306]: nginx: the configuration file /nix/store/kijspw8hclw37aj8kl8y20jfn91c8ssx-nginx.conf syntax is ok container-test-run-certificates> ca # [6080386.431617] ca nginx-pre-start[306]: nginx: configuration file /nix/store/kijspw8hclw37aj8kl8y20jfn91c8ssx-nginx.conf test is successful container-test-run-certificates> ca # [6080386.476412] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [6080386.476939] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [6080386.478575] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca # [6080387.029530] ca acme-order-renew-ca.foo-start[309]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6080387.032817] ca acme-order-renew-ca.foo-start[309]: + set -euo pipefail container-test-run-certificates> ca # [6080387.032918] ca acme-order-renew-ca.foo-start[309]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [6080387.033004] ca acme-order-renew-ca.foo-start[309]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [6080387.034029] ca acme-order-renew-ca.foo-start[309]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> ca # [6080387.053357] ca acme-order-renew-ca.foo-start[320]: 2026/08/18 08:23:33 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [6080387.053854] ca acme-order-renew-ca.foo-start[320]: 2026/08/18 08:23:33 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [6080387.084837] ca step-ca[204]: time="2026-08-18T08:23:33Z" level=info duration="92.761µs" duration-ns=92761 fields.time="2026-08-18T08:23:33Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=48483142-bff9-430b-9bbf-de004b80a8eb response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6080387.085573] ca acme-order-renew-ca.foo-start[320]: 2026/08/18 08:23:33 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> ca # [6080387.096453] ca step-ca[204]: time="2026-08-18T08:23:33Z" level=info duration=11.015994ms duration-ns=11015994 fields.time="2026-08-18T08:23:33Z" method=HEAD name=ca nonce=Uk5xNUtGZFA5WGZGd2N1c3pDTDRSeFpOYXhuYm92SlM path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=f758de90-921a-4a3c-9529-a7d5211f4292 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6080387.098815] ca step-ca[204]: time="2026-08-18T08:23:33Z" level=info duration=1.521421ms duration-ns=1521421 fields.time="2026-08-18T08:23:33Z" method=POST name=ca nonce=dUFxdXg4M21FTGhsUURjeG1sNFk1bzVUZ0R3SkhvNlM path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=0902ccae-a9bc-43fb-b87f-5000bc9ddae7 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/2rlPKAFiug3veow0TIy9Lb8pEFsSpoNq/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6080387.099261] ca acme-order-renew-ca.foo-start[320]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [6080387.099261] ca acme-order-renew-ca.foo-start[320]: Your account credentials have been saved in your container-test-run-certificates> ca # [6080387.099261] ca acme-order-renew-ca.foo-start[320]: configuration directory at "accounts". container-test-run-certificates> ca # [6080387.099261] ca acme-order-renew-ca.foo-start[320]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [6080387.099261] ca acme-order-renew-ca.foo-start[320]: configuration directory will also contain private keys container-test-run-certificates> ca # [6080387.099261] ca acme-order-renew-ca.foo-start[320]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [6080387.099261] ca acme-order-renew-ca.foo-start[320]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [6080387.099552] ca acme-order-renew-ca.foo-start[320]: 2026/08/18 08:23:33 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [6080387.103890] ca step-ca[204]: time="2026-08-18T08:23:33Z" level=info duration=3.945775ms duration-ns=3945775 fields.time="2026-08-18T08:23:33Z" method=POST name=ca nonce=SE4zT2o3MjFWbEtkb3pxTE5ENjRHY3RYNmlBVks0RmI path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=85169033-97e9-4581-b427-b0fe61b9db54 response="{\"id\":\"Zi91IZGSMdZlw8fuJfzzJEIs1uyBd6Cq\",\"status\":\"pending\",\"expires\":\"2026-08-19T08:23:33Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-18T08:22:33Z\",\"notAfter\":\"2026-11-16T08:23:33Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/ULRiTyRQWJLcNhn3ZV3i19ZE6KAKuvkt\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/Zi91IZGSMdZlw8fuJfzzJEIs1uyBd6Cq/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6080387.163291] ca step-ca[204]: time="2026-08-18T08:23:33Z" level=info duration=2.108949ms duration-ns=2108949 fields.time="2026-08-18T08:23:33Z" method=POST name=ca nonce=NXNRYWFGY0VPN2ZMUXliSGRRNHdFUm5wSVdqeWpOUVY path=/acme/acme/authz/ULRiTyRQWJLcNhn3ZV3i19ZE6KAKuvkt protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=db48806f-3547-4271-864a-50b937310221 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"Eallh6OoABzJbv6DHpSjVc7l7ZxEYhbj\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/ULRiTyRQWJLcNhn3ZV3i19ZE6KAKuvkt/nyPcE2BF77Mn9OEcy6ecTVlilLo6gtAn\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"Eallh6OoABzJbv6DHpSjVc7l7ZxEYhbj\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/ULRiTyRQWJLcNhn3ZV3i19ZE6KAKuvkt/atALGN2XIUy2mMqvaiO932oWpC9TcH1O\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"Eallh6OoABzJbv6DHpSjVc7l7ZxEYhbj\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/ULRiTyRQWJLcNhn3ZV3i19ZE6KAKuvkt/LDzxzTO3LcPH4pjq8dt3uiLQA4d5FihJ\"}],\"wildcard\":false,\"expires\":\"2026-08-19T08:23:33Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6080387.163728] ca acme-order-renew-ca.foo-start[320]: 2026/08/18 08:23:33 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/ULRiTyRQWJLcNhn3ZV3i19ZE6KAKuvkt container-test-run-certificates> ca # [6080387.163728] ca acme-order-renew-ca.foo-start[320]: 2026/08/18 08:23:33 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [6080387.163728] ca acme-order-renew-ca.foo-start[320]: 2026/08/18 08:23:33 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [6080387.163728] ca acme-order-renew-ca.foo-start[320]: 2026/08/18 08:23:33 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> ca # [6080387.169401] ca step-ca[204]: time="2026-08-18T08:23:33Z" level=info duration=4.838307ms duration-ns=4838307 fields.time="2026-08-18T08:23:33Z" method=POST name=ca nonce=MVNqV1p4ZVAwcEx0SXZuWjhrUGdWSHJrYnNDb1BxVEg path=/acme/acme/challenge/ULRiTyRQWJLcNhn3ZV3i19ZE6KAKuvkt/atALGN2XIUy2mMqvaiO932oWpC9TcH1O protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=02695b36-2a2f-404e-93b8-bf5d25cca107 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"Eallh6OoABzJbv6DHpSjVc7l7ZxEYhbj\",\"validated\":\"2026-08-18T08:23:33Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/ULRiTyRQWJLcNhn3ZV3i19ZE6KAKuvkt/atALGN2XIUy2mMqvaiO932oWpC9TcH1O\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6080387.169812] ca acme-order-renew-ca.foo-start[320]: 2026/08/18 08:23:33 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [6080387.169910] ca acme-order-renew-ca.foo-start[320]: 2026/08/18 08:23:33 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [6080387.180785] ca step-ca[204]: time="2026-08-18T08:23:33Z" level=info duration=9.160808ms duration-ns=9160808 fields.time="2026-08-18T08:23:33Z" method=POST name=ca nonce=T0t3TnRqbE1Xd2lGckFsRUdVNkdwaFFhQjBFQ0tPWEg path=/acme/acme/order/Zi91IZGSMdZlw8fuJfzzJEIs1uyBd6Cq/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=897941de-5db6-4588-ba05-4bbcae6d89a6 response="{\"id\":\"Zi91IZGSMdZlw8fuJfzzJEIs1uyBd6Cq\",\"status\":\"valid\",\"expires\":\"2026-08-19T08:23:33Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-18T08:22:33Z\",\"notAfter\":\"2026-11-16T08:23:33Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/ULRiTyRQWJLcNhn3ZV3i19ZE6KAKuvkt\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/Zi91IZGSMdZlw8fuJfzzJEIs1uyBd6Cq/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/9xIVIgsCwOWzGxwdO5hFN6lVoIX33ZJE\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6080387.183785] ca step-ca[204]: time="2026-08-18T08:23:33Z" level=info certificate=MIIB0zCCAXmgAwIBAgIQGI7QTRetMf3XzfCKWir2MjAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MTgwODIyMzNaFw0yNjExMTYwODIzMzNaMBExDzANBgNVBAMTBmNhLmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABD8ovfSg33/ACLpiwzbqvslaTZf4UHYXjGkzOIsaBeEqPuulOvnwHYA1CKaS+It114T3gsr/ZHaQCAd3Fr0qJnujgaQwgaEwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQU+CltP37RsQNU+vryyDJ63wIIk4MwHwYDVR0jBBgwFoAUKF8nguOtO9anXpNHCp5FwGZblWwwEQYDVR0RBAowCIIGY2EuZm9vMB0GDCsGAQQBgqRkxihAAQQNMAsCAQYEBGFjbWUEADAKBggqhkjOPQQDAgNIADBFAiBhTKOqSbgtY+g4LMj+3Ye67llcoC/iQyP8YRvPrUHsOQIhAJ3As4Bu12RhcAdo5n0pgePUOT/nF77moge2qt8pu5Wf duration=2.047229ms duration-ns=2047229 fields.time="2026-08-18T08:23:33Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=RWdpQmJRanN2MVhFTkkxUnhwMHB5OFhtSjZxV1pIRnY path=/acme/acme/certificate/9xIVIgsCwOWzGxwdO5hFN6lVoIX33ZJE protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=bf330ce0-0e54-4659-a53f-e15879765945 sans="map[dns:[ca.foo]]" serial=32643002901843535089963403911044462130 size=1340 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-18T08:22:33Z" valid-to="2026-11-16T08:23:33Z" container-test-run-certificates> ca # [6080387.184202] ca acme-order-renew-ca.foo-start[320]: 2026/08/18 08:23:33 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [6080387.191098] ca acme-order-renew-ca.foo-start[309]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [6080387.192850] ca acme-order-renew-ca.foo-start[309]: + touch out/acme-success container-test-run-certificates> ca # [6080387.194673] ca acme-order-renew-ca.foo-start[309]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6080387.196262] ca acme-order-renew-ca.foo-start[309]: + touch out/renewed container-test-run-certificates> ca # [6080387.197853] ca acme-order-renew-ca.foo-start[309]: + echo Installing new certificate container-test-run-certificates> ca # [6080387.197853] ca acme-order-renew-ca.foo-start[309]: Installing new certificate container-test-run-certificates> ca # [6080387.197853] ca acme-order-renew-ca.foo-start[309]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6080387.199673] ca acme-order-renew-ca.foo-start[352]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [6080387.200053] ca acme-order-renew-ca.foo-start[309]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [6080387.201439] ca acme-order-renew-ca.foo-start[353]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [6080387.201754] ca acme-order-renew-ca.foo-start[309]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [6080387.202867] ca acme-order-renew-ca.foo-start[354]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [6080387.203161] ca acme-order-renew-ca.foo-start[309]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [6080387.204880] ca acme-order-renew-ca.foo-start[309]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [6080387.206619] ca acme-order-renew-ca.foo-start[309]: + for fixpath in out certificates container-test-run-certificates> ca # [6080387.206619] ca acme-order-renew-ca.foo-start[309]: + '[' -d out ']' container-test-run-certificates> ca # [6080387.206712] ca acme-order-renew-ca.foo-start[309]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6080387.208586] ca acme-order-renew-ca.foo-start[309]: + chown -R acme:nginx out container-test-run-certificates> ca # [6080387.212260] ca acme-order-renew-ca.foo-start[309]: + for fixpath in out certificates container-test-run-certificates> ca # [6080387.212260] ca acme-order-renew-ca.foo-start[309]: + '[' -d certificates ']' container-test-run-certificates> ca # [6080387.212413] ca acme-order-renew-ca.foo-start[309]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [6080387.214035] ca acme-order-renew-ca.foo-start[309]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [6080387.217822] ca acme-order-renew-ca.foo-start[309]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6080387.372084] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [6080387.022053] server acme-order-renew-test.foo-start[270]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6080387.025695] server acme-order-renew-test.foo-start[270]: + set -euo pipefail container-test-run-certificates> server # [6080387.025796] server acme-order-renew-test.foo-start[270]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [6080387.025883] server acme-order-renew-test.foo-start[270]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [6080387.027002] server acme-order-renew-test.foo-start[270]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [6080387.053345] server acme-order-renew-test.foo-start[281]: 2026/08/18 08:23:33 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [6080387.053667] server acme-order-renew-test.foo-start[281]: 2026/08/18 08:23:33 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> server # [6080387.082298] server acme-order-renew-test.foo-start[281]: 2026/08/18 08:23:33 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority container-test-run-certificates> server # [6080387.082897] server acme-order-renew-test.foo-start[270]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [6080387.082897] server acme-order-renew-test.foo-start[270]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [6080387.082897] server acme-order-renew-test.foo-start[270]: + exit 10 container-test-run-certificates> server # [6080387.085816] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a container-test-run-certificates> server # [6080387.085904] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'. container-test-run-certificates> server # [6080387.086273] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [6080387.086612] server systemd[1]: Startup finished in 4.993s. container-test-run-certificates> ca # [6080387.376412] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [6080387.376598] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> ca # [6080387.964251] ca nginx[370]: nginx: the configuration file /nix/store/kijspw8hclw37aj8kl8y20jfn91c8ssx-nginx.conf syntax is ok container-test-run-certificates> ca # [6080387.964843] ca nginx[370]: nginx: configuration file /nix/store/kijspw8hclw37aj8kl8y20jfn91c8ssx-nginx.conf test is successful container-test-run-certificates> ca # [6080388.485489] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [6080388.486168] ca systemd[1]: Startup finished in 6.375s. container-test-run-certificates> ca # [6080388.777789] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca # [6080389.325094] ca acme-order-renew-ca.foo-start[385]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6080389.328479] ca acme-order-renew-ca.foo-start[385]: + set -euo pipefail container-test-run-certificates> ca # [6080389.328561] ca acme-order-renew-ca.foo-start[385]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [6080389.328666] ca acme-order-renew-ca.foo-start[385]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [6080389.330233] ca acme-order-renew-ca.foo-start[385]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [6080389.330233] ca acme-order-renew-ca.foo-start[385]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [6080389.330751] ca acme-order-renew-ca.foo-start[393]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [6080389.333978] ca acme-order-renew-ca.foo-start[385]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [6080389.334055] ca acme-order-renew-ca.foo-start[385]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [6080389.380142] ca step-ca[204]: time="2026-08-18T08:23:35Z" level=info duration="51.6µs" duration-ns=51600 fields.time="2026-08-18T08:23:35Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=7d8e85cf-ce2b-4a97-8d85-e123d6c96a12 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6080389.380636] ca acme-order-renew-ca.foo-start[394]: 2026/08/18 08:23:35 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [6080389.380636] ca acme-order-renew-ca.foo-start[394]: 2026/08/18 08:23:35 [INFO] [ca.foo] The certificate expires at 2026-11-16T08:23:33Z, the renewal can be performed in 1439h59m37.566326267s: no renewal. container-test-run-certificates> ca # [6080389.380949] ca acme-order-renew-ca.foo-start[385]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [6080389.383280] ca acme-order-renew-ca.foo-start[385]: + touch out/acme-success container-test-run-certificates> ca # [6080389.385082] ca acme-order-renew-ca.foo-start[385]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6080389.387790] ca acme-order-renew-ca.foo-start[385]: + for fixpath in out certificates container-test-run-certificates> ca # [6080389.387790] ca acme-order-renew-ca.foo-start[385]: + '[' -d out ']' container-test-run-certificates> ca # [6080389.387790] ca acme-order-renew-ca.foo-start[385]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6080389.387941] ca acme-order-renew-ca.foo-start[385]: + chown -R acme:nginx out container-test-run-certificates> ca # [6080389.390777] ca acme-order-renew-ca.foo-start[385]: + for fixpath in out certificates container-test-run-certificates> ca # [6080389.390816] ca acme-order-renew-ca.foo-start[385]: + '[' -d certificates ']' container-test-run-certificates> ca # [6080389.390816] ca acme-order-renew-ca.foo-start[385]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [6080389.392267] ca acme-order-renew-ca.foo-start[385]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [6080389.394795] ca acme-order-renew-ca.foo-start[385]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 5.00 seconds) container-test-run-certificates> ca # [6080389.617722] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [6080389.617912] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server # [6080392.639770] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [6080392.639932] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [6080392.640773] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [6080392.682722] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.79 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1010 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 18 08:23:31 2026 GMT container-test-run-certificates> * expire date: Sep 17 08:23:31 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 142cc5 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6080393.384775] server acme-test.foo-start[314]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6080393.387182] server acme-test.foo-start[314]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [6080393.387182] server acme-test.foo-start[314]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [6080393.402418] server acme-test.foo-start[324]: + cd test.foo container-test-run-certificates> server # [6080393.403034] server acme-test.foo-start[324]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [6080393.403965] server acme-test.foo-start[325]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [6080393.404327] server acme-test.foo-start[324]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [6080393.405669] server acme-test.foo-start[324]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [6080393.405928] server acme-test.foo-start[314]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [6080393.408306] server acme-test.foo-start[314]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [6080393.411369] server acme-test.foo-start[314]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6080393.413497] server acme-test.foo-start[314]: + for fixpath in out certificates container-test-run-certificates> server # [6080393.413497] server acme-test.foo-start[314]: + '[' -d out ']' container-test-run-certificates> server # [6080393.413595] server acme-test.foo-start[314]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6080393.415501] server acme-test.foo-start[314]: + chown -R acme:nginx out container-test-run-certificates> server # [6080393.418636] server acme-test.foo-start[314]: + for fixpath in out certificates container-test-run-certificates> server # [6080393.418636] server acme-test.foo-start[314]: + '[' -d certificates ']' container-test-run-certificates> server # [6080393.422526] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [6080393.425563] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> server # [6080394.078800] server acme-order-renew-test.foo-start[332]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6080394.081636] server acme-order-renew-test.foo-start[332]: + set -euo pipefail container-test-run-certificates> server # [6080394.081716] server acme-order-renew-test.foo-start[332]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [6080394.081827] server acme-order-renew-test.foo-start[332]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [6080394.083057] server acme-order-renew-test.foo-start[332]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [6080394.125639] server acme-order-renew-test.foo-start[340]: 2026/08/18 08:23:40 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [6080394.143375] server acme-order-renew-test.foo-start[340]: !!!! HEADS UP !!!! container-test-run-certificates> server # [6080394.143375] server acme-order-renew-test.foo-start[340]: Your account credentials have been saved in your container-test-run-certificates> server # [6080394.143375] server acme-order-renew-test.foo-start[340]: configuration directory at "accounts". container-test-run-certificates> server # [6080394.143375] server acme-order-renew-test.foo-start[340]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [6080394.143375] server acme-order-renew-test.foo-start[340]: configuration directory will also contain private keys container-test-run-certificates> server # [6080394.143375] server acme-order-renew-test.foo-start[340]: generated by lego and certificates obtained from the ACME container-test-run-certificates> server # [6080394.143375] server acme-order-renew-test.foo-start[340]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [6080394.143720] server acme-order-renew-test.foo-start[340]: 2026/08/18 08:23:40 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> server # [6080394.215961] server acme-order-renew-test.foo-start[340]: 2026/08/18 08:23:40 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/3VUTu6QJ9CgLlHXWW97xVjADwqbLNvVo container-test-run-certificates> server # [6080394.215961] server acme-order-renew-test.foo-start[340]: 2026/08/18 08:23:40 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [6080394.215961] server acme-order-renew-test.foo-start[340]: 2026/08/18 08:23:40 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [6080394.215961] server acme-order-renew-test.foo-start[340]: 2026/08/18 08:23:40 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [6080394.224485] server acme-order-renew-test.foo-start[340]: 2026/08/18 08:23:40 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [6080394.224597] server acme-order-renew-test.foo-start[340]: 2026/08/18 08:23:40 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [6080394.245271] server acme-order-renew-test.foo-start[340]: 2026/08/18 08:23:40 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [6080394.249778] server acme-order-renew-test.foo-start[332]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [6080394.251933] server acme-order-renew-test.foo-start[332]: + touch out/acme-success container-test-run-certificates> server # [6080394.253508] server acme-order-renew-test.foo-start[332]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [6080394.254823] server acme-order-renew-test.foo-start[332]: + touch out/renewed container-test-run-certificates> server # [6080394.257215] server acme-order-renew-test.foo-start[332]: + echo Installing new certificate container-test-run-certificates> server # [6080394.257215] server acme-order-renew-test.foo-start[332]: Installing new certificate container-test-run-certificates> server # [6080394.257215] server acme-order-renew-test.foo-start[332]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [6080394.259066] server acme-order-renew-test.foo-start[371]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [6080394.259449] server acme-order-renew-test.foo-start[332]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [6080394.261155] server acme-order-renew-test.foo-start[372]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [6080394.261467] server acme-order-renew-test.foo-start[332]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [6080394.262893] server acme-order-renew-test.foo-start[373]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [6080394.263191] server acme-order-renew-test.foo-start[332]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [6080394.264720] server acme-order-renew-test.foo-start[332]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6080394.266532] server acme-order-renew-test.foo-start[332]: + for fixpath in out certificates container-test-run-certificates> server # [6080394.266532] server acme-order-renew-test.foo-start[332]: + '[' -d out ']' container-test-run-certificates> server # [6080394.266628] server acme-order-renew-test.foo-start[332]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6080394.268142] server acme-order-renew-test.foo-start[332]: + chown -R acme:nginx out container-test-run-certificates> server # [6080394.273766] server acme-order-renew-test.foo-start[332]: + for fixpath in out certificates container-test-run-certificates> server # [6080394.273766] server acme-order-renew-test.foo-start[332]: + '[' -d certificates ']' container-test-run-certificates> server # [6080394.273867] server acme-order-renew-test.foo-start[332]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [6080394.275406] server acme-order-renew-test.foo-start[332]: + chown -R acme:nginx certificates container-test-run-certificates> server # [6080394.278319] server acme-order-renew-test.foo-start[332]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6080394.124916] ca step-ca[204]: time="2026-08-18T08:23:40Z" level=info duration="48.12µs" duration-ns=48120 fields.time="2026-08-18T08:23:40Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=a91c75bf-becc-482e-8123-35d4d9c72daa response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6080394.136108] ca step-ca[204]: time="2026-08-18T08:23:40Z" level=info duration=6.374008ms duration-ns=6374008 fields.time="2026-08-18T08:23:40Z" method=HEAD name=ca nonce=Y3cwUXhVZ1NzZUhaMDVMbEd2ek5EOGs1c3F2RGduM2Q path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=14ca3766-c618-4085-803d-cffad28bca6b size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6080394.142775] ca step-ca[204]: time="2026-08-18T08:23:40Z" level=info duration=3.062202ms duration-ns=3062202 fields.time="2026-08-18T08:23:40Z" method=POST name=ca nonce=TjN0RDlDWERCYXVtQkZKVzJ1OWpDMGdBOEFFZ0JmcUI path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=f95c570f-6482-4249-baee-5a3f4b82f4e7 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/z6NKd0yPbYjmhUm7fcFpk7Z8ik82UbI0/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6080394.153254] ca step-ca[204]: time="2026-08-18T08:23:40Z" level=info duration=5.618438ms duration-ns=5618438 fields.time="2026-08-18T08:23:40Z" method=POST name=ca nonce=UnczcndiMW00d0RxNHh5UFhNZUZta3ZUaGx5dFpyVUU path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=8021078b-7f7a-4fd0-9b07-d6c21f57425f response="{\"id\":\"4Wtr7wHvgwcbG71IR1mJEvm8U8klc6Ob\",\"status\":\"pending\",\"expires\":\"2026-08-19T08:23:40Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-18T08:22:40Z\",\"notAfter\":\"2026-11-16T08:23:40Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/3VUTu6QJ9CgLlHXWW97xVjADwqbLNvVo\"],\"finalize\":\"https://ca.foo/acme/acme/order/4Wtr7wHvgwcbG71IR1mJEvm8U8klc6Ob/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6080394.215323] ca step-ca[204]: time="2026-08-18T08:23:40Z" level=info duration=2.067109ms duration-ns=2067109 fields.time="2026-08-18T08:23:40Z" method=POST name=ca nonce=NTVYWE9ORXBqWGozZ1J3MjA4SGtEdTNRbkpFZExqQXQ path=/acme/acme/authz/3VUTu6QJ9CgLlHXWW97xVjADwqbLNvVo protocol=HTTP/1.1 referer= remote-address="::1" request-id=5b37a29e-d9ea-44e7-8ac4-16b3124900ce response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"Wty9twzwg3J2wLpX5I1EXmot2iOcYHWx\",\"url\":\"https://ca.foo/acme/acme/challenge/3VUTu6QJ9CgLlHXWW97xVjADwqbLNvVo/kKi6xxrKXm8xVObRFKWwEStIFFKAqqbP\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"Wty9twzwg3J2wLpX5I1EXmot2iOcYHWx\",\"url\":\"https://ca.foo/acme/acme/challenge/3VUTu6QJ9CgLlHXWW97xVjADwqbLNvVo/IrKvkLWyTZH42up3fTudAy61HcfT7AyI\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"Wty9twzwg3J2wLpX5I1EXmot2iOcYHWx\",\"url\":\"https://ca.foo/acme/acme/challenge/3VUTu6QJ9CgLlHXWW97xVjADwqbLNvVo/YVAOYHBPLdb0FGaemAaUwrAydeiA8n0U\"}],\"wildcard\":false,\"expires\":\"2026-08-19T08:23:40Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6080394.223840] ca step-ca[204]: time="2026-08-18T08:23:40Z" level=info duration=4.404741ms duration-ns=4404741 fields.time="2026-08-18T08:23:40Z" method=POST name=ca nonce=V1l1TmpsNWxsaVVNZThLcWlSakJVdmhjQXlkWnJXWVI path=/acme/acme/challenge/3VUTu6QJ9CgLlHXWW97xVjADwqbLNvVo/IrKvkLWyTZH42up3fTudAy61HcfT7AyI protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=7922f2e5-428a-4ccc-8dd9-b4610e982478 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"Wty9twzwg3J2wLpX5I1EXmot2iOcYHWx\",\"validated\":\"2026-08-18T08:23:40Z\",\"url\":\"https://ca.foo/acme/acme/challenge/3VUTu6QJ9CgLlHXWW97xVjADwqbLNvVo/IrKvkLWyTZH42up3fTudAy61HcfT7AyI\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6080394.237915] ca step-ca[204]: time="2026-08-18T08:23:40Z" level=info duration=8.401117ms duration-ns=8401117 fields.time="2026-08-18T08:23:40Z" method=POST name=ca nonce=cEVUM25wNnc2T3BnSTBvenFnSFdUcWxmQ2c0SGE3WFc path=/acme/acme/order/4Wtr7wHvgwcbG71IR1mJEvm8U8klc6Ob/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=6d3f9665-57b2-4442-9f13-f2665928e5ea response="{\"id\":\"4Wtr7wHvgwcbG71IR1mJEvm8U8klc6Ob\",\"status\":\"valid\",\"expires\":\"2026-08-19T08:23:40Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-18T08:22:40Z\",\"notAfter\":\"2026-11-16T08:23:40Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/3VUTu6QJ9CgLlHXWW97xVjADwqbLNvVo\"],\"finalize\":\"https://ca.foo/acme/acme/order/4Wtr7wHvgwcbG71IR1mJEvm8U8klc6Ob/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/8Bb8YeJs5w5rkKBs13XyIA9Ay2d4Ay2B\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6080394.244749] ca step-ca[204]: time="2026-08-18T08:23:40Z" level=info certificate="MIIB2DCCAX2gAwIBAgIQReqxhLb5x9m3r0ar00/LnTAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MTgwODIyNDBaFw0yNjExMTYwODIzNDBaMBMxETAPBgNVBAMTCHRlc3QuZm9vMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEq3oXHQMseGMV3iKk7E2AJsN7n7QU+7BORvXYmFEvqq6Mv6nC7PrdshJ8NVEjc9R+Mn2CXsjK9vxKiRiSfwcMdaOBpjCBozAOBgNVHQ8BAf8EBAMCB4AwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBRRBVVulArskWSq8xDKCs/gHBiUQDAfBgNVHSMEGDAWgBQoXyeC46071qdek0cKnkXAZluVbDATBgNVHREEDDAKggh0ZXN0LmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSQAwRgIhAO3ct48XOjTYUy0ifFyphCWIsasADhkqO7Lip1r5sQdsAiEAqLb80N3BQh2IlaW+kcMq1Y0LwV5PoNX1cyJDQibquCw=" duration=2.023748ms duration-ns=2023748 fields.time="2026-08-18T08:23:40Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=eXRSbmR5ZE1lSHYwR3gzakpOWUlwTFg1a2VNcUE4MzY path=/acme/acme/certificate/8Bb8YeJs5w5rkKBs13XyIA9Ay2d4Ay2B protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=73e87adc-637e-4a78-b0f4-62c83aff8e88 sans="map[dns:[test.foo]]" serial=92935329675301881207674700072106314653 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-18T08:22:40Z" valid-to="2026-11-16T08:23:40Z" container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1010 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 18 08:23:31 2026 GMT container-test-run-certificates> * expire date: Sep 17 08:23:31 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 142cc5 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6080394.464766] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [6080394.468690] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [6080394.468908] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [6080394.995785] server nginx[389]: nginx: the configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf syntax is ok container-test-run-certificates> server # [6080394.996400] server nginx[389]: nginx: configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf test is successful container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [932 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [80 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 18 08:22:40 2026 GMT container-test-run-certificates> * expire date: Nov 16 08:23:40 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 55544 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 667 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 2.17 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> 45:ea:b1:84:b6:f9:c7:d9:b7:af:46:ab:d3:4f:cb:9d container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Aug 18 08:22:40 2026 GMT container-test-run-certificates> Not After : Nov 16 08:23:40 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:ab:7a:17:1d:03:2c:78:63:15:de:22:a4:ec:4d: container-test-run-certificates> 80:26:c3:7b:9f:b4:14:fb:b0:4e:46:f5:d8:98:51: container-test-run-certificates> 2f:aa:ae:8c:bf:a9:c2:ec:fa:dd:b2:12:7c:35:51: container-test-run-certificates> 23:73:d4:7e:32:7d:82:5e:c8:ca:f6:fc:4a:89:18: container-test-run-certificates> 92:7f:07:0c:75 container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> 51:05:55:6E:94:0A:EC:91:64:AA:F3:10:CA:0A:CF:E0:1C:18:94:40 container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> 28:5F:27:82:E3:AD:3B:D6:A7:5E:93:47:0A:9E:45:C0:66:5B:95:6C container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:46:02:21:00:ed:dc:b7:8f:17:3a:34:d8:53:2d:22:7c:5c: container-test-run-certificates> a9:84:25:88:b1:ab:00:0e:19:2a:3b:b2:e2:a7:5a:f9:b1:07: container-test-run-certificates> 6c:02:21:00:a8:b6:fc:d0:dd:c1:42:1d:88:95:a5:be:91:c3: container-test-run-certificates> 2a:d5:8d:0b:c1:5e:4f:a0:d5:f5:73:22:43:42:26:ea:b8:2c container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.04 seconds) container-test-run-certificates> (finished: run the VM test script, in 14.02 seconds) container-test-run-certificates> test script finished in 14.08s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 53) container-test-run-certificates> kill NspawnMachine (pid 55) container-test-run-certificates> kill NspawnMachine (pid 54) container-test-run-certificates> server # [6080395.541753] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.34 seconds) container-test-run-certificates> Container server terminated by signal KILL. post-build step Upload to niks3: ok time=2026-08-18T08:23:42.539Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-08-18T08:23:49.282Z level=INFO msg="Uploading 1 narinfos" time=2026-08-18T08:23:49.771Z level=INFO msg="Upload complete. (7.293s)"