these 119 derivations will be built: /nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv /nix/store/pz8cs4lg35mq4mi7ck3am5chl70g70yx-firewall-start.drv /nix/store/1h3016b7n1wag10qh4dax4mdvk4hiydh-firewall-reload.drv /nix/store/5mrdkkv0rkyrgkwxwdj3gbwks10c6i55-users-groups.json.drv /nix/store/7bm5w0wpz1gk6ma416c9i77kslkzgm9m-decrypt-age-secrets.drv /nix/store/hvpdgppc2ph0w7r40a0nla0cl5zy2x1k-dry-activate.drv /nix/store/r83pgfxcw1n2v781qbslkwagg3w0p541-system-path.drv /nix/store/hfdp8pwsxxzhasg8ndcg2w197prj0nxb-dbus-1.drv /nix/store/pkyvq9bzv5p1p73rgk7y09vkimippi4r-X-Restart-Triggers-dbus-broker.drv /nix/store/gibl8vf5nh7rz7km47zqnhslnk5xdf1d-unit-dbus-broker.service.drv /nix/store/36cy4w2pi2w6k7jg152rzzpm1plchm8z-user-units.drv /nix/store/2xj8ma1f4q37pw3g0ias2wvisyf6jsbi-unit-nix-gc.service.drv /nix/store/50m6cfa5x1dxaslnp49g6lxj4p7np9bp-unit-systemd-networkd.service.drv /nix/store/n8sp574dsmhbggqmf9hb0wmrri9l2qq3-tmpfiles.d.drv /nix/store/3wbzl5zadk20cplik16z31fcvghbrlcz-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/7hgnzq5d0x9pk0i03d6a0ia7i525pzmi-unit-systemd-tmpfiles-resetup.service.drv /nix/store/9wq3xd2sy586pzs7rnpcsl1857hf2a4x-unit-systemd-journald-.service.drv /nix/store/g2gpd27y6vw63m3l59xsfrqf44l31igf-unit-systemd-sysctl.service.drv /nix/store/g9bfvl6h2n1ags2vhzcymd11bzbp5vsc-unit-systemd-journald.service.drv /nix/store/55r3xbviq6l3zgziig53rhs351x7xj6l-cacert-extra-certificates-bundle.crt.drv /nix/store/x52vjn5rprsx9n1jd5m287f9yhs1ffqn-cacert-blocklist.txt.drv /nix/store/hfkx72smrjg3my0r04xwnjgl62ypyxjv-nss-cacert-3.126.drv /nix/store/gk2jg7awfap5x1fpczlgrvxhb1skj3ws-unit-nix-daemon.service.drv /nix/store/hylqa47xmlzklb4mr8hi3kb4bvj1bb5f-unit-dbus-broker.service.drv /nix/store/wk7m48i09fl5440y04scqvbjjx6v5blg-firewall-reload.drv /nix/store/i8g688x99787cjd8jvlsmddvhq71rcv2-unit-firewall.service.drv /nix/store/yba88nb1hykyxa4w2m2i207xjk5kpazf-getty.drv /nix/store/sqw4bjlrvfm5l56jar3vmi77wwalcvif-unit-getty-.service.drv /nix/store/v0clim1zszqklxri4dwhf4gr45rx79ja-unit-systemd-resolved.service.drv /nix/store/v75n6iibh1hdrjkqg7cig45jy07dhyfa-unit-generate-shutdown-ramfs.service.drv /nix/store/dbw90gxma3wms6h7svs7gqvjij38f9n0-system-units.drv /nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv /nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv /nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv /nix/store/p2afnx0grm7k6hb2i24daqbnjjdzmkp9-etc.drv /nix/store/mfzcfhs93p76qlxjbk76zgvfvzw983nc-activate.drv /nix/store/1j1r5vl57kg1ys7ygqaw1n1qbkkg2r3h-nixos-system-client-test.drv /nix/store/l4s3hilg46786l91xxnck8qrd5zk5c39-system-path.drv /nix/store/53gz0xpb6hi1n7f8k9iaf0j65rb177yi-dbus-1.drv /nix/store/3yyv0623ddraws79zmjfk1qcwpy46j4w-X-Restart-Triggers-dbus-broker.drv /nix/store/3f4j3in4icr0w7mmf5azp7wrbb87lvrd-unit-dbus-broker.service.drv /nix/store/2afbh3vl9b4wqmi7rhmal5s3lqq5d2di-user-units.drv /nix/store/v3r6klh4wv9zb6hmz7fwb1gyzyil9a5n-unit-40-eth1.network.drv /nix/store/ycl6gbj04ywcaxa7ad5ms35wranp5b1r-X-Reload-Triggers-systemd-networkd.drv /nix/store/2y5dcvasfw9vhxcmcgzy70r1w1bd6jg9-unit-systemd-networkd.service.drv /nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv /nix/store/qxhrn5k10q3b7l2q99pvdzmkpi020xl6-system-path.drv /nix/store/am9qkfk9c09a47pkjf3vp7w6d4pqkk2b-dbus-1.drv /nix/store/qrrxsdc2h8nzpxn9dc9msx5xy2588qwx-X-Restart-Triggers-dbus-broker.drv /nix/store/4b2qclyk27xay6ar619c5acmkskacj4y-unit-dbus-broker.service.drv /nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv /nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv /nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv /nix/store/5k59m3qhfcaxaxyz5kkrpzsj2v6c4j3s-nixos-test-driver-1.1.drv /nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv /nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv /nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv /nix/store/d4vj54sx388dyibi2ja6r7jckm4ra5bl-nginx.conf.drv /nix/store/6z5jc0sp4vjkgzd37icya2gy22sk8q70-nixos-tmpfiles.d.drv /nix/store/79kfpjcg65c0rrnp43qfppivwzfx8yvi-10-acme.conf.drv /nix/store/dxhcs8f88vsb624k3l6b10b549cv921m-tmpfiles.d.drv /nix/store/j3lmyghsa4g7nacl7gf67lvx5m91k2br-unit-script-acme-setup-start.drv /nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv /nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv /nix/store/8v8nx7xkgmlz39rnf6l90mdmzhz8c9yx-unit-script-nginx-pre-start.drv /nix/store/j2jdcyp4233cn5lky6zlsk016msb24sr-unit-nginx.service.drv /nix/store/kx6mamh3kwimxnppg229zxy58cb8bgpr-unit-dbus-broker.service.drv /nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv /nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv /nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv /nix/store/ra9f6mzgpig8bxfp26sd4f4dhdymamc3-unit-firewall.service.drv /nix/store/y9vs2brijwc8c2b5mh0vxrsz0hh37z6h-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/rmxiym60q7p0pgy3rvrqhgl15ngv7yc5-unit-systemd-tmpfiles-resetup.service.drv /nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv /nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv /nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv /nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv /nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv /nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/iczvp7a1zyf41wzdhbxx3m3fzb4z39zl-system-units.drv /nix/store/96z1nya4phwbfg3jaivl9gm73ni265x2-etc.drv /nix/store/6iqp3w8xkd1kvmlijfz0jlrx5yv0dbj6-activate.drv /nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv /nix/store/7y65k5c6xap6176dxk0ylcxdl9al2s9r-run-client-nspawn.drv /nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv /nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv /nix/store/li9ychnih4daxqa5jybw82yym5l1x5a5-nixos-system-server-test.drv /nix/store/sifhnisbimh4dzik8ja1m83nqgm1pd8c-run-server-nspawn.drv /nix/store/p58gpq8dlbza3dklkqrzwj7blz2knydv-nginx-recommended-proxy_set_header-headers.conf.drv /nix/store/9lh8sdpdkzz7yxx4wl2s7y1qsgqcpzl3-nginx.conf.drv /nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv /nix/store/bx9ay666mdpxmqa49l3hw83wkl8bjvvs-user-generators.drv /nix/store/wwlslfgw81qzfz9qlyr94hwf26df1iah-unit-dbus-broker.service.drv /nix/store/d7kgyvbw6k4b3qpsbhrgp60hg0dd7df9-user-units.drv /nix/store/n9g0f07vxaqnxyhk0kknrkn9p86b038l-ca.json.drv /nix/store/hzgn023msyi298l2f9svhhnkfsiswhl5-X-Restart-Triggers-step-ca.drv /nix/store/7xhzzhwx91bfjzgmbb86yh8p45gcx7ry-unit-step-ca.service.drv /nix/store/fx7ik3vx6rfz50jgfpv7iqc1npfpfzn6-unit-systemd-networkd.service.drv /nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/y3r62hd0kzamcjn9mhrlvalrlbjbvhrh-unit-script-nginx-pre-start.drv /nix/store/q14rpc2w5wbl9zpsz927f7c67ly53fy9-unit-nginx.service.drv /nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv /nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv /nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv /nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv /nix/store/ilmc2rj57mwbi2mjz8f84ifndsv83qn7-system-units.drv /nix/store/imw2kazzmfl6nlf52psv7h2vlnfpdxn3-system-shutdown.drv /nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv /nix/store/rr3k22qcv35qb8krj0p5bp7b2yvqp8ml-system-generators.drv /nix/store/bl26lxig1nxs8v53kz5ldfar0lv058qb-etc.drv /nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv /nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv /nix/store/m2dpp5zyadkyzx76wvkfsz4km9krk5mq-activate.drv /nix/store/cc3z1gzghwrm8gkqlmz0j2127g2h2vv8-nixos-system-ca-test.drv /nix/store/wdqp1chk06hkdwxr558vnr7s5jvng4dy-run-ca-nspawn.drv /nix/store/75q7wqalg6xzcvgz0hj5kh46vam2jbxn-driverConfiguration.json.drv /nix/store/xbwnpn42v35vn5kwfr1km6n7rjjl3bmc-nixos-test-driver-certificates.drv /nix/store/zdwf49xlvsz2yhav45mas4f5n8q2pc3g-container-test-run-certificates.drv these 17 paths will be fetched (45.8 MiB download, 150.1 MiB unpacked): /nix/store/rfjs1fcacfd1xysy7cmvxsrb9znz6iln-certdata.txt /nix/store/3japwvq6a40ykrmxjjjvm695q2z6c66c-flock-0.4.0 /nix/store/6nr0a4775j5z9nr71ciasfd9pzz076zs-gixy-0.1.21 /nix/store/p12aczsxidgl3m4jkpc4dl4y7kzf8vck-lego-4.35.2 /nix/store/fqcqw4nlcg6q6n77z3gnxhgg3ll6gjvy-minica-1.1.0 /nix/store/pjqhdi88bpspx4a01qlsw96jn2isl11k-nginx-1.30.4 /nix/store/g59y871mjn55fgjswdn72g51qc62j6wa-nginx-config-formatter-1.4.0 /nix/store/n0hdbypqp52bcmm1b5bhxgha5yl8hjs1-nginx-mod-moreheaders-0.40 /nix/store/zzhdyl8d6l7z4jfl5i36ijwqz2vpja7i-nginx-mod-rtmp-1.2.2 /nix/store/1psq003v8r8611bv7bk74xdwz9z6dgaj-openssl-3.6.3-man /nix/store/06pcrb4pj0c0sk6pa39hgmfddprslv4k-openssl-4.0.1 /nix/store/fkylsp720lag8s97n9cbxcafx78clj31-python3.14-buildcatrust-0.5.1 /nix/store/kjz0wmk9imvcj2nrm6ls5yd4mw8awajj-python3.14-cached-property-2.0.1 /nix/store/pfxx0s91wb2bhph7m1hdmzik1d8r9jn9-python3.14-configargparse-1.7.5 /nix/store/fdr01jdc50hn18dn90hx7q9p2jhkaw6m-python3.14-pyparsing-2.4.7 /nix/store/9zffz42v1gbfs8dwi61v4m09skszgl9x-step-ca-0.30.2 /nix/store/j345y5z7axzdpxivknd0swxi5yccyxq4-zlib-ng-2.3.3 building '/nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v3r6klh4wv9zb6hmz7fwb1gyzyil9a5n-unit-40-eth1.network.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/79kfpjcg65c0rrnp43qfppivwzfx8yvi-10-acme.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p58gpq8dlbza3dklkqrzwj7blz2knydv-nginx-recommended-proxy_set_header-headers.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6z5jc0sp4vjkgzd37icya2gy22sk8q70-nixos-tmpfiles.d.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/pz8cs4lg35mq4mi7ck3am5chl70g70yx-firewall-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/j3lmyghsa4g7nacl7gf67lvx5m91k2br-unit-script-acme-setup-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/n9g0f07vxaqnxyhk0kknrkn9p86b038l-ca.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/x52vjn5rprsx9n1jd5m287f9yhs1ffqn-cacert-blocklist.txt.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/55r3xbviq6l3zgziig53rhs351x7xj6l-cacert-extra-certificates-bundle.crt.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv' building '/nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv' building '/nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv' building '/nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv' building '/nix/store/p58gpq8dlbza3dklkqrzwj7blz2knydv-nginx-recommended-proxy_set_header-headers.conf.drv' building '/nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv' unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled building '/nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv' building '/nix/store/9lh8sdpdkzz7yxx4wl2s7y1qsgqcpzl3-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/j3lmyghsa4g7nacl7gf67lvx5m91k2br-unit-script-acme-setup-start.drv' building '/nix/store/pz8cs4lg35mq4mi7ck3am5chl70g70yx-firewall-start.drv' building '/nix/store/79kfpjcg65c0rrnp43qfppivwzfx8yvi-10-acme.conf.drv' building '/nix/store/n9g0f07vxaqnxyhk0kknrkn9p86b038l-ca.json.drv' ca.json> structuredAttrs is enabled building '/nix/store/hzgn023msyi298l2f9svhhnkfsiswhl5-X-Restart-Triggers-step-ca.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv' building '/nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv' building '/nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv' building '/nix/store/v3r6klh4wv9zb6hmz7fwb1gyzyil9a5n-unit-40-eth1.network.drv' unit-40-eth1.network> structuredAttrs is enabled building '/nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv' unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled building '/nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/x52vjn5rprsx9n1jd5m287f9yhs1ffqn-cacert-blocklist.txt.drv' building '/nix/store/55r3xbviq6l3zgziig53rhs351x7xj6l-cacert-extra-certificates-bundle.crt.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv' unit-acme-renew-ca.foo.timer> structuredAttrs is enabled building '/nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv' unit-acme-renew-test.foo.timer> structuredAttrs is enabled building '/nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv' vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully building '/nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/d4vj54sx388dyibi2ja6r7jckm4ra5bl-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rr3k22qcv35qb8krj0p5bp7b2yvqp8ml-system-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/l4s3hilg46786l91xxnck8qrd5zk5c39-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qxhrn5k10q3b7l2q99pvdzmkpi020xl6-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/r83pgfxcw1n2v781qbslkwagg3w0p541-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/imw2kazzmfl6nlf52psv7h2vlnfpdxn3-system-shutdown.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/bx9ay666mdpxmqa49l3hw83wkl8bjvvs-user-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv' building '/nix/store/1h3016b7n1wag10qh4dax4mdvk4hiydh-firewall-reload.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6z5jc0sp4vjkgzd37icya2gy22sk8q70-nixos-tmpfiles.d.drv' building '/nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv' building '/nix/store/ycl6gbj04ywcaxa7ad5ms35wranp5b1r-X-Reload-Triggers-systemd-networkd.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/hfkx72smrjg3my0r04xwnjgl62ypyxjv-nss-cacert-3.126.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv' building '/nix/store/dxhcs8f88vsb624k3l6b10b549cv921m-tmpfiles.d.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv' building '/nix/store/hzgn023msyi298l2f9svhhnkfsiswhl5-X-Restart-Triggers-step-ca.drv' building '/nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv' building '/nix/store/7xhzzhwx91bfjzgmbb86yh8p45gcx7ry-unit-step-ca.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/9lh8sdpdkzz7yxx4wl2s7y1qsgqcpzl3-nginx.conf.drv' nginx.conf> structuredAttrs is enabled building '/nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv' building '/nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/y3r62hd0kzamcjn9mhrlvalrlbjbvhrh-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/d4vj54sx388dyibi2ja6r7jckm4ra5bl-nginx.conf.drv' nginx.conf> structuredAttrs is enabled building '/nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/8v8nx7xkgmlz39rnf6l90mdmzhz8c9yx-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rr3k22qcv35qb8krj0p5bp7b2yvqp8ml-system-generators.drv' building '/nix/store/qxhrn5k10q3b7l2q99pvdzmkpi020xl6-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/r83pgfxcw1n2v781qbslkwagg3w0p541-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/l4s3hilg46786l91xxnck8qrd5zk5c39-system-path.drv' system-path> structuredAttrs is enabled building '/nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv' building '/nix/store/imw2kazzmfl6nlf52psv7h2vlnfpdxn3-system-shutdown.drv' building '/nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv' system-path> created 1718 symlinks in user environment building '/nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv' building '/nix/store/bx9ay666mdpxmqa49l3hw83wkl8bjvvs-user-generators.drv' building '/nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ycl6gbj04ywcaxa7ad5ms35wranp5b1r-X-Reload-Triggers-systemd-networkd.drv' building '/nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/1h3016b7n1wag10qh4dax4mdvk4hiydh-firewall-reload.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/ra9f6mzgpig8bxfp26sd4f4dhdymamc3-unit-firewall.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/hfkx72smrjg3my0r04xwnjgl62ypyxjv-nss-cacert-3.126.drv' building '/nix/store/7xhzzhwx91bfjzgmbb86yh8p45gcx7ry-unit-step-ca.service.drv' unit-step-ca.service> structuredAttrs is enabled nss-cacert-3.126> Running phase: unpackPhase nss-cacert-3.126> Running phase: patchPhase building '/nix/store/2y5dcvasfw9vhxcmcgzy70r1w1bd6jg9-unit-systemd-networkd.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase building '/nix/store/dxhcs8f88vsb624k3l6b10b549cv921m-tmpfiles.d.drv' building '/nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv' nss-cacert-3.126> Running phase: installPhase nss-cacert-3.126> Running phase: fixupPhase nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/71w9yl59gjgj860klfvjavl61nsn01mj-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/71w9yl59gjgj860klfvjavl61nsn01mj-nss-cacert-3.126... nss-cacert-3.126> patching script interpreter paths in /nix/store/71w9yl59gjgj860klfvjavl61nsn01mj-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/bh4z9rzwsbms55bwhlh34zfr561dq731-nss-cacert-3.126-unbundled nss-cacert-3.126> checking for references to /build/ in /nix/store/bh4z9rzwsbms55bwhlh34zfr561dq731-nss-cacert-3.126-unbundled... nss-cacert-3.126> patching script interpreter paths in /nix/store/bh4z9rzwsbms55bwhlh34zfr561dq731-nss-cacert-3.126-unbundled building '/nix/store/hfdp8pwsxxzhasg8ndcg2w197prj0nxb-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/q5087i3qbf8kc16y51d8g8h6lpql03cj-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/q5087i3qbf8kc16y51d8g8h6lpql03cj-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/q5087i3qbf8kc16y51d8g8h6lpql03cj-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/cm3hncx7la5am6sa2bifhj7j7i2kr5i8-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/cm3hncx7la5am6sa2bifhj7j7i2kr5i8-nss-cacert-3.126-hashed... nss-cacert-3.126> patching script interpreter paths in /nix/store/cm3hncx7la5am6sa2bifhj7j7i2kr5i8-nss-cacert-3.126-hashed building '/nix/store/8v8nx7xkgmlz39rnf6l90mdmzhz8c9yx-unit-script-nginx-pre-start.drv' building '/nix/store/am9qkfk9c09a47pkjf3vp7w6d4pqkk2b-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/y3r62hd0kzamcjn9mhrlvalrlbjbvhrh-unit-script-nginx-pre-start.drv' building '/nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv' building '/nix/store/y9vs2brijwc8c2b5mh0vxrsz0hh37z6h-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/53gz0xpb6hi1n7f8k9iaf0j65rb177yi-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv' building '/nix/store/j2jdcyp4233cn5lky6zlsk016msb24sr-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/q14rpc2w5wbl9zpsz927f7c67ly53fy9-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/gk2jg7awfap5x1fpczlgrvxhb1skj3ws-unit-nix-daemon.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv' unit-acme-order-renew-test.foo.service> structuredAttrs is enabled building '/nix/store/ra9f6mzgpig8bxfp26sd4f4dhdymamc3-unit-firewall.service.drv' unit-firewall.service> structuredAttrs is enabled building '/nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv' unit-acme-ca.foo.service> structuredAttrs is enabled building '/nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv' unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled building '/nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv' unit-acme-test.foo.service> structuredAttrs is enabled building '/nix/store/2y5dcvasfw9vhxcmcgzy70r1w1bd6jg9-unit-systemd-networkd.service.drv' unit-systemd-networkd.service> structuredAttrs is enabled building '/nix/store/y9vs2brijwc8c2b5mh0vxrsz0hh37z6h-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' building '/nix/store/hfdp8pwsxxzhasg8ndcg2w197prj0nxb-dbus-1.drv' building '/nix/store/pkyvq9bzv5p1p73rgk7y09vkimippi4r-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/am9qkfk9c09a47pkjf3vp7w6d4pqkk2b-dbus-1.drv' building '/nix/store/j2jdcyp4233cn5lky6zlsk016msb24sr-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/gk2jg7awfap5x1fpczlgrvxhb1skj3ws-unit-nix-daemon.service.drv' unit-nix-daemon.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/q14rpc2w5wbl9zpsz927f7c67ly53fy9-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/53gz0xpb6hi1n7f8k9iaf0j65rb177yi-dbus-1.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/3yyv0623ddraws79zmjfk1qcwpy46j4w-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qrrxsdc2h8nzpxn9dc9msx5xy2588qwx-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rmxiym60q7p0pgy3rvrqhgl15ngv7yc5-unit-systemd-tmpfiles-resetup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/pkyvq9bzv5p1p73rgk7y09vkimippi4r-X-Restart-Triggers-dbus-broker.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/gibl8vf5nh7rz7km47zqnhslnk5xdf1d-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/hylqa47xmlzklb4mr8hi3kb4bvj1bb5f-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3yyv0623ddraws79zmjfk1qcwpy46j4w-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/3f4j3in4icr0w7mmf5azp7wrbb87lvrd-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kx6mamh3kwimxnppg229zxy58cb8bgpr-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qrrxsdc2h8nzpxn9dc9msx5xy2588qwx-X-Restart-Triggers-dbus-broker.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/rmxiym60q7p0pgy3rvrqhgl15ngv7yc5-unit-systemd-tmpfiles-resetup.service.drv' unit-systemd-tmpfiles-resetup.service> structuredAttrs is enabled building '/nix/store/gibl8vf5nh7rz7km47zqnhslnk5xdf1d-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/4b2qclyk27xay6ar619c5acmkskacj4y-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wwlslfgw81qzfz9qlyr94hwf26df1iah-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/36cy4w2pi2w6k7jg152rzzpm1plchm8z-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/kx6mamh3kwimxnppg229zxy58cb8bgpr-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/wwlslfgw81qzfz9qlyr94hwf26df1iah-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/d7kgyvbw6k4b3qpsbhrgp60hg0dd7df9-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/4b2qclyk27xay6ar619c5acmkskacj4y-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/iczvp7a1zyf41wzdhbxx3m3fzb4z39zl-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/hylqa47xmlzklb4mr8hi3kb4bvj1bb5f-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/dbw90gxma3wms6h7svs7gqvjij38f9n0-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3f4j3in4icr0w7mmf5azp7wrbb87lvrd-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/2afbh3vl9b4wqmi7rhmal5s3lqq5d2di-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/36cy4w2pi2w6k7jg152rzzpm1plchm8z-user-units.drv' building '/nix/store/ilmc2rj57mwbi2mjz8f84ifndsv83qn7-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/d7kgyvbw6k4b3qpsbhrgp60hg0dd7df9-user-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/iczvp7a1zyf41wzdhbxx3m3fzb4z39zl-system-units.drv' building '/nix/store/dbw90gxma3wms6h7svs7gqvjij38f9n0-system-units.drv' building '/nix/store/2afbh3vl9b4wqmi7rhmal5s3lqq5d2di-user-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/ilmc2rj57mwbi2mjz8f84ifndsv83qn7-system-units.drv' building '/nix/store/96z1nya4phwbfg3jaivl9gm73ni265x2-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/bl26lxig1nxs8v53kz5ldfar0lv058qb-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p2afnx0grm7k6hb2i24daqbnjjdzmkp9-etc.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/p2afnx0grm7k6hb2i24daqbnjjdzmkp9-etc.drv' building '/nix/store/bl26lxig1nxs8v53kz5ldfar0lv058qb-etc.drv' building '/nix/store/m2dpp5zyadkyzx76wvkfsz4km9krk5mq-activate.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/mfzcfhs93p76qlxjbk76zgvfvzw983nc-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/96z1nya4phwbfg3jaivl9gm73ni265x2-etc.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/6iqp3w8xkd1kvmlijfz0jlrx5yv0dbj6-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/m2dpp5zyadkyzx76wvkfsz4km9krk5mq-activate.drv' building '/nix/store/cc3z1gzghwrm8gkqlmz0j2127g2h2vv8-nixos-system-ca-test.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/mfzcfhs93p76qlxjbk76zgvfvzw983nc-activate.drv' building '/nix/store/6iqp3w8xkd1kvmlijfz0jlrx5yv0dbj6-activate.drv' building '/nix/store/li9ychnih4daxqa5jybw82yym5l1x5a5-nixos-system-server-test.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/1j1r5vl57kg1ys7ygqaw1n1qbkkg2r3h-nixos-system-client-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/1j1r5vl57kg1ys7ygqaw1n1qbkkg2r3h-nixos-system-client-test.drv' nixos-system-client-test> structuredAttrs is enabled building '/nix/store/7y65k5c6xap6176dxk0ylcxdl9al2s9r-run-client-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/li9ychnih4daxqa5jybw82yym5l1x5a5-nixos-system-server-test.drv' nixos-system-server-test> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/sifhnisbimh4dzik8ja1m83nqgm1pd8c-run-server-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/cc3z1gzghwrm8gkqlmz0j2127g2h2vv8-nixos-system-ca-test.drv' nixos-system-ca-test> structuredAttrs is enabled building '/nix/store/wdqp1chk06hkdwxr558vnr7s5jvng4dy-run-ca-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7y65k5c6xap6176dxk0ylcxdl9al2s9r-run-client-nspawn.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/wdqp1chk06hkdwxr558vnr7s5jvng4dy-run-ca-nspawn.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/sifhnisbimh4dzik8ja1m83nqgm1pd8c-run-server-nspawn.drv' building '/nix/store/75q7wqalg6xzcvgz0hj5kh46vam2jbxn-driverConfiguration.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/75q7wqalg6xzcvgz0hj5kh46vam2jbxn-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/xbwnpn42v35vn5kwfr1km6n7rjjl3bmc-nixos-test-driver-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/xbwnpn42v35vn5kwfr1km6n7rjjl3bmc-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/zdwf49xlvsz2yhav45mas4f5n8q2pc3g-container-test-run-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/zdwf49xlvsz2yhav45mas4f5n8q2pc3g-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> ca: systemd-nspawn running (pid 52) container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> server: systemd-nspawn running (pid 55) container-test-run-certificates> client: systemd-nspawn running (pid 56) container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.00 seconds) container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> ca # [6500611.861316] ca systemd-journald[78]: Journal started container-test-run-certificates> ca # [6500611.861381] ca systemd-journald[78]: Runtime Journal (/run/log/journal/2a921ad8cd154f2989f75d2fd5cf3562) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> ca # [6500611.869281] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [6500611.870065] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [6500611.871091] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [6500611.880106] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/2a921ad8cd154f2989f75d2fd5cf3562 is 1.589ms for 5 entries. container-test-run-certificates> ca # [6500611.880106] ca systemd-journald[78]: System Journal (/var/log/journal/2a921ad8cd154f2989f75d2fd5cf3562) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [6500611.889459] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [6500611.890654] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> ca # [6500611.890769] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [6500611.891591] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [6500611.891638] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [6500611.892919] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [6500611.892969] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [6500611.900946] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> ca # [6500611.903444] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [6500611.917696] ca systemd-tmpfiles[123]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> ca # [6500611.917913] ca systemd-tmpfiles[123]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> ca # [6500611.918061] ca systemd-tmpfiles[123]: fchmod() of /var/log/journal/2a921ad8cd154f2989f75d2fd5cf3562 failed: Operation not permitted container-test-run-certificates> ca # [6500611.918278] ca systemd-tmpfiles[123]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> ca # [6500611.919931] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> ca # [6500611.920948] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> ca # [6500611.921627] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [6500611.928097] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> ca # [6500611.932993] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [6500611.940185] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> ca # [6500611.941636] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> ca # [6500611.951788] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [6500611.857405] server systemd-journald[69]: Journal started container-test-run-certificates> server # [6500611.857466] server systemd-journald[69]: Runtime Journal (/run/log/journal/37f6c3329ee44a62ae708ed5ffa2fd5c) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> server # [6500611.864803] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> server # [6500611.865573] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> server # [6500611.866267] server systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> server # [6500611.873572] server systemd-journald[69]: Time spent on flushing to /var/log/journal/37f6c3329ee44a62ae708ed5ffa2fd5c is 1.602ms for 5 entries. container-test-run-certificates> server # [6500611.873572] server systemd-journald[69]: System Journal (/var/log/journal/37f6c3329ee44a62ae708ed5ffa2fd5c) is 8M, max 4G, 3.9G free. container-test-run-certificates> server # [6500611.884823] server systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> server # [6500611.885533] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> server # [6500611.885649] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> server # [6500611.886487] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> server # [6500611.886530] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6500611.887371] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [6500611.887410] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [6500611.901134] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [6500611.903018] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> server # [6500611.920585] server systemd-tmpfiles[119]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [6500611.920797] server systemd-tmpfiles[119]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [6500611.850824] client systemd-journald[69]: Journal started container-test-run-certificates> server # [6500611.921169] server systemd-tmpfiles[119]: fchmod() of /var/log/journal/37f6c3329ee44a62ae708ed5ffa2fd5c failed: Operation not permitted container-test-run-certificates> client # [6500611.850882] client systemd-journald[69]: Runtime Journal (/run/log/journal/68f0507a662d47329cd277824b4ceed4) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> server # [6500611.921376] server systemd-tmpfiles[119]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [6500611.852408] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> server # [6500611.923687] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [6500611.924833] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [6500611.925596] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [6500611.925936] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [6500611.937864] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [6500611.943449] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [6500611.944465] server systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [6500611.953404] server systemd[1]: Finished Update is Completed. container-test-run-certificates> client # [6500611.861447] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [6500611.862344] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [6500611.863225] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [6500611.872581] client systemd-journald[69]: Time spent on flushing to /var/log/journal/68f0507a662d47329cd277824b4ceed4 is 1.544ms for 6 entries. container-test-run-certificates> client # [6500611.872581] client systemd-journald[69]: System Journal (/var/log/journal/68f0507a662d47329cd277824b4ceed4) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [6500611.879377] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [6500611.880084] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [6500611.880224] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [6500611.881072] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [6500611.881114] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [6500611.882022] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> client # [6500611.882059] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> client # [6500611.900472] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [6500611.901706] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> client # [6500611.916904] client systemd-tmpfiles[120]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [6500611.917114] client systemd-tmpfiles[120]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [6500611.917259] client systemd-tmpfiles[120]: fchmod() of /var/log/journal/68f0507a662d47329cd277824b4ceed4 failed: Operation not permitted container-test-run-certificates> client # [6500611.917485] client systemd-tmpfiles[120]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [6500611.919617] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> client # [6500611.920817] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> client # [6500611.921623] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> client # [6500611.927827] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> client # [6500611.933015] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> client # [6500611.940388] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> client # [6500611.941474] client systemd[1]: Starting Update is Completed... container-test-run-certificates> client # [6500611.952132] client systemd[1]: Finished Update is Completed. container-test-run-certificates> client # [6500612.076719] client systemd[1]: Finished Firewall. container-test-run-certificates> client # [6500612.076867] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [6500612.077080] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [6500612.078089] client systemd[1]: Starting Network Management... container-test-run-certificates> ca # [6500612.144177] ca systemd[1]: Finished Firewall. container-test-run-certificates> ca # [6500612.144363] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [6500612.144568] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> ca # [6500612.145665] ca systemd[1]: Starting Network Management... container-test-run-certificates> server # [6500612.144215] server systemd[1]: Finished Firewall. container-test-run-certificates> server # [6500612.144865] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> server # [6500612.145147] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [6500612.146248] server systemd[1]: Starting Network Management... container-test-run-certificates> client # [6500612.551313] client systemd-networkd[183]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6500612.551402] client systemd-networkd[183]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6500612.558414] client systemd-networkd[183]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [6500612.558572] client systemd-networkd[183]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [6500612.558726] client systemd-networkd[183]: lo: Link UP container-test-run-certificates> client # [6500612.558730] client systemd-networkd[183]: lo: Gained carrier container-test-run-certificates> client # [6500612.558897] client systemd-networkd[183]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [6500612.559276] client systemd[1]: Started Network Management. container-test-run-certificates> client # [6500612.559356] client systemd-networkd[183]: eth1: Link UP container-test-run-certificates> client # [6500612.559674] client systemd-networkd[183]: eth1: Gained carrier container-test-run-certificates> client # [6500612.560259] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> client # [6500612.581966] client systemd-resolved[93]: Positive Trust Anchors: container-test-run-certificates> client # [6500612.581976] client systemd-resolved[93]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> client # [6500612.581981] client systemd-resolved[93]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [6500612.582016] client systemd-resolved[93]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [6500612.600789] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> client # [6500612.604495] client systemd-resolved[93]: Using system hostname 'client'. container-test-run-certificates> client # [6500612.605849] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> client # [6500612.605973] client systemd[1]: Reached target Network. container-test-run-certificates> client # [6500612.606087] client systemd[1]: Reached target System Initialization. container-test-run-certificates> client # [6500612.606182] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [6500612.606242] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> client # [6500612.606280] client systemd[1]: Reached target Timer Units. container-test-run-certificates> client # [6500612.606500] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [6500612.606713] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> client # [6500612.606925] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> client # [6500612.606972] client systemd[1]: Reached target Socket Units. container-test-run-certificates> client # [6500612.607053] client systemd[1]: Reached target Basic System. container-test-run-certificates> client # [6500612.608791] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> client # [6500612.610283] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> client # [6500612.612540] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> client # [6500612.631712] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> client # [6500612.794059] client nsncd[189]: Aug 23 05:07:18.847 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [6500612.794211] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [6500612.794319] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [6500612.794419] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> client # [6500612.796394] client systemd[1]: Starting User Login Management... container-test-run-certificates> client # [6500612.797872] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [6500612.565875] server systemd-networkd[187]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [6500612.565960] server systemd-networkd[187]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [6500612.573153] server systemd-networkd[187]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [6500612.573468] server systemd-networkd[187]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [6500612.573608] server systemd-networkd[187]: lo: Link UP container-test-run-certificates> server # [6500612.573612] server systemd-networkd[187]: lo: Gained carrier container-test-run-certificates> server # [6500612.573775] server systemd-networkd[187]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [6500612.574188] server systemd[1]: Started Network Management. container-test-run-certificates> server # [6500612.592196] server systemd-resolved[92]: Positive Trust Anchors: container-test-run-certificates> server # [6500612.592206] server systemd-resolved[92]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [6500612.592209] server systemd-resolved[92]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [6500612.592245] server systemd-resolved[92]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [6500612.592337] server systemd-networkd[187]: eth1: Link UP container-test-run-certificates> server # [6500612.592677] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> server # [6500612.592713] server systemd-networkd[187]: eth1: Gained carrier container-test-run-certificates> server # [6500612.614036] server systemd-resolved[92]: Using system hostname 'server'. container-test-run-certificates> server # [6500612.615309] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [6500612.615390] server systemd[1]: Reached target Network. container-test-run-certificates> server # [6500612.615457] server systemd[1]: Reached target Network is Online. container-test-run-certificates> server # [6500612.615505] server systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [6500612.615723] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> server # [6500612.615756] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6500612.615782] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [6500612.615804] server systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [6500612.615934] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [6500612.616063] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [6500612.616187] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [6500612.616216] server systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [6500612.616259] server systemd[1]: Reached target Basic System. container-test-run-certificates> server # [6500612.617562] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> server # [6500612.618409] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [6500612.618451] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> server # [6500612.619349] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [6500612.620787] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [6500612.640256] server systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [6500612.646081] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [6500612.743524] server acme-setup-privileged[191]: + set -euo pipefail container-test-run-certificates> server # [6500612.743524] server acme-setup-privileged[191]: + cd /var/lib/acme container-test-run-certificates> server # [6500612.743964] server acme-setup-privileged[191]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> server # [6500612.745202] server acme-setup-privileged[191]: + chown -R acme .lego/accounts container-test-run-certificates> server # [6500612.746805] server acme-setup-privileged[191]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [6500612.746839] server acme-setup-privileged[191]: + '[' -d test.foo ']' container-test-run-certificates> server # [6500612.746839] server acme-setup-privileged[191]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [6500612.746839] server acme-setup-privileged[191]: + '[' -d .lego/test.foo ']' container-test-run-certificates> server # [6500612.779450] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> server # [6500612.779708] server nsncd[193]: Aug 23 05:07:18.832 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> server # [6500612.779536] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> server # [6500612.779605] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [6500612.780960] server systemd[1]: Starting User Login Management... container-test-run-certificates> server # [6500612.782072] server systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [6500612.792687] server systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [6500612.794425] server systemd[1]: Started Console Getty. container-test-run-certificates> server # [6500612.794476] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [6500612.794497] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca # [6500612.567360] ca systemd-networkd[196]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [6500612.567439] ca systemd-networkd[196]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [6500612.574573] ca systemd-networkd[196]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [6500612.574737] ca systemd-networkd[196]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [6500612.574875] ca systemd-networkd[196]: lo: Link UP container-test-run-certificates> ca # [6500612.574879] ca systemd-networkd[196]: lo: Gained carrier container-test-run-certificates> ca # [6500612.575054] ca systemd-networkd[196]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> ca # [6500612.575414] ca systemd[1]: Started Network Management. container-test-run-certificates> ca # [6500612.587751] ca systemd-resolved[99]: Positive Trust Anchors: container-test-run-certificates> ca # [6500612.587761] ca systemd-resolved[99]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [6500612.587765] ca systemd-resolved[99]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [6500612.587799] ca systemd-resolved[99]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [6500612.592489] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [6500612.592674] ca systemd-networkd[196]: eth1: Link UP container-test-run-certificates> ca # [6500612.592984] ca systemd-networkd[196]: eth1: Gained carrier container-test-run-certificates> ca # [6500612.609344] ca systemd-resolved[99]: Using system hostname 'ca'. container-test-run-certificates> ca # [6500612.610656] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [6500612.610777] ca systemd[1]: Reached target Network. container-test-run-certificates> ca # [6500612.610886] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [6500612.610983] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [6500612.611341] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> ca # [6500612.611392] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [6500612.611439] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [6500612.611477] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> ca # [6500612.611692] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> ca # [6500612.611883] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [6500612.612127] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [6500612.612180] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [6500612.612265] ca systemd[1]: Reached target Basic System. container-test-run-certificates> ca # [6500612.614404] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> ca # [6500612.615705] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [6500612.615778] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> ca # [6500612.617196] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [6500612.618873] ca systemd[1]: Starting step-ca service... container-test-run-certificates> ca # [6500612.621275] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> ca # [6500612.640921] ca systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> ca # [6500612.643220] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> ca # [6500612.777410] ca acme-setup-privileged[200]: + set -euo pipefail container-test-run-certificates> ca # [6500612.777410] ca acme-setup-privileged[200]: + cd /var/lib/acme container-test-run-certificates> ca # [6500612.777410] ca acme-setup-privileged[200]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> ca # [6500612.779225] ca acme-setup-privileged[200]: + chown -R acme .lego/accounts container-test-run-certificates> ca # [6500612.780879] ca acme-setup-privileged[200]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [6500612.780924] ca acme-setup-privileged[200]: + '[' -d ca.foo ']' container-test-run-certificates> ca # [6500612.780924] ca acme-setup-privileged[200]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [6500612.780924] ca acme-setup-privileged[200]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> ca # [6500612.797793] ca nsncd[202]: Aug 23 05:07:18.850 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [6500612.797977] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [6500612.798088] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [6500612.798195] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [6500612.800195] ca systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [6500612.801414] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [6500612.811375] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [6500612.812723] ca systemd[1]: Started Console Getty. container-test-run-certificates> ca # [6500612.812775] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> ca # [6500612.812797] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca # [6500612.846125] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> client # [6500612.808282] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> client # [6500612.810161] client systemd[1]: Started Console Getty. container-test-run-certificates> client # [6500612.810211] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> client # [6500612.810237] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> client # [6500612.835064] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> client # [6500612.895904] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> client # [6500612.896873] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [6500612.896873] client dbus-broker-launch[190]: Invalid user-name in /nix/store/s0a40wv0lnwiz13r43fk318ri3wv536k-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [6500612.897249] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> client # [6500612.904814] client dbus-broker-launch[190]: Ready container-test-run-certificates> ca # [6500612.921347] ca dbus-broker-launch[204]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [6500612.922186] ca dbus-broker-launch[204]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> ca # [6500612.922186] ca dbus-broker-launch[204]: Invalid user-name in /nix/store/mfvkn1zwby5692v4kx3ynjdz34b2lkq3-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> ca # [6500612.922599] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [6500612.929789] ca dbus-broker-launch[204]: Ready container-test-run-certificates> server # [6500612.843470] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [6500612.914133] server dbus-broker-launch[194]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [6500612.916228] server dbus-broker-launch[194]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [6500612.916228] server dbus-broker-launch[194]: Invalid user-name in /nix/store/lxnlg1wvz5bx4xfzc75k21l11ngxkyck-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [6500612.916606] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [6500612.926656] server dbus-broker-launch[194]: Ready container-test-run-certificates> ca # [6500613.271567] ca systemd-logind[235]: New seat seat0. container-test-run-certificates> ca # [6500613.271840] ca systemd[1]: Started User Login Management. container-test-run-certificates> ca # [6500613.300737] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> ca # [6500613.312549] ca acme-setup-start[219]: + set -euo pipefail container-test-run-certificates> ca # [6500613.312549] ca acme-setup-start[219]: + test -e ca/key.pem container-test-run-certificates> ca # [6500613.313125] ca acme-setup-start[219]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [6500613.313412] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [6500613.313491] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [6500613.331359] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [6500613.332904] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> server # [6500613.251252] server systemd-logind[224]: New seat seat0. container-test-run-certificates> server # [6500613.251481] server systemd[1]: Started User Login Management. container-test-run-certificates> server # [6500613.253549] server systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [6500613.284169] server acme-setup-start[208]: + set -euo pipefail container-test-run-certificates> server # [6500613.284169] server acme-setup-start[208]: + test -e ca/key.pem container-test-run-certificates> server # [6500613.284169] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> server # [6500613.308584] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> server # [6500613.311202] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server # [6500613.311779] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> server # [6500613.311958] server systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [6500613.252934] client systemd-logind[205]: New seat seat0. container-test-run-certificates> client # [6500613.253103] client systemd[1]: Started User Login Management. container-test-run-certificates> client # [6500613.254947] client systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [6500613.311755] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> client # [6500613.311927] client systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [6500613.312516] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> client # [6500613.312785] client systemd[1]: Startup finished in 1.854s. container-test-run-certificates> ca # [6500613.549326] ca step-ca[203]: badger 2026/08/23 05:07:19 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [6500613.553143] ca step-ca[203]: 2026/08/23 05:07:19 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> ca # [6500613.558816] ca step-ca[203]: 2026/08/23 05:07:19 Starting Smallstep CA/0.30.2 (linux/arm64) container-test-run-certificates> ca # [6500613.558816] ca step-ca[203]: 2026/08/23 05:07:19 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> ca # [6500613.558816] ca step-ca[203]: 2026/08/23 05:07:19 Community Discord: https://u.step.sm/discord container-test-run-certificates> ca # [6500613.558816] ca step-ca[203]: 2026/08/23 05:07:19 Config file: /etc/smallstep/ca.json container-test-run-certificates> ca # [6500613.558816] ca step-ca[203]: 2026/08/23 05:07:19 The primary server URL is https://ca.foo:1443 container-test-run-certificates> ca # [6500613.558816] ca step-ca[203]: 2026/08/23 05:07:19 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [6500613.559125] ca step-ca[203]: 2026/08/23 05:07:19 X.509 Root Fingerprint: fcec151c7705057538ab7b446472065d7ea631e5f4168a5856ccb5b20a98592a container-test-run-certificates> ca # [6500613.559465] ca systemd[1]: Started step-ca service. container-test-run-certificates> ca # [6500613.559885] ca step-ca[203]: 2026/08/23 05:07:19 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> ca # [6500613.732248] ca systemd-networkd[196]: eth1: Gained IPv6LL container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> server # [6500613.794091] server acme-test.foo-start[244]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6500613.796916] server acme-test.foo-start[244]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [6500613.797002] server acme-test.foo-start[244]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [6500613.812135] server acme-test.foo-start[255]: + cd test.foo container-test-run-certificates> server # [6500613.812135] server acme-test.foo-start[255]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [6500613.813939] server acme-test.foo-start[256]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [6500613.814281] server acme-test.foo-start[255]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [6500613.815419] server acme-test.foo-start[255]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [6500613.815674] server acme-test.foo-start[244]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [6500613.817430] server acme-test.foo-start[244]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [6500613.819128] server acme-test.foo-start[244]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6500613.821041] server acme-test.foo-start[244]: + for fixpath in out certificates container-test-run-certificates> server # [6500613.821041] server acme-test.foo-start[244]: + '[' -d out ']' container-test-run-certificates> server # [6500613.821147] server acme-test.foo-start[244]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6500613.822626] server acme-test.foo-start[244]: + chown -R acme:nginx out container-test-run-certificates> server # [6500613.826215] server acme-test.foo-start[244]: + for fixpath in out certificates container-test-run-certificates> server # [6500613.826215] server acme-test.foo-start[244]: + '[' -d certificates ']' container-test-run-certificates> server # [6500613.829548] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [6500613.832119] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> ca # [6500613.826065] ca acme-ca.foo-start[256]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6500613.829999] ca acme-ca.foo-start[256]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [6500613.829999] ca acme-ca.foo-start[256]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> ca # [6500613.845408] ca acme-ca.foo-start[294]: + cd ca.foo container-test-run-certificates> ca # [6500613.845955] ca acme-ca.foo-start[294]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> ca # [6500613.847186] ca acme-ca.foo-start[295]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [6500613.847495] ca acme-ca.foo-start[294]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> ca # [6500613.848745] ca acme-ca.foo-start[294]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [6500613.848971] ca acme-ca.foo-start[256]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [6500613.850966] ca acme-ca.foo-start[256]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [6500613.852786] ca acme-ca.foo-start[256]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [6500613.854564] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [6500613.854564] ca acme-ca.foo-start[256]: + '[' -d out ']' container-test-run-certificates> ca # [6500613.854666] ca acme-ca.foo-start[256]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6500613.856138] ca acme-ca.foo-start[256]: + chown -R acme:nginx out container-test-run-certificates> ca # [6500613.859559] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [6500613.859610] ca acme-ca.foo-start[256]: + '[' -d certificates ']' container-test-run-certificates> ca # [6500613.868317] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> ca # [6500613.870679] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> server # [6500614.144189] server systemd-networkd[187]: eth1: Gained IPv6LL container-test-run-certificates> server # [6500614.380547] server nginx-pre-start[267]: nginx: the configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf syntax is ok container-test-run-certificates> server # [6500614.381111] server nginx-pre-start[267]: nginx: configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf test is successful container-test-run-certificates> server # [6500614.387477] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [6500614.388399] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [6500614.390661] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> ca # [6500614.380742] ca nginx-pre-start[306]: nginx: the configuration file /nix/store/lfwd10qpyi3s44q1cn5nrgcwqdpyj8fr-nginx.conf syntax is ok container-test-run-certificates> ca # [6500614.381301] ca nginx-pre-start[306]: nginx: configuration file /nix/store/lfwd10qpyi3s44q1cn5nrgcwqdpyj8fr-nginx.conf test is successful container-test-run-certificates> ca # [6500614.386980] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [6500614.387861] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [6500614.390157] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> client # [6500614.592474] client systemd-networkd[183]: eth1: Gained IPv6LL container-test-run-certificates> server # [6500614.949405] server acme-order-renew-test.foo-start[270]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6500614.952430] server acme-order-renew-test.foo-start[270]: + set -euo pipefail container-test-run-certificates> server # [6500614.952505] server acme-order-renew-test.foo-start[270]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [6500614.952629] server acme-order-renew-test.foo-start[270]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [6500614.954363] server acme-order-renew-test.foo-start[270]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> ca # [6500614.981200] ca acme-order-renew-ca.foo-start[309]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6500614.986951] server acme-order-renew-test.foo-start[282]: 2026/08/23 05:07:21 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [6500614.984214] ca acme-order-renew-ca.foo-start[309]: + set -euo pipefail container-test-run-certificates> server # [6500614.987308] server acme-order-renew-test.foo-start[282]: 2026/08/23 05:07:21 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [6500614.984294] ca acme-order-renew-ca.foo-start[309]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> server # [6500615.019164] server acme-order-renew-test.foo-start[282]: 2026/08/23 05:07:21 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority container-test-run-certificates> ca # [6500614.984415] ca acme-order-renew-ca.foo-start[309]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [6500615.019647] server acme-order-renew-test.foo-start[270]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> ca # [6500614.985486] ca acme-order-renew-ca.foo-start[309]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> server # [6500615.019647] server acme-order-renew-test.foo-start[270]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> ca # [6500615.001540] ca acme-order-renew-ca.foo-start[321]: 2026/08/23 05:07:21 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [6500615.019711] server acme-order-renew-test.foo-start[270]: + exit 10 container-test-run-certificates> ca # [6500615.001870] ca acme-order-renew-ca.foo-start[321]: 2026/08/23 05:07:21 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> server # [6500615.024294] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a container-test-run-certificates> ca # [6500615.030121] ca step-ca[203]: time="2026-08-23T05:07:21Z" level=info duration="140.802µs" duration-ns=140802 fields.time="2026-08-23T05:07:21Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=548494c3-34f7-474e-8301-1ce479c80ffe response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> server # [6500615.024493] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'. container-test-run-certificates> ca # [6500615.030578] ca acme-order-renew-ca.foo-start[321]: 2026/08/23 05:07:21 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [6500615.024903] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo. container-test-run-certificates> ca # [6500615.064964] ca step-ca[203]: time="2026-08-23T05:07:21Z" level=info duration=34.12683ms duration-ns=34126830 fields.time="2026-08-23T05:07:21Z" method=HEAD name=ca nonce=WDVpZkRUSThiTjh3SlpXSzFVUVBIM0pkVnFpaXRZeHY path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=75fa54f2-aecd-46ff-adbf-61d24d9ff185 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> server # [6500615.025397] server systemd[1]: Startup finished in 3.551s. container-test-run-certificates> ca # [6500615.070946] ca step-ca[203]: time="2026-08-23T05:07:21Z" level=info duration=4.845987ms duration-ns=4845987 fields.time="2026-08-23T05:07:21Z" method=POST name=ca nonce=N1N5R2o3ZnFZemg4aFZBbkNGVXhnTElTb2RZbzU4Rm4 path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=4d4afc02-c130-4244-b678-772bdcabdbe6 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/G5R8VvwgrrJVywpJufSegqCZbjp4aoIr/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6500615.071504] ca acme-order-renew-ca.foo-start[321]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [6500615.071504] ca acme-order-renew-ca.foo-start[321]: Your account credentials have been saved in your container-test-run-certificates> ca # [6500615.071504] ca acme-order-renew-ca.foo-start[321]: configuration directory at "accounts". container-test-run-certificates> ca # [6500615.071504] ca acme-order-renew-ca.foo-start[321]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [6500615.071504] ca acme-order-renew-ca.foo-start[321]: configuration directory will also contain private keys container-test-run-certificates> ca # [6500615.071504] ca acme-order-renew-ca.foo-start[321]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [6500615.071504] ca acme-order-renew-ca.foo-start[321]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [6500615.071637] ca acme-order-renew-ca.foo-start[321]: 2026/08/23 05:07:21 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [6500615.077920] ca step-ca[203]: time="2026-08-23T05:07:21Z" level=info duration=5.101351ms duration-ns=5101351 fields.time="2026-08-23T05:07:21Z" method=POST name=ca nonce=ZDlQS3V4UEpVaGhoR2JrMXBveGc3SDlQZ0FtMHFYTXk path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=39f0c766-178e-4479-924a-886eb685e66e response="{\"id\":\"CXpO6n2ZbXn2Bho3QxH0UbptGRGnlaj8\",\"status\":\"pending\",\"expires\":\"2026-08-24T05:07:21Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-23T05:06:21Z\",\"notAfter\":\"2026-11-21T05:07:21Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/kvXGJMkXSxLUgqhgEvmnAOBKUnULZOIs\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/CXpO6n2ZbXn2Bho3QxH0UbptGRGnlaj8/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6500615.137419] ca step-ca[203]: time="2026-08-23T05:07:21Z" level=info duration=2.17059ms duration-ns=2170590 fields.time="2026-08-23T05:07:21Z" method=POST name=ca nonce=SXRQSXJTREthdzZOVkJKYmdxbmpzOXowZ3RRTGlkNlE path=/acme/acme/authz/kvXGJMkXSxLUgqhgEvmnAOBKUnULZOIs protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=773bd64c-ba93-4ed9-9768-5a3d1dc339d5 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"fHXaEl3PYFw1ysZJgvSom07qQF7PTFxY\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/kvXGJMkXSxLUgqhgEvmnAOBKUnULZOIs/VWnhR7wyAWWHZaXSfFBCShY5Rr1XAdHu\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"fHXaEl3PYFw1ysZJgvSom07qQF7PTFxY\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/kvXGJMkXSxLUgqhgEvmnAOBKUnULZOIs/XasNQ7IiMyQQY8KBjLoSV6fDJtlRmJ0R\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"fHXaEl3PYFw1ysZJgvSom07qQF7PTFxY\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/kvXGJMkXSxLUgqhgEvmnAOBKUnULZOIs/sTNDgBbN06jXY5MefWWSaFDKXORUQk0F\"}],\"wildcard\":false,\"expires\":\"2026-08-24T05:07:21Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6500615.137835] ca acme-order-renew-ca.foo-start[321]: 2026/08/23 05:07:21 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/kvXGJMkXSxLUgqhgEvmnAOBKUnULZOIs container-test-run-certificates> ca # [6500615.137835] ca acme-order-renew-ca.foo-start[321]: 2026/08/23 05:07:21 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [6500615.137903] ca acme-order-renew-ca.foo-start[321]: 2026/08/23 05:07:21 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [6500615.137903] ca acme-order-renew-ca.foo-start[321]: 2026/08/23 05:07:21 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> ca # [6500615.143245] ca step-ca[203]: time="2026-08-23T05:07:21Z" level=info duration=4.543663ms duration-ns=4543663 fields.time="2026-08-23T05:07:21Z" method=POST name=ca nonce=eG9pbVBka1lhZjRORmRZc0ZWVjVpYlc5MDhpR1poVmM path=/acme/acme/challenge/kvXGJMkXSxLUgqhgEvmnAOBKUnULZOIs/XasNQ7IiMyQQY8KBjLoSV6fDJtlRmJ0R protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=338e0c7c-c3c9-49a2-be57-6ac950dc4155 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"fHXaEl3PYFw1ysZJgvSom07qQF7PTFxY\",\"validated\":\"2026-08-23T05:07:21Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/kvXGJMkXSxLUgqhgEvmnAOBKUnULZOIs/XasNQ7IiMyQQY8KBjLoSV6fDJtlRmJ0R\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6500615.143655] ca acme-order-renew-ca.foo-start[321]: 2026/08/23 05:07:21 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [6500615.143759] ca acme-order-renew-ca.foo-start[321]: 2026/08/23 05:07:21 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [6500615.153901] ca step-ca[203]: time="2026-08-23T05:07:21Z" level=info duration=8.353075ms duration-ns=8353075 fields.time="2026-08-23T05:07:21Z" method=POST name=ca nonce=YnFDNkh6S3JrcW5KNm4xdm9iUU1hN0JlREJ0Rmk0UmE path=/acme/acme/order/CXpO6n2ZbXn2Bho3QxH0UbptGRGnlaj8/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=50394c24-e025-4d2e-b144-6518c5e72a7f response="{\"id\":\"CXpO6n2ZbXn2Bho3QxH0UbptGRGnlaj8\",\"status\":\"valid\",\"expires\":\"2026-08-24T05:07:21Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-23T05:06:21Z\",\"notAfter\":\"2026-11-21T05:07:21Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/kvXGJMkXSxLUgqhgEvmnAOBKUnULZOIs\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/CXpO6n2ZbXn2Bho3QxH0UbptGRGnlaj8/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/I4eGuXnaFODGmMnw9z2N6PYIFc79EsCC\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6500615.156748] ca step-ca[203]: time="2026-08-23T05:07:21Z" level=info certificate=MIIB0zCCAXmgAwIBAgIQLL+SdUkxaVehxXVozU3fGzAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MjMwNTA2MjFaFw0yNjExMjEwNTA3MjFaMBExDzANBgNVBAMTBmNhLmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABHpcXSAt9JBTZpXzJjzyh/SHfk1Wcs7MRTFpKvERZ6zRgWCTo5+ON2rvepKVSAgoRb7RvX4up3TqmlS0qgMMMUajgaQwgaEwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQURdoTElgWrVYb7AqodImklu7+hVEwHwYDVR0jBBgwFoAUBhLd2fH1XPFp+3X9Op4Cu9r3zY0wEQYDVR0RBAowCIIGY2EuZm9vMB0GDCsGAQQBgqRkxihAAQQNMAsCAQYEBGFjbWUEADAKBggqhkjOPQQDAgNIADBFAiEAzE8DOqyfwbLcJMzOgh53FVeQHvZHKfS/XXb9eQQq8OgCIHBUAA9y2hXBpFUhN7PYVj83RN+H+1zHvnCP0u6sTB1V duration=1.821105ms duration-ns=1821105 fields.time="2026-08-23T05:07:21Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=dlg0TnhaQzU0b3UwdzRKbnI4Zk9NNnRkMGttd0NxcGM path=/acme/acme/certificate/I4eGuXnaFODGmMnw9z2N6PYIFc79EsCC protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=0ef02efc-43a8-4b55-b8cc-bf6a4ce03cf6 sans="map[dns:[ca.foo]]" serial=59480731038665738344749825069994073883 size=1340 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-23T05:06:21Z" valid-to="2026-11-21T05:07:21Z" container-test-run-certificates> ca # [6500615.157066] ca acme-order-renew-ca.foo-start[321]: 2026/08/23 05:07:21 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [6500615.163447] ca acme-order-renew-ca.foo-start[309]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [6500615.165175] ca acme-order-renew-ca.foo-start[309]: + touch out/acme-success container-test-run-certificates> ca # [6500615.166944] ca acme-order-renew-ca.foo-start[309]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6500615.168255] ca acme-order-renew-ca.foo-start[309]: + touch out/renewed container-test-run-certificates> ca # [6500615.170086] ca acme-order-renew-ca.foo-start[309]: + echo Installing new certificate container-test-run-certificates> ca # [6500615.170086] ca acme-order-renew-ca.foo-start[309]: Installing new certificate container-test-run-certificates> ca # [6500615.170129] ca acme-order-renew-ca.foo-start[309]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6500615.171763] ca acme-order-renew-ca.foo-start[353]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [6500615.171995] ca acme-order-renew-ca.foo-start[309]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [6500615.173507] ca acme-order-renew-ca.foo-start[354]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [6500615.173751] ca acme-order-renew-ca.foo-start[309]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [6500615.175152] ca acme-order-renew-ca.foo-start[355]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [6500615.175381] ca acme-order-renew-ca.foo-start[309]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [6500615.176875] ca acme-order-renew-ca.foo-start[309]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [6500615.178643] ca acme-order-renew-ca.foo-start[309]: + for fixpath in out certificates container-test-run-certificates> ca # [6500615.178665] ca acme-order-renew-ca.foo-start[309]: + '[' -d out ']' container-test-run-certificates> ca # [6500615.178665] ca acme-order-renew-ca.foo-start[309]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6500615.180210] ca acme-order-renew-ca.foo-start[309]: + chown -R acme:nginx out container-test-run-certificates> ca # [6500615.182670] ca acme-order-renew-ca.foo-start[309]: + for fixpath in out certificates container-test-run-certificates> ca # [6500615.182706] ca acme-order-renew-ca.foo-start[309]: + '[' -d certificates ']' container-test-run-certificates> ca # [6500615.182706] ca acme-order-renew-ca.foo-start[309]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [6500615.184450] ca acme-order-renew-ca.foo-start[309]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [6500615.187374] ca acme-order-renew-ca.foo-start[309]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6500615.322770] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> ca # [6500615.326710] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [6500615.326902] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> ca # [6500615.875183] ca nginx[371]: nginx: the configuration file /nix/store/lfwd10qpyi3s44q1cn5nrgcwqdpyj8fr-nginx.conf syntax is ok container-test-run-certificates> ca # [6500615.875824] ca nginx[371]: nginx: configuration file /nix/store/lfwd10qpyi3s44q1cn5nrgcwqdpyj8fr-nginx.conf test is successful container-test-run-certificates> ca # [6500616.401291] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [6500616.401789] ca systemd[1]: Startup finished in 4.907s. container-test-run-certificates> ca # [6500616.634000] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 3.37 seconds) container-test-run-certificates> ca # [6500617.160546] ca acme-order-renew-ca.foo-start[386]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6500617.163402] ca acme-order-renew-ca.foo-start[386]: + set -euo pipefail container-test-run-certificates> ca # [6500617.163477] ca acme-order-renew-ca.foo-start[386]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [6500617.163580] ca acme-order-renew-ca.foo-start[386]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [6500617.164877] ca acme-order-renew-ca.foo-start[386]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [6500617.164909] ca acme-order-renew-ca.foo-start[386]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [6500617.165346] ca acme-order-renew-ca.foo-start[394]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [6500617.168394] ca acme-order-renew-ca.foo-start[386]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [6500617.168458] ca acme-order-renew-ca.foo-start[386]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [6500617.209228] ca step-ca[203]: time="2026-08-23T05:07:23Z" level=info duration="61.401µs" duration-ns=61401 fields.time="2026-08-23T05:07:23Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=3ad63061-f386-440a-9ebf-1620a28b6722 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6500617.209537] ca acme-order-renew-ca.foo-start[395]: 2026/08/23 05:07:23 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [6500617.209537] ca acme-order-renew-ca.foo-start[395]: 2026/08/23 05:07:23 [INFO] [ca.foo] The certificate expires at 2026-11-21T05:07:21Z, the renewal can be performed in 1439h59m37.737312855s: no renewal. container-test-run-certificates> ca # [6500617.210133] ca acme-order-renew-ca.foo-start[386]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [6500617.212185] ca acme-order-renew-ca.foo-start[386]: + touch out/acme-success container-test-run-certificates> ca # [6500617.213535] ca acme-order-renew-ca.foo-start[386]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6500617.214782] ca acme-order-renew-ca.foo-start[386]: + for fixpath in out certificates container-test-run-certificates> ca # [6500617.214804] ca acme-order-renew-ca.foo-start[386]: + '[' -d out ']' container-test-run-certificates> ca # [6500617.214804] ca acme-order-renew-ca.foo-start[386]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6500617.216311] ca acme-order-renew-ca.foo-start[386]: + chown -R acme:nginx out container-test-run-certificates> ca # [6500617.219235] ca acme-order-renew-ca.foo-start[386]: + for fixpath in out certificates container-test-run-certificates> ca # [6500617.219255] ca acme-order-renew-ca.foo-start[386]: + '[' -d certificates ']' container-test-run-certificates> ca # [6500617.219273] ca acme-order-renew-ca.foo-start[386]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [6500617.221023] ca acme-order-renew-ca.foo-start[386]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [6500617.223914] ca acme-order-renew-ca.foo-start[386]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6500617.315930] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [6500617.316263] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server # [6500620.348390] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [6500620.348760] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [6500620.350000] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [6500620.352271] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.55 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1009 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 23 05:07:19 2026 GMT container-test-run-certificates> * expire date: Sep 22 05:07:19 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 7f712c container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6500620.825977] server acme-test.foo-start[316]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6500620.828277] server acme-test.foo-start[316]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [6500620.828277] server acme-test.foo-start[316]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [6500620.841762] server acme-test.foo-start[326]: + cd test.foo container-test-run-certificates> server # [6500620.842281] server acme-test.foo-start[326]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [6500620.843177] server acme-test.foo-start[327]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [6500620.843485] server acme-test.foo-start[326]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [6500620.844473] server acme-test.foo-start[326]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [6500620.844676] server acme-test.foo-start[316]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [6500620.846112] server acme-test.foo-start[316]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [6500620.847916] server acme-test.foo-start[316]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6500620.850108] server acme-test.foo-start[316]: + for fixpath in out certificates container-test-run-certificates> server # [6500620.850108] server acme-test.foo-start[316]: + '[' -d out ']' container-test-run-certificates> server # [6500620.850203] server acme-test.foo-start[316]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6500620.851968] server acme-test.foo-start[316]: + chown -R acme:nginx out container-test-run-certificates> server # [6500620.854518] server acme-test.foo-start[316]: + for fixpath in out certificates container-test-run-certificates> server # [6500620.854518] server acme-test.foo-start[316]: + '[' -d certificates ']' container-test-run-certificates> server # [6500620.880267] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [6500620.883040] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> server # [6500621.345960] server acme-order-renew-test.foo-start[334]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6500621.348701] server acme-order-renew-test.foo-start[334]: + set -euo pipefail container-test-run-certificates> server # [6500621.348784] server acme-order-renew-test.foo-start[334]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [6500621.348887] server acme-order-renew-test.foo-start[334]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [6500621.349946] server acme-order-renew-test.foo-start[334]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [6500621.401353] server acme-order-renew-test.foo-start[342]: 2026/08/23 05:07:27 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [6500621.435275] server acme-order-renew-test.foo-start[342]: !!!! HEADS UP !!!! container-test-run-certificates> server # [6500621.435275] server acme-order-renew-test.foo-start[342]: Your account credentials have been saved in your container-test-run-certificates> server # [6500621.435275] server acme-order-renew-test.foo-start[342]: configuration directory at "accounts". container-test-run-certificates> server # [6500621.435275] server acme-order-renew-test.foo-start[342]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [6500621.435275] server acme-order-renew-test.foo-start[342]: configuration directory will also contain private keys container-test-run-certificates> server # [6500621.435275] server acme-order-renew-test.foo-start[342]: generated by lego and certificates obtained from the ACME container-test-run-certificates> server # [6500621.435275] server acme-order-renew-test.foo-start[342]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [6500621.435504] server acme-order-renew-test.foo-start[342]: 2026/08/23 05:07:27 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> server # [6500621.508973] server acme-order-renew-test.foo-start[342]: 2026/08/23 05:07:27 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/ACETKuLpYHJB507ZvDiEB1O8pdwBIKyl container-test-run-certificates> server # [6500621.508973] server acme-order-renew-test.foo-start[342]: 2026/08/23 05:07:27 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [6500621.508973] server acme-order-renew-test.foo-start[342]: 2026/08/23 05:07:27 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [6500621.508973] server acme-order-renew-test.foo-start[342]: 2026/08/23 05:07:27 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [6500621.514900] server acme-order-renew-test.foo-start[342]: 2026/08/23 05:07:27 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [6500621.514998] server acme-order-renew-test.foo-start[342]: 2026/08/23 05:07:27 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [6500621.532434] server acme-order-renew-test.foo-start[342]: 2026/08/23 05:07:27 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [6500621.537629] server acme-order-renew-test.foo-start[334]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [6500621.539398] server acme-order-renew-test.foo-start[334]: + touch out/acme-success container-test-run-certificates> server # [6500621.540976] server acme-order-renew-test.foo-start[334]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [6500621.541981] server acme-order-renew-test.foo-start[334]: + touch out/renewed container-test-run-certificates> server # [6500621.543879] server acme-order-renew-test.foo-start[334]: + echo Installing new certificate container-test-run-certificates> server # [6500621.543879] server acme-order-renew-test.foo-start[334]: Installing new certificate container-test-run-certificates> server # [6500621.543879] server acme-order-renew-test.foo-start[334]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [6500621.545212] server acme-order-renew-test.foo-start[373]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [6500621.545468] server acme-order-renew-test.foo-start[334]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [6500621.547212] server acme-order-renew-test.foo-start[374]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [6500621.547804] server acme-order-renew-test.foo-start[334]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [6500621.548897] server acme-order-renew-test.foo-start[375]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [6500621.549215] server acme-order-renew-test.foo-start[334]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [6500621.550694] server acme-order-renew-test.foo-start[334]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6500621.552766] server acme-order-renew-test.foo-start[334]: + for fixpath in out certificates container-test-run-certificates> server # [6500621.552766] server acme-order-renew-test.foo-start[334]: + '[' -d out ']' container-test-run-certificates> server # [6500621.552879] server acme-order-renew-test.foo-start[334]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6500621.554451] server acme-order-renew-test.foo-start[334]: + chown -R acme:nginx out container-test-run-certificates> server # [6500621.557937] server acme-order-renew-test.foo-start[334]: + for fixpath in out certificates container-test-run-certificates> server # [6500621.557937] server acme-order-renew-test.foo-start[334]: + '[' -d certificates ']' container-test-run-certificates> server # [6500621.557937] server acme-order-renew-test.foo-start[334]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [6500621.559535] server acme-order-renew-test.foo-start[334]: + chown -R acme:nginx certificates container-test-run-certificates> server # [6500621.562257] server acme-order-renew-test.foo-start[334]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> server # [6500621.676386] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> ca # [6500621.400750] ca step-ca[203]: time="2026-08-23T05:07:27Z" level=info duration="46.6µs" duration-ns=46600 fields.time="2026-08-23T05:07:27Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=f5d56d68-f43b-41b3-8a99-c47e8c073e92 response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6500621.427513] ca step-ca[203]: time="2026-08-23T05:07:27Z" level=info duration=24.020731ms duration-ns=24020731 fields.time="2026-08-23T05:07:27Z" method=HEAD name=ca nonce=U0RIQk41VUh1Y3didWI4YTdHUlFVdTNHVlBrUHNVMzk path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=89e49d32-f31f-4df6-9c05-abcfd0c74674 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6500621.434274] ca step-ca[203]: time="2026-08-23T05:07:27Z" level=info duration=3.125963ms duration-ns=3125963 fields.time="2026-08-23T05:07:27Z" method=POST name=ca nonce=TFNQQ2dMMGlQS2oyS2hwWDZjVWxlZVJEaDZsMk5XWks path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=6324d669-d3b2-48a2-b334-9d1a8031ced9 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/igIzwC3W85NeXgDRwp8lpZLI0ZVWVU2G/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6500621.441749] ca step-ca[203]: time="2026-08-23T05:07:27Z" level=info duration=3.034001ms duration-ns=3034001 fields.time="2026-08-23T05:07:27Z" method=POST name=ca nonce=ckJ4Q0VSNHZVdHBRTXVHWGNLNXUzdElEZlRja3M2Zjc path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=5e886723-2633-439a-b1a7-36d62ee3cafb response="{\"id\":\"RndZXJdzQRfnyMbfhxHerCvOnirDurtx\",\"status\":\"pending\",\"expires\":\"2026-08-24T05:07:27Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-23T05:06:27Z\",\"notAfter\":\"2026-11-21T05:07:27Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/ACETKuLpYHJB507ZvDiEB1O8pdwBIKyl\"],\"finalize\":\"https://ca.foo/acme/acme/order/RndZXJdzQRfnyMbfhxHerCvOnirDurtx/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6500621.508492] ca step-ca[203]: time="2026-08-23T05:07:27Z" level=info duration=5.889402ms duration-ns=5889402 fields.time="2026-08-23T05:07:27Z" method=POST name=ca nonce=S1Z5WWVncjNxTmlmWnpOQVkxa2dob2FpRlpQM0VQMkM path=/acme/acme/authz/ACETKuLpYHJB507ZvDiEB1O8pdwBIKyl protocol=HTTP/1.1 referer= remote-address="::1" request-id=b6c28cc4-788b-4b57-bd6f-d90a55209d19 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"VnHx3izpK8QZFHDiRVh8Wlgskkh4dwWQ\",\"url\":\"https://ca.foo/acme/acme/challenge/ACETKuLpYHJB507ZvDiEB1O8pdwBIKyl/mCrqSQrUr1VIgn4DzF6aAVDZadurcqLO\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"VnHx3izpK8QZFHDiRVh8Wlgskkh4dwWQ\",\"url\":\"https://ca.foo/acme/acme/challenge/ACETKuLpYHJB507ZvDiEB1O8pdwBIKyl/B2nU2zTfL2u2s2YzjIbJeyA24jbm2xFy\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"VnHx3izpK8QZFHDiRVh8Wlgskkh4dwWQ\",\"url\":\"https://ca.foo/acme/acme/challenge/ACETKuLpYHJB507ZvDiEB1O8pdwBIKyl/kLci9guDgRQ2k2r9LiVcrUhJQdBzfHqE\"}],\"wildcard\":false,\"expires\":\"2026-08-24T05:07:27Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6500621.514397] ca step-ca[203]: time="2026-08-23T05:07:27Z" level=info duration=3.371246ms duration-ns=3371246 fields.time="2026-08-23T05:07:27Z" method=POST name=ca nonce=c2pBb1pvZDgzSUROTFQ0R0RIWEZpN0oxNW5tTDMwcDI path=/acme/acme/challenge/ACETKuLpYHJB507ZvDiEB1O8pdwBIKyl/B2nU2zTfL2u2s2YzjIbJeyA24jbm2xFy protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=4461682d-6fba-44bb-90df-a15f71f8b7af response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"VnHx3izpK8QZFHDiRVh8Wlgskkh4dwWQ\",\"validated\":\"2026-08-23T05:07:27Z\",\"url\":\"https://ca.foo/acme/acme/challenge/ACETKuLpYHJB507ZvDiEB1O8pdwBIKyl/B2nU2zTfL2u2s2YzjIbJeyA24jbm2xFy\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6500621.528081] ca step-ca[203]: time="2026-08-23T05:07:27Z" level=info duration=8.014591ms duration-ns=8014591 fields.time="2026-08-23T05:07:27Z" method=POST name=ca nonce=RzIwUXhIVHVtakM2TnBDbjE1VGRza2pHbXU2VGVBUWM path=/acme/acme/order/RndZXJdzQRfnyMbfhxHerCvOnirDurtx/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=6905658c-13ad-4576-98ad-56be6b1ce030 response="{\"id\":\"RndZXJdzQRfnyMbfhxHerCvOnirDurtx\",\"status\":\"valid\",\"expires\":\"2026-08-24T05:07:27Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-23T05:06:27Z\",\"notAfter\":\"2026-11-21T05:07:27Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/ACETKuLpYHJB507ZvDiEB1O8pdwBIKyl\"],\"finalize\":\"https://ca.foo/acme/acme/order/RndZXJdzQRfnyMbfhxHerCvOnirDurtx/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/IpL2sAOC4reACaCXuPzKVH7OMULvfaeq\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6500621.532064] ca step-ca[203]: time="2026-08-23T05:07:27Z" level=info certificate=MIIB1jCCAX2gAwIBAgIQZvr1PMqh20LLd7C1dZt7izAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MjMwNTA2MjdaFw0yNjExMjEwNTA3MjdaMBMxETAPBgNVBAMTCHRlc3QuZm9vMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEtDB3wMWmGHzIgkpa6wtXgEfPPloIYxar+bwZJ9QEO/FiS/iyZWyxrEpxrDnVaAjuDz1QTn+guHGvF+NMJWKqHqOBpjCBozAOBgNVHQ8BAf8EBAMCB4AwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBSRLm3cwwN92rKOFoTaiEm+ePDd5zAfBgNVHSMEGDAWgBQGEt3Z8fVc8Wn7df06ngK72vfNjTATBgNVHREEDDAKggh0ZXN0LmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDRwAwRAIgG2YMD62b6kEiM+sxkFNU5mMAK8V6JSooo48adHgLZw8CIHFLtHwr1DoCPcQJchr7zbUn358B3CQGGzMxweIzz7B/ duration=1.569022ms duration-ns=1569022 fields.time="2026-08-23T05:07:27Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=MXFSS3FZQmhpQkZpOXUzOGRnMTd4TXNMbE8wNU9rYkQ path=/acme/acme/certificate/IpL2sAOC4reACaCXuPzKVH7OMULvfaeq protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=1a39db71-e715-4902-ba45-e2f031fe0e1b sans="map[dns:[test.foo]]" serial=136884303791449415929710964822104570763 size=1344 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-23T05:06:27Z" valid-to="2026-11-21T05:07:27Z" container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1009 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 23 05:07:19 2026 GMT container-test-run-certificates> * expire date: Sep 22 05:07:19 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 7f712c container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6500621.681116] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [6500621.681476] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [6500622.194547] server nginx[391]: nginx: the configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf syntax is ok container-test-run-certificates> server # [6500622.195083] server nginx[391]: nginx: configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf test is successful container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [929 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [79 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 23 05:06:27 2026 GMT container-test-run-certificates> * expire date: Nov 21 05:07:27 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 45794 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 829 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 2.13 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> 66:fa:f5:3c:ca:a1:db:42:cb:77:b0:b5:75:9b:7b:8b container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Aug 23 05:06:27 2026 GMT container-test-run-certificates> Not After : Nov 21 05:07:27 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:b4:30:77:c0:c5:a6:18:7c:c8:82:4a:5a:eb:0b: container-test-run-certificates> 57:80:47:cf:3e:5a:08:63:16:ab:f9:bc:19:27:d4: container-test-run-certificates> 04:3b:f1:62:4b:f8:b2:65:6c:b1:ac:4a:71:ac:39: container-test-run-certificates> d5:68:08:ee:0f:3d:50:4e:7f:a0:b8:71:af:17:e3: container-test-run-certificates> 4c:25:62:aa:1e container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> 91:2E:6D:DC:C3:03:7D:DA:B2:8E:16:84:DA:88:49:BE:78:F0:DD:E7 container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> 06:12:DD:D9:F1:F5:5C:F1:69:FB:75:FD:3A:9E:02:BB:DA:F7:CD:8D container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:44:02:20:1b:66:0c:0f:ad:9b:ea:41:22:33:eb:31:90:53: container-test-run-certificates> 54:e6:63:00:2b:c5:7a:25:2a:28:a3:8f:1a:74:78:0b:67:0f: container-test-run-certificates> 02:20:71:4b:b4:7c:2b:d4:3a:02:3d:c4:09:72:1a:fb:cd:b5: container-test-run-certificates> 27:df:9f:01:dc:24:06:1b:33:31:c1:e2:33:cf:b0:7f container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.04 seconds) container-test-run-certificates> (finished: run the VM test script, in 12.10 seconds) container-test-run-certificates> server # [6500622.806688] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> test script finished in 12.15s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 52) container-test-run-certificates> kill NspawnMachine (pid 56) container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> kill NspawnMachine (pid 55) container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> Container server terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.54 seconds) warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy post-build step Upload to niks3: ok time=2026-08-23T05:07:32.733Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-08-23T05:07:33.042Z level=INFO msg="Uploading 1 narinfos" time=2026-08-23T05:07:33.260Z level=INFO msg="Upload complete. (607ms)"