these 174 derivations will be built: /nix/store/036blsc4zrqllkxan7f78dh9gd9ch2zr-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/07182vp9nm48fkgibfn911dbhlvs6isg-vars-check-certificates.drv /nix/store/khgs7ihg3g7vh72ix6dxh9ia91y4hjx3-mount-secret-fs.drv /nix/store/5jqj162zjfjrmhrjl5bs8al1ynvy5ryz-decrypt-age-secrets.drv /nix/store/79wgv1358924zi13p4q1kdh7v81cm9ww-mounts.sh.drv /nix/store/yaq1v5mpwvwcmlxjmd2l8xdpbwz0wa70-hashed-password.root.drv /nix/store/laiy4wdfcimms3cl04fm3sn937fal9qp-users-groups.json.drv /nix/store/avlwy5jy9zv3hhg6afzphr9drn1ry34q-extra-hosts.drv /nix/store/f1fz88a2dr2nxbc1qz3212629xhprw00-localhost-hosts.drv /nix/store/nkmcxp3a6fc4ddajmj6v2glyjzq33blh-string-hosts.drv /nix/store/17212vlrjfmvkqaswkiz14msw9an4lhv-hosts.drv /nix/store/206g7s9riiy6lv7v18s759skhyssvl7h-etc-os-release.drv /nix/store/4jmsfw3k4gmpf29v59xiy8lg5jj2g454-unit-40-eth1.network.drv /nix/store/6w49gzpshs71lyvgsdjs7pjq6md86kla-issue.drv /nix/store/7f78x2fmrsc9klkk2bnfp2wycywk8rmn-etc-shells.drv /nix/store/89vwpz3bz4fz4damgb9ynfkw7whg8s7p-etc-ssh-ssh_config.drv /nix/store/791h9g6qz4m9cfn07nwzi3aghnz7fc9w-cacert-blocklist.txt.drv /nix/store/v6gnvpsqg2zy7lh9z4y7mrpi1fw5dgw4-cacert-extra-certificates-bundle.crt.drv /nix/store/97xdsmfjcs1fj7yldc4vh4l8kzhzw9i9-nss-cacert-3.126.drv /nix/store/d8ff6hxagc6l6hin0m2hq0r0nrkvq1nw-etc-systemd-journald.conf.drv /nix/store/g8q751dagdaxa2ljj43b6c9agzfq245j-fontconfig-etc.drv /nix/store/gsypd4p0iypxmf53bh23b9hyda2kdj15-etc-sysctl.d-60-nixos.conf.drv /nix/store/h2nswfhm1dlk7xk4z8k9c5ddgbr8a69x-etc-systemd-system.conf.drv /nix/store/qpyg3ymybdm6vga454s1q8hhwzf4vplp-nix.conf.drv /nix/store/xkqslb4vv7lakqjgqqfmk2bjpy6qpfcq-X-Restart-Triggers-nix-daemon.drv /nix/store/12dlk1fjr09bmgmkq760npv4kwj959nl-unit-nix-daemon.service.drv /nix/store/0c327af2fd5cnkww69224q282fhqif1m-nixos-version.drv /nix/store/xp35r326fj62za90d48wq8wc4bkd3kw2-system-path.drv /nix/store/nihq11xlx2x2v5r4qai3r52bnw21ylrw-dbus-1.drv /nix/store/3cvhiixn9p70zaxj52can8zb98c2h82z-X-Restart-Triggers-dbus-broker.drv /nix/store/1r4r6xhvb5z70v8691ynlnk2ndgrjqkv-unit-dbus-broker.service.drv /nix/store/pmnycx38zniwbw8hm1bk8ffpyva22z4n-X-Restart-Triggers-systemd-journald.drv /nix/store/40j99f0lg5ah7qm70wni3rcdgc8yvapd-unit-systemd-journald.service.drv /nix/store/41akw2ffnkpsxh6ns0nvpbv9h8122q3m-unit-systemd-timedated.service.drv /nix/store/4c69mj6pj2q8zv6g1hr9w9hxjnm5skkk-unit-systemd-fsck-.service.drv /nix/store/6ldnq6arjyd9r09a9mbjyb1g5glhlycm-unit-console-getty.service.drv /nix/store/3sa3xcmqapmjqbib7w953639g4pschv1-X-Restart-Triggers-systemd-networkd.drv /nix/store/lsmdqplqyqqsad0jad6fiwpp6cn3y7az-X-Reload-Triggers-systemd-networkd.drv /nix/store/98fx6s8m7rp3sp8y3xrcr43pcn5hkbps-unit-systemd-networkd.service.drv /nix/store/ck3idjnbv8mdwy53vxzvw4nks8qb4b7r-unit-serial-getty-ttyAMA0.service-disabled.drv /nix/store/zrlrzqqfagjz0jcz42yvi1cj0lw3mjmj-etc-systemd-resolved.conf.drv /nix/store/204dxl6q98aagw0i8wfjp7dag8l7c4kh-X-Reload-Triggers-systemd-resolved.drv /nix/store/cya14f0ilf8j8xqw8hr52g1k19qggbxj-unit-systemd-resolved.service.drv /nix/store/47flc519dahv34nbbw8kifxgdfvjcdwg-X-Restart-Triggers-systemd-sysctl.drv /nix/store/flkfj59gdkzn377j4vx8j3hz0yfyysy0-unit-systemd-sysctl.service.drv /nix/store/p4nwmvczbf1aramqjbp8g0c1gy66vi7d-shutdown-ramfs-contents.json.drv /nix/store/fx2936y2z43mv5k4anjsbrly8nh8xw93-unit-generate-shutdown-ramfs.service.drv /nix/store/nypkzlrjjxkmh8ihsb5ffv5cmz99ml8w-X-Restart-Triggers-systemd-journald-.drv /nix/store/iwbbqq0szaipxfl6z500g78r2r4am7gm-unit-systemd-journald-.service.drv /nix/store/kicwid2acpsgdyfzmx7wq9a81gv25fw8-unit-nix-optimise.service.drv /nix/store/lg4q0w5rxy73klw02s88fhzr904mmsfh-unit-serial-getty-.service.drv /nix/store/lmhxk40mj9hm6fqxssbrv692r9n6lqbk-unit-resolvconf.service-disabled.drv /nix/store/mwc5c1h7kc7s9yd2kpg9jpah3k92q0j8-unit-serial-getty-hvc0.service-disabled.drv /nix/store/s25zfsar9afmppnmhr5p97sa0gvfmn7f-firewall-start.drv /nix/store/mxm71xxx5yfvkwmwi771pmw6iz44nl4y-firewall-reload.drv /nix/store/n8af5xibzvhqggjmph1wbpwbmlc6nsnr-unit-firewall.service.drv /nix/store/nfsb6wnspim9z90liacbz5d5ivf3hvka-unit-suid-sgid-wrappers.service-disabled.drv /nix/store/pghpah75x548w51shvbilx2by5khmw4d-unit-systemd-makefs-.service.drv /nix/store/gya49ya05hxgyjmw0q3zhv5jqgrqa1iy-nixos-tmpfiles.d.drv /nix/store/icrgzyl3wwpyr7jb8yd2x5wddllzil0m-tmpfiles.d.drv /nix/store/x3m1dsfh6zm5cbgvp1nlwi6vj18nn1k6-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/qgpr7v625jnbdlqhrcd8n30df096078i-unit-systemd-tmpfiles-resetup.service.drv /nix/store/nq99azn1ndbxls4gb7nqjmmvkx440hry-unit-script-nix-gc-start.drv /nix/store/x854xplzbs213rgdkfzqljsdikki38dg-unit-nix-gc.service.drv /nix/store/hi3xd3yb6y1r3nfi6rnr4y14lgk3n39j-system-units.drv /nix/store/xrhb93sk5vaxqsd5p0kpsy0npnhb66ix-set-environment.drv /nix/store/ixfd32bzms4lnna1mnfvdjg3fsk86x02-etc-profile.drv /nix/store/iz06l0qnliwjxriy68zhlzz32y9ldpxf-etc-hostname.drv /nix/store/jwsj8l7jnx6i89xg8dqvsyqa1mrnyp6j-useradd.drv /nix/store/n3ppy744kf9khg1vvzv4qfgylgc32zws-etc-systemd-sleep.conf.drv /nix/store/ri012zg7hplgcrszi2sw51y9i5k5hjzn-etc-pam-environment.drv /nix/store/svx4s645mc3j5nfhi30d6sv6lgifv4ny-etc-fstab.drv /nix/store/vq7y4hrging6m8zivlly08lzk1bdd6sd-etc-systemd-user.conf.drv /nix/store/bsv76v513ifi8hh3pdjiw7lkq1aa33fb-unit-dbus-broker.service.drv /nix/store/x63hc8x0m0klf52jc7cb8zzlk18n8yli-user-units.drv /nix/store/y45g5n9jahbf13da7nnvn0isalxx9k1v-etc-lvm-lvm.conf.drv /nix/store/y68j8f7ylr7dqq735kv2q9yh6lgzshhz-etc-ssh-ssh_known_hosts.drv /nix/store/yj48gb9bf7a5xmra8d86r67yr0ziafkf-etc-nix-registry.json.drv /nix/store/z5767hi6a200q7kai4ag4a06c6d2lv91-etc-bashrc.drv /nix/store/zvxh3p3mrb8y1xcnpzmx691i9ncvmgaf-etc.drv /nix/store/1vq587c2qgpp5fsmzadg6r8hfm6x0vad-activate.drv /nix/store/aablpnhbgk1rgyyikmjz9h0b21kkcpbb-ensure-all-wrappers-paths-exist.drv /nix/store/mj20q92j38nc657gk8v0vzbmwwjparr7-dry-activate.drv /nix/store/rv3573hrr5mdx1flkrli0b7ywchdw8dc-stage-2-init.sh.drv /nix/store/08kdakamrn0bmgafskbf146f91cvcq90-nixos-system-client-test.drv /nix/store/55f9lva7k6y69isr6l4606a87783kyj1-system-path.drv /nix/store/0fgv91gxpg863ikjkcqkgvqpdy20k3ss-dbus-1.drv /nix/store/0sggpnpx0hb7ps7mipz1v6p0j50j74f9-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/0zdzqh8g7k3r2bwrjb5s1dj9xvfzj537-etc-hostname.drv /nix/store/10cjbryhq5paprzm1glmzihlq892wip3-etc-hostname.drv /nix/store/1nk8gzqdwcbys8cscgg83vgibcwy841s-unit-acme-renew-test.foo.timer.drv /nix/store/5mg2klpahqbhhj18pc86bzcjzwryrqag-nixos-tmpfiles.d.drv /nix/store/rv9gkiwp80lshzgggldij33s91qcbhz3-10-acme.conf.drv /nix/store/1nkv0v377n31jy983ily8bqz76grf2f5-tmpfiles.d.drv /nix/store/p47hngn6zbdrmdwc5prb4iy0kaw2f2kp-firewall-start.drv /nix/store/1z3aifsiz4y9cs7rbjl3m6bx31jn97b2-firewall-reload.drv /nix/store/qhjp8r9fvamgbhsi2vllmi94vh41kmhb-nginx-recommended-proxy_set_header-headers.conf.drv /nix/store/7ywwl4r8l72w3sfh97zc39q5il8mhrw4-nginx.conf.drv /nix/store/hvn4sk793fk9pbj3jm3sv7d378kymx4k-unit-script-nginx-pre-start.drv /nix/store/2imh6icv5ryhq7vssyil7241r6lznw4r-unit-nginx.service.drv /nix/store/346x4w58bsshz20k49dilgs4s18r1hyv-decrypt-age-secrets.drv /nix/store/di1sgdiyzlm65p5kpam2px5qrwg223hx-acme-postrun.drv /nix/store/w7nqaqnlj2zf8lbzf5qy6i2yx8hrw8hs-unit-script-acme-order-renew-test.foo-start.drv /nix/store/35a5msij0380fgxm7ckwqrc2hd9rg2za-unit-acme-order-renew-test.foo.service.drv /nix/store/3qbzpkzqfykrppymh72m1ifiswms94iv-X-Restart-Triggers-acme-test.foo.drv /nix/store/3x9q456fy4k9p5j89dji9y9mpl6qpj0b-unit-40-eth1.network.drv /nix/store/i7m0gybsphnlx20ymfzaqysx0v3w094p-system-path.drv /nix/store/w4qdj5p84rmf9r68byxc43sc9yiq2p23-dbus-1.drv /nix/store/xqj7p4mqjc9wdybczp1nz9zdwswrrp3v-X-Restart-Triggers-dbus-broker.drv /nix/store/4r5sl2xj5mcx5s3sw2bc4wx70blbv6b5-unit-dbus-broker.service.drv /nix/store/xhhbkra230h3h37sfmjzrx9pry9wyrd0-unit-40-eth1.network.drv /nix/store/509xd8748dnlngc6nf21aggssb5s0swr-X-Reload-Triggers-systemd-networkd.drv /nix/store/qmyis2dzw5mgw8xrk10l8p0yr3v98z34-users-groups.json.drv /nix/store/56w0h3a4fpvg80qy29nsga20p8w05148-dry-activate.drv /nix/store/5g0i3ihpykv6r1fx4mw25gs5fs6fgwhb-unit-systemd-networkd.service.drv /nix/store/bjj3534h4wyky0f37a7m2d7n964w54wh-acme-setup-privileged.drv /nix/store/gawjnj6ywdqsjb33sfpdn87jjwh4x030-unit-script-acme-setup-start.drv /nix/store/5h5ima3fyiinwyj2xb2bq3y2dba3lij3-unit-acme-setup.service.drv /nix/store/61vgapasj8nxhaqk3sk97194mj3hg0nj-unit-nginx-config-reload.service.drv /nix/store/jgkn1fj8dvcsa4ny8dg4aznv46za5mvy-system-generators.drv /nix/store/jxpdl2yvphkmb625h927mpnk59k3wk49-ca.json.drv /nix/store/6x8vlzfw6a1jwykqww188jzl2wgvirva-unit-nginx-config-reload.service.drv /nix/store/7yik6sfchavysp6hdgfdqy5f3px4n50d-unit-firewall.service.drv /nix/store/97m1jalfv4s1y5mvy3z6dj0xv0m1zvng-unit-acme-renew-ca.foo.timer.drv /nix/store/p2pajkvlgbsiqwjk6fr7rara76y5slbm-X-Restart-Triggers-dbus-broker.drv /nix/store/ga9j6b9clrzkykvwqnxsjmfsdavcv1ai-unit-dbus-broker.service.drv /nix/store/9f6p9w5xf1g9a8rmdvn87z28xqfbjsjr-X-Restart-Triggers-acme-ca.foo.drv /nix/store/j06h07j5hl1jqwhfrjy1bd3dm5y6ypr3-unit-script-acme-ca.foo-start.drv /nix/store/h7c9v4lnmls01zx9587yy0wvdr953bvn-unit-acme-ca.foo.service.drv /nix/store/y898rkhm36am6993pvcnnaa5laap4y5a-acme-postrun.drv /nix/store/p3bvivbjsggzi4ffpblddgslgf0f7qc2-unit-acme-order-renew-ca.foo.service.drv /nix/store/ppcmml1d42bis7nzxsyx769ahv8b25fb-acme-setup-privileged.drv /nix/store/rql21w9n48yizvh0qwz5z9cqwcan37m4-unit-acme-setup.service.drv /nix/store/q7mn3bk0yndwz8isxqjmlcy5vjsbkn5b-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/s0n4fxc8q9f6zhhg06cy28fjq4bl84n1-unit-systemd-tmpfiles-resetup.service.drv /nix/store/hklmlxjv3jsypnx63x06d2sw8dhmm8n9-X-Restart-Triggers-step-ca.drv /nix/store/vmas20ycygcwskilmr2xgibipcbxjv51-unit-step-ca.service.drv /nix/store/qby0arlghmjjb4r1vy6qw0pz9bmir7p5-X-Reload-Triggers-systemd-networkd.drv /nix/store/xxvrywgz666irh40lbw4m2jd7q1nxkdf-unit-systemd-networkd.service.drv /nix/store/n9zrgh7v0wa6y4mxlqzx536lcgk6rx5z-system-units.drv /nix/store/p037k6aw6dkczp797q66csvh9gw3wl20-user-generators.drv /nix/store/i2dj4hz76ic7bsjdifxs6ck848im76kx-string-hosts.drv /nix/store/qbsv3xqikz30whfw55dx28jgb2pxkglf-hosts.drv /nix/store/wyskiha16j5lfb3b6jsjmy9r4zvy16s9-system-shutdown.drv /nix/store/765lb4n55pyp19fkdh5xk7w0p9krr7br-unit-dbus-broker.service.drv /nix/store/yar80azcmf9pfvznisxdvzn3v3fllsxx-user-units.drv /nix/store/6dd00c7f0x2ci3apdf6nlkxr1zkac4ds-etc.drv /nix/store/d1asqq2n5mj32zr7bzpwz5a9p9kwhjg6-python3.14-nixos-test-lib-1.0.0.drv /nix/store/igsggv20kygiaizhgd6qdhlrpkbagj48-nixos-test-driver-1.1.drv /nix/store/qc93adsfvqp1ykah9sj9gzshblp1lcmb-test-script.drv /nix/store/fb8byr1m4lwyvp4v852ipvwb982i6q28-activate.drv /nix/store/gyp6k7hc03qa7j66x12fj0y5mp7h1vd2-nixos-system-ca-test.drv /nix/store/b6w9n082px5jqxgfl37pagbi5wb767rz-run-ca-nspawn.drv /nix/store/imvb1y7ysyskxzdk3yjlkji4jx4js6m0-run-client-nspawn.drv /nix/store/khh0ng1amj88i5fyfss43lpi12a2pk2c-nginx.conf.drv /nix/store/b235wnldakyza7759nqsqcqnswaglih7-unit-script-acme-test.foo-start.drv /nix/store/9wqw1c35dyazfkqk1mb0asw40q50qr0b-unit-acme-test.foo.service.drv /nix/store/nb6pmnhsmblmjl22yzlv69gpcz1ilb8k-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/92ksa4f5ds8xfc7hzs0f0n67y2afp25z-unit-script-nginx-pre-start.drv /nix/store/ymar08pjr9p8jihhwi1yvdjsy25hrzz5-unit-nginx.service.drv /nix/store/n6s0yw4rqqn5b5cb21lpbrfxjxxa7py6-system-units.drv /nix/store/lgk45vajijsh6rkn95gk9p4k35llbqff-unit-dbus-broker.service.drv /nix/store/s8i1msjm157aqwqz225fbd303xcaqz2v-user-units.drv /nix/store/ngmx324ppgdy1kkqnbc6jjmj2qxp726f-string-hosts.drv /nix/store/vp9kqhkx48jvrr07a7j93914h0njf5jb-hosts.drv /nix/store/i63b7qsp0z6rsw8rahwgjsc6srinh608-etc.drv /nix/store/znkkq5v4lfmsl9a3bjahlhlrw5d9vrxw-users-groups.json.drv /nix/store/71sgdjpz1lb813n4i66fhwc2j9i20clr-activate.drv /nix/store/yzr953km1bdy7jf2h2vz3i3mp254q9vq-dry-activate.drv /nix/store/sqmy24sxq0zh2jm4ygi8a9j3lkr56rr5-nixos-system-server-test.drv /nix/store/n4phfwljsh5n3siss3hb5i3y222rzdxz-run-server-nspawn.drv /nix/store/y1i418ky3a0x88vx0rx9ffkl1gi5h5c6-driverConfiguration.json.drv /nix/store/6lqr927cy4l894m00cbl123bmliryv3y-nixos-test-driver-certificates.drv /nix/store/arv6cii9x1km1nhwmd7k1m26p5kd7fa0-container-test-run-certificates.drv these 16 paths will be fetched (45.5 MiB download, 150.3 MiB unpacked): /nix/store/3dasan0q8dfvh9k9w38h1h67d37y7h9l-flock-0.4.0 /nix/store/aakb43z0k7gywf8xqz7lw4ashd7xkv6b-gixy-0.1.21 /nix/store/m83jgn44gl01c0jc9n7a4zkmpdl821zp-lego-4.35.2 /nix/store/15s822ngb5ik60b2q50317iqz3shq46v-minica-1.1.0 /nix/store/02x438lhk40svzvmv4yxfccvq2jr00c4-nginx-1.30.4 /nix/store/i63i6lmhrzq0fwg8fxid2hnfavb8i3d2-nginx-config-formatter-1.4.0 /nix/store/w40l43ygihy9q79nmvq1nk26rd7qqv7n-nginx-mod-moreheaders-0.40 /nix/store/gyhchka2gri0p0360xiz89wqa15dkn7q-nginx-mod-rtmp-1.2.2 /nix/store/g00jzi34lq18jqfalq12s2psxr9ln9k6-openssl-3.6.3-man /nix/store/5143c16q2d1qfjspicc8w7wkzbmhrain-openssl-4.0.1 /nix/store/rg795q2f38r1mmdfi3qbzv8si8iab1l7-python3.14-buildcatrust-0.5.1 /nix/store/09655jj6sbfrjyxa317qjczdm6ir577x-python3.14-cached-property-2.0.1 /nix/store/qzlwxl8a118rw7zal6s7c4xy9baga4hq-python3.14-configargparse-1.7.5 /nix/store/bmx919fsx8i1l6hak9nwbhvdwdili3rj-python3.14-pyparsing-2.4.7 /nix/store/3ahxigmadhbxwr2fx33x5qwwfs0aj1kb-step-ca-0.30.2 /nix/store/h9avm2x8xacpq4fp0skz2aiqkcz8l5ff-zlib-ng-2.3.3 building '/nix/store/qc93adsfvqp1ykah9sj9gzshblp1lcmb-test-script.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/aablpnhbgk1rgyyikmjz9h0b21kkcpbb-ensure-all-wrappers-paths-exist.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/z5767hi6a200q7kai4ag4a06c6d2lv91-etc-bashrc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/svx4s645mc3j5nfhi30d6sv6lgifv4ny-etc-fstab.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0zdzqh8g7k3r2bwrjb5s1dj9xvfzj537-etc-hostname.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/10cjbryhq5paprzm1glmzihlq892wip3-etc-hostname.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rv9gkiwp80lshzgggldij33s91qcbhz3-10-acme.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/9f6p9w5xf1g9a8rmdvn87z28xqfbjsjr-X-Restart-Triggers-acme-ca.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qc93adsfvqp1ykah9sj9gzshblp1lcmb-test-script.drv' building '/nix/store/3qbzpkzqfykrppymh72m1ifiswms94iv-X-Restart-Triggers-acme-test.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/di1sgdiyzlm65p5kpam2px5qrwg223hx-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/y898rkhm36am6993pvcnnaa5laap4y5a-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/bjj3534h4wyky0f37a7m2d7n964w54wh-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ppcmml1d42bis7nzxsyx769ahv8b25fb-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/z5767hi6a200q7kai4ag4a06c6d2lv91-etc-bashrc.drv' building '/nix/store/aablpnhbgk1rgyyikmjz9h0b21kkcpbb-ensure-all-wrappers-paths-exist.drv' ensure-all-wrappers-paths-exist> Checking that Nix store paths of all wrapped programs exist... OK ensure-all-wrappers-paths-exist> Checking that all capabilities of all wrapped programs are valid... OK building '/nix/store/svx4s645mc3j5nfhi30d6sv6lgifv4ny-etc-fstab.drv' building '/nix/store/10cjbryhq5paprzm1glmzihlq892wip3-etc-hostname.drv' building '/nix/store/0zdzqh8g7k3r2bwrjb5s1dj9xvfzj537-etc-hostname.drv' building '/nix/store/rv9gkiwp80lshzgggldij33s91qcbhz3-10-acme.conf.drv' building '/nix/store/9f6p9w5xf1g9a8rmdvn87z28xqfbjsjr-X-Restart-Triggers-acme-ca.foo.drv' building '/nix/store/jxpdl2yvphkmb625h927mpnk59k3wk49-ca.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/791h9g6qz4m9cfn07nwzi3aghnz7fc9w-cacert-blocklist.txt.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v6gnvpsqg2zy7lh9z4y7mrpi1fw5dgw4-cacert-extra-certificates-bundle.crt.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7f78x2fmrsc9klkk2bnfp2wycywk8rmn-etc-shells.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/89vwpz3bz4fz4damgb9ynfkw7whg8s7p-etc-ssh-ssh_config.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/y68j8f7ylr7dqq735kv2q9yh6lgzshhz-etc-ssh-ssh_known_hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/gsypd4p0iypxmf53bh23b9hyda2kdj15-etc-sysctl.d-60-nixos.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/d8ff6hxagc6l6hin0m2hq0r0nrkvq1nw-etc-systemd-journald.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/zrlrzqqfagjz0jcz42yvi1cj0lw3mjmj-etc-systemd-resolved.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5mg2klpahqbhhj18pc86bzcjzwryrqag-nixos-tmpfiles.d.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/gya49ya05hxgyjmw0q3zhv5jqgrqa1iy-nixos-tmpfiles.d.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0c327af2fd5cnkww69224q282fhqif1m-nixos-version.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/vq7y4hrging6m8zivlly08lzk1bdd6sd-etc-systemd-user.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/avlwy5jy9zv3hhg6afzphr9drn1ry34q-extra-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p47hngn6zbdrmdwc5prb4iy0kaw2f2kp-firewall-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/s25zfsar9afmppnmhr5p97sa0gvfmn7f-firewall-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/g8q751dagdaxa2ljj43b6c9agzfq245j-fontconfig-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/yaq1v5mpwvwcmlxjmd2l8xdpbwz0wa70-hashed-password.root.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6w49gzpshs71lyvgsdjs7pjq6md86kla-issue.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/f1fz88a2dr2nxbc1qz3212629xhprw00-localhost-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/khgs7ihg3g7vh72ix6dxh9ia91y4hjx3-mount-secret-fs.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/79wgv1358924zi13p4q1kdh7v81cm9ww-mounts.sh.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qhjp8r9fvamgbhsi2vllmi94vh41kmhb-nginx-recommended-proxy_set_header-headers.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/khh0ng1amj88i5fyfss43lpi12a2pk2c-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/i2dj4hz76ic7bsjdifxs6ck848im76kx-string-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jgkn1fj8dvcsa4ny8dg4aznv46za5mvy-system-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wyskiha16j5lfb3b6jsjmy9r4zvy16s9-system-shutdown.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/4jmsfw3k4gmpf29v59xiy8lg5jj2g454-unit-40-eth1.network.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/xhhbkra230h3h37sfmjzrx9pry9wyrd0-unit-40-eth1.network.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/nb6pmnhsmblmjl22yzlv69gpcz1ilb8k-unit-acme-account-2c44cb477b4787b2cf13.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0sggpnpx0hb7ps7mipz1v6p0j50j74f9-unit-acme-account-d22a46d9459bf683a338.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/97m1jalfv4s1y5mvy3z6dj0xv0m1zvng-unit-acme-renew-ca.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/1nk8gzqdwcbys8cscgg83vgibcwy841s-unit-acme-renew-test.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6x8vlzfw6a1jwykqww188jzl2wgvirva-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3qbzpkzqfykrppymh72m1ifiswms94iv-X-Restart-Triggers-acme-test.foo.drv' building '/nix/store/791h9g6qz4m9cfn07nwzi3aghnz7fc9w-cacert-blocklist.txt.drv' building '/nix/store/v6gnvpsqg2zy7lh9z4y7mrpi1fw5dgw4-cacert-extra-certificates-bundle.crt.drv' building '/nix/store/di1sgdiyzlm65p5kpam2px5qrwg223hx-acme-postrun.drv' building '/nix/store/y898rkhm36am6993pvcnnaa5laap4y5a-acme-postrun.drv' building '/nix/store/bjj3534h4wyky0f37a7m2d7n964w54wh-acme-setup-privileged.drv' building '/nix/store/ppcmml1d42bis7nzxsyx769ahv8b25fb-acme-setup-privileged.drv' building '/nix/store/7f78x2fmrsc9klkk2bnfp2wycywk8rmn-etc-shells.drv' building '/nix/store/89vwpz3bz4fz4damgb9ynfkw7whg8s7p-etc-ssh-ssh_config.drv' building '/nix/store/y68j8f7ylr7dqq735kv2q9yh6lgzshhz-etc-ssh-ssh_known_hosts.drv' building '/nix/store/gsypd4p0iypxmf53bh23b9hyda2kdj15-etc-sysctl.d-60-nixos.conf.drv' building '/nix/store/d8ff6hxagc6l6hin0m2hq0r0nrkvq1nw-etc-systemd-journald.conf.drv' building '/nix/store/zrlrzqqfagjz0jcz42yvi1cj0lw3mjmj-etc-systemd-resolved.conf.drv' building '/nix/store/jxpdl2yvphkmb625h927mpnk59k3wk49-ca.json.drv' ca.json> structuredAttrs is enabled building '/nix/store/5mg2klpahqbhhj18pc86bzcjzwryrqag-nixos-tmpfiles.d.drv' building '/nix/store/gya49ya05hxgyjmw0q3zhv5jqgrqa1iy-nixos-tmpfiles.d.drv' building '/nix/store/icrgzyl3wwpyr7jb8yd2x5wddllzil0m-tmpfiles.d.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/vq7y4hrging6m8zivlly08lzk1bdd6sd-etc-systemd-user.conf.drv' building '/nix/store/0c327af2fd5cnkww69224q282fhqif1m-nixos-version.drv' nixos-version> Running phase: patchPhase nixos-version> Running phase: updateAutotoolsGnuConfigScriptsPhase nixos-version> Running phase: configurePhase nixos-version> no configure script, doing nothing nixos-version> Running phase: buildPhase nixos-version> Running phase: checkPhase nixos-version> Running phase: installPhase nixos-version> no Makefile or custom installPhase, doing nothing nixos-version> Running phase: fixupPhase nixos-version> shrinking RPATHs of ELF executables and libraries in /nix/store/aci98w27chk7f2h5pr5njjrh527vhhm6-nixos-version nixos-version> checking for references to /build/ in /nix/store/aci98w27chk7f2h5pr5njjrh527vhhm6-nixos-version... nixos-version> gzipping man pages under /nix/store/aci98w27chk7f2h5pr5njjrh527vhhm6-nixos-version/share/man/ nixos-version> patching script interpreter paths in /nix/store/aci98w27chk7f2h5pr5njjrh527vhhm6-nixos-version building '/nix/store/1nkv0v377n31jy983ily8bqz76grf2f5-tmpfiles.d.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/avlwy5jy9zv3hhg6afzphr9drn1ry34q-extra-hosts.drv' building '/nix/store/p47hngn6zbdrmdwc5prb4iy0kaw2f2kp-firewall-start.drv' building '/nix/store/1z3aifsiz4y9cs7rbjl3m6bx31jn97b2-firewall-reload.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/s25zfsar9afmppnmhr5p97sa0gvfmn7f-firewall-start.drv' building '/nix/store/mxm71xxx5yfvkwmwi771pmw6iz44nl4y-firewall-reload.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/hklmlxjv3jsypnx63x06d2sw8dhmm8n9-X-Restart-Triggers-step-ca.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/f1fz88a2dr2nxbc1qz3212629xhprw00-localhost-hosts.drv' building '/nix/store/g8q751dagdaxa2ljj43b6c9agzfq245j-fontconfig-etc.drv' fontconfig-etc> structuredAttrs is enabled fontconfig-etc> created 1 symlinks in user environment building '/nix/store/khgs7ihg3g7vh72ix6dxh9ia91y4hjx3-mount-secret-fs.drv' building '/nix/store/yaq1v5mpwvwcmlxjmd2l8xdpbwz0wa70-hashed-password.root.drv' building '/nix/store/laiy4wdfcimms3cl04fm3sn937fal9qp-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qmyis2dzw5mgw8xrk10l8p0yr3v98z34-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/znkkq5v4lfmsl9a3bjahlhlrw5d9vrxw-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6w49gzpshs71lyvgsdjs7pjq6md86kla-issue.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/79wgv1358924zi13p4q1kdh7v81cm9ww-mounts.sh.drv' building '/nix/store/qhjp8r9fvamgbhsi2vllmi94vh41kmhb-nginx-recommended-proxy_set_header-headers.conf.drv' building '/nix/store/346x4w58bsshz20k49dilgs4s18r1hyv-decrypt-age-secrets.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5jqj162zjfjrmhrjl5bs8al1ynvy5ryz-decrypt-age-secrets.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rv3573hrr5mdx1flkrli0b7ywchdw8dc-stage-2-init.sh.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/i2dj4hz76ic7bsjdifxs6ck848im76kx-string-hosts.drv' building '/nix/store/7ywwl4r8l72w3sfh97zc39q5il8mhrw4-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/khh0ng1amj88i5fyfss43lpi12a2pk2c-nginx.conf.drv' nginx.conf> structuredAttrs is enabled nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/92ksa4f5ds8xfc7hzs0f0n67y2afp25z-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/4jmsfw3k4gmpf29v59xiy8lg5jj2g454-unit-40-eth1.network.drv' unit-40-eth1.network> structuredAttrs is enabled building '/nix/store/xhhbkra230h3h37sfmjzrx9pry9wyrd0-unit-40-eth1.network.drv' unit-40-eth1.network> structuredAttrs is enabled building '/nix/store/nb6pmnhsmblmjl22yzlv69gpcz1ilb8k-unit-acme-account-2c44cb477b4787b2cf13.target.drv' unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled building '/nix/store/lsmdqplqyqqsad0jad6fiwpp6cn3y7az-X-Reload-Triggers-systemd-networkd.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qbsv3xqikz30whfw55dx28jgb2pxkglf-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/97xdsmfjcs1fj7yldc4vh4l8kzhzw9i9-nss-cacert-3.126.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/55f9lva7k6y69isr6l4606a87783kyj1-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/i7m0gybsphnlx20ymfzaqysx0v3w094p-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/xp35r326fj62za90d48wq8wc4bkd3kw2-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0sggpnpx0hb7ps7mipz1v6p0j50j74f9-unit-acme-account-d22a46d9459bf683a338.target.drv' unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled building '/nix/store/97m1jalfv4s1y5mvy3z6dj0xv0m1zvng-unit-acme-renew-ca.foo.timer.drv' unit-acme-renew-ca.foo.timer> structuredAttrs is enabled building '/nix/store/1z3aifsiz4y9cs7rbjl3m6bx31jn97b2-firewall-reload.drv' building '/nix/store/1nkv0v377n31jy983ily8bqz76grf2f5-tmpfiles.d.drv' building '/nix/store/icrgzyl3wwpyr7jb8yd2x5wddllzil0m-tmpfiles.d.drv' building '/nix/store/6x8vlzfw6a1jwykqww188jzl2wgvirva-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/mxm71xxx5yfvkwmwi771pmw6iz44nl4y-firewall-reload.drv' building '/nix/store/jgkn1fj8dvcsa4ny8dg4aznv46za5mvy-system-generators.drv' building '/nix/store/1nk8gzqdwcbys8cscgg83vgibcwy841s-unit-acme-renew-test.foo.timer.drv' unit-acme-renew-test.foo.timer> structuredAttrs is enabled building '/nix/store/x3m1dsfh6zm5cbgvp1nlwi6vj18nn1k6-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wyskiha16j5lfb3b6jsjmy9r4zvy16s9-system-shutdown.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/q7mn3bk0yndwz8isxqjmlcy5vjsbkn5b-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/509xd8748dnlngc6nf21aggssb5s0swr-X-Reload-Triggers-systemd-networkd.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/n8af5xibzvhqggjmph1wbpwbmlc6nsnr-unit-firewall.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/qmyis2dzw5mgw8xrk10l8p0yr3v98z34-users-groups.json.drv' building '/nix/store/laiy4wdfcimms3cl04fm3sn937fal9qp-users-groups.json.drv' building '/nix/store/hklmlxjv3jsypnx63x06d2sw8dhmm8n9-X-Restart-Triggers-step-ca.drv' building '/nix/store/znkkq5v4lfmsl9a3bjahlhlrw5d9vrxw-users-groups.json.drv' building '/nix/store/346x4w58bsshz20k49dilgs4s18r1hyv-decrypt-age-secrets.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/7ywwl4r8l72w3sfh97zc39q5il8mhrw4-nginx.conf.drv' nginx.conf> structuredAttrs is enabled building '/nix/store/17212vlrjfmvkqaswkiz14msw9an4lhv-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/vp9kqhkx48jvrr07a7j93914h0njf5jb-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/61vgapasj8nxhaqk3sk97194mj3hg0nj-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/j06h07j5hl1jqwhfrjy1bd3dm5y6ypr3-unit-script-acme-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/036blsc4zrqllkxan7f78dh9gd9ch2zr-unit-script-acme-order-renew-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/w7nqaqnlj2zf8lbzf5qy6i2yx8hrw8hs-unit-script-acme-order-renew-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/gawjnj6ywdqsjb33sfpdn87jjwh4x030-unit-script-acme-setup-start.drv' on 'ssh-ng://builder@build01.clan.lol' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/lsmdqplqyqqsad0jad6fiwpp6cn3y7az-X-Reload-Triggers-systemd-networkd.drv' building '/nix/store/qbsv3xqikz30whfw55dx28jgb2pxkglf-hosts.drv' building '/nix/store/rv3573hrr5mdx1flkrli0b7ywchdw8dc-stage-2-init.sh.drv' stage-2-init.sh> Running phase: patchPhase stage-2-init.sh> Running phase: updateAutotoolsGnuConfigScriptsPhase building '/nix/store/92ksa4f5ds8xfc7hzs0f0n67y2afp25z-unit-script-nginx-pre-start.drv' building '/nix/store/5jqj162zjfjrmhrjl5bs8al1ynvy5ryz-decrypt-age-secrets.drv' stage-2-init.sh> Running phase: configurePhase stage-2-init.sh> no configure script, doing nothing stage-2-init.sh> Running phase: buildPhase stage-2-init.sh> Running phase: checkPhase stage-2-init.sh> Running phase: installPhase stage-2-init.sh> no Makefile or custom installPhase, doing nothing stage-2-init.sh> Running phase: fixupPhase stage-2-init.sh> shrinking RPATHs of ELF executables and libraries in /nix/store/fx6v8jr8rrff1banhkkkj3asqn0xjh7a-stage-2-init.sh stage-2-init.sh> checking for references to /build/ in /nix/store/fx6v8jr8rrff1banhkkkj3asqn0xjh7a-stage-2-init.sh... stage-2-init.sh> patching script interpreter paths in /nix/store/fx6v8jr8rrff1banhkkkj3asqn0xjh7a-stage-2-init.sh building '/nix/store/97xdsmfjcs1fj7yldc4vh4l8kzhzw9i9-nss-cacert-3.126.drv' nss-cacert-3.126> structuredAttrs is enabled nss-cacert-3.126> Running phase: unpackPhase nss-cacert-3.126> Running phase: patchPhase nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase nss-cacert-3.126> Running phase: installPhase nss-cacert-3.126> Running phase: fixupPhase nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/xk1gmn41111cpcwzl6axjg4la7l4lgiv-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/xk1gmn41111cpcwzl6axjg4la7l4lgiv-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/xk1gmn41111cpcwzl6axjg4la7l4lgiv-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/ap0nvw9sr1wl64c9vhqwpc9si7qbri94-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/ap0nvw9sr1wl64c9vhqwpc9si7qbri94-nss-cacert-3.126-hashed... nss-cacert-3.126> patching script interpreter paths in /nix/store/ap0nvw9sr1wl64c9vhqwpc9si7qbri94-nss-cacert-3.126-hashed nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/r9f58lpb048rj4jvpczn4gcdy14brr0k-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/r9f58lpb048rj4jvpczn4gcdy14brr0k-nss-cacert-3.126... nss-cacert-3.126> patching script interpreter paths in /nix/store/r9f58lpb048rj4jvpczn4gcdy14brr0k-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/34vnlfqrfw71shiyd5k666yxkghgbmya-nss-cacert-3.126-unbundled nss-cacert-3.126> checking for references to /build/ in /nix/store/34vnlfqrfw71shiyd5k666yxkghgbmya-nss-cacert-3.126-unbundled... nss-cacert-3.126> patching script interpreter paths in /nix/store/34vnlfqrfw71shiyd5k666yxkghgbmya-nss-cacert-3.126-unbundled building '/nix/store/12dlk1fjr09bmgmkq760npv4kwj959nl-unit-nix-daemon.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/xp35r326fj62za90d48wq8wc4bkd3kw2-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/q7mn3bk0yndwz8isxqjmlcy5vjsbkn5b-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/s0n4fxc8q9f6zhhg06cy28fjq4bl84n1-unit-systemd-tmpfiles-resetup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/x3m1dsfh6zm5cbgvp1nlwi6vj18nn1k6-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' building '/nix/store/56w0h3a4fpvg80qy29nsga20p8w05148-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/mj20q92j38nc657gk8v0vzbmwwjparr7-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/509xd8748dnlngc6nf21aggssb5s0swr-X-Reload-Triggers-systemd-networkd.drv' building '/nix/store/n8af5xibzvhqggjmph1wbpwbmlc6nsnr-unit-firewall.service.drv' unit-firewall.service> structuredAttrs is enabled building '/nix/store/55f9lva7k6y69isr6l4606a87783kyj1-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/5g0i3ihpykv6r1fx4mw25gs5fs6fgwhb-unit-systemd-networkd.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/i7m0gybsphnlx20ymfzaqysx0v3w094p-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/vp9kqhkx48jvrr07a7j93914h0njf5jb-hosts.drv' building '/nix/store/j06h07j5hl1jqwhfrjy1bd3dm5y6ypr3-unit-script-acme-ca.foo-start.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/61vgapasj8nxhaqk3sk97194mj3hg0nj-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/yzr953km1bdy7jf2h2vz3i3mp254q9vq-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7yik6sfchavysp6hdgfdqy5f3px4n50d-unit-firewall.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ymar08pjr9p8jihhwi1yvdjsy25hrzz5-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/b235wnldakyza7759nqsqcqnswaglih7-unit-script-acme-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/hvn4sk793fk9pbj3jm3sv7d378kymx4k-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/vmas20ycygcwskilmr2xgibipcbxjv51-unit-step-ca.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/17212vlrjfmvkqaswkiz14msw9an4lhv-hosts.drv' building '/nix/store/036blsc4zrqllkxan7f78dh9gd9ch2zr-unit-script-acme-order-renew-ca.foo-start.drv' building '/nix/store/w7nqaqnlj2zf8lbzf5qy6i2yx8hrw8hs-unit-script-acme-order-renew-test.foo-start.drv' building '/nix/store/12dlk1fjr09bmgmkq760npv4kwj959nl-unit-nix-daemon.service.drv' unit-nix-daemon.service> structuredAttrs is enabled building '/nix/store/p3bvivbjsggzi4ffpblddgslgf0f7qc2-unit-acme-order-renew-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/gawjnj6ywdqsjb33sfpdn87jjwh4x030-unit-script-acme-setup-start.drv' building '/nix/store/56w0h3a4fpvg80qy29nsga20p8w05148-dry-activate.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/5g0i3ihpykv6r1fx4mw25gs5fs6fgwhb-unit-systemd-networkd.service.drv' unit-systemd-networkd.service> structuredAttrs is enabled building '/nix/store/nihq11xlx2x2v5r4qai3r52bnw21ylrw-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/s0n4fxc8q9f6zhhg06cy28fjq4bl84n1-unit-systemd-tmpfiles-resetup.service.drv' unit-systemd-tmpfiles-resetup.service> structuredAttrs is enabled building '/nix/store/mj20q92j38nc657gk8v0vzbmwwjparr7-dry-activate.drv' building '/nix/store/5h5ima3fyiinwyj2xb2bq3y2dba3lij3-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rql21w9n48yizvh0qwz5z9cqwcan37m4-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0fgv91gxpg863ikjkcqkgvqpdy20k3ss-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/w4qdj5p84rmf9r68byxc43sc9yiq2p23-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ymar08pjr9p8jihhwi1yvdjsy25hrzz5-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/b235wnldakyza7759nqsqcqnswaglih7-unit-script-acme-test.foo-start.drv' building '/nix/store/9wqw1c35dyazfkqk1mb0asw40q50qr0b-unit-acme-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7yik6sfchavysp6hdgfdqy5f3px4n50d-unit-firewall.service.drv' unit-firewall.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/h7c9v4lnmls01zx9587yy0wvdr953bvn-unit-acme-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/hvn4sk793fk9pbj3jm3sv7d378kymx4k-unit-script-nginx-pre-start.drv' building '/nix/store/yzr953km1bdy7jf2h2vz3i3mp254q9vq-dry-activate.drv' building '/nix/store/vmas20ycygcwskilmr2xgibipcbxjv51-unit-step-ca.service.drv' unit-step-ca.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/2imh6icv5ryhq7vssyil7241r6lznw4r-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p3bvivbjsggzi4ffpblddgslgf0f7qc2-unit-acme-order-renew-ca.foo.service.drv' unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled building '/nix/store/nihq11xlx2x2v5r4qai3r52bnw21ylrw-dbus-1.drv' building '/nix/store/rql21w9n48yizvh0qwz5z9cqwcan37m4-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/35a5msij0380fgxm7ckwqrc2hd9rg2za-unit-acme-order-renew-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p037k6aw6dkczp797q66csvh9gw3wl20-user-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5h5ima3fyiinwyj2xb2bq3y2dba3lij3-unit-acme-setup.service.drv' building '/nix/store/9wqw1c35dyazfkqk1mb0asw40q50qr0b-unit-acme-test.foo.service.drv' unit-acme-setup.service> structuredAttrs is enabled unit-acme-test.foo.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/h7c9v4lnmls01zx9587yy0wvdr953bvn-unit-acme-ca.foo.service.drv' unit-acme-ca.foo.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/w4qdj5p84rmf9r68byxc43sc9yiq2p23-dbus-1.drv' building '/nix/store/3cvhiixn9p70zaxj52can8zb98c2h82z-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/xqj7p4mqjc9wdybczp1nz9zdwswrrp3v-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/2imh6icv5ryhq7vssyil7241r6lznw4r-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/0fgv91gxpg863ikjkcqkgvqpdy20k3ss-dbus-1.drv' building '/nix/store/p2pajkvlgbsiqwjk6fr7rara76y5slbm-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/07182vp9nm48fkgibfn911dbhlvs6isg-vars-check-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p037k6aw6dkczp797q66csvh9gw3wl20-user-generators.drv' building '/nix/store/35a5msij0380fgxm7ckwqrc2hd9rg2za-unit-acme-order-renew-test.foo.service.drv' unit-acme-order-renew-test.foo.service> structuredAttrs is enabled building '/nix/store/3cvhiixn9p70zaxj52can8zb98c2h82z-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/1r4r6xhvb5z70v8691ynlnk2ndgrjqkv-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/bsv76v513ifi8hh3pdjiw7lkq1aa33fb-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/xqj7p4mqjc9wdybczp1nz9zdwswrrp3v-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/4r5sl2xj5mcx5s3sw2bc4wx70blbv6b5-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/lgk45vajijsh6rkn95gk9p4k35llbqff-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p2pajkvlgbsiqwjk6fr7rara76y5slbm-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/765lb4n55pyp19fkdh5xk7w0p9krr7br-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/07182vp9nm48fkgibfn911dbhlvs6isg-vars-check-certificates.drv' vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully building '/nix/store/1r4r6xhvb5z70v8691ynlnk2ndgrjqkv-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/bsv76v513ifi8hh3pdjiw7lkq1aa33fb-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/ga9j6b9clrzkykvwqnxsjmfsdavcv1ai-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/hi3xd3yb6y1r3nfi6rnr4y14lgk3n39j-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/lgk45vajijsh6rkn95gk9p4k35llbqff-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/4r5sl2xj5mcx5s3sw2bc4wx70blbv6b5-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/s8i1msjm157aqwqz225fbd303xcaqz2v-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/x63hc8x0m0klf52jc7cb8zzlk18n8yli-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/n6s0yw4rqqn5b5cb21lpbrfxjxxa7py6-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/765lb4n55pyp19fkdh5xk7w0p9krr7br-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/yar80azcmf9pfvznisxdvzn3v3fllsxx-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ga9j6b9clrzkykvwqnxsjmfsdavcv1ai-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/s8i1msjm157aqwqz225fbd303xcaqz2v-user-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/hi3xd3yb6y1r3nfi6rnr4y14lgk3n39j-system-units.drv' building '/nix/store/x63hc8x0m0klf52jc7cb8zzlk18n8yli-user-units.drv' building '/nix/store/zvxh3p3mrb8y1xcnpzmx691i9ncvmgaf-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/n6s0yw4rqqn5b5cb21lpbrfxjxxa7py6-system-units.drv' building '/nix/store/yar80azcmf9pfvznisxdvzn3v3fllsxx-user-units.drv' building '/nix/store/n9zrgh7v0wa6y4mxlqzx536lcgk6rx5z-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/i63b7qsp0z6rsw8rahwgjsc6srinh608-etc.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/zvxh3p3mrb8y1xcnpzmx691i9ncvmgaf-etc.drv' building '/nix/store/n9zrgh7v0wa6y4mxlqzx536lcgk6rx5z-system-units.drv' building '/nix/store/1vq587c2qgpp5fsmzadg6r8hfm6x0vad-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6dd00c7f0x2ci3apdf6nlkxr1zkac4ds-etc.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/i63b7qsp0z6rsw8rahwgjsc6srinh608-etc.drv' building '/nix/store/71sgdjpz1lb813n4i66fhwc2j9i20clr-activate.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/6dd00c7f0x2ci3apdf6nlkxr1zkac4ds-etc.drv' building '/nix/store/1vq587c2qgpp5fsmzadg6r8hfm6x0vad-activate.drv' building '/nix/store/fb8byr1m4lwyvp4v852ipvwb982i6q28-activate.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/08kdakamrn0bmgafskbf146f91cvcq90-nixos-system-client-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/71sgdjpz1lb813n4i66fhwc2j9i20clr-activate.drv' building '/nix/store/fb8byr1m4lwyvp4v852ipvwb982i6q28-activate.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/gyp6k7hc03qa7j66x12fj0y5mp7h1vd2-nixos-system-ca-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/sqmy24sxq0zh2jm4ygi8a9j3lkr56rr5-nixos-system-server-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/08kdakamrn0bmgafskbf146f91cvcq90-nixos-system-client-test.drv' nixos-system-client-test> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/gyp6k7hc03qa7j66x12fj0y5mp7h1vd2-nixos-system-ca-test.drv' nixos-system-ca-test> structuredAttrs is enabled building '/nix/store/imvb1y7ysyskxzdk3yjlkji4jx4js6m0-run-client-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/b6w9n082px5jqxgfl37pagbi5wb767rz-run-ca-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/sqmy24sxq0zh2jm4ygi8a9j3lkr56rr5-nixos-system-server-test.drv' nixos-system-server-test> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/imvb1y7ysyskxzdk3yjlkji4jx4js6m0-run-client-nspawn.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/b6w9n082px5jqxgfl37pagbi5wb767rz-run-ca-nspawn.drv' building '/nix/store/n4phfwljsh5n3siss3hb5i3y222rzdxz-run-server-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/n4phfwljsh5n3siss3hb5i3y222rzdxz-run-server-nspawn.drv' building '/nix/store/y1i418ky3a0x88vx0rx9ffkl1gi5h5c6-driverConfiguration.json.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/y1i418ky3a0x88vx0rx9ffkl1gi5h5c6-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/6lqr927cy4l894m00cbl123bmliryv3y-nixos-test-driver-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/6lqr927cy4l894m00cbl123bmliryv3y-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/arv6cii9x1km1nhwmd7k1m26p5kd7fa0-container-test-run-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/arv6cii9x1km1nhwmd7k1m26p5kd7fa0-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> ca: systemd-nspawn running (pid 53) container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> server: systemd-nspawn running (pid 56) container-test-run-certificates> client: systemd-nspawn running (pid 54) container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.00 seconds) container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> ca # [7056628.910695] ca systemd-journald[78]: Journal started container-test-run-certificates> client # [7056628.900507] client systemd-journald[69]: Journal started container-test-run-certificates> ca # [7056628.910752] ca systemd-journald[78]: Runtime Journal (/run/log/journal/9b2b87879f4241b4b8eef0ed3475387b) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> client # [7056628.900565] client systemd-journald[69]: Runtime Journal (/run/log/journal/b65ec803ba224011bb1d5f7ff6c75afe) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> ca # [7056628.920421] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [7056628.906032] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [7056628.921172] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [7056628.906878] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [7056628.921785] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [7056628.907632] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [7056628.930046] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/9b2b87879f4241b4b8eef0ed3475387b is 1.460ms for 5 entries. container-test-run-certificates> client # [7056628.916738] client systemd-journald[69]: Time spent on flushing to /var/log/journal/b65ec803ba224011bb1d5f7ff6c75afe is 1.780ms for 5 entries. container-test-run-certificates> ca # [7056628.930046] ca systemd-journald[78]: System Journal (/var/log/journal/9b2b87879f4241b4b8eef0ed3475387b) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [7056628.916738] client systemd-journald[69]: System Journal (/var/log/journal/b65ec803ba224011bb1d5f7ff6c75afe) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [7056628.938343] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [7056628.924260] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [7056628.939052] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [7056628.924499] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> ca # [7056628.939168] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [7056628.924647] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [7056628.939981] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [7056628.925382] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [7056628.940045] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [7056628.925440] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [7056628.940902] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> client # [7056628.926339] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [7056628.940934] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> client # [7056628.926377] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [7056628.945098] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [7056628.932914] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> ca # [7056628.946715] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> client # [7056628.934353] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [7056628.963752] ca systemd-tmpfiles[122]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [7056628.948904] client systemd-tmpfiles[111]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> ca # [7056628.964542] ca systemd-tmpfiles[122]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [7056628.949079] client systemd-tmpfiles[111]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> ca # [7056628.964670] ca systemd-tmpfiles[122]: fchmod() of /var/log/journal/9b2b87879f4241b4b8eef0ed3475387b failed: Operation not permitted container-test-run-certificates> client # [7056628.949198] client systemd-tmpfiles[111]: fchmod() of /var/log/journal/b65ec803ba224011bb1d5f7ff6c75afe failed: Operation not permitted container-test-run-certificates> server # [7056628.910113] server systemd-journald[69]: Journal started container-test-run-certificates> client # [7056628.949379] client systemd-tmpfiles[111]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> ca # [7056628.964858] ca systemd-tmpfiles[122]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [7056628.950688] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [7056628.910178] server systemd-journald[69]: Runtime Journal (/run/log/journal/f188ccca11014bac99ff51cdac8199bb) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> client # [7056628.951734] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> ca # [7056628.967456] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> client # [7056628.952425] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [7056628.968552] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> client # [7056628.963656] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [7056628.969229] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [7056628.914309] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [7056628.981701] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> client # [7056628.972518] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [7056628.915061] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [7056628.991604] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [7056628.915823] server systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [7056628.992897] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [7056628.923269] server systemd-journald[69]: Time spent on flushing to /var/log/journal/f188ccca11014bac99ff51cdac8199bb is 1.486ms for 5 entries. container-test-run-certificates> client # [7056628.973621] client systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [7056628.923269] server systemd-journald[69]: System Journal (/var/log/journal/f188ccca11014bac99ff51cdac8199bb) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [7056628.986102] client systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [7056628.931575] server systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> server # [7056628.932305] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> server # [7056628.932495] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> server # [7056628.933438] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> server # [7056628.933489] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [7056628.934385] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [7056628.934422] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [7056628.934870] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [7056628.936269] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> server # [7056628.954375] server systemd-tmpfiles[108]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [7056628.954585] server systemd-tmpfiles[108]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [7056628.954727] server systemd-tmpfiles[108]: fchmod() of /var/log/journal/f188ccca11014bac99ff51cdac8199bb failed: Operation not permitted container-test-run-certificates> server # [7056628.954965] server systemd-tmpfiles[108]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [7056628.956432] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [7056628.957480] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [7056628.958209] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [7056628.970168] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [7056628.976651] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [7056628.977784] server systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [7056628.986576] server systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [7056629.053228] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [7056629.061208] server systemd[1]: Finished Firewall. container-test-run-certificates> server # [7056629.061345] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> server # [7056629.061556] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [7056629.062549] server systemd[1]: Starting Network Management... container-test-run-certificates> client # [7056629.046970] client systemd[1]: Finished Firewall. container-test-run-certificates> client # [7056629.047938] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [7056629.048404] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [7056629.049523] client systemd[1]: Starting Network Management... container-test-run-certificates> client # [7056629.049921] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> ca # [7056629.002256] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> ca # [7056629.051439] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> ca # [7056629.065533] ca systemd[1]: Finished Firewall. container-test-run-certificates> ca # [7056629.065674] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [7056629.065934] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> ca # [7056629.066898] ca systemd[1]: Starting Network Management... container-test-run-certificates> client # [7056629.547229] client systemd-networkd[182]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [7056629.547320] client systemd-networkd[182]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [7056629.554023] client systemd-networkd[182]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [7056629.554186] client systemd-networkd[182]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [7056629.554347] client systemd-networkd[182]: lo: Link UP container-test-run-certificates> client # [7056629.554351] client systemd-networkd[182]: lo: Gained carrier container-test-run-certificates> client # [7056629.554548] client systemd-networkd[182]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [7056629.554958] client systemd[1]: Started Network Management. container-test-run-certificates> client # [7056629.554990] client systemd-networkd[182]: eth1: Link UP container-test-run-certificates> client # [7056629.555284] client systemd-networkd[182]: eth1: Gained carrier container-test-run-certificates> client # [7056629.556760] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> client # [7056629.640918] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> client # [7056629.691737] client systemd-resolved[90]: Positive Trust Anchors: container-test-run-certificates> client # [7056629.691748] client systemd-resolved[90]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> client # [7056629.691751] client systemd-resolved[90]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [7056629.691785] client systemd-resolved[90]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [7056629.713865] client systemd-resolved[90]: Using system hostname 'client'. container-test-run-certificates> client # [7056629.715416] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> client # [7056629.715487] client systemd[1]: Reached target Network. container-test-run-certificates> client # [7056629.715548] client systemd[1]: Reached target System Initialization. container-test-run-certificates> client # [7056629.715593] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [7056629.715615] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> client # [7056629.715629] client systemd[1]: Reached target Timer Units. container-test-run-certificates> client # [7056629.715740] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [7056629.715840] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> client # [7056629.716015] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> client # [7056629.716041] client systemd[1]: Reached target Socket Units. container-test-run-certificates> client # [7056629.716079] client systemd[1]: Reached target Basic System. container-test-run-certificates> client # [7056629.717103] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> client # [7056629.717998] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> client # [7056629.719207] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [7056629.558374] server systemd-networkd[187]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [7056629.558464] server systemd-networkd[187]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [7056629.565176] server systemd-networkd[187]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [7056629.565334] server systemd-networkd[187]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [7056629.565489] server systemd-networkd[187]: lo: Link UP container-test-run-certificates> server # [7056629.565493] server systemd-networkd[187]: lo: Gained carrier container-test-run-certificates> server # [7056629.565677] server systemd-networkd[187]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [7056629.566037] server systemd[1]: Started Network Management. container-test-run-certificates> server # [7056629.632458] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> server # [7056629.632651] server systemd-networkd[187]: eth1: Link UP container-test-run-certificates> server # [7056629.632963] server systemd-networkd[187]: eth1: Gained carrier container-test-run-certificates> server # [7056629.666226] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [7056629.705027] server systemd-resolved[90]: Positive Trust Anchors: container-test-run-certificates> server # [7056629.705036] server systemd-resolved[90]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [7056629.705040] server systemd-resolved[90]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [7056629.705073] server systemd-resolved[90]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [7056629.726459] server systemd-resolved[90]: Using system hostname 'server'. container-test-run-certificates> server # [7056629.727786] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [7056629.727916] server systemd[1]: Reached target Network. container-test-run-certificates> server # [7056629.728040] server systemd[1]: Reached target Network is Online. container-test-run-certificates> server # [7056629.728146] server systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [7056629.728538] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> server # [7056629.728616] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [7056629.728677] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [7056629.728719] server systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [7056629.728943] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [7056629.729136] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [7056629.729346] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [7056629.729398] server systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [7056629.729472] server systemd[1]: Reached target Basic System. container-test-run-certificates> server # [7056629.781639] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> server # [7056629.783187] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [7056629.783258] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> server # [7056629.784622] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [7056629.786847] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [7056629.805036] server systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [7056629.889721] server acme-setup-privileged[192]: + set -euo pipefail container-test-run-certificates> server # [7056629.889721] server acme-setup-privileged[192]: + cd /var/lib/acme container-test-run-certificates> server # [7056629.889721] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> ca # [7056629.555414] ca systemd-networkd[196]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [7056629.555503] ca systemd-networkd[196]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [7056629.562542] ca systemd-networkd[196]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [7056629.562706] ca systemd-networkd[196]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [7056629.562863] ca systemd-networkd[196]: lo: Link UP container-test-run-certificates> ca # [7056629.562868] ca systemd-networkd[196]: lo: Gained carrier container-test-run-certificates> ca # [7056629.563041] ca systemd-networkd[196]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> ca # [7056629.563491] ca systemd[1]: Started Network Management. container-test-run-certificates> ca # [7056629.632305] ca systemd-networkd[196]: eth1: Link UP container-test-run-certificates> ca # [7056629.632392] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [7056629.632700] ca systemd-networkd[196]: eth1: Gained carrier container-test-run-certificates> ca # [7056629.661902] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> ca # [7056629.704756] ca systemd-resolved[102]: Positive Trust Anchors: container-test-run-certificates> ca # [7056629.704767] ca systemd-resolved[102]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [7056629.704770] ca systemd-resolved[102]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [7056629.704805] ca systemd-resolved[102]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [7056629.726458] ca systemd-resolved[102]: Using system hostname 'ca'. container-test-run-certificates> ca # [7056629.727763] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [7056629.727840] ca systemd[1]: Reached target Network. container-test-run-certificates> ca # [7056629.727897] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [7056629.727935] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [7056629.728152] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> ca # [7056629.728178] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [7056629.728198] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [7056629.728213] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> ca # [7056629.728334] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> ca # [7056629.728440] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [7056629.728549] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [7056629.728570] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [7056629.728607] ca systemd[1]: Reached target Basic System. container-test-run-certificates> ca # [7056629.781214] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> ca # [7056629.782104] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [7056629.782144] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> ca # [7056629.782987] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [7056629.784150] ca systemd[1]: Starting step-ca service... container-test-run-certificates> ca # [7056629.785375] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> ca # [7056629.803379] ca systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> ca # [7056629.900191] ca acme-setup-privileged[201]: + set -euo pipefail container-test-run-certificates> ca # [7056629.900191] ca acme-setup-privileged[201]: + cd /var/lib/acme container-test-run-certificates> ca # [7056629.900191] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> ca # [7056629.901542] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts container-test-run-certificates> client # [7056629.798951] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> client # [7056629.894335] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> client # [7056629.931192] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [7056629.931282] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [7056629.931803] client nsncd[189]: Aug 29 15:34:15.984 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [7056629.931384] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> client # [7056629.950149] client systemd[1]: Starting User Login Management... container-test-run-certificates> client # [7056629.951178] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> client # [7056629.961446] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> client # [7056629.962589] client systemd[1]: Started Console Getty. container-test-run-certificates> client # [7056629.962636] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> client # [7056629.962662] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> client # [7056630.048505] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> client # [7056630.049732] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [7056630.049732] client dbus-broker-launch[190]: Invalid user-name in /nix/store/ssk8893k9jd7id6pd9yzim0h6prlbdma-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [7056630.050080] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [7056629.891629] server acme-setup-privileged[192]: + chown -R acme .lego/accounts container-test-run-certificates> server # [7056629.892804] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [7056629.893608] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [7056629.893608] server acme-setup-privileged[192]: + '[' -d test.foo ']' container-test-run-certificates> server # [7056629.893608] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [7056629.893608] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']' container-test-run-certificates> server # [7056629.915787] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [7056629.903264] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> server # [7056629.915858] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [7056629.903307] ca acme-setup-privileged[201]: + '[' -d ca.foo ']' container-test-run-certificates> ca # [7056629.903307] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [7056629.903307] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> ca # [7056629.905561] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [7056629.930611] ca nsncd[203]: Aug 29 15:34:15.983 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [7056629.949091] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [7056629.949996] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [7056629.950155] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [7056629.952309] ca systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [7056629.953509] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [7056629.964814] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [7056629.965871] ca systemd[1]: Started Console Getty. container-test-run-certificates> ca # [7056629.965918] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [7056629.916193] server nsncd[194]: Aug 29 15:34:15.969 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [7056629.965937] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [7056629.915923] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [7056630.029761] ca dbus-broker-launch[205]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [7056629.949256] server systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [7056630.030767] ca dbus-broker-launch[205]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [7056629.950177] server systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [7056630.030767] ca dbus-broker-launch[205]: Invalid user-name in /nix/store/nrvy3kisslkv7qydv3v2ib6szfdky5q3-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> ca # [7056630.031232] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [7056630.038311] ca dbus-broker-launch[205]: Ready container-test-run-certificates> server # [7056629.960444] server systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [7056629.961611] server systemd[1]: Started Console Getty. container-test-run-certificates> server # [7056629.961659] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [7056629.961679] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [7056630.025756] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [7056630.028785] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [7056630.028785] server dbus-broker-launch[195]: Invalid user-name in /nix/store/aszr859gd9lnmlsj2dls188ya32g6xf8-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [7056630.029104] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [7056630.037500] server dbus-broker-launch[195]: Ready container-test-run-certificates> client # [7056630.057950] client dbus-broker-launch[190]: Ready container-test-run-certificates> client # [7056630.449203] client systemd-logind[205]: New seat seat0. container-test-run-certificates> client # [7056630.449403] client systemd[1]: Started User Login Management. container-test-run-certificates> server # [7056630.458545] server systemd-logind[220]: New seat seat0. container-test-run-certificates> client # [7056630.451592] client systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [7056630.458801] server systemd[1]: Started User Login Management. container-test-run-certificates> client # [7056630.525880] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> server # [7056630.512829] server systemd[1]: Starting linger-users.service... container-test-run-certificates> ca # [7056630.459032] ca systemd-logind[230]: New seat seat0. container-test-run-certificates> server # [7056630.525997] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [7056630.459264] ca systemd[1]: Started User Login Management. container-test-run-certificates> server # [7056630.526128] server systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [7056630.510319] ca acme-setup-start[218]: + set -euo pipefail container-test-run-certificates> server # [7056630.546473] server acme-setup-start[208]: + set -euo pipefail container-test-run-certificates> client # [7056630.526069] client systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [7056630.510319] ca acme-setup-start[218]: + test -e ca/key.pem container-test-run-certificates> client # [7056630.526638] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [7056630.546473] server acme-setup-start[208]: + test -e ca/key.pem container-test-run-certificates> client # [7056630.526948] client systemd[1]: Startup finished in 2.054s. container-test-run-certificates> server # [7056630.546914] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [7056630.510319] ca acme-setup-start[218]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> server # [7056630.569126] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [7056630.513100] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [7056630.570826] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> ca # [7056630.527319] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [7056630.527409] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [7056630.534382] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [7056630.536204] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> ca # [7056630.692170] ca step-ca[204]: badger 2026/08/29 15:34:16 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [7056630.698035] ca step-ca[204]: 2026/08/29 15:34:16 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> ca # [7056630.706812] ca step-ca[204]: 2026/08/29 15:34:16 Starting Smallstep CA/0.30.2 (linux/arm64) container-test-run-certificates> ca # [7056630.706812] ca step-ca[204]: 2026/08/29 15:34:16 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> ca # [7056630.706812] ca step-ca[204]: 2026/08/29 15:34:16 Community Discord: https://u.step.sm/discord container-test-run-certificates> ca # [7056630.706812] ca step-ca[204]: 2026/08/29 15:34:16 Config file: /etc/smallstep/ca.json container-test-run-certificates> ca # [7056630.706812] ca step-ca[204]: 2026/08/29 15:34:16 The primary server URL is https://ca.foo:1443 container-test-run-certificates> ca # [7056630.706812] ca step-ca[204]: 2026/08/29 15:34:16 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [7056630.707132] ca step-ca[204]: 2026/08/29 15:34:16 X.509 Root Fingerprint: 244f64410040a0ce4ba4c01b6a7dd648108aeee8aeac01f52a03a273e40d8a07 container-test-run-certificates> ca # [7056630.707438] ca systemd[1]: Started step-ca service. container-test-run-certificates> ca # [7056630.707802] ca step-ca[204]: 2026/08/29 15:34:16 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> client # [7056630.944242] client systemd-networkd[182]: eth1: Gained IPv6LL container-test-run-certificates> ca # [7056631.038188] ca acme-ca.foo-start[262]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [7056631.040677] ca acme-ca.foo-start[262]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [7056631.040762] ca acme-ca.foo-start[262]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> ca # [7056631.051537] ca acme-ca.foo-start[295]: + cd ca.foo container-test-run-certificates> ca # [7056631.051853] ca acme-ca.foo-start[295]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> ca # [7056631.054019] ca acme-ca.foo-start[296]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [7056631.054339] ca acme-ca.foo-start[295]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> ca # [7056631.055386] ca acme-ca.foo-start[295]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [7056631.055571] ca acme-ca.foo-start[262]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [7056631.057425] ca acme-ca.foo-start[262]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [7056631.059174] ca acme-ca.foo-start[262]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [7056631.061263] ca acme-ca.foo-start[262]: + for fixpath in out certificates container-test-run-certificates> ca # [7056631.061298] ca acme-ca.foo-start[262]: + '[' -d out ']' container-test-run-certificates> ca # [7056631.061298] ca acme-ca.foo-start[262]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [7056631.063052] ca acme-ca.foo-start[262]: + chown -R acme:nginx out container-test-run-certificates> ca # [7056631.066039] ca acme-ca.foo-start[262]: + for fixpath in out certificates container-test-run-certificates> ca # [7056631.066069] ca acme-ca.foo-start[262]: + '[' -d certificates ']' container-test-run-certificates> ca # [7056631.069092] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> server # [7056631.073231] server acme-test.foo-start[245]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [7056631.105453] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> server # [7056631.075657] server acme-test.foo-start[245]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [7056631.075698] server acme-test.foo-start[245]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [7056631.090424] server acme-test.foo-start[255]: + cd test.foo container-test-run-certificates> server # [7056631.090792] server acme-test.foo-start[255]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [7056631.091964] server acme-test.foo-start[256]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [7056631.092197] server acme-test.foo-start[255]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [7056631.093265] server acme-test.foo-start[255]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [7056631.093454] server acme-test.foo-start[245]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [7056631.095308] server acme-test.foo-start[245]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [7056631.096760] server acme-test.foo-start[245]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [7056631.098376] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [7056631.098400] server acme-test.foo-start[245]: + '[' -d out ']' container-test-run-certificates> server # [7056631.098400] server acme-test.foo-start[245]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [7056631.099739] server acme-test.foo-start[245]: + chown -R acme:nginx out container-test-run-certificates> server # [7056631.102636] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [7056631.102636] server acme-test.foo-start[245]: + '[' -d certificates ']' container-test-run-certificates> server # [7056631.106764] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [7056631.108275] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> ca # [7056631.488276] ca systemd-networkd[196]: eth1: Gained IPv6LL container-test-run-certificates> ca # [7056631.644678] ca nginx-pre-start[307]: nginx: the configuration file /nix/store/hw5agv0zd5hxyng79124v1vhs1zxdw01-nginx.conf syntax is ok container-test-run-certificates> ca # [7056631.645259] ca nginx-pre-start[307]: nginx: configuration file /nix/store/hw5agv0zd5hxyng79124v1vhs1zxdw01-nginx.conf test is successful container-test-run-certificates> ca # [7056631.668551] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [7056631.669218] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [7056631.671220] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> server # [7056631.630166] server nginx-pre-start[267]: nginx: the configuration file /nix/store/jz7kmd1pqz9d3z4szhmwj70infw1zqg3-nginx.conf syntax is ok container-test-run-certificates> server # [7056631.630792] server nginx-pre-start[267]: nginx: configuration file /nix/store/jz7kmd1pqz9d3z4szhmwj70infw1zqg3-nginx.conf test is successful container-test-run-certificates> server # [7056631.634797] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [7056631.636229] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [7056631.638255] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> server # [7056631.648106] server systemd-networkd[187]: eth1: Gained IPv6LL container-test-run-certificates> ca # [7056632.235943] ca acme-order-renew-ca.foo-start[310]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [7056632.238792] ca acme-order-renew-ca.foo-start[310]: + set -euo pipefail container-test-run-certificates> ca # [7056632.238870] ca acme-order-renew-ca.foo-start[310]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [7056632.238980] ca acme-order-renew-ca.foo-start[310]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [7056632.240459] ca acme-order-renew-ca.foo-start[310]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> ca # [7056632.255240] ca acme-order-renew-ca.foo-start[322]: 2026/08/29 15:34:18 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [7056632.255733] ca acme-order-renew-ca.foo-start[322]: 2026/08/29 15:34:18 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [7056632.280336] ca step-ca[204]: time="2026-08-29T15:34:18Z" level=info duration="158.443µs" duration-ns=158443 fields.time="2026-08-29T15:34:18Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=12458c35-9e10-4d46-9ff5-db3809362b73 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7056632.281050] ca acme-order-renew-ca.foo-start[322]: 2026/08/29 15:34:18 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> ca # [7056632.349301] ca step-ca[204]: time="2026-08-29T15:34:18Z" level=info duration=68.291148ms duration-ns=68291148 fields.time="2026-08-29T15:34:18Z" method=HEAD name=ca nonce=d3o1WTlaUFFJZGF6V3gyVDJtUGRBUW1lSVNJOVFtOVQ path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=3ac800e3-ca33-4c11-9e08-2ade7039c509 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7056632.355560] ca step-ca[204]: time="2026-08-29T15:34:18Z" level=info duration=5.417645ms duration-ns=5417645 fields.time="2026-08-29T15:34:18Z" method=POST name=ca nonce=dXdsMkVIeG1MemIzUXFkUFc5eUh0eEZVZDhpS0d4SVU path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=d6b8c92e-5cec-44a6-800d-829810145cf5 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/EGprDje77eG69xvF9pxAvtgf7QqN9uQo/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7056632.355940] ca acme-order-renew-ca.foo-start[322]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [7056632.355940] ca acme-order-renew-ca.foo-start[322]: Your account credentials have been saved in your container-test-run-certificates> ca # [7056632.355940] ca acme-order-renew-ca.foo-start[322]: configuration directory at "accounts". container-test-run-certificates> ca # [7056632.355940] ca acme-order-renew-ca.foo-start[322]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [7056632.355940] ca acme-order-renew-ca.foo-start[322]: configuration directory will also contain private keys container-test-run-certificates> ca # [7056632.355940] ca acme-order-renew-ca.foo-start[322]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [7056632.355940] ca acme-order-renew-ca.foo-start[322]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [7056632.356284] ca acme-order-renew-ca.foo-start[322]: 2026/08/29 15:34:18 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [7056632.360476] ca step-ca[204]: time="2026-08-29T15:34:18Z" level=info duration=3.925702ms duration-ns=3925702 fields.time="2026-08-29T15:34:18Z" method=POST name=ca nonce=cGFSM2xyaUdNdk9qZXVrMUpTMU8xVVVpNDdBYXJsN24 path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=30a69c80-4b4c-4628-b971-008c3b2fa4e9 response="{\"id\":\"rsC1vZPb0iAizXsyN1g72QHj6CDcqiRj\",\"status\":\"pending\",\"expires\":\"2026-08-30T15:34:18Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-29T15:33:18Z\",\"notAfter\":\"2026-11-27T15:34:18Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/1gELcaMB0YtMqHbJ6ofgqSGgHuuxQyMG\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/rsC1vZPb0iAizXsyN1g72QHj6CDcqiRj/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7056632.420457] ca step-ca[204]: time="2026-08-29T15:34:18Z" level=info duration=2.57588ms duration-ns=2575880 fields.time="2026-08-29T15:34:18Z" method=POST name=ca nonce=RnVvd2RlZHlNTDZkR1ZyRmVPNkhGSDE5enM2V2NwVnQ path=/acme/acme/authz/1gELcaMB0YtMqHbJ6ofgqSGgHuuxQyMG protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=eb504dc1-a060-4dcd-acc9-9abb4d710a95 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"RCnra5Zihk0vRFnFEi2YHifpypVp0id9\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/1gELcaMB0YtMqHbJ6ofgqSGgHuuxQyMG/bOcySKW0PqaXIjMN9UfnCksyGibzs0AP\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"RCnra5Zihk0vRFnFEi2YHifpypVp0id9\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/1gELcaMB0YtMqHbJ6ofgqSGgHuuxQyMG/czYbyqeo2cWq2JbgA1ii2a1pjoIWqreV\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"RCnra5Zihk0vRFnFEi2YHifpypVp0id9\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/1gELcaMB0YtMqHbJ6ofgqSGgHuuxQyMG/lTsaYRSbpcZYF8CsQQsW67Xqs2NWJbOE\"}],\"wildcard\":false,\"expires\":\"2026-08-30T15:34:18Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7056632.420880] ca acme-order-renew-ca.foo-start[322]: 2026/08/29 15:34:18 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/1gELcaMB0YtMqHbJ6ofgqSGgHuuxQyMG container-test-run-certificates> ca # [7056632.420880] ca acme-order-renew-ca.foo-start[322]: 2026/08/29 15:34:18 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [7056632.420880] ca acme-order-renew-ca.foo-start[322]: 2026/08/29 15:34:18 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [7056632.420880] ca acme-order-renew-ca.foo-start[322]: 2026/08/29 15:34:18 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> ca # [7056632.427660] ca step-ca[204]: time="2026-08-29T15:34:18Z" level=info duration=5.949053ms duration-ns=5949053 fields.time="2026-08-29T15:34:18Z" method=POST name=ca nonce=Nlc0bnZHdnRNRHBXM1p1OWZDa0RZSEk3RVpvUVpQa1Q path=/acme/acme/challenge/1gELcaMB0YtMqHbJ6ofgqSGgHuuxQyMG/czYbyqeo2cWq2JbgA1ii2a1pjoIWqreV protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=ef943318-d2e5-4660-bf57-7be948b4a7d5 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"RCnra5Zihk0vRFnFEi2YHifpypVp0id9\",\"validated\":\"2026-08-29T15:34:18Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/1gELcaMB0YtMqHbJ6ofgqSGgHuuxQyMG/czYbyqeo2cWq2JbgA1ii2a1pjoIWqreV\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7056632.427989] ca acme-order-renew-ca.foo-start[322]: 2026/08/29 15:34:18 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [7056632.428103] ca acme-order-renew-ca.foo-start[322]: 2026/08/29 15:34:18 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [7056632.438983] ca step-ca[204]: time="2026-08-29T15:34:18Z" level=info duration=9.62227ms duration-ns=9622270 fields.time="2026-08-29T15:34:18Z" method=POST name=ca nonce=Tm9vam5pVHFZZE1jN0h1d0x3Ung3VDdVSmZRR0ppaDI path=/acme/acme/order/rsC1vZPb0iAizXsyN1g72QHj6CDcqiRj/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=7f1d1f7a-0fee-455c-bf55-f08ae8e9a2d8 response="{\"id\":\"rsC1vZPb0iAizXsyN1g72QHj6CDcqiRj\",\"status\":\"valid\",\"expires\":\"2026-08-30T15:34:18Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-29T15:33:18Z\",\"notAfter\":\"2026-11-27T15:34:18Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/1gELcaMB0YtMqHbJ6ofgqSGgHuuxQyMG\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/rsC1vZPb0iAizXsyN1g72QHj6CDcqiRj/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/6DR7Gg2mfZE6J0m0zfRQRb0eMtC2VVnc\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7056632.441773] ca step-ca[204]: time="2026-08-29T15:34:18Z" level=info certificate="MIIB1DCCAXmgAwIBAgIQF5r1J/4fr0UnSB5eGFwDxzAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MjkxNTMzMThaFw0yNjExMjcxNTM0MThaMBExDzANBgNVBAMTBmNhLmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABN0BM4GikB2nbvlkYv0Hgn7Ej4TJ784e4jFm7w8SMQGTJb3cWHxliP1G9WSelHJi9TLxio3g4Z1UCwaXI5WpeHCjgaQwgaEwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUssOny3qymhWyRy/4OmdcMNXXdTQwHwYDVR0jBBgwFoAUzv/Hq8iXs2XTVEXZXIp7IZLtcdMwEQYDVR0RBAowCIIGY2EuZm9vMB0GDCsGAQQBgqRkxihAAQQNMAsCAQYEBGFjbWUEADAKBggqhkjOPQQDAgNJADBGAiEAsXmePG7TlDzxlrckMRi5EU2S/8oSbFbIOrNtwjcBcRgCIQCPFSYSzlz9GFWk+IBNqzyWTdYaj32fgnBqUZVJRV5yFw==" duration=1.869909ms duration-ns=1869909 fields.time="2026-08-29T15:34:18Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=VE5ORGVGMUxCQWRTYmUzcmNNdDVnZnlHemtkMHhrek4 path=/acme/acme/certificate/6DR7Gg2mfZE6J0m0zfRQRb0eMtC2VVnc protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=f84a1fa4-a3bc-444e-b83e-2b1696f9e837 sans="map[dns:[ca.foo]]" serial=31376829978166158131964382035595494343 size=1344 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-29T15:33:18Z" valid-to="2026-11-27T15:34:18Z" container-test-run-certificates> ca # [7056632.442232] ca acme-order-renew-ca.foo-start[322]: 2026/08/29 15:34:18 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [7056632.448241] ca acme-order-renew-ca.foo-start[310]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [7056632.450166] ca acme-order-renew-ca.foo-start[310]: + touch out/acme-success container-test-run-certificates> ca # [7056632.452121] ca acme-order-renew-ca.foo-start[310]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [7056632.453159] ca acme-order-renew-ca.foo-start[310]: + touch out/renewed container-test-run-certificates> ca # [7056632.454766] ca acme-order-renew-ca.foo-start[310]: + echo Installing new certificate container-test-run-certificates> ca # [7056632.454766] ca acme-order-renew-ca.foo-start[310]: Installing new certificate container-test-run-certificates> ca # [7056632.454817] ca acme-order-renew-ca.foo-start[310]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [7056632.456492] ca acme-order-renew-ca.foo-start[354]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [7056632.456737] ca acme-order-renew-ca.foo-start[310]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [7056632.458136] ca acme-order-renew-ca.foo-start[355]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [7056632.458353] ca acme-order-renew-ca.foo-start[310]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [7056632.459618] ca acme-order-renew-ca.foo-start[356]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [7056632.459822] ca acme-order-renew-ca.foo-start[310]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [7056632.461661] ca acme-order-renew-ca.foo-start[310]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [7056632.463498] ca acme-order-renew-ca.foo-start[310]: + for fixpath in out certificates container-test-run-certificates> ca # [7056632.463528] ca acme-order-renew-ca.foo-start[310]: + '[' -d out ']' container-test-run-certificates> ca # [7056632.463553] ca acme-order-renew-ca.foo-start[310]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [7056632.465141] ca acme-order-renew-ca.foo-start[310]: + chown -R acme:nginx out container-test-run-certificates> ca # [7056632.468220] ca acme-order-renew-ca.foo-start[310]: + for fixpath in out certificates container-test-run-certificates> ca # [7056632.468256] ca acme-order-renew-ca.foo-start[310]: + '[' -d certificates ']' container-test-run-certificates> ca # [7056632.468282] ca acme-order-renew-ca.foo-start[310]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [7056632.470298] ca acme-order-renew-ca.foo-start[310]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [7056632.473391] ca acme-order-renew-ca.foo-start[310]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> server # [7056632.221593] server acme-order-renew-test.foo-start[270]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [7056632.223905] server acme-order-renew-test.foo-start[270]: + set -euo pipefail container-test-run-certificates> server # [7056632.224056] server acme-order-renew-test.foo-start[270]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [7056632.224144] server acme-order-renew-test.foo-start[270]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [7056632.225252] server acme-order-renew-test.foo-start[270]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [7056632.254527] server acme-order-renew-test.foo-start[282]: 2026/08/29 15:34:18 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [7056632.254856] server acme-order-renew-test.foo-start[282]: 2026/08/29 15:34:18 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> server # [7056632.283880] server acme-order-renew-test.foo-start[282]: 2026/08/29 15:34:18 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority container-test-run-certificates> server # [7056632.284597] server acme-order-renew-test.foo-start[270]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [7056632.284597] server acme-order-renew-test.foo-start[270]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [7056632.284663] server acme-order-renew-test.foo-start[270]: + exit 10 container-test-run-certificates> server # [7056632.287806] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a container-test-run-certificates> server # [7056632.287929] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'. container-test-run-certificates> server # [7056632.360310] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [7056632.360702] server systemd[1]: Startup finished in 3.874s. container-test-run-certificates> ca # [7056632.570965] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> ca # [7056632.574901] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [7056632.575094] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> ca # [7056633.090892] ca nginx[372]: nginx: the configuration file /nix/store/hw5agv0zd5hxyng79124v1vhs1zxdw01-nginx.conf syntax is ok container-test-run-certificates> ca # [7056633.091454] ca nginx[372]: nginx: configuration file /nix/store/hw5agv0zd5hxyng79124v1vhs1zxdw01-nginx.conf test is successful container-test-run-certificates> ca # [7056633.577222] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [7056633.577691] ca systemd[1]: Startup finished in 5.068s. container-test-run-certificates> ca # [7056633.643318] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 3.39 seconds) container-test-run-certificates> ca # [7056634.123853] ca acme-order-renew-ca.foo-start[387]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [7056634.127022] ca acme-order-renew-ca.foo-start[387]: + set -euo pipefail container-test-run-certificates> ca # [7056634.127091] ca acme-order-renew-ca.foo-start[387]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [7056634.127224] ca acme-order-renew-ca.foo-start[387]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [7056634.128358] ca acme-order-renew-ca.foo-start[387]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [7056634.128358] ca acme-order-renew-ca.foo-start[387]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [7056634.128927] ca acme-order-renew-ca.foo-start[395]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [7056634.132016] ca acme-order-renew-ca.foo-start[387]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [7056634.132120] ca acme-order-renew-ca.foo-start[387]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [7056634.174624] ca step-ca[204]: time="2026-08-29T15:34:20Z" level=info duration="65.641µs" duration-ns=65641 fields.time="2026-08-29T15:34:20Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=b6587719-a093-406a-87d0-7fe7d6150005 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7056634.175078] ca acme-order-renew-ca.foo-start[396]: 2026/08/29 15:34:20 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [7056634.175078] ca acme-order-renew-ca.foo-start[396]: 2026/08/29 15:34:20 [INFO] [ca.foo] The certificate expires at 2026-11-27T15:34:18Z, the renewal can be performed in 1439h59m37.771795064s: no renewal. container-test-run-certificates> ca # [7056634.175683] ca acme-order-renew-ca.foo-start[387]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [7056634.177702] ca acme-order-renew-ca.foo-start[387]: + touch out/acme-success container-test-run-certificates> ca # [7056634.179599] ca acme-order-renew-ca.foo-start[387]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [7056634.181086] ca acme-order-renew-ca.foo-start[387]: + for fixpath in out certificates container-test-run-certificates> ca # [7056634.181121] ca acme-order-renew-ca.foo-start[387]: + '[' -d out ']' container-test-run-certificates> ca # [7056634.181121] ca acme-order-renew-ca.foo-start[387]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [7056634.182972] ca acme-order-renew-ca.foo-start[387]: + chown -R acme:nginx out container-test-run-certificates> ca # [7056634.186070] ca acme-order-renew-ca.foo-start[387]: + for fixpath in out certificates container-test-run-certificates> ca # [7056634.186099] ca acme-order-renew-ca.foo-start[387]: + '[' -d certificates ']' container-test-run-certificates> ca # [7056634.186124] ca acme-order-renew-ca.foo-start[387]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [7056634.187781] ca acme-order-renew-ca.foo-start[387]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [7056634.190703] ca acme-order-renew-ca.foo-start[387]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [7056634.363554] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [7056634.363767] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server # [7056637.391610] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [7056637.391761] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [7056637.392520] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [7056637.393817] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.57 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1009 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 29 15:34:17 2026 GMT container-test-run-certificates> * expire date: Sep 28 15:34:17 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 4088eb container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [7056637.917948] server acme-test.foo-start[315]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [7056637.920739] server acme-test.foo-start[315]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [7056637.920739] server acme-test.foo-start[315]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [7056637.934542] server acme-test.foo-start[325]: + cd test.foo container-test-run-certificates> server # [7056637.935056] server acme-test.foo-start[325]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [7056637.936209] server acme-test.foo-start[326]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [7056637.936510] server acme-test.foo-start[325]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [7056637.937789] server acme-test.foo-start[325]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [7056637.938052] server acme-test.foo-start[315]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [7056637.939864] server acme-test.foo-start[315]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [7056637.941602] server acme-test.foo-start[315]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [7056637.943630] server acme-test.foo-start[315]: + for fixpath in out certificates container-test-run-certificates> server # [7056637.943630] server acme-test.foo-start[315]: + '[' -d out ']' container-test-run-certificates> server # [7056637.943718] server acme-test.foo-start[315]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [7056637.945387] server acme-test.foo-start[315]: + chown -R acme:nginx out container-test-run-certificates> server # [7056637.948914] server acme-test.foo-start[315]: + for fixpath in out certificates container-test-run-certificates> server # [7056637.948914] server acme-test.foo-start[315]: + '[' -d certificates ']' container-test-run-certificates> server # [7056637.952703] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [7056637.957448] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> server # [7056638.493365] server acme-order-renew-test.foo-start[333]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [7056638.495983] server acme-order-renew-test.foo-start[333]: + set -euo pipefail container-test-run-certificates> server # [7056638.496079] server acme-order-renew-test.foo-start[333]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [7056638.496182] server acme-order-renew-test.foo-start[333]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [7056638.497532] server acme-order-renew-test.foo-start[333]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [7056638.543963] server acme-order-renew-test.foo-start[341]: 2026/08/29 15:34:24 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [7056638.579555] server acme-order-renew-test.foo-start[341]: !!!! HEADS UP !!!! container-test-run-certificates> server # [7056638.579555] server acme-order-renew-test.foo-start[341]: Your account credentials have been saved in your container-test-run-certificates> server # [7056638.579555] server acme-order-renew-test.foo-start[341]: configuration directory at "accounts". container-test-run-certificates> server # [7056638.579555] server acme-order-renew-test.foo-start[341]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [7056638.579555] server acme-order-renew-test.foo-start[341]: configuration directory will also contain private keys container-test-run-certificates> server # [7056638.579555] server acme-order-renew-test.foo-start[341]: generated by lego and certificates obtained from the ACME container-test-run-certificates> server # [7056638.579555] server acme-order-renew-test.foo-start[341]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [7056638.579751] server acme-order-renew-test.foo-start[341]: 2026/08/29 15:34:24 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> server # [7056638.656955] server acme-order-renew-test.foo-start[341]: 2026/08/29 15:34:24 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/nEKdR2BxzWfBNg5Nt8hilt2Pv9NX9gaR container-test-run-certificates> server # [7056638.656955] server acme-order-renew-test.foo-start[341]: 2026/08/29 15:34:24 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [7056638.656955] server acme-order-renew-test.foo-start[341]: 2026/08/29 15:34:24 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [7056638.656955] server acme-order-renew-test.foo-start[341]: 2026/08/29 15:34:24 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [7056638.662640] server acme-order-renew-test.foo-start[341]: 2026/08/29 15:34:24 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [7056638.662709] server acme-order-renew-test.foo-start[341]: 2026/08/29 15:34:24 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [7056638.673840] server acme-order-renew-test.foo-start[341]: 2026/08/29 15:34:24 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [7056638.677596] server acme-order-renew-test.foo-start[333]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [7056638.679491] server acme-order-renew-test.foo-start[333]: + touch out/acme-success container-test-run-certificates> server # [7056638.681253] server acme-order-renew-test.foo-start[333]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [7056638.682286] server acme-order-renew-test.foo-start[333]: + touch out/renewed container-test-run-certificates> server # [7056638.683500] server acme-order-renew-test.foo-start[333]: + echo Installing new certificate container-test-run-certificates> server # [7056638.683500] server acme-order-renew-test.foo-start[333]: Installing new certificate container-test-run-certificates> server # [7056638.683544] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [7056638.685060] server acme-order-renew-test.foo-start[373]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [7056638.685291] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [7056638.686603] server acme-order-renew-test.foo-start[374]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [7056638.686808] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [7056638.688296] server acme-order-renew-test.foo-start[375]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [7056638.688552] server acme-order-renew-test.foo-start[333]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [7056638.689940] server acme-order-renew-test.foo-start[333]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [7056638.691469] server acme-order-renew-test.foo-start[333]: + for fixpath in out certificates container-test-run-certificates> server # [7056638.691493] server acme-order-renew-test.foo-start[333]: + '[' -d out ']' container-test-run-certificates> server # [7056638.691493] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [7056638.693104] server acme-order-renew-test.foo-start[333]: + chown -R acme:nginx out container-test-run-certificates> server # [7056638.695431] server acme-order-renew-test.foo-start[333]: + for fixpath in out certificates container-test-run-certificates> server # [7056638.695454] server acme-order-renew-test.foo-start[333]: + '[' -d certificates ']' container-test-run-certificates> server # [7056638.695454] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [7056638.696974] server acme-order-renew-test.foo-start[333]: + chown -R acme:nginx certificates container-test-run-certificates> server # [7056638.699685] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [7056638.543107] ca step-ca[204]: time="2026-08-29T15:34:24Z" level=info duration="49.96µs" duration-ns=49960 fields.time="2026-08-29T15:34:24Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=ac8021b8-cd81-4b84-a4c8-6497e64cd4db response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7056638.571824] ca step-ca[204]: time="2026-08-29T15:34:24Z" level=info duration=25.256474ms duration-ns=25256474 fields.time="2026-08-29T15:34:24Z" method=HEAD name=ca nonce=emNhR0p0UFI5UGdBYUd0SW9hVEdOYzR4c3F2blpZVVk path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=7646f9c3-44ef-4a55-87a4-41acf03c685a size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7056638.579103] ca step-ca[204]: time="2026-08-29T15:34:24Z" level=info duration=4.601632ms duration-ns=4601632 fields.time="2026-08-29T15:34:24Z" method=POST name=ca nonce=aTYzaTN3SHJ1dFdGaldHQXRlUmRIZndDOXZYcngwYmk path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=a9ac6c69-6cbb-4330-93cd-85156407abb1 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/pwlvMSiegBKnCbUvwvdCwRE5pZu5UW3V/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7056638.585984] ca step-ca[204]: time="2026-08-29T15:34:24Z" level=info duration=4.252267ms duration-ns=4252267 fields.time="2026-08-29T15:34:24Z" method=POST name=ca nonce=N2VDbjEwWDFmZDMyS0pmQmI0ODE3NTJBZWZPMFVjNFY path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=d9d53bb8-85c1-46b6-8a9c-fd3321b48fef response="{\"id\":\"cVWEHOBJNQlHxgKcjvOmHgk4ecLcNjuP\",\"status\":\"pending\",\"expires\":\"2026-08-30T15:34:24Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-29T15:33:24Z\",\"notAfter\":\"2026-11-27T15:34:24Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/nEKdR2BxzWfBNg5Nt8hilt2Pv9NX9gaR\"],\"finalize\":\"https://ca.foo/acme/acme/order/cVWEHOBJNQlHxgKcjvOmHgk4ecLcNjuP/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7056638.656435] ca step-ca[204]: time="2026-08-29T15:34:24Z" level=info duration=11.669662ms duration-ns=11669662 fields.time="2026-08-29T15:34:24Z" method=POST name=ca nonce=QThpMDVWWnlsdU1jU3dkQVhxc2hVenI4MkRDSTk0R2Q path=/acme/acme/authz/nEKdR2BxzWfBNg5Nt8hilt2Pv9NX9gaR protocol=HTTP/1.1 referer= remote-address="::1" request-id=64c9bb53-7ac1-4603-a50a-47054f02b271 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"k3IxejOrO5Xj6KoxQjurOy32UhF0nDkj\",\"url\":\"https://ca.foo/acme/acme/challenge/nEKdR2BxzWfBNg5Nt8hilt2Pv9NX9gaR/QsOW62o9FuXRvcBMnYipRn3k3ZSIbCsi\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"k3IxejOrO5Xj6KoxQjurOy32UhF0nDkj\",\"url\":\"https://ca.foo/acme/acme/challenge/nEKdR2BxzWfBNg5Nt8hilt2Pv9NX9gaR/yK0DDQfCBDa7MhzOZY2QmKIa0QujeoUw\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"k3IxejOrO5Xj6KoxQjurOy32UhF0nDkj\",\"url\":\"https://ca.foo/acme/acme/challenge/nEKdR2BxzWfBNg5Nt8hilt2Pv9NX9gaR/0CKyTohOMQUowGshxsaPXDHmldxHkS0a\"}],\"wildcard\":false,\"expires\":\"2026-08-30T15:34:24Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7056638.662199] ca step-ca[204]: time="2026-08-29T15:34:24Z" level=info duration=3.074209ms duration-ns=3074209 fields.time="2026-08-29T15:34:24Z" method=POST name=ca nonce=YlZDZmwyWWF3Q0pFTnQzZW9RT21INVVOaXJDRTBxWXU path=/acme/acme/challenge/nEKdR2BxzWfBNg5Nt8hilt2Pv9NX9gaR/yK0DDQfCBDa7MhzOZY2QmKIa0QujeoUw protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=35920c33-f852-491a-bf98-32abad83cc79 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"k3IxejOrO5Xj6KoxQjurOy32UhF0nDkj\",\"validated\":\"2026-08-29T15:34:24Z\",\"url\":\"https://ca.foo/acme/acme/challenge/nEKdR2BxzWfBNg5Nt8hilt2Pv9NX9gaR/yK0DDQfCBDa7MhzOZY2QmKIa0QujeoUw\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7056638.669924] ca step-ca[204]: time="2026-08-29T15:34:24Z" level=info duration=4.700633ms duration-ns=4700633 fields.time="2026-08-29T15:34:24Z" method=POST name=ca nonce=aFhLY0prQndwVkJvZWNBUnVlZ29mWlNsUXhKcGhINkY path=/acme/acme/order/cVWEHOBJNQlHxgKcjvOmHgk4ecLcNjuP/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=0cc3853f-de04-4c16-bbc0-81f4fe08478e response="{\"id\":\"cVWEHOBJNQlHxgKcjvOmHgk4ecLcNjuP\",\"status\":\"valid\",\"expires\":\"2026-08-30T15:34:24Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-29T15:33:24Z\",\"notAfter\":\"2026-11-27T15:34:24Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/nEKdR2BxzWfBNg5Nt8hilt2Pv9NX9gaR\"],\"finalize\":\"https://ca.foo/acme/acme/order/cVWEHOBJNQlHxgKcjvOmHgk4ecLcNjuP/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/j2zJfbJIx72LWjkVhEC6Hp2OwUPTwgQG\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [7056638.673507] ca step-ca[204]: time="2026-08-29T15:34:24Z" level=info certificate=MIIB2TCCAX6gAwIBAgIRAOghpyfDPRRGjU+zdWa9iX4wCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwODI5MTUzMzI0WhcNMjYxMTI3MTUzNDI0WjATMREwDwYDVQQDEwh0ZXN0LmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABHzf9BnkeUPrrBDDkzRAHLe7iusM/9ISamLrfk4zO3VN90c0Yt7nc33KX61tsj9uzs3s9AB2iezEANGTj3OTqC2jgaYwgaMwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQU+jOT1Kv8Xodx7+S05A4pIf+nV80wHwYDVR0jBBgwFoAUzv/Hq8iXs2XTVEXZXIp7IZLtcdMwEwYDVR0RBAwwCoIIdGVzdC5mb28wHQYMKwYBBAGCpGTGKEABBA0wCwIBBgQEYWNtZQQAMAoGCCqGSM49BAMCA0kAMEYCIQCmc/AVgc+3Fv8jW5neJwI1Ruzv+JF4W6hgreGnBpFUYgIhAIivpHZnk6cIiWUiUUjEl0pxc2b58Ej3i4lFBaUmv5m1 duration=1.28578ms duration-ns=1285780 fields.time="2026-08-29T15:34:24Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=UVdNeTNsYmdEbVdpc3ZhMktyRUNFMUxzWjUzZjZGTmY path=/acme/acme/certificate/j2zJfbJIx72LWjkVhEC6Hp2OwUPTwgQG protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=c002a8a1-27bf-4a26-b09f-91696a5f39b6 sans="map[dns:[test.foo]]" serial=308555631131157696849637787635969526142 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-29T15:33:24Z" valid-to="2026-11-27T15:34:24Z" container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1009 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [110 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 29 15:34:17 2026 GMT container-test-run-certificates> * expire date: Sep 28 15:34:17 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 4088eb container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [7056638.816488] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [7056638.820422] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [7056638.820613] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [7056639.282791] server nginx[391]: nginx: the configuration file /nix/store/jz7kmd1pqz9d3z4szhmwj70infw1zqg3-nginx.conf syntax is ok container-test-run-certificates> server # [7056639.283366] server nginx[391]: nginx: configuration file /nix/store/jz7kmd1pqz9d3z4szhmwj70infw1zqg3-nginx.conf test is successful container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [932 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [79 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 29 15:33:24 2026 GMT container-test-run-certificates> * expire date: Nov 27 15:34:24 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 37598 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 682 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 2.15 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> e8:21:a7:27:c3:3d:14:46:8d:4f:b3:75:66:bd:89:7e container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Aug 29 15:33:24 2026 GMT container-test-run-certificates> Not After : Nov 27 15:34:24 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:7c:df:f4:19:e4:79:43:eb:ac:10:c3:93:34:40: container-test-run-certificates> 1c:b7:bb:8a:eb:0c:ff:d2:12:6a:62:eb:7e:4e:33: container-test-run-certificates> 3b:75:4d:f7:47:34:62:de:e7:73:7d:ca:5f:ad:6d: container-test-run-certificates> b2:3f:6e:ce:cd:ec:f4:00:76:89:ec:c4:00:d1:93: container-test-run-certificates> 8f:73:93:a8:2d container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> FA:33:93:D4:AB:FC:5E:87:71:EF:E4:B4:E4:0E:29:21:FF:A7:57:CD container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> CE:FF:C7:AB:C8:97:B3:65:D3:54:45:D9:5C:8A:7B:21:92:ED:71:D3 container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:46:02:21:00:a6:73:f0:15:81:cf:b7:16:ff:23:5b:99:de: container-test-run-certificates> 27:02:35:46:ec:ef:f8:91:78:5b:a8:60:ad:e1:a7:06:91:54: container-test-run-certificates> 62:02:21:00:88:af:a4:76:67:93:a7:08:89:65:22:51:48:c4: container-test-run-certificates> 97:4a:71:73:66:f9:f0:48:f7:8b:89:45:05:a5:26:bf:99:b5 container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.04 seconds) container-test-run-certificates> (finished: run the VM test script, in 12.16 seconds) container-test-run-certificates> server # [7056639.826564] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> test script finished in 13.67s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 53) container-test-run-certificates> kill NspawnMachine (pid 54) container-test-run-certificates> kill NspawnMachine (pid 56) container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> Container server terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.64 seconds) warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy post-build step Upload to niks3: ok time=2026-08-29T15:34:31.108Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-08-29T15:34:31.371Z level=INFO msg="Uploading 1 narinfos" time=2026-08-29T15:34:31.506Z level=INFO msg="Upload complete. (448ms)"