these 100 derivations will be built: /nix/store/s407hfs58r89dgajy0ki0jpa4dy6hk7y-ca.json.drv /nix/store/0735qv5my58pfg7phs435b0dphq9wn9l-X-Restart-Triggers-step-ca.drv /nix/store/18fph232asdns0l1wpwxnqc3v86zzx7r-system-path.drv /nix/store/pa90nb5i4avk1dcjbzqw29l30fm150sx-dbus-1.drv /nix/store/ixvvfqmkvpvfkz56fq4946vh61msr5hh-X-Restart-Triggers-dbus-broker.drv /nix/store/0b9f0r4388f6f8hmhac74gfzn1rgk82q-unit-dbus-broker.service.drv /nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv /nix/store/pz8cs4lg35mq4mi7ck3am5chl70g70yx-firewall-start.drv /nix/store/1h3016b7n1wag10qh4dax4mdvk4hiydh-firewall-reload.drv /nix/store/c4fbynx5fd1rrxwjc0lz2lavigal41hi-system-path.drv /nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv /nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv /nix/store/pcnshfwmx0pai079bwabz5xkg6xx9976-dbus-1.drv /nix/store/73hr9ga3nmp6xbkx5lfh22n9das8a3qk-X-Restart-Triggers-dbus-broker.drv /nix/store/4vmdhi01wjbc35gr3hbhw007gp34p9vc-unit-dbus-broker.service.drv /nix/store/55r3xbviq6l3zgziig53rhs351x7xj6l-cacert-extra-certificates-bundle.crt.drv /nix/store/x52vjn5rprsx9n1jd5m287f9yhs1ffqn-cacert-blocklist.txt.drv /nix/store/pvxpinlzhyj20daqql9mw83faxiinj8x-nss-cacert-3.126.drv /nix/store/y0d0x8j8xcisb2hcgdczz7hbadlyx5sc-unit-nix-daemon.service.drv /nix/store/fll03gck15qgrqwvzkwxqh5zspgz0h8i-system-units.drv /nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv /nix/store/pz32s1dvwxxi3kv0z31isr5qrzvpra0m-unit-dbus-broker.service.drv /nix/store/l7rzpls3kbqdq5zi9q9r91qg33fj3ffy-user-units.drv /nix/store/fpn9bs0b2aa41sdfdd3i69k1j1l3wr71-etc.drv /nix/store/l20zhsdn81djw38vlw8w9r6cy7l30n9y-activate.drv /nix/store/q3k7cdy2q50fbq09pm3gwv33g9d16j4l-nixos-system-client-test.drv /nix/store/3fsq78djhvp7nr1ghyc47pyzfzn06xyj-run-client-nspawn.drv /nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv /nix/store/6z5jc0sp4vjkgzd37icya2gy22sk8q70-nixos-tmpfiles.d.drv /nix/store/79kfpjcg65c0rrnp43qfppivwzfx8yvi-10-acme.conf.drv /nix/store/3rxxn6h88dq0dw8c0jb09b175y7dx7ys-tmpfiles.d.drv /nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv /nix/store/d4vj54sx388dyibi2ja6r7jckm4ra5bl-nginx.conf.drv /nix/store/v3r6klh4wv9zb6hmz7fwb1gyzyil9a5n-unit-40-eth1.network.drv /nix/store/ycl6gbj04ywcaxa7ad5ms35wranp5b1r-X-Reload-Triggers-systemd-networkd.drv /nix/store/2y5dcvasfw9vhxcmcgzy70r1w1bd6jg9-unit-systemd-networkd.service.drv /nix/store/j3lmyghsa4g7nacl7gf67lvx5m91k2br-unit-script-acme-setup-start.drv /nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv /nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv /nix/store/8v8nx7xkgmlz39rnf6l90mdmzhz8c9yx-unit-script-nginx-pre-start.drv /nix/store/j2jdcyp4233cn5lky6zlsk016msb24sr-unit-nginx.service.drv /nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv /nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv /nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv /nix/store/ra9f6mzgpig8bxfp26sd4f4dhdymamc3-unit-firewall.service.drv /nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv /nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv /nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv /nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv /nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv /nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/sg6xid8vdr82bvgaxxp97z15ijj6xlyh-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/wdrjpapm3vz3asakl6v1mj7l3ps5ri5r-unit-systemd-tmpfiles-resetup.service.drv /nix/store/iyva6ffym0q3wmf9ci95a3ijrqyqani0-system-units.drv /nix/store/966l9k8f9k6y5373c1rsvdh4647rcvjf-unit-dbus-broker.service.drv /nix/store/zp4xg9lzm2xahzw1jncgrn6qgq5gl73m-user-units.drv /nix/store/x9ids987ccip2fa6n7vh9a1pby6gggdz-etc.drv /nix/store/h3c19rkmkccjvvgchk2sxaymd1irzgyv-activate.drv /nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv /nix/store/8hksl4wwdzhg8s7a800rs46gzyh27p8b-nixos-system-server-test.drv /nix/store/6kwm050s3bksfk3b7cvjd6a96s3ks66k-run-server-nspawn.drv /nix/store/57rffvyz1v996a4nmx5rzak7gaiffd8d-system-path.drv /nix/store/p58gpq8dlbza3dklkqrzwj7blz2knydv-nginx-recommended-proxy_set_header-headers.conf.drv /nix/store/7nasssrkv6521p26c67b9018l4h300zy-nginx.conf.drv /nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv /nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv /nix/store/c2pygc22m06f5j91981i00smr1dw9d9f-user-generators.drv /nix/store/k398xkx7mfqk70rwygca42rjfj745kf2-dbus-1.drv /nix/store/h3d7mc9w4db0f16y276r3v617dg92b7d-X-Restart-Triggers-dbus-broker.drv /nix/store/q09l6f2dgvy5zb98z7ypkhsf8hqkmxac-unit-dbus-broker.service.drv /nix/store/f2lrnjzwsjlgwcgy4k6irw184vg9sayn-user-units.drv /nix/store/ikk469l2wssyvzhq1n3iyvza3f30jvc5-system-shutdown.drv /nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv /nix/store/kv244kzjv2wsq4aj781mgqyi03rkwppz-system-generators.drv /nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv /nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv /nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv /nix/store/84y63g9jnm1wzggblz2ch6sslj97gm2q-unit-dbus-broker.service.drv /nix/store/c6mkanv5sx15z8dy9yr6wgrbqs57lhpr-unit-step-ca.service.drv /nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv /nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv /nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv /nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv /nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv /nix/store/215nr7ma6i2hsphv9li485za6hdvv9as-unit-script-nginx-pre-start.drv /nix/store/xakh8r4l0g3ymmx0s79h0bmbrxfwvjxj-unit-nginx.service.drv /nix/store/n8v1z77idsjp2c313ix2ky5c36y9lb9z-system-units.drv /nix/store/iq061qrwgdp31gsz5nl9snbk3vv9wnp3-etc.drv /nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv /nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv /nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv /nix/store/ywdyg6cr0l25ib1cgyafgnzkyj98kfqv-activate.drv /nix/store/nv3s82cfyiysmq922wp7sx690i94c37y-nixos-system-ca-test.drv /nix/store/njcwz5p45vrnhxhsxh068xskgdxgzdci-run-ca-nspawn.drv /nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv /nix/store/9dm0m0zxnmkj302mpz8xkq0l83d9xb49-driverConfiguration.json.drv /nix/store/z7r7g4vk61lva1yanw5waynfkwdbsa23-nixos-test-driver-certificates.drv /nix/store/1kgcngj6rcrnfgbvzaimn351d6lypvkd-container-test-run-certificates.drv these 19 paths will be fetched (46.2 MiB download, 152.3 MiB unpacked): /nix/store/rfjs1fcacfd1xysy7cmvxsrb9znz6iln-certdata.txt /nix/store/3japwvq6a40ykrmxjjjvm695q2z6c66c-flock-0.4.0 /nix/store/6nr0a4775j5z9nr71ciasfd9pzz076zs-gixy-0.1.21 /nix/store/p12aczsxidgl3m4jkpc4dl4y7kzf8vck-lego-4.35.2 /nix/store/fqcqw4nlcg6q6n77z3gnxhgg3ll6gjvy-minica-1.1.0 /nix/store/pjqhdi88bpspx4a01qlsw96jn2isl11k-nginx-1.30.4 /nix/store/g59y871mjn55fgjswdn72g51qc62j6wa-nginx-config-formatter-1.4.0 /nix/store/n0hdbypqp52bcmm1b5bhxgha5yl8hjs1-nginx-mod-moreheaders-0.40 /nix/store/zzhdyl8d6l7z4jfl5i36ijwqz2vpja7i-nginx-mod-rtmp-1.2.2 /nix/store/1psq003v8r8611bv7bk74xdwz9z6dgaj-openssl-3.6.3-man /nix/store/06pcrb4pj0c0sk6pa39hgmfddprslv4k-openssl-4.0.1 /nix/store/fkylsp720lag8s97n9cbxcafx78clj31-python3.14-buildcatrust-0.5.1 /nix/store/kjz0wmk9imvcj2nrm6ls5yd4mw8awajj-python3.14-cached-property-2.0.1 /nix/store/pfxx0s91wb2bhph7m1hdmzik1d8r9jn9-python3.14-configargparse-1.7.5 /nix/store/91xfmmv1iq2l30dzzbnn1brjpllbbfhi-python3.14-jinja2-3.1.6 /nix/store/64dnq6ahy02vyw342bjh479y7m74gnj1-python3.14-markupsafe-3.0.3 /nix/store/fdr01jdc50hn18dn90hx7q9p2jhkaw6m-python3.14-pyparsing-2.4.7 /nix/store/9zffz42v1gbfs8dwi61v4m09skszgl9x-step-ca-0.30.2 /nix/store/j345y5z7axzdpxivknd0swxi5yccyxq4-zlib-ng-2.3.3 building '/nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v3r6klh4wv9zb6hmz7fwb1gyzyil9a5n-unit-40-eth1.network.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/79kfpjcg65c0rrnp43qfppivwzfx8yvi-10-acme.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p58gpq8dlbza3dklkqrzwj7blz2knydv-nginx-recommended-proxy_set_header-headers.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6z5jc0sp4vjkgzd37icya2gy22sk8q70-nixos-tmpfiles.d.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/pz8cs4lg35mq4mi7ck3am5chl70g70yx-firewall-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/j3lmyghsa4g7nacl7gf67lvx5m91k2br-unit-script-acme-setup-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/79kfpjcg65c0rrnp43qfppivwzfx8yvi-10-acme.conf.drv' building '/nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv' building '/nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv' building '/nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv' building '/nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv' building '/nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv' building '/nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv' building '/nix/store/pz8cs4lg35mq4mi7ck3am5chl70g70yx-firewall-start.drv' building '/nix/store/p58gpq8dlbza3dklkqrzwj7blz2knydv-nginx-recommended-proxy_set_header-headers.conf.drv' building '/nix/store/6z5jc0sp4vjkgzd37icya2gy22sk8q70-nixos-tmpfiles.d.drv' building '/nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv' building '/nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv' building '/nix/store/v3r6klh4wv9zb6hmz7fwb1gyzyil9a5n-unit-40-eth1.network.drv' unit-40-eth1.network> structuredAttrs is enabled building '/nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv' unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled building '/nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv' unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled building '/nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv' unit-acme-renew-ca.foo.timer> structuredAttrs is enabled building '/nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv' unit-acme-renew-test.foo.timer> structuredAttrs is enabled building '/nix/store/s407hfs58r89dgajy0ki0jpa4dy6hk7y-ca.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/x52vjn5rprsx9n1jd5m287f9yhs1ffqn-cacert-blocklist.txt.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/55r3xbviq6l3zgziig53rhs351x7xj6l-cacert-extra-certificates-bundle.crt.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/x52vjn5rprsx9n1jd5m287f9yhs1ffqn-cacert-blocklist.txt.drv' building '/nix/store/55r3xbviq6l3zgziig53rhs351x7xj6l-cacert-extra-certificates-bundle.crt.drv' building '/nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/ycl6gbj04ywcaxa7ad5ms35wranp5b1r-X-Reload-Triggers-systemd-networkd.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/18fph232asdns0l1wpwxnqc3v86zzx7r-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/57rffvyz1v996a4nmx5rzak7gaiffd8d-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/c4fbynx5fd1rrxwjc0lz2lavigal41hi-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/j3lmyghsa4g7nacl7gf67lvx5m91k2br-unit-script-acme-setup-start.drv' building '/nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv' building '/nix/store/1h3016b7n1wag10qh4dax4mdvk4hiydh-firewall-reload.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kv244kzjv2wsq4aj781mgqyi03rkwppz-system-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ikk469l2wssyvzhq1n3iyvza3f30jvc5-system-shutdown.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/c2pygc22m06f5j91981i00smr1dw9d9f-user-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv' building '/nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv' building '/nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv' vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully building '/nix/store/pvxpinlzhyj20daqql9mw83faxiinj8x-nss-cacert-3.126.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3rxxn6h88dq0dw8c0jb09b175y7dx7ys-tmpfiles.d.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ycl6gbj04ywcaxa7ad5ms35wranp5b1r-X-Reload-Triggers-systemd-networkd.drv' building '/nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv' building '/nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv' building '/nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv' building '/nix/store/7nasssrkv6521p26c67b9018l4h300zy-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/d4vj54sx388dyibi2ja6r7jckm4ra5bl-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv' building '/nix/store/s407hfs58r89dgajy0ki0jpa4dy6hk7y-ca.json.drv' ca.json> structuredAttrs is enabled building '/nix/store/2y5dcvasfw9vhxcmcgzy70r1w1bd6jg9-unit-systemd-networkd.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0735qv5my58pfg7phs435b0dphq9wn9l-X-Restart-Triggers-step-ca.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv' building '/nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv' building '/nix/store/57rffvyz1v996a4nmx5rzak7gaiffd8d-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/c4fbynx5fd1rrxwjc0lz2lavigal41hi-system-path.drv' system-path> structuredAttrs is enabled building '/nix/store/1h3016b7n1wag10qh4dax4mdvk4hiydh-firewall-reload.drv' building '/nix/store/18fph232asdns0l1wpwxnqc3v86zzx7r-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' system-path> created 1718 symlinks in user environment building '/nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv' building '/nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv' building '/nix/store/ra9f6mzgpig8bxfp26sd4f4dhdymamc3-unit-firewall.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ikk469l2wssyvzhq1n3iyvza3f30jvc5-system-shutdown.drv' building '/nix/store/kv244kzjv2wsq4aj781mgqyi03rkwppz-system-generators.drv' building '/nix/store/c2pygc22m06f5j91981i00smr1dw9d9f-user-generators.drv' building '/nix/store/pvxpinlzhyj20daqql9mw83faxiinj8x-nss-cacert-3.126.drv' nss-cacert-3.126> Running phase: unpackPhase building '/nix/store/3rxxn6h88dq0dw8c0jb09b175y7dx7ys-tmpfiles.d.drv' nss-cacert-3.126> Running phase: patchPhase nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase building '/nix/store/sg6xid8vdr82bvgaxxp97z15ijj6xlyh-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv' building '/nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' nss-cacert-3.126> Running phase: installPhase nss-cacert-3.126> Running phase: fixupPhase nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/zwshds51fl7r8smyn97rms12sfrgv445-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/zwshds51fl7r8smyn97rms12sfrgv445-nss-cacert-3.126... nss-cacert-3.126> patching script interpreter paths in /nix/store/zwshds51fl7r8smyn97rms12sfrgv445-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/fnr6j0mrif54mll43wpcpz1jrhsw17dy-nss-cacert-3.126-unbundled nss-cacert-3.126> checking for references to /build/ in /nix/store/fnr6j0mrif54mll43wpcpz1jrhsw17dy-nss-cacert-3.126-unbundled... nss-cacert-3.126> patching script interpreter paths in /nix/store/fnr6j0mrif54mll43wpcpz1jrhsw17dy-nss-cacert-3.126-unbundled nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/yzbhz2qxmhcbq8mfjyb7fhjmpirdalsr-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/yzbhz2qxmhcbq8mfjyb7fhjmpirdalsr-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/yzbhz2qxmhcbq8mfjyb7fhjmpirdalsr-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/vxyph44gnjfag7i7k76px8ralli5cib6-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/vxyph44gnjfag7i7k76px8ralli5cib6-nss-cacert-3.126-hashed... nss-cacert-3.126> patching script interpreter paths in /nix/store/vxyph44gnjfag7i7k76px8ralli5cib6-nss-cacert-3.126-hashed building '/nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/ra9f6mzgpig8bxfp26sd4f4dhdymamc3-unit-firewall.service.drv' unit-firewall.service> structuredAttrs is enabled building '/nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv' unit-acme-ca.foo.service> structuredAttrs is enabled building '/nix/store/0735qv5my58pfg7phs435b0dphq9wn9l-X-Restart-Triggers-step-ca.drv' building '/nix/store/k398xkx7mfqk70rwygca42rjfj745kf2-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/pcnshfwmx0pai079bwabz5xkg6xx9976-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv' unit-acme-test.foo.service> structuredAttrs is enabled building '/nix/store/pa90nb5i4avk1dcjbzqw29l30fm150sx-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/c6mkanv5sx15z8dy9yr6wgrbqs57lhpr-unit-step-ca.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/2y5dcvasfw9vhxcmcgzy70r1w1bd6jg9-unit-systemd-networkd.service.drv' unit-systemd-networkd.service> structuredAttrs is enabled building '/nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv' unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled building '/nix/store/pcnshfwmx0pai079bwabz5xkg6xx9976-dbus-1.drv' building '/nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv' unit-acme-order-renew-test.foo.service> structuredAttrs is enabled building '/nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/sg6xid8vdr82bvgaxxp97z15ijj6xlyh-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' building '/nix/store/wdrjpapm3vz3asakl6v1mj7l3ps5ri5r-unit-systemd-tmpfiles-resetup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7nasssrkv6521p26c67b9018l4h300zy-nginx.conf.drv' nginx.conf> structuredAttrs is enabled building '/nix/store/73hr9ga3nmp6xbkx5lfh22n9das8a3qk-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/d4vj54sx388dyibi2ja6r7jckm4ra5bl-nginx.conf.drv' nginx.conf> structuredAttrs is enabled nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/y0d0x8j8xcisb2hcgdczz7hbadlyx5sc-unit-nix-daemon.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/73hr9ga3nmp6xbkx5lfh22n9das8a3qk-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/pa90nb5i4avk1dcjbzqw29l30fm150sx-dbus-1.drv' building '/nix/store/4vmdhi01wjbc35gr3hbhw007gp34p9vc-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/pz32s1dvwxxi3kv0z31isr5qrzvpra0m-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/k398xkx7mfqk70rwygca42rjfj745kf2-dbus-1.drv' building '/nix/store/wdrjpapm3vz3asakl6v1mj7l3ps5ri5r-unit-systemd-tmpfiles-resetup.service.drv' unit-systemd-tmpfiles-resetup.service> structuredAttrs is enabled building '/nix/store/c6mkanv5sx15z8dy9yr6wgrbqs57lhpr-unit-step-ca.service.drv' unit-step-ca.service> structuredAttrs is enabled building '/nix/store/8v8nx7xkgmlz39rnf6l90mdmzhz8c9yx-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/215nr7ma6i2hsphv9li485za6hdvv9as-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/y0d0x8j8xcisb2hcgdczz7hbadlyx5sc-unit-nix-daemon.service.drv' unit-nix-daemon.service> structuredAttrs is enabled building '/nix/store/h3d7mc9w4db0f16y276r3v617dg92b7d-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ixvvfqmkvpvfkz56fq4946vh61msr5hh-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/pz32s1dvwxxi3kv0z31isr5qrzvpra0m-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/215nr7ma6i2hsphv9li485za6hdvv9as-unit-script-nginx-pre-start.drv' building '/nix/store/8v8nx7xkgmlz39rnf6l90mdmzhz8c9yx-unit-script-nginx-pre-start.drv' building '/nix/store/l7rzpls3kbqdq5zi9q9r91qg33fj3ffy-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/h3d7mc9w4db0f16y276r3v617dg92b7d-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/xakh8r4l0g3ymmx0s79h0bmbrxfwvjxj-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/j2jdcyp4233cn5lky6zlsk016msb24sr-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/l7rzpls3kbqdq5zi9q9r91qg33fj3ffy-user-units.drv' building '/nix/store/84y63g9jnm1wzggblz2ch6sslj97gm2q-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/q09l6f2dgvy5zb98z7ypkhsf8hqkmxac-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/4vmdhi01wjbc35gr3hbhw007gp34p9vc-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/j2jdcyp4233cn5lky6zlsk016msb24sr-unit-nginx.service.drv' building '/nix/store/fll03gck15qgrqwvzkwxqh5zspgz0h8i-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ixvvfqmkvpvfkz56fq4946vh61msr5hh-X-Restart-Triggers-dbus-broker.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/xakh8r4l0g3ymmx0s79h0bmbrxfwvjxj-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/0b9f0r4388f6f8hmhac74gfzn1rgk82q-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/966l9k8f9k6y5373c1rsvdh4647rcvjf-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/q09l6f2dgvy5zb98z7ypkhsf8hqkmxac-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/84y63g9jnm1wzggblz2ch6sslj97gm2q-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/f2lrnjzwsjlgwcgy4k6irw184vg9sayn-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0b9f0r4388f6f8hmhac74gfzn1rgk82q-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/fll03gck15qgrqwvzkwxqh5zspgz0h8i-system-units.drv' building '/nix/store/n8v1z77idsjp2c313ix2ky5c36y9lb9z-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/966l9k8f9k6y5373c1rsvdh4647rcvjf-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/zp4xg9lzm2xahzw1jncgrn6qgq5gl73m-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/iyva6ffym0q3wmf9ci95a3ijrqyqani0-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/f2lrnjzwsjlgwcgy4k6irw184vg9sayn-user-units.drv' building '/nix/store/fpn9bs0b2aa41sdfdd3i69k1j1l3wr71-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/iyva6ffym0q3wmf9ci95a3ijrqyqani0-system-units.drv' building '/nix/store/zp4xg9lzm2xahzw1jncgrn6qgq5gl73m-user-units.drv' building '/nix/store/n8v1z77idsjp2c313ix2ky5c36y9lb9z-system-units.drv' building '/nix/store/fpn9bs0b2aa41sdfdd3i69k1j1l3wr71-etc.drv' building '/nix/store/x9ids987ccip2fa6n7vh9a1pby6gggdz-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/l20zhsdn81djw38vlw8w9r6cy7l30n9y-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/iq061qrwgdp31gsz5nl9snbk3vv9wnp3-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/l20zhsdn81djw38vlw8w9r6cy7l30n9y-activate.drv' building '/nix/store/x9ids987ccip2fa6n7vh9a1pby6gggdz-etc.drv' building '/nix/store/q3k7cdy2q50fbq09pm3gwv33g9d16j4l-nixos-system-client-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/h3c19rkmkccjvvgchk2sxaymd1irzgyv-activate.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/h3c19rkmkccjvvgchk2sxaymd1irzgyv-activate.drv' building '/nix/store/q3k7cdy2q50fbq09pm3gwv33g9d16j4l-nixos-system-client-test.drv' nixos-system-client-test> structuredAttrs is enabled building '/nix/store/iq061qrwgdp31gsz5nl9snbk3vv9wnp3-etc.drv' building '/nix/store/8hksl4wwdzhg8s7a800rs46gzyh27p8b-nixos-system-server-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3fsq78djhvp7nr1ghyc47pyzfzn06xyj-run-client-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ywdyg6cr0l25ib1cgyafgnzkyj98kfqv-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3fsq78djhvp7nr1ghyc47pyzfzn06xyj-run-client-nspawn.drv' building '/nix/store/8hksl4wwdzhg8s7a800rs46gzyh27p8b-nixos-system-server-test.drv' nixos-system-server-test> structuredAttrs is enabled building '/nix/store/6kwm050s3bksfk3b7cvjd6a96s3ks66k-run-server-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ywdyg6cr0l25ib1cgyafgnzkyj98kfqv-activate.drv' building '/nix/store/nv3s82cfyiysmq922wp7sx690i94c37y-nixos-system-ca-test.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/nv3s82cfyiysmq922wp7sx690i94c37y-nixos-system-ca-test.drv' nixos-system-ca-test> structuredAttrs is enabled building '/nix/store/njcwz5p45vrnhxhsxh068xskgdxgzdci-run-ca-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6kwm050s3bksfk3b7cvjd6a96s3ks66k-run-server-nspawn.drv' building '/nix/store/njcwz5p45vrnhxhsxh068xskgdxgzdci-run-ca-nspawn.drv' building '/nix/store/9dm0m0zxnmkj302mpz8xkq0l83d9xb49-driverConfiguration.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/9dm0m0zxnmkj302mpz8xkq0l83d9xb49-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/z7r7g4vk61lva1yanw5waynfkwdbsa23-nixos-test-driver-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/z7r7g4vk61lva1yanw5waynfkwdbsa23-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! building '/nix/store/1kgcngj6rcrnfgbvzaimn351d6lypvkd-container-test-run-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/1kgcngj6rcrnfgbvzaimn351d6lypvkd-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> client: systemd-nspawn running (pid 54) container-test-run-certificates> ca: systemd-nspawn running (pid 53) container-test-run-certificates> server: systemd-nspawn running (pid 55) container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.00 seconds) container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> server # [6334107.972227] server systemd-journald[69]: Journal started container-test-run-certificates> server # [6334107.972281] server systemd-journald[69]: Runtime Journal (/run/log/journal/aa649514f2cf435da6d2a208176a17ba) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> server # [6334107.973683] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> server # [6334107.982043] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> server # [6334107.983060] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> server # [6334107.983675] server systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> server # [6334107.992696] server systemd-journald[69]: Time spent on flushing to /var/log/journal/aa649514f2cf435da6d2a208176a17ba is 1.474ms for 6 entries. container-test-run-certificates> server # [6334107.992696] server systemd-journald[69]: System Journal (/var/log/journal/aa649514f2cf435da6d2a208176a17ba) is 8M, max 4G, 3.9G free. container-test-run-certificates> server # [6334107.998649] server systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> server # [6334107.999291] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> server # [6334107.999395] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> server # [6334108.000212] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> server # [6334108.000254] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6334108.001041] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [6334108.001071] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [6334108.022195] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [6334108.023907] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> server # [6334108.039003] server systemd-tmpfiles[122]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [6334108.039182] server systemd-tmpfiles[122]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [6334108.039300] server systemd-tmpfiles[122]: fchmod() of /var/log/journal/aa649514f2cf435da6d2a208176a17ba failed: Operation not permitted container-test-run-certificates> server # [6334108.039474] server systemd-tmpfiles[122]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [6334108.040736] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [6334108.041813] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [6334108.042506] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [6334108.053735] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [6334108.060171] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [6334108.061136] server systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [6334108.071774] server systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [6334108.118649] server systemd[1]: Finished Firewall. container-test-run-certificates> server # [6334108.118760] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> server # [6334108.118971] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [6334108.119939] server systemd[1]: Starting Network Management... container-test-run-certificates> client # [6334107.971867] client systemd-journald[69]: Journal started container-test-run-certificates> client # [6334107.971936] client systemd-journald[69]: Runtime Journal (/run/log/journal/b5450de641364331b4cc176738266903) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> client # [6334107.979645] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [6334107.980526] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [6334107.981287] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [6334107.990303] client systemd-journald[69]: Time spent on flushing to /var/log/journal/b5450de641364331b4cc176738266903 is 1.775ms for 5 entries. container-test-run-certificates> client # [6334107.990303] client systemd-journald[69]: System Journal (/var/log/journal/b5450de641364331b4cc176738266903) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [6334107.994132] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [6334107.994363] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [6334107.994450] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [6334107.995168] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [6334107.995210] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [6334107.996076] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> client # [6334107.996111] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> client # [6334108.022298] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [6334108.023885] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> client # [6334108.038010] client systemd-tmpfiles[126]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [6334108.038173] client systemd-tmpfiles[126]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [6334108.038280] client systemd-tmpfiles[126]: fchmod() of /var/log/journal/b5450de641364331b4cc176738266903 failed: Operation not permitted container-test-run-certificates> client # [6334108.038439] client systemd-tmpfiles[126]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [6334108.040288] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> client # [6334108.041371] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> client # [6334108.042160] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> client # [6334108.054084] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [6334107.971390] ca systemd-journald[78]: Journal started container-test-run-certificates> client # [6334108.059970] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> ca # [6334107.971444] ca systemd-journald[78]: Runtime Journal (/run/log/journal/1dfb6be1eaa447178d71f30ea0c1436f) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> client # [6334108.061075] client systemd[1]: Starting Update is Completed... container-test-run-certificates> ca # [6334107.973624] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> client # [6334108.070693] client systemd[1]: Finished Update is Completed. container-test-run-certificates> ca # [6334107.982032] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [6334108.104166] client systemd[1]: Finished Firewall. container-test-run-certificates> ca # [6334107.984153] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [6334108.104321] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [6334107.984785] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [6334108.104527] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> ca # [6334107.990302] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/1dfb6be1eaa447178d71f30ea0c1436f is 1.609ms for 6 entries. container-test-run-certificates> client # [6334108.105576] client systemd[1]: Starting Network Management... container-test-run-certificates> ca # [6334107.990302] ca systemd-journald[78]: System Journal (/var/log/journal/1dfb6be1eaa447178d71f30ea0c1436f) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [6334108.000075] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [6334108.000713] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> ca # [6334108.000825] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [6334108.001623] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [6334108.001668] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [6334108.002482] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [6334108.002517] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [6334108.021603] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> ca # [6334108.023240] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [6334108.039573] ca systemd-tmpfiles[131]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> ca # [6334108.039751] ca systemd-tmpfiles[131]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> ca # [6334108.039866] ca systemd-tmpfiles[131]: fchmod() of /var/log/journal/1dfb6be1eaa447178d71f30ea0c1436f failed: Operation not permitted container-test-run-certificates> ca # [6334108.040055] ca systemd-tmpfiles[131]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> ca # [6334108.041524] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> ca # [6334108.042550] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> ca # [6334108.043228] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [6334108.054612] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [6334108.062463] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> ca # [6334108.063481] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> ca # [6334108.072619] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> ca # [6334108.113428] ca systemd[1]: Finished Firewall. container-test-run-certificates> ca # [6334108.113579] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [6334108.113784] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> ca # [6334108.114772] ca systemd[1]: Starting Network Management... container-test-run-certificates> client # [6334108.243225] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [6334108.244254] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> ca # [6334108.243998] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> client # [6334108.503494] client systemd-networkd[182]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6334108.503583] client systemd-networkd[182]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6334108.511499] client systemd-networkd[182]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [6334108.509555] ca systemd-networkd[195]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6334108.511671] client systemd-networkd[182]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [6334108.509635] ca systemd-networkd[195]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6334108.511826] client systemd-networkd[182]: lo: Link UP container-test-run-certificates> ca # [6334108.517715] ca systemd-networkd[195]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [6334108.511830] client systemd-networkd[182]: lo: Gained carrier container-test-run-certificates> ca # [6334108.517874] ca systemd-networkd[195]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [6334108.512037] client systemd-networkd[182]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> ca # [6334108.518023] ca systemd-networkd[195]: lo: Link UP container-test-run-certificates> client # [6334108.512417] client systemd[1]: Started Network Management. container-test-run-certificates> ca # [6334108.518026] ca systemd-networkd[195]: lo: Gained carrier container-test-run-certificates> client # [6334108.532482] client systemd-networkd[182]: eth1: Link UP container-test-run-certificates> ca # [6334108.518197] ca systemd-networkd[195]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [6334108.532939] client systemd-networkd[182]: eth1: Gained carrier container-test-run-certificates> ca # [6334108.518553] ca systemd[1]: Started Network Management. container-test-run-certificates> client # [6334108.532950] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [6334108.532898] ca systemd-networkd[195]: eth1: Link UP container-test-run-certificates> client # [6334108.546675] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> ca # [6334108.532980] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> client # [6334108.666444] client systemd-resolved[94]: Positive Trust Anchors: container-test-run-certificates> ca # [6334108.533395] ca systemd-networkd[195]: eth1: Gained carrier container-test-run-certificates> client # [6334108.666457] client systemd-resolved[94]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [6334108.569937] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> client # [6334108.666460] client systemd-resolved[94]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [6334108.659926] ca systemd-resolved[100]: Positive Trust Anchors: container-test-run-certificates> client # [6334108.666495] client systemd-resolved[94]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [6334108.659937] ca systemd-resolved[100]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> client # [6334108.688611] client systemd-resolved[94]: Using system hostname 'client'. container-test-run-certificates> ca # [6334108.659941] ca systemd-resolved[100]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [6334108.690041] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [6334108.659975] ca systemd-resolved[100]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [6334108.690166] client systemd[1]: Reached target Network. container-test-run-certificates> ca # [6334108.682116] ca systemd-resolved[100]: Using system hostname 'ca'. container-test-run-certificates> client # [6334108.690282] client systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [6334108.683528] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [6334108.507897] server systemd-networkd[186]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6334108.690374] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6334108.507981] server systemd-networkd[186]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [6334108.683657] ca systemd[1]: Reached target Network. container-test-run-certificates> server # [6334108.516647] server systemd-networkd[186]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [6334108.690424] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [6334108.516810] server systemd-networkd[186]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [6334108.683763] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> server # [6334108.516962] server systemd-networkd[186]: lo: Link UP container-test-run-certificates> client # [6334108.690458] client systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [6334108.516965] server systemd-networkd[186]: lo: Gained carrier container-test-run-certificates> ca # [6334108.683858] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [6334108.517125] server systemd-networkd[186]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [6334108.690684] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [6334108.517575] server systemd[1]: Started Network Management. container-test-run-certificates> ca # [6334108.684269] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> server # [6334108.532828] server systemd-networkd[186]: eth1: Link UP container-test-run-certificates> client # [6334108.690888] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [6334108.533326] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [6334108.684334] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6334108.533382] server systemd-networkd[186]: eth1: Gained carrier container-test-run-certificates> client # [6334108.691095] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [6334108.570239] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> ca # [6334108.684383] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [6334108.675140] server systemd-resolved[91]: Positive Trust Anchors: container-test-run-certificates> client # [6334108.691147] client systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [6334108.675150] server systemd-resolved[91]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [6334108.684420] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [6334108.675153] server systemd-resolved[91]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [6334108.691223] client systemd[1]: Reached target Basic System. container-test-run-certificates> server # [6334108.675214] server systemd-resolved[91]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [6334108.705916] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [6334108.684654] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [6334108.707455] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [6334108.684840] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> client # [6334108.709786] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> ca # [6334108.685069] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> client # [6334108.727687] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> ca # [6334108.685116] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [6334108.698888] server systemd-resolved[91]: Using system hostname 'server'. container-test-run-certificates> ca # [6334108.685193] ca systemd[1]: Reached target Basic System. container-test-run-certificates> server # [6334108.700230] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [6334108.705691] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> server # [6334108.700304] server systemd[1]: Reached target Network. container-test-run-certificates> ca # [6334108.707229] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [6334108.700358] server systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [6334108.707312] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> server # [6334108.700399] server systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [6334108.708885] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [6334108.700604] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> ca # [6334108.710564] ca systemd[1]: Starting step-ca service... container-test-run-certificates> server # [6334108.700643] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [6334108.712772] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [6334108.700667] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [6334108.728208] ca systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [6334108.700684] server systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [6334108.700803] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [6334108.700899] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [6334108.700993] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [6334108.701018] server systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [6334108.701051] server systemd[1]: Reached target Basic System. container-test-run-certificates> server # [6334108.705249] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> server # [6334108.706273] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [6334108.706312] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> server # [6334108.707066] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [6334108.708318] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [6334108.728510] server systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [6334108.822606] server acme-setup-privileged[192]: + set -euo pipefail container-test-run-certificates> server # [6334108.822606] server acme-setup-privileged[192]: + cd /var/lib/acme container-test-run-certificates> server # [6334108.822606] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> server # [6334108.824491] server acme-setup-privileged[192]: + chown -R acme .lego/accounts container-test-run-certificates> server # [6334108.826129] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [6334108.826187] server acme-setup-privileged[192]: + '[' -d test.foo ']' container-test-run-certificates> server # [6334108.826187] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [6334108.826187] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']' container-test-run-certificates> server # [6334108.848136] server nsncd[194]: Aug 21 06:52:14.901 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> server # [6334108.860691] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> server # [6334108.860847] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> server # [6334108.860911] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [6334108.862196] server systemd[1]: Starting User Login Management... container-test-run-certificates> server # [6334108.863059] server systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [6334108.874773] server systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [6334108.876613] server systemd[1]: Started Console Getty. container-test-run-certificates> server # [6334108.876690] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [6334108.876733] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [6334108.953743] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [6334108.963503] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [6334108.964935] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [6334108.964935] server dbus-broker-launch[195]: Invalid user-name in /nix/store/3mkgnlb89jy49c4a1z0swjahhcvmnw8p-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [6334108.965375] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [6334108.973730] server dbus-broker-launch[195]: Ready container-test-run-certificates> ca # [6334108.824737] ca acme-setup-privileged[201]: + set -euo pipefail container-test-run-certificates> ca # [6334108.824737] ca acme-setup-privileged[201]: + cd /var/lib/acme container-test-run-certificates> ca # [6334108.824737] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> ca # [6334108.826193] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts container-test-run-certificates> ca # [6334108.828178] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [6334108.828223] ca acme-setup-privileged[201]: + '[' -d ca.foo ']' container-test-run-certificates> ca # [6334108.828223] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [6334108.828223] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> ca # [6334108.879542] ca nsncd[203]: Aug 21 06:52:14.932 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [6334108.879622] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [6334108.879692] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [6334108.879762] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [6334108.881032] ca systemd[1]: Starting User Login Management... container-test-run-certificates> client # [6334108.863640] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [6334108.864186] client nsncd[189]: Aug 21 06:52:14.916 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [6334108.863756] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [6334108.863866] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> client # [6334108.865968] client systemd[1]: Starting User Login Management... container-test-run-certificates> client # [6334108.867432] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [6334108.881929] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> client # [6334108.879358] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [6334108.892250] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> client # [6334108.881001] client systemd[1]: Started Console Getty. container-test-run-certificates> ca # [6334108.893782] ca systemd[1]: Started Console Getty. container-test-run-certificates> client # [6334108.881057] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> ca # [6334108.893832] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> client # [6334108.881079] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca # [6334108.893849] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> client # [6334108.966123] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [6334108.960959] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> client # [6334108.972411] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [6334108.978006] ca dbus-broker-launch[206]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> client # [6334108.973784] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> ca # [6334108.979046] ca dbus-broker-launch[206]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [6334108.973784] client dbus-broker-launch[190]: Invalid user-name in /nix/store/71vmh4xl6s5dgp2wq5sm5rdd4lr016c0-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> ca # [6334108.979093] ca dbus-broker-launch[206]: Invalid user-name in /nix/store/bz7ygr15ilclf6krkxd1w5j7l4dw4kny-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [6334108.974531] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [6334108.979529] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> client # [6334108.982209] client dbus-broker-launch[190]: Ready container-test-run-certificates> ca # [6334108.986327] ca dbus-broker-launch[206]: Ready container-test-run-certificates> ca # [6334109.357157] ca systemd-logind[235]: New seat seat0. container-test-run-certificates> ca # [6334109.357415] ca systemd[1]: Started User Login Management. container-test-run-certificates> ca # [6334109.359576] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> ca # [6334109.398276] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [6334109.398425] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [6334109.413118] ca acme-setup-start[219]: + set -euo pipefail container-test-run-certificates> ca # [6334109.413344] ca acme-setup-start[219]: + test -e ca/key.pem container-test-run-certificates> ca # [6334109.413344] ca acme-setup-start[219]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [6334109.438968] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [6334109.440652] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> ca # [6334109.603547] ca step-ca[204]: badger 2026/08/21 06:52:15 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [6334109.607935] ca step-ca[204]: 2026/08/21 06:52:15 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> client # [6334109.369401] client systemd-logind[205]: New seat seat0. container-test-run-certificates> client # [6334109.369571] client systemd[1]: Started User Login Management. container-test-run-certificates> client # [6334109.388687] client systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [6334109.402237] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> client # [6334109.402346] client systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [6334109.403513] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> client # [6334109.403760] client systemd[1]: Startup finished in 1.829s. container-test-run-certificates> server # [6334109.365166] server systemd-logind[219]: New seat seat0. container-test-run-certificates> server # [6334109.365316] server systemd[1]: Started User Login Management. container-test-run-certificates> server # [6334109.388482] server systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [6334109.401996] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> server # [6334109.402209] server systemd[1]: Finished linger-users.service. container-test-run-certificates> server # [6334109.402662] server acme-setup-start[208]: + set -euo pipefail container-test-run-certificates> server # [6334109.402941] server acme-setup-start[208]: + test -e ca/key.pem container-test-run-certificates> server # [6334109.402941] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> server # [6334109.421461] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> server # [6334109.423999] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> ca # [6334109.615702] ca step-ca[204]: 2026/08/21 06:52:15 Starting Smallstep CA/0.30.2 (linux/arm64) container-test-run-certificates> ca # [6334109.615702] ca step-ca[204]: 2026/08/21 06:52:15 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> ca # [6334109.615702] ca step-ca[204]: 2026/08/21 06:52:15 Community Discord: https://u.step.sm/discord container-test-run-certificates> ca # [6334109.615702] ca step-ca[204]: 2026/08/21 06:52:15 Config file: /etc/smallstep/ca.json container-test-run-certificates> ca # [6334109.615702] ca step-ca[204]: 2026/08/21 06:52:15 The primary server URL is https://ca.foo:1443 container-test-run-certificates> ca # [6334109.615966] ca step-ca[204]: 2026/08/21 06:52:15 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [6334109.615966] ca step-ca[204]: 2026/08/21 06:52:15 X.509 Root Fingerprint: 1a7ad12f92f4a81d1038b71212f5a044a8d7b0fb93aa69f507b3d4033bfed054 container-test-run-certificates> ca # [6334109.616394] ca systemd[1]: Started step-ca service. container-test-run-certificates> ca # [6334109.616695] ca step-ca[204]: 2026/08/21 06:52:15 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> server # [6334109.764451] server systemd-networkd[186]: eth1: Gained IPv6LL container-test-run-certificates> server # [6334109.903573] server acme-test.foo-start[245]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6334109.906532] server acme-test.foo-start[245]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [6334109.906628] server acme-test.foo-start[245]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [6334109.921473] server acme-test.foo-start[255]: + cd test.foo container-test-run-certificates> server # [6334109.922026] server acme-test.foo-start[255]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [6334109.923082] server acme-test.foo-start[256]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [6334109.923426] server acme-test.foo-start[255]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [6334109.924572] server acme-test.foo-start[255]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [6334109.924815] server acme-test.foo-start[245]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [6334109.926250] server acme-test.foo-start[245]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [6334109.927632] server acme-test.foo-start[245]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6334109.929505] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [6334109.929505] server acme-test.foo-start[245]: + '[' -d out ']' container-test-run-certificates> server # [6334109.929621] server acme-test.foo-start[245]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6334109.930942] server acme-test.foo-start[245]: + chown -R acme:nginx out container-test-run-certificates> server # [6334109.934918] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [6334109.934918] server acme-test.foo-start[245]: + '[' -d certificates ']' container-test-run-certificates> server # [6334109.940260] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [6334109.942014] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> client # [6334109.920287] client systemd-networkd[182]: eth1: Gained IPv6LL container-test-run-certificates> ca # [6334109.913807] ca acme-ca.foo-start[256]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6334109.916845] ca acme-ca.foo-start[256]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [6334109.916845] ca acme-ca.foo-start[256]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> ca # [6334109.931569] ca acme-ca.foo-start[292]: + cd ca.foo container-test-run-certificates> ca # [6334109.932018] ca acme-ca.foo-start[292]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> ca # [6334109.933320] ca acme-ca.foo-start[293]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [6334109.933558] ca acme-ca.foo-start[292]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> ca # [6334109.934906] ca acme-ca.foo-start[292]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [6334109.935231] ca acme-ca.foo-start[256]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [6334109.937386] ca acme-ca.foo-start[256]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [6334109.939441] ca acme-ca.foo-start[256]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [6334109.941226] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [6334109.941268] ca acme-ca.foo-start[256]: + '[' -d out ']' container-test-run-certificates> ca # [6334109.941268] ca acme-ca.foo-start[256]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6334109.942615] ca acme-ca.foo-start[256]: + chown -R acme:nginx out container-test-run-certificates> ca # [6334109.946233] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [6334109.946233] ca acme-ca.foo-start[256]: + '[' -d certificates ']' container-test-run-certificates> ca # [6334109.949963] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> ca # [6334109.952443] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> ca # [6334110.240238] ca systemd-networkd[195]: eth1: Gained IPv6LL container-test-run-certificates> ca # [6334110.442150] ca nginx-pre-start[304]: nginx: the configuration file /nix/store/m0ydhgw5ib8qadqvijibx910rjv6ds7z-nginx.conf syntax is ok container-test-run-certificates> ca # [6334110.442555] ca nginx-pre-start[304]: nginx: configuration file /nix/store/m0ydhgw5ib8qadqvijibx910rjv6ds7z-nginx.conf test is successful container-test-run-certificates> ca # [6334110.448210] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [6334110.448620] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [6334110.449756] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> server # [6334110.441988] server nginx-pre-start[267]: nginx: the configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf syntax is ok container-test-run-certificates> server # [6334110.442400] server nginx-pre-start[267]: nginx: configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf test is successful container-test-run-certificates> server # [6334110.448465] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [6334110.448999] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [6334110.450632] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> ca # [6334110.996210] ca acme-order-renew-ca.foo-start[307]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6334110.999129] ca acme-order-renew-ca.foo-start[307]: + set -euo pipefail container-test-run-certificates> ca # [6334110.999203] ca acme-order-renew-ca.foo-start[307]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [6334110.999320] ca acme-order-renew-ca.foo-start[307]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [6334111.000413] ca acme-order-renew-ca.foo-start[307]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> ca # [6334111.029068] ca acme-order-renew-ca.foo-start[318]: 2026/08/21 06:52:17 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [6334111.029403] ca acme-order-renew-ca.foo-start[318]: 2026/08/21 06:52:17 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [6334111.058771] ca step-ca[204]: time="2026-08-21T06:52:17Z" level=info duration="103.522µs" duration-ns=103522 fields.time="2026-08-21T06:52:17Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=9c8bb88a-d170-4c2d-a14d-423eaa595fc4 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6334111.059231] ca acme-order-renew-ca.foo-start[318]: 2026/08/21 06:52:17 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> ca # [6334111.063778] ca step-ca[204]: time="2026-08-21T06:52:17Z" level=info duration=4.381901ms duration-ns=4381901 fields.time="2026-08-21T06:52:17Z" method=HEAD name=ca nonce=MkEwNE51ZDFReUZ4NFRhZ3NyUlg5MEl3dnVBaDVPSzg path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=01a5c44b-bb61-4d09-91bb-79fcc9888213 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6334111.066177] ca step-ca[204]: time="2026-08-21T06:52:17Z" level=info duration=1.734144ms duration-ns=1734144 fields.time="2026-08-21T06:52:17Z" method=POST name=ca nonce=dGtDZjZlTTlGV0VoZUFPa0s0U0dSVlo1em5WRE5nQ0Y path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=819537b7-2593-4e94-811a-b0b95d9456c0 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/GZHSfNdybUqZ5a8lOVeSqijt88oA5KYY/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6334111.066683] ca acme-order-renew-ca.foo-start[318]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [6334111.066683] ca acme-order-renew-ca.foo-start[318]: Your account credentials have been saved in your container-test-run-certificates> ca # [6334111.066683] ca acme-order-renew-ca.foo-start[318]: configuration directory at "accounts". container-test-run-certificates> ca # [6334111.066683] ca acme-order-renew-ca.foo-start[318]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [6334111.066683] ca acme-order-renew-ca.foo-start[318]: configuration directory will also contain private keys container-test-run-certificates> ca # [6334111.066683] ca acme-order-renew-ca.foo-start[318]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [6334111.066683] ca acme-order-renew-ca.foo-start[318]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [6334111.066850] ca acme-order-renew-ca.foo-start[318]: 2026/08/21 06:52:17 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [6334111.070289] ca step-ca[204]: time="2026-08-21T06:52:17Z" level=info duration=2.93ms duration-ns=2930000 fields.time="2026-08-21T06:52:17Z" method=POST name=ca nonce=enQ2cngzUlVkVlhuYlBjbzZVQjRuWXBrODRLdjA4Zzk path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=63ce572e-4921-4182-8e29-9bcb32038492 response="{\"id\":\"AXwnZy43jnJTz9LEXaDSNfVkdPVwqUCf\",\"status\":\"pending\",\"expires\":\"2026-08-22T06:52:17Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-21T06:51:17Z\",\"notAfter\":\"2026-11-19T06:52:17Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/InWDfe6AR8j0b2Gz9bRRTpzzSO1XMiXP\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/AXwnZy43jnJTz9LEXaDSNfVkdPVwqUCf/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6334111.131716] ca step-ca[204]: time="2026-08-21T06:52:17Z" level=info duration=4.526783ms duration-ns=4526783 fields.time="2026-08-21T06:52:17Z" method=POST name=ca nonce=cmtzZjZDcjY0aFJWRXhselFGa29jNXlQblhPSGxNbFU path=/acme/acme/authz/InWDfe6AR8j0b2Gz9bRRTpzzSO1XMiXP protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=b199a137-f85e-47fa-9b2a-82f282cd7d1c response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"9TDMuI7CKkkeWoQCoRd697SgBZQbSAt1\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/InWDfe6AR8j0b2Gz9bRRTpzzSO1XMiXP/alAbecbT4fVEqghp1sELrC9dh1oL73kh\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"9TDMuI7CKkkeWoQCoRd697SgBZQbSAt1\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/InWDfe6AR8j0b2Gz9bRRTpzzSO1XMiXP/Jrk9SFxEYCKioQBDyTkfEmGRXYXcfzxT\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"9TDMuI7CKkkeWoQCoRd697SgBZQbSAt1\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/InWDfe6AR8j0b2Gz9bRRTpzzSO1XMiXP/ylrrjv9KmrXmv7SF7runJ9t4XJByUIP0\"}],\"wildcard\":false,\"expires\":\"2026-08-22T06:52:17Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6334111.132102] ca acme-order-renew-ca.foo-start[318]: 2026/08/21 06:52:17 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/InWDfe6AR8j0b2Gz9bRRTpzzSO1XMiXP container-test-run-certificates> ca # [6334111.132102] ca acme-order-renew-ca.foo-start[318]: 2026/08/21 06:52:17 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [6334111.132102] ca acme-order-renew-ca.foo-start[318]: 2026/08/21 06:52:17 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [6334111.132102] ca acme-order-renew-ca.foo-start[318]: 2026/08/21 06:52:17 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> ca # [6334111.136057] ca step-ca[204]: time="2026-08-21T06:52:17Z" level=info duration=3.507929ms duration-ns=3507929 fields.time="2026-08-21T06:52:17Z" method=POST name=ca nonce=STltRlhCRGUzSHdKVlRSZUY0UTI3b1lWRnUxMVE1N1g path=/acme/acme/challenge/InWDfe6AR8j0b2Gz9bRRTpzzSO1XMiXP/Jrk9SFxEYCKioQBDyTkfEmGRXYXcfzxT protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=32e7d03f-ff3d-4b5e-823f-2b0769d2c371 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"9TDMuI7CKkkeWoQCoRd697SgBZQbSAt1\",\"validated\":\"2026-08-21T06:52:17Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/InWDfe6AR8j0b2Gz9bRRTpzzSO1XMiXP/Jrk9SFxEYCKioQBDyTkfEmGRXYXcfzxT\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6334111.136273] ca acme-order-renew-ca.foo-start[318]: 2026/08/21 06:52:17 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [6334111.136338] ca acme-order-renew-ca.foo-start[318]: 2026/08/21 06:52:17 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [6334111.145049] ca step-ca[204]: time="2026-08-21T06:52:17Z" level=info duration=7.979111ms duration-ns=7979111 fields.time="2026-08-21T06:52:17Z" method=POST name=ca nonce=MGkyQ3hiQzNiVFZxdnJDakRvRjQweE1Kd1hVMkR3d1A path=/acme/acme/order/AXwnZy43jnJTz9LEXaDSNfVkdPVwqUCf/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=5d82e61b-e6cb-45a9-93a1-dd43be5b47e4 response="{\"id\":\"AXwnZy43jnJTz9LEXaDSNfVkdPVwqUCf\",\"status\":\"valid\",\"expires\":\"2026-08-22T06:52:17Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-21T06:51:17Z\",\"notAfter\":\"2026-11-19T06:52:17Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/InWDfe6AR8j0b2Gz9bRRTpzzSO1XMiXP\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/AXwnZy43jnJTz9LEXaDSNfVkdPVwqUCf/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/Wjr8AJkVVjVIhJsrvqqKUzuhdto0Vf0D\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6334111.146862] ca step-ca[204]: time="2026-08-21T06:52:17Z" level=info certificate=MIIB0zCCAXqgAwIBAgIRALtw9Hlab3+xBqeKKSFhmBQwCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwODIxMDY1MTE3WhcNMjYxMTE5MDY1MjE3WjARMQ8wDQYDVQQDEwZjYS5mb28wWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAAQ67LdM1kVYWCmdY2UsQ/VufDuU+oPmGwDqVUfKamZaaJyJ8UzitleHbSsn2As4P1S3MWW4A31Ht9u4S+5I/54lo4GkMIGhMA4GA1UdDwEB/wQEAwIHgDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwHQYDVR0OBBYEFPq0tmYr+wLx3MZmFak03/SRLi/aMB8GA1UdIwQYMBaAFKRym5lMRsWP2nBvfx8dseFDn8uXMBEGA1UdEQQKMAiCBmNhLmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDRwAwRAIgX4Swy4SzZYA9qgGhy2GsIRibZ3ciAS+DVy/nnI+BQxcCIFw3lkT5VGDDUjQUN7iDZfTRzMnhwLTq5VApT9CFFV6a duration=1.200576ms duration-ns=1200576 fields.time="2026-08-21T06:52:17Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=QXhlUGtDQ3FsVlpmaE9kTEJzV0l6SW9xckFzQkpDSng path=/acme/acme/certificate/Wjr8AJkVVjVIhJsrvqqKUzuhdto0Vf0D protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=b1996c22-c3de-45d5-95b8-a2a7ae299875 sans="map[dns:[ca.foo]]" serial=249152130982474568816970437119180904468 size=1340 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-21T06:51:17Z" valid-to="2026-11-19T06:52:17Z" container-test-run-certificates> ca # [6334111.147161] ca acme-order-renew-ca.foo-start[318]: 2026/08/21 06:52:17 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [6334111.152587] ca acme-order-renew-ca.foo-start[307]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [6334111.154530] ca acme-order-renew-ca.foo-start[307]: + touch out/acme-success container-test-run-certificates> ca # [6334111.156128] ca acme-order-renew-ca.foo-start[307]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6334111.157177] ca acme-order-renew-ca.foo-start[307]: + touch out/renewed container-test-run-certificates> ca # [6334111.158667] ca acme-order-renew-ca.foo-start[307]: + echo Installing new certificate container-test-run-certificates> ca # [6334111.158667] ca acme-order-renew-ca.foo-start[307]: Installing new certificate container-test-run-certificates> ca # [6334111.158725] ca acme-order-renew-ca.foo-start[307]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6334111.160202] ca acme-order-renew-ca.foo-start[350]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [6334111.160451] ca acme-order-renew-ca.foo-start[307]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [6334111.161765] ca acme-order-renew-ca.foo-start[351]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [6334111.161972] ca acme-order-renew-ca.foo-start[307]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [6334111.163277] ca acme-order-renew-ca.foo-start[352]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [6334111.163479] ca acme-order-renew-ca.foo-start[307]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [6334111.165260] ca acme-order-renew-ca.foo-start[307]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [6334111.166882] ca acme-order-renew-ca.foo-start[307]: + for fixpath in out certificates container-test-run-certificates> ca # [6334111.166917] ca acme-order-renew-ca.foo-start[307]: + '[' -d out ']' container-test-run-certificates> ca # [6334111.166917] ca acme-order-renew-ca.foo-start[307]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6334111.168924] ca acme-order-renew-ca.foo-start[307]: + chown -R acme:nginx out container-test-run-certificates> ca # [6334111.171501] ca acme-order-renew-ca.foo-start[307]: + for fixpath in out certificates container-test-run-certificates> ca # [6334111.171531] ca acme-order-renew-ca.foo-start[307]: + '[' -d certificates ']' container-test-run-certificates> ca # [6334111.171531] ca acme-order-renew-ca.foo-start[307]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [6334111.173191] ca acme-order-renew-ca.foo-start[307]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [6334111.175935] ca acme-order-renew-ca.foo-start[307]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> server # [6334111.030445] server acme-order-renew-test.foo-start[270]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6334111.033353] server acme-order-renew-test.foo-start[270]: + set -euo pipefail container-test-run-certificates> server # [6334111.033434] server acme-order-renew-test.foo-start[270]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [6334111.033543] server acme-order-renew-test.foo-start[270]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [6334111.034796] server acme-order-renew-test.foo-start[270]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [6334111.049124] server acme-order-renew-test.foo-start[282]: 2026/08/21 06:52:17 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [6334111.049705] server acme-order-renew-test.foo-start[282]: 2026/08/21 06:52:17 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> server # [6334111.083804] server acme-order-renew-test.foo-start[282]: 2026/08/21 06:52:17 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority container-test-run-certificates> server # [6334111.084389] server acme-order-renew-test.foo-start[270]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [6334111.084389] server acme-order-renew-test.foo-start[270]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [6334111.084389] server acme-order-renew-test.foo-start[270]: + exit 10 container-test-run-certificates> server # [6334111.087439] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a container-test-run-certificates> server # [6334111.087530] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'. container-test-run-certificates> server # [6334111.104319] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [6334111.104702] server systemd[1]: Startup finished in 3.523s. container-test-run-certificates> ca # [6334111.317705] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> ca # [6334111.321607] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [6334111.321792] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> ca # [6334111.844204] ca nginx[368]: nginx: the configuration file /nix/store/m0ydhgw5ib8qadqvijibx910rjv6ds7z-nginx.conf syntax is ok container-test-run-certificates> ca # [6334111.844495] ca nginx[368]: nginx: configuration file /nix/store/m0ydhgw5ib8qadqvijibx910rjv6ds7z-nginx.conf test is successful container-test-run-certificates> ca # [6334112.325834] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [6334112.326352] ca systemd[1]: Startup finished in 4.748s. container-test-run-certificates> ca # [6334112.799466] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 3.44 seconds) container-test-run-certificates> ca # [6334113.333753] ca acme-order-renew-ca.foo-start[383]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6334113.336143] ca acme-order-renew-ca.foo-start[383]: + set -euo pipefail container-test-run-certificates> ca # [6334113.336203] ca acme-order-renew-ca.foo-start[383]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [6334113.336298] ca acme-order-renew-ca.foo-start[383]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [6334113.337284] ca acme-order-renew-ca.foo-start[383]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [6334113.337284] ca acme-order-renew-ca.foo-start[383]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [6334113.337644] ca acme-order-renew-ca.foo-start[391]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [6334113.339716] ca acme-order-renew-ca.foo-start[383]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [6334113.339752] ca acme-order-renew-ca.foo-start[383]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [6334113.379090] ca step-ca[204]: time="2026-08-21T06:52:19Z" level=info duration="67.361µs" duration-ns=67361 fields.time="2026-08-21T06:52:19Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=12ce56fd-40c6-48ba-b7c6-4e2cb31870d9 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6334113.379588] ca acme-order-renew-ca.foo-start[392]: 2026/08/21 06:52:19 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [6334113.379819] ca acme-order-renew-ca.foo-start[392]: 2026/08/21 06:52:19 [INFO] [ca.foo] The certificate expires at 2026-11-19T06:52:17Z, the renewal can be performed in 1439h59m37.567233278s: no renewal. container-test-run-certificates> ca # [6334113.380098] ca acme-order-renew-ca.foo-start[383]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [6334113.381665] ca acme-order-renew-ca.foo-start[383]: + touch out/acme-success container-test-run-certificates> ca # [6334113.383284] ca acme-order-renew-ca.foo-start[383]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6334113.384459] ca acme-order-renew-ca.foo-start[383]: + for fixpath in out certificates container-test-run-certificates> ca # [6334113.384483] ca acme-order-renew-ca.foo-start[383]: + '[' -d out ']' container-test-run-certificates> ca # [6334113.384483] ca acme-order-renew-ca.foo-start[383]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6334113.385858] ca acme-order-renew-ca.foo-start[383]: + chown -R acme:nginx out container-test-run-certificates> ca # [6334113.388753] ca acme-order-renew-ca.foo-start[383]: + for fixpath in out certificates container-test-run-certificates> ca # [6334113.388778] ca acme-order-renew-ca.foo-start[383]: + '[' -d certificates ']' container-test-run-certificates> ca # [6334113.388778] ca acme-order-renew-ca.foo-start[383]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [6334113.390105] ca acme-order-renew-ca.foo-start[383]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [6334113.392491] ca acme-order-renew-ca.foo-start[383]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6334113.531834] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [6334113.564256] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server # [6334116.595147] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [6334116.595519] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [6334116.596781] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [6334116.599075] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.57 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1009 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 21 06:52:15 2026 GMT container-test-run-certificates> * expire date: Sep 20 06:52:15 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 0e0d4c container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6334117.108270] server acme-test.foo-start[315]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6334117.111642] server acme-test.foo-start[315]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [6334117.111642] server acme-test.foo-start[315]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [6334117.126825] server acme-test.foo-start[325]: + cd test.foo container-test-run-certificates> server # [6334117.127253] server acme-test.foo-start[325]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [6334117.128468] server acme-test.foo-start[326]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [6334117.128791] server acme-test.foo-start[325]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [6334117.130045] server acme-test.foo-start[325]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [6334117.130286] server acme-test.foo-start[315]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [6334117.132122] server acme-test.foo-start[315]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [6334117.134035] server acme-test.foo-start[315]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6334117.135650] server acme-test.foo-start[315]: + for fixpath in out certificates container-test-run-certificates> server # [6334117.135650] server acme-test.foo-start[315]: + '[' -d out ']' container-test-run-certificates> server # [6334117.135743] server acme-test.foo-start[315]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6334117.137316] server acme-test.foo-start[315]: + chown -R acme:nginx out container-test-run-certificates> server # [6334117.140358] server acme-test.foo-start[315]: + for fixpath in out certificates container-test-run-certificates> server # [6334117.140358] server acme-test.foo-start[315]: + '[' -d certificates ']' container-test-run-certificates> server # [6334117.143470] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [6334117.145835] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> server # [6334117.679510] server acme-order-renew-test.foo-start[333]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6334117.682465] server acme-order-renew-test.foo-start[333]: + set -euo pipefail container-test-run-certificates> server # [6334117.682538] server acme-order-renew-test.foo-start[333]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [6334117.682656] server acme-order-renew-test.foo-start[333]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [6334117.683960] server acme-order-renew-test.foo-start[333]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [6334117.732154] server acme-order-renew-test.foo-start[341]: 2026/08/21 06:52:23 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [6334117.775558] server acme-order-renew-test.foo-start[341]: !!!! HEADS UP !!!! container-test-run-certificates> server # [6334117.775558] server acme-order-renew-test.foo-start[341]: Your account credentials have been saved in your container-test-run-certificates> server # [6334117.775558] server acme-order-renew-test.foo-start[341]: configuration directory at "accounts". container-test-run-certificates> server # [6334117.775558] server acme-order-renew-test.foo-start[341]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [6334117.775558] server acme-order-renew-test.foo-start[341]: configuration directory will also contain private keys container-test-run-certificates> server # [6334117.775558] server acme-order-renew-test.foo-start[341]: generated by lego and certificates obtained from the ACME container-test-run-certificates> server # [6334117.775558] server acme-order-renew-test.foo-start[341]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [6334117.775746] server acme-order-renew-test.foo-start[341]: 2026/08/21 06:52:23 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> server # [6334117.846745] server acme-order-renew-test.foo-start[341]: 2026/08/21 06:52:23 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/lQvttpGKGSx7prBZ5PykR12C9CLD3NiC container-test-run-certificates> server # [6334117.846745] server acme-order-renew-test.foo-start[341]: 2026/08/21 06:52:23 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [6334117.846745] server acme-order-renew-test.foo-start[341]: 2026/08/21 06:52:23 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [6334117.846925] server acme-order-renew-test.foo-start[341]: 2026/08/21 06:52:23 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [6334117.856662] server acme-order-renew-test.foo-start[341]: 2026/08/21 06:52:23 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [6334117.856747] server acme-order-renew-test.foo-start[341]: 2026/08/21 06:52:23 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [6334117.875959] server acme-order-renew-test.foo-start[341]: 2026/08/21 06:52:23 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [6334117.881527] server acme-order-renew-test.foo-start[333]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [6334117.883671] server acme-order-renew-test.foo-start[333]: + touch out/acme-success container-test-run-certificates> server # [6334117.885614] server acme-order-renew-test.foo-start[333]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [6334117.886786] server acme-order-renew-test.foo-start[333]: + touch out/renewed container-test-run-certificates> server # [6334117.888306] server acme-order-renew-test.foo-start[333]: + echo Installing new certificate container-test-run-certificates> server # [6334117.888306] server acme-order-renew-test.foo-start[333]: Installing new certificate container-test-run-certificates> server # [6334117.888306] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [6334117.889890] server acme-order-renew-test.foo-start[373]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [6334117.890239] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [6334117.891821] server acme-order-renew-test.foo-start[374]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [6334117.892136] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [6334117.893583] server acme-order-renew-test.foo-start[375]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [6334117.893880] server acme-order-renew-test.foo-start[333]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [6334117.895485] server acme-order-renew-test.foo-start[333]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6334117.897554] server acme-order-renew-test.foo-start[333]: + for fixpath in out certificates container-test-run-certificates> server # [6334117.897554] server acme-order-renew-test.foo-start[333]: + '[' -d out ']' container-test-run-certificates> server # [6334117.897651] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6334117.899217] server acme-order-renew-test.foo-start[333]: + chown -R acme:nginx out container-test-run-certificates> server # [6334117.902378] server acme-order-renew-test.foo-start[333]: + for fixpath in out certificates container-test-run-certificates> server # [6334117.902378] server acme-order-renew-test.foo-start[333]: + '[' -d certificates ']' container-test-run-certificates> server # [6334117.902490] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [6334117.904057] server acme-order-renew-test.foo-start[333]: + chown -R acme:nginx certificates container-test-run-certificates> server # [6334117.907158] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6334117.731241] ca step-ca[204]: time="2026-08-21T06:52:23Z" level=info duration="40.241µs" duration-ns=40241 fields.time="2026-08-21T06:52:23Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=4ed710d0-725f-4ee0-b9a5-7e139f929728 response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6334117.769307] ca step-ca[204]: time="2026-08-21T06:52:23Z" level=info duration=34.838085ms duration-ns=34838085 fields.time="2026-08-21T06:52:23Z" method=HEAD name=ca nonce=NVZka1VDRm1leTdqWmFXbThlenk1QmFVSjJRclBjdUM path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=86d3fd31-f6be-4c9a-83fb-12d6b59515d7 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6334117.774695] ca step-ca[204]: time="2026-08-21T06:52:23Z" level=info duration=2.636396ms duration-ns=2636396 fields.time="2026-08-21T06:52:23Z" method=POST name=ca nonce=dFFhMHlFblIzMWdiRjdEWUFhVHh3cG11OVJmVFpFcDg path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=2106b02d-6fd0-4d8c-b7c9-1d752edc37d5 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/1YnxLoLS7NeVeFSbbkqdLh7cTAFp6Tuk/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6334117.783240] ca step-ca[204]: time="2026-08-21T06:52:23Z" level=info duration=3.916295ms duration-ns=3916295 fields.time="2026-08-21T06:52:23Z" method=POST name=ca nonce=S1h3ZVFjNHlOTXJjWVFWcVBIVzZ6M0NuWUN1OXNhek4 path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=358a5409-c108-4bc5-9fd0-532b0ad35462 response="{\"id\":\"ZJYoJGRNGT62iKIoDSAzQQm6Zji4qn1L\",\"status\":\"pending\",\"expires\":\"2026-08-22T06:52:23Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-21T06:51:23Z\",\"notAfter\":\"2026-11-19T06:52:23Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/lQvttpGKGSx7prBZ5PykR12C9CLD3NiC\"],\"finalize\":\"https://ca.foo/acme/acme/order/ZJYoJGRNGT62iKIoDSAzQQm6Zji4qn1L/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6334117.846094] ca step-ca[204]: time="2026-08-21T06:52:23Z" level=info duration=2.081469ms duration-ns=2081469 fields.time="2026-08-21T06:52:23Z" method=POST name=ca nonce=S05lcHUyNzRjbDJTTXZwamIyRmM4RjFoMmRoYUlPMVk path=/acme/acme/authz/lQvttpGKGSx7prBZ5PykR12C9CLD3NiC protocol=HTTP/1.1 referer= remote-address="::1" request-id=bc19e724-a8e1-4778-817c-7f24f28cd01b response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"o1uWyS6gFKeQzB6L6Yrd6aPgeWu1EilZ\",\"url\":\"https://ca.foo/acme/acme/challenge/lQvttpGKGSx7prBZ5PykR12C9CLD3NiC/rtUTTDifO17sJVqyPfCYYqXxeNsKcZJA\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"o1uWyS6gFKeQzB6L6Yrd6aPgeWu1EilZ\",\"url\":\"https://ca.foo/acme/acme/challenge/lQvttpGKGSx7prBZ5PykR12C9CLD3NiC/wkCjPjOoVHiD4tAyDaqAgvtvaUIk6TU0\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"o1uWyS6gFKeQzB6L6Yrd6aPgeWu1EilZ\",\"url\":\"https://ca.foo/acme/acme/challenge/lQvttpGKGSx7prBZ5PykR12C9CLD3NiC/FihMK3C4bfEo4jE3YmxDxeps6eeb7qg8\"}],\"wildcard\":false,\"expires\":\"2026-08-22T06:52:23Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6334117.855974] ca step-ca[204]: time="2026-08-21T06:52:23Z" level=info duration=5.180033ms duration-ns=5180033 fields.time="2026-08-21T06:52:23Z" method=POST name=ca nonce=ZmoxQkZ0M0xqWWJ0TzJOem5YaHlNZktMU2tQTXdXd0U path=/acme/acme/challenge/lQvttpGKGSx7prBZ5PykR12C9CLD3NiC/wkCjPjOoVHiD4tAyDaqAgvtvaUIk6TU0 protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=bc1f6f99-7beb-4185-a0ba-0b2fa2f262ee response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"o1uWyS6gFKeQzB6L6Yrd6aPgeWu1EilZ\",\"validated\":\"2026-08-21T06:52:23Z\",\"url\":\"https://ca.foo/acme/acme/challenge/lQvttpGKGSx7prBZ5PykR12C9CLD3NiC/wkCjPjOoVHiD4tAyDaqAgvtvaUIk6TU0\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6334117.868875] ca step-ca[204]: time="2026-08-21T06:52:23Z" level=info duration=7.654146ms duration-ns=7654146 fields.time="2026-08-21T06:52:23Z" method=POST name=ca nonce=ZXkxYlJiMEV2cnFvRDQxM3pkdlk5Q1EwNUlZUWxUelY path=/acme/acme/order/ZJYoJGRNGT62iKIoDSAzQQm6Zji4qn1L/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=f43dc4df-a13a-453c-9eff-b375fc0b48e9 response="{\"id\":\"ZJYoJGRNGT62iKIoDSAzQQm6Zji4qn1L\",\"status\":\"valid\",\"expires\":\"2026-08-22T06:52:23Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-21T06:51:23Z\",\"notAfter\":\"2026-11-19T06:52:23Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/lQvttpGKGSx7prBZ5PykR12C9CLD3NiC\"],\"finalize\":\"https://ca.foo/acme/acme/order/ZJYoJGRNGT62iKIoDSAzQQm6Zji4qn1L/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/nUIlsbfJs0QOdlPX0p4F1sY75X0r0DIR\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6334117.875320] ca step-ca[204]: time="2026-08-21T06:52:23Z" level=info certificate=MIIB2TCCAX6gAwIBAgIRANe8RaaQ8AVVk3tAdRI5NFEwCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwODIxMDY1MTIzWhcNMjYxMTE5MDY1MjIzWjATMREwDwYDVQQDEwh0ZXN0LmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABPUiOiKoODLhiDecYIDaPqiB7EU18m+ayHcorODy203kIrc4lsyd6JU9RLjMUq/y2liQWlKMl1R4ZxfzHEoVlV6jgaYwgaMwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUnKKbkRfVrdxpLTNeiBH00HLNT84wHwYDVR0jBBgwFoAUpHKbmUxGxY/acG9/Hx2x4UOfy5cwEwYDVR0RBAwwCoIIdGVzdC5mb28wHQYMKwYBBAGCpGTGKEABBA0wCwIBBgQEYWNtZQQAMAoGCCqGSM49BAMCA0kAMEYCIQCVhsrxpj4l/l+LjcTn3hXhEVUhXAO00ua5FSbxkyhISgIhAMwBWLQuhG71YzAkXKTVv05twdxv7jGkBmDT053DlUYp duration=2.028388ms duration-ns=2028388 fields.time="2026-08-21T06:52:23Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=c2NmY1JLUUZ4MjVZUTJHQnlPNmRhVGxZS3BxZjNVNUM path=/acme/acme/certificate/nUIlsbfJs0QOdlPX0p4F1sY75X0r0DIR protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=727cec06-a702-43f7-bb26-e6372a8d6782 sans="map[dns:[test.foo]]" serial=286761583586155098403035564287909770321 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-21T06:51:23Z" valid-to="2026-11-19T06:52:23Z" container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1009 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 21 06:52:15 2026 GMT container-test-run-certificates> * expire date: Sep 20 06:52:15 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 0e0d4c container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6334118.078486] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [6334118.083461] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [6334118.083772] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [6334118.613022] server nginx[391]: nginx: the configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf syntax is ok container-test-run-certificates> server # [6334118.613593] server nginx[391]: nginx: configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf test is successful container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [932 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [79 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 21 06:51:23 2026 GMT container-test-run-certificates> * expire date: Nov 19 06:52:23 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 45100 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 585 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 2.16 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> d7:bc:45:a6:90:f0:05:55:93:7b:40:75:12:39:34:51 container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Aug 21 06:51:23 2026 GMT container-test-run-certificates> Not After : Nov 19 06:52:23 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:f5:22:3a:22:a8:38:32:e1:88:37:9c:60:80:da: container-test-run-certificates> 3e:a8:81:ec:45:35:f2:6f:9a:c8:77:28:ac:e0:f2: container-test-run-certificates> db:4d:e4:22:b7:38:96:cc:9d:e8:95:3d:44:b8:cc: container-test-run-certificates> 52:af:f2:da:58:90:5a:52:8c:97:54:78:67:17:f3: container-test-run-certificates> 1c:4a:15:95:5e container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> 9C:A2:9B:91:17:D5:AD:DC:69:2D:33:5E:88:11:F4:D0:72:CD:4F:CE container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> A4:72:9B:99:4C:46:C5:8F:DA:70:6F:7F:1F:1D:B1:E1:43:9F:CB:97 container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:46:02:21:00:95:86:ca:f1:a6:3e:25:fe:5f:8b:8d:c4:e7: container-test-run-certificates> de:15:e1:11:55:21:5c:03:b4:d2:e6:b9:15:26:f1:93:28:48: container-test-run-certificates> 4a:02:21:00:cc:01:58:b4:2e:84:6e:f5:63:30:24:5c:a4:d5: container-test-run-certificates> bf:4e:6d:c1:dc:6f:ee:31:a4:06:60:d3:d3:9d:c3:95:46:29 container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.04 seconds) container-test-run-certificates> (finished: run the VM test script, in 12.21 seconds) container-test-run-certificates> server # [6334119.148300] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> test script finished in 12.46s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 53) container-test-run-certificates> kill NspawnMachine (pid 54) container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> kill NspawnMachine (pid 55) container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.44 seconds) container-test-run-certificates> Container server terminated by signal KILL. post-build step Upload to niks3: ok time=2026-08-21T06:52:26.706Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-08-21T06:52:27.378Z level=INFO msg="Uploading 1 narinfos" time=2026-08-21T06:52:27.444Z level=INFO msg="Upload complete. (794ms)"