these 116 derivations will be built: /nix/store/036blsc4zrqllkxan7f78dh9gd9ch2zr-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/07182vp9nm48fkgibfn911dbhlvs6isg-vars-check-certificates.drv /nix/store/7cnvsby4x32q8ln7gh7hjc9dgwkg9fll-system-path.drv /nix/store/yll0q6ljy9rfnnphbg1m0vnbpsmvm3q1-dbus-1.drv /nix/store/46ciwslw4lnhil7v9q4h1p1gppfrbj41-X-Restart-Triggers-dbus-broker.drv /nix/store/0nx9bnyx7j795swlzd32k0hd83nyvxj7-unit-dbus-broker.service.drv /nix/store/0sggpnpx0hb7ps7mipz1v6p0j50j74f9-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/0zdzqh8g7k3r2bwrjb5s1dj9xvfzj537-etc-hostname.drv /nix/store/dqvgx3mishwyspmig2fi98lgvzw4n876-ca.json.drv /nix/store/105vgajzp65wlwmkjzw3kjmg9a62dkyy-X-Restart-Triggers-step-ca.drv /nix/store/avlwy5jy9zv3hhg6afzphr9drn1ry34q-extra-hosts.drv /nix/store/nkmcxp3a6fc4ddajmj6v2glyjzq33blh-string-hosts.drv /nix/store/17212vlrjfmvkqaswkiz14msw9an4lhv-hosts.drv /nix/store/1nk8gzqdwcbys8cscgg83vgibcwy841s-unit-acme-renew-test.foo.timer.drv /nix/store/1qpr37x364y6lmlbrq9dy5idrbw2hp3w-decrypt-age-secrets.drv /nix/store/p47hngn6zbdrmdwc5prb4iy0kaw2f2kp-firewall-start.drv /nix/store/1z3aifsiz4y9cs7rbjl3m6bx31jn97b2-firewall-reload.drv /nix/store/qhjp8r9fvamgbhsi2vllmi94vh41kmhb-nginx-recommended-proxy_set_header-headers.conf.drv /nix/store/2n9jkw7mdsbl0av1rmpymvbdhksrdga7-nginx.conf.drv /nix/store/8vwzf0zl4zs9v9z7cqf6adhnz3j0hrf6-nss-cacert-3.126.drv /nix/store/a2bvbd17bachsijl4c82ykfhz4kl364q-nix.conf.drv /nix/store/b56kr6jp2kbmx38pp7zy4ccnmq77446n-X-Restart-Triggers-nix-daemon.drv /nix/store/5lqpf5bmbhqcs600dpmqhrzhndd9hckr-unit-nix-daemon.service.drv /nix/store/6x8vlzfw6a1jwykqww188jzl2wgvirva-unit-nginx-config-reload.service.drv /nix/store/mkryfxz2pfh6gr8rhncv3clg33q5mgai-etc-systemd-journald.conf.drv /nix/store/fjma41d7rl9wp8jx7vnqish2fvp0l65y-X-Restart-Triggers-systemd-journald-.drv /nix/store/701afl0wgr66w3j89vhin5g2pdikc5sm-unit-systemd-journald-.service.drv /nix/store/5mg2klpahqbhhj18pc86bzcjzwryrqag-nixos-tmpfiles.d.drv /nix/store/rv9gkiwp80lshzgggldij33s91qcbhz3-10-acme.conf.drv /nix/store/kgrkxjg75x766c8hhwn7jxg7nn0l3j9m-tmpfiles.d.drv /nix/store/k9azhkcqcv57qjfkz6q9pmlp7w0mkq04-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/78w96nms9z36n2z4h2a49cd705aisvq8-unit-systemd-tmpfiles-resetup.service.drv /nix/store/7yik6sfchavysp6hdgfdqy5f3px4n50d-unit-firewall.service.drv /nix/store/97m1jalfv4s1y5mvy3z6dj0xv0m1zvng-unit-acme-renew-ca.foo.timer.drv /nix/store/kg3f7q9sks9rmxpy683i2accxdpinmr5-unit-script-nginx-pre-start.drv /nix/store/h1gwc83hkwvl0rjd94kw42spiqryfhls-unit-nginx.service.drv /nix/store/9f6p9w5xf1g9a8rmdvn87z28xqfbjsjr-X-Restart-Triggers-acme-ca.foo.drv /nix/store/j06h07j5hl1jqwhfrjy1bd3dm5y6ypr3-unit-script-acme-ca.foo-start.drv /nix/store/h7c9v4lnmls01zx9587yy0wvdr953bvn-unit-acme-ca.foo.service.drv /nix/store/i37iqa1gansd71k9j9lqdwjxlrc4wa9x-unit-step-ca.service.drv /nix/store/j92r1clnb7bbnf8hdj2r8k7sfrk0drnd-unit-nix-optimise.service.drv /nix/store/msls07dxbgpvjl2kwx2mn55rxsds8h0p-system-path.drv /nix/store/sgrskgjgz27hz6l3ywf9nni9m6nns2js-dbus-1.drv /nix/store/a6333yi6qpkvlh16v27ii4x89h5g7fhl-X-Restart-Triggers-dbus-broker.drv /nix/store/m6xvyg09j9w4qg6qql39r5pc9hiyp4wv-unit-dbus-broker.service.drv /nix/store/grr6h5lhv5x38x5v4qr1mkls6a76rr8r-unit-script-nix-gc-start.drv /nix/store/nszfkjz4qq4qg3fgwp8c83mh9zi1wllq-unit-nix-gc.service.drv /nix/store/y898rkhm36am6993pvcnnaa5laap4y5a-acme-postrun.drv /nix/store/p3bvivbjsggzi4ffpblddgslgf0f7qc2-unit-acme-order-renew-ca.foo.service.drv /nix/store/mvd322wkjibcc0jzgssc54ggfkc1avvh-X-Restart-Triggers-systemd-journald.drv /nix/store/r84kbdywm1rz4cylkhmdg18h42fkrahi-unit-systemd-journald.service.drv /nix/store/gawjnj6ywdqsjb33sfpdn87jjwh4x030-unit-script-acme-setup-start.drv /nix/store/ppcmml1d42bis7nzxsyx769ahv8b25fb-acme-setup-privileged.drv /nix/store/rql21w9n48yizvh0qwz5z9cqwcan37m4-unit-acme-setup.service.drv /nix/store/34n4l0kvqaj7d5jqdxqm3rz74vx2m3v3-system-units.drv /nix/store/di1sgdiyzlm65p5kpam2px5qrwg223hx-acme-postrun.drv /nix/store/w7nqaqnlj2zf8lbzf5qy6i2yx8hrw8hs-unit-script-acme-order-renew-test.foo-start.drv /nix/store/35a5msij0380fgxm7ckwqrc2hd9rg2za-unit-acme-order-renew-test.foo.service.drv /nix/store/5pq2kh3b44ymqkr3f1gbfhaywadf1lrc-system-path.drv /nix/store/x0raav55fd1vcwk6jafn32j04kmk6yk6-tmpfiles.d.drv /nix/store/in0x3b8kic30gfz93gw9cxmxkmb5bvqr-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/hcchgqpbb1avbb1cxkrji253g152dwkn-unit-systemd-tmpfiles-resetup.service.drv /nix/store/w66s8vv18l5y1f78fn2lj78zwq10zmqc-dbus-1.drv /nix/store/asb33lr6cjwwnz7zf9grxnvh64xyiqfr-X-Restart-Triggers-dbus-broker.drv /nix/store/pvk1lyf80mdav3shkaxfyzhfrka5zkfq-unit-dbus-broker.service.drv /nix/store/71znniis8d1lbkvb02h5s9pchz895fcx-system-units.drv /nix/store/iz06l0qnliwjxriy68zhlzz32y9ldpxf-etc-hostname.drv /nix/store/idgp8qkb88ni10wl7i2s8ayn3w2qdi90-unit-dbus-broker.service.drv /nix/store/xqh0da2c97vz8adfxd4r9nlh7z1jgj8c-user-units.drv /nix/store/jaxldl2h85gp6ah03fla3598jh2fidbz-etc.drv /nix/store/3k8w6v5bh2l8x1ksgqskszjimpx6fm28-activate.drv /nix/store/3qbzpkzqfykrppymh72m1ifiswms94iv-X-Restart-Triggers-acme-test.foo.drv /nix/store/3v4bg9a3qamb0bm2ziqm6cc7bzf4issj-user-generators.drv /nix/store/qmyis2dzw5mgw8xrk10l8p0yr3v98z34-users-groups.json.drv /nix/store/7cv835y8lfj1ahd75a2kl0gwg1igckv8-dry-activate.drv /nix/store/6a9hs49cq4s7md9ny7pri0g713id1s6b-system-generators.drv /nix/store/r8k75xgw7bjkw7mshn2w19kl52a9vmjc-unit-dbus-broker.service.drv /nix/store/hyz198np31gbamdizdi0qba1b6zvh6x7-user-units.drv /nix/store/i2dj4hz76ic7bsjdifxs6ck848im76kx-string-hosts.drv /nix/store/qbsv3xqikz30whfw55dx28jgb2pxkglf-hosts.drv /nix/store/w0a13fr2fv59hg246hmdlf3nhavsd0gg-system-shutdown.drv /nix/store/mnxm53c04agddk613sh0ab17nb09b4yv-etc.drv /nix/store/d2qdsqfgwcxy9vyx9dbi4mbcxzmipx7q-activate.drv /nix/store/rh0xz77dx4ngjzr60z6c9p7jm4r2n4mi-nixos-system-ca-test.drv /nix/store/57vprx6r7pik8x0if7xi9hbf8fn8ldzq-run-ca-nspawn.drv /nix/store/509xd8748dnlngc6nf21aggssb5s0swr-X-Reload-Triggers-systemd-networkd.drv /nix/store/5g0i3ihpykv6r1fx4mw25gs5fs6fgwhb-unit-systemd-networkd.service.drv /nix/store/bjj3534h4wyky0f37a7m2d7n964w54wh-acme-setup-privileged.drv /nix/store/5h5ima3fyiinwyj2xb2bq3y2dba3lij3-unit-acme-setup.service.drv /nix/store/61vgapasj8nxhaqk3sk97194mj3hg0nj-unit-nginx-config-reload.service.drv /nix/store/b235wnldakyza7759nqsqcqnswaglih7-unit-script-acme-test.foo-start.drv /nix/store/9wqw1c35dyazfkqk1mb0asw40q50qr0b-unit-acme-test.foo.service.drv /nix/store/s1q4g3njblrv12v29als39vvg4f753rk-nginx.conf.drv /nix/store/w142xcnwysmrw2pjqis19jg1ikmia9jp-unit-script-nginx-pre-start.drv /nix/store/blvbi6ql6710rbyd771j2s09b3dfd1j8-unit-nginx.service.drv /nix/store/nb6pmnhsmblmjl22yzlv69gpcz1ilb8k-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/5vm9ymzdliqg7fqxcr150mp4646d3dp9-system-units.drv /nix/store/gnxzvcgqp1rar2dmfzcidlnsgjc00834-unit-dbus-broker.service.drv /nix/store/sc565ssdx5949bi7h3r8136nr23db5da-user-units.drv /nix/store/ngmx324ppgdy1kkqnbc6jjmj2qxp726f-string-hosts.drv /nix/store/vp9kqhkx48jvrr07a7j93914h0njf5jb-hosts.drv /nix/store/abr5z01d6mwmrlvclmg3j0f9w7bhxmgf-etc.drv /nix/store/znkkq5v4lfmsl9a3bjahlhlrw5d9vrxw-users-groups.json.drv /nix/store/dyw3dw9hw5qh54y477rag02ll36dm2y7-activate.drv /nix/store/ynfyapp5cancgb9wh78nfp5pzxpbjjxn-dry-activate.drv /nix/store/xj7qx7q0h1b7by56ffrm2zprl7py7xri-nixos-system-server-test.drv /nix/store/80a3zk5r7mr5jmbdljv398qcmb380hwr-run-server-nspawn.drv /nix/store/xlb36ixss5wsrxhlz65s5615fpa8vnsm-dry-activate.drv /nix/store/vaxw5cmffhzd42qhfdvy6ilr0yis3qq9-nixos-system-client-test.drv /nix/store/dya6b4ghpxwjfhhgxwl35z8f92hfs3a9-run-client-nspawn.drv /nix/store/qc93adsfvqp1ykah9sj9gzshblp1lcmb-test-script.drv /nix/store/4aw9bbwjacr50dnzhpm7jsms130s47wn-driverConfiguration.json.drv /nix/store/d3my8hip65hjhcx0myar3s96bf2k4sxx-python3.14-nixos-test-lib-1.0.0.drv /nix/store/kzmbyrp2y9hr0x04lx7qk6g8gnb4q1p8-nixos-test-driver-1.1.drv /nix/store/k3vnxkrnp5vdhgcf7kbjqdysqv856zcr-nixos-test-driver-certificates.drv /nix/store/mh2xw6jxhr5538fjby9rsq6klc6pd19w-container-test-run-certificates.drv this path will be fetched (19.6 MiB download, 68.5 MiB unpacked): /nix/store/3ahxigmadhbxwr2fx33x5qwwfs0aj1kb-step-ca-0.30.2 building '/nix/store/qc93adsfvqp1ykah9sj9gzshblp1lcmb-test-script.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/9f6p9w5xf1g9a8rmdvn87z28xqfbjsjr-X-Restart-Triggers-acme-ca.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qc93adsfvqp1ykah9sj9gzshblp1lcmb-test-script.drv' building '/nix/store/9f6p9w5xf1g9a8rmdvn87z28xqfbjsjr-X-Restart-Triggers-acme-ca.foo.drv' building '/nix/store/3qbzpkzqfykrppymh72m1ifiswms94iv-X-Restart-Triggers-acme-test.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/s1q4g3njblrv12v29als39vvg4f753rk-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/3qbzpkzqfykrppymh72m1ifiswms94iv-X-Restart-Triggers-acme-test.foo.drv' building '/nix/store/s1q4g3njblrv12v29als39vvg4f753rk-nginx.conf.drv' nginx.conf> structuredAttrs is enabled nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/w142xcnwysmrw2pjqis19jg1ikmia9jp-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/w142xcnwysmrw2pjqis19jg1ikmia9jp-unit-script-nginx-pre-start.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/blvbi6ql6710rbyd771j2s09b3dfd1j8-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/di1sgdiyzlm65p5kpam2px5qrwg223hx-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/y898rkhm36am6993pvcnnaa5laap4y5a-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/bjj3534h4wyky0f37a7m2d7n964w54wh-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ppcmml1d42bis7nzxsyx769ahv8b25fb-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/blvbi6ql6710rbyd771j2s09b3dfd1j8-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/y898rkhm36am6993pvcnnaa5laap4y5a-acme-postrun.drv' building '/nix/store/ppcmml1d42bis7nzxsyx769ahv8b25fb-acme-setup-privileged.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/bjj3534h4wyky0f37a7m2d7n964w54wh-acme-setup-privileged.drv' building '/nix/store/5h5ima3fyiinwyj2xb2bq3y2dba3lij3-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/rql21w9n48yizvh0qwz5z9cqwcan37m4-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/5h5ima3fyiinwyj2xb2bq3y2dba3lij3-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/di1sgdiyzlm65p5kpam2px5qrwg223hx-acme-postrun.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/dqvgx3mishwyspmig2fi98lgvzw4n876-ca.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/1qpr37x364y6lmlbrq9dy5idrbw2hp3w-decrypt-age-secrets.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/rql21w9n48yizvh0qwz5z9cqwcan37m4-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/0zdzqh8g7k3r2bwrjb5s1dj9xvfzj537-etc-hostname.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/avlwy5jy9zv3hhg6afzphr9drn1ry34q-extra-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/2n9jkw7mdsbl0av1rmpymvbdhksrdga7-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/8vwzf0zl4zs9v9z7cqf6adhnz3j0hrf6-nss-cacert-3.126.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dqvgx3mishwyspmig2fi98lgvzw4n876-ca.json.drv' ca.json> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/105vgajzp65wlwmkjzw3kjmg9a62dkyy-X-Restart-Triggers-step-ca.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/0zdzqh8g7k3r2bwrjb5s1dj9xvfzj537-etc-hostname.drv' building '/nix/store/8vwzf0zl4zs9v9z7cqf6adhnz3j0hrf6-nss-cacert-3.126.drv' nss-cacert-3.126> structuredAttrs is enabled nss-cacert-3.126> Running phase: unpackPhase nss-cacert-3.126> Running phase: patchPhase nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase nss-cacert-3.126> Running phase: installPhase nss-cacert-3.126> Running phase: fixupPhase nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/lfsxiqcshjj2c2z0bbvcbxkbn55mkgpq-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/lfsxiqcshjj2c2z0bbvcbxkbn55mkgpq-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/lfsxiqcshjj2c2z0bbvcbxkbn55mkgpq-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/6jqqamk35idanan9mirmgvh1l1yvd7n7-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/6jqqamk35idanan9mirmgvh1l1yvd7n7-nss-cacert-3.126-hashed... nss-cacert-3.126> patching script interpreter paths in /nix/store/6jqqamk35idanan9mirmgvh1l1yvd7n7-nss-cacert-3.126-hashed nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/4z43i8j042aw6yz9shlhfaj8fln6fm90-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/4z43i8j042aw6yz9shlhfaj8fln6fm90-nss-cacert-3.126... nss-cacert-3.126> patching script interpreter paths in /nix/store/4z43i8j042aw6yz9shlhfaj8fln6fm90-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/lgizlvyqwxyijj95di09c0ydsdxd9v9b-nss-cacert-3.126-unbundled nss-cacert-3.126> checking for references to /build/ in /nix/store/lgizlvyqwxyijj95di09c0ydsdxd9v9b-nss-cacert-3.126-unbundled... nss-cacert-3.126> patching script interpreter paths in /nix/store/lgizlvyqwxyijj95di09c0ydsdxd9v9b-nss-cacert-3.126-unbundled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/2n9jkw7mdsbl0av1rmpymvbdhksrdga7-nginx.conf.drv' nginx.conf> structuredAttrs is enabled nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/kg3f7q9sks9rmxpy683i2accxdpinmr5-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/avlwy5jy9zv3hhg6afzphr9drn1ry34q-extra-hosts.drv' building '/nix/store/1qpr37x364y6lmlbrq9dy5idrbw2hp3w-decrypt-age-secrets.drv' building '/nix/store/5lqpf5bmbhqcs600dpmqhrzhndd9hckr-unit-nix-daemon.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/i2dj4hz76ic7bsjdifxs6ck848im76kx-string-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/105vgajzp65wlwmkjzw3kjmg9a62dkyy-X-Restart-Triggers-step-ca.drv' building '/nix/store/17212vlrjfmvkqaswkiz14msw9an4lhv-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/vp9kqhkx48jvrr07a7j93914h0njf5jb-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/i37iqa1gansd71k9j9lqdwjxlrc4wa9x-unit-step-ca.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/kg3f7q9sks9rmxpy683i2accxdpinmr5-unit-script-nginx-pre-start.drv' building '/nix/store/h1gwc83hkwvl0rjd94kw42spiqryfhls-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/i2dj4hz76ic7bsjdifxs6ck848im76kx-string-hosts.drv' building '/nix/store/5lqpf5bmbhqcs600dpmqhrzhndd9hckr-unit-nix-daemon.service.drv' unit-nix-daemon.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/qbsv3xqikz30whfw55dx28jgb2pxkglf-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/17212vlrjfmvkqaswkiz14msw9an4lhv-hosts.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/vp9kqhkx48jvrr07a7j93914h0njf5jb-hosts.drv' building '/nix/store/6a9hs49cq4s7md9ny7pri0g713id1s6b-system-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5pq2kh3b44ymqkr3f1gbfhaywadf1lrc-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/i37iqa1gansd71k9j9lqdwjxlrc4wa9x-unit-step-ca.service.drv' unit-step-ca.service> structuredAttrs is enabled building '/nix/store/7cnvsby4x32q8ln7gh7hjc9dgwkg9fll-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/h1gwc83hkwvl0rjd94kw42spiqryfhls-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/6a9hs49cq4s7md9ny7pri0g713id1s6b-system-generators.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/msls07dxbgpvjl2kwx2mn55rxsds8h0p-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7cnvsby4x32q8ln7gh7hjc9dgwkg9fll-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/qbsv3xqikz30whfw55dx28jgb2pxkglf-hosts.drv' building '/nix/store/msls07dxbgpvjl2kwx2mn55rxsds8h0p-system-path.drv' system-path> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy system-path> created 1718 symlinks in user environment building '/nix/store/5pq2kh3b44ymqkr3f1gbfhaywadf1lrc-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/w66s8vv18l5y1f78fn2lj78zwq10zmqc-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/yll0q6ljy9rfnnphbg1m0vnbpsmvm3q1-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/sgrskgjgz27hz6l3ywf9nni9m6nns2js-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/w0a13fr2fv59hg246hmdlf3nhavsd0gg-system-shutdown.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/w66s8vv18l5y1f78fn2lj78zwq10zmqc-dbus-1.drv' building '/nix/store/yll0q6ljy9rfnnphbg1m0vnbpsmvm3q1-dbus-1.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/asb33lr6cjwwnz7zf9grxnvh64xyiqfr-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/w0a13fr2fv59hg246hmdlf3nhavsd0gg-system-shutdown.drv' building '/nix/store/sgrskgjgz27hz6l3ywf9nni9m6nns2js-dbus-1.drv' building '/nix/store/a6333yi6qpkvlh16v27ii4x89h5g7fhl-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/46ciwslw4lnhil7v9q4h1p1gppfrbj41-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/b235wnldakyza7759nqsqcqnswaglih7-unit-script-acme-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/asb33lr6cjwwnz7zf9grxnvh64xyiqfr-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/b235wnldakyza7759nqsqcqnswaglih7-unit-script-acme-test.foo-start.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/46ciwslw4lnhil7v9q4h1p1gppfrbj41-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/a6333yi6qpkvlh16v27ii4x89h5g7fhl-X-Restart-Triggers-dbus-broker.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/idgp8qkb88ni10wl7i2s8ayn3w2qdi90-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/9wqw1c35dyazfkqk1mb0asw40q50qr0b-unit-acme-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0nx9bnyx7j795swlzd32k0hd83nyvxj7-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/gnxzvcgqp1rar2dmfzcidlnsgjc00834-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/idgp8qkb88ni10wl7i2s8ayn3w2qdi90-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/gnxzvcgqp1rar2dmfzcidlnsgjc00834-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/xqh0da2c97vz8adfxd4r9nlh7z1jgj8c-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0nx9bnyx7j795swlzd32k0hd83nyvxj7-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/sc565ssdx5949bi7h3r8136nr23db5da-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/9wqw1c35dyazfkqk1mb0asw40q50qr0b-unit-acme-test.foo.service.drv' unit-acme-test.foo.service> structuredAttrs is enabled building '/nix/store/nb6pmnhsmblmjl22yzlv69gpcz1ilb8k-unit-acme-account-2c44cb477b4787b2cf13.target.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/xqh0da2c97vz8adfxd4r9nlh7z1jgj8c-user-units.drv' building '/nix/store/0sggpnpx0hb7ps7mipz1v6p0j50j74f9-unit-acme-account-d22a46d9459bf683a338.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/sc565ssdx5949bi7h3r8136nr23db5da-user-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/nb6pmnhsmblmjl22yzlv69gpcz1ilb8k-unit-acme-account-2c44cb477b4787b2cf13.target.drv' unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled building '/nix/store/0sggpnpx0hb7ps7mipz1v6p0j50j74f9-unit-acme-account-d22a46d9459bf683a338.target.drv' unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled building '/nix/store/97m1jalfv4s1y5mvy3z6dj0xv0m1zvng-unit-acme-renew-ca.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/1nk8gzqdwcbys8cscgg83vgibcwy841s-unit-acme-renew-test.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/m6xvyg09j9w4qg6qql39r5pc9hiyp4wv-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/pvk1lyf80mdav3shkaxfyzhfrka5zkfq-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/r8k75xgw7bjkw7mshn2w19kl52a9vmjc-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/61vgapasj8nxhaqk3sk97194mj3hg0nj-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6x8vlzfw6a1jwykqww188jzl2wgvirva-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/97m1jalfv4s1y5mvy3z6dj0xv0m1zvng-unit-acme-renew-ca.foo.timer.drv' unit-acme-renew-ca.foo.timer> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/r8k75xgw7bjkw7mshn2w19kl52a9vmjc-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/j06h07j5hl1jqwhfrjy1bd3dm5y6ypr3-unit-script-acme-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/036blsc4zrqllkxan7f78dh9gd9ch2zr-unit-script-acme-order-renew-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/w7nqaqnlj2zf8lbzf5qy6i2yx8hrw8hs-unit-script-acme-order-renew-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3v4bg9a3qamb0bm2ziqm6cc7bzf4issj-user-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qmyis2dzw5mgw8xrk10l8p0yr3v98z34-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/m6xvyg09j9w4qg6qql39r5pc9hiyp4wv-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/hyz198np31gbamdizdi0qba1b6zvh6x7-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/61vgapasj8nxhaqk3sk97194mj3hg0nj-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/pvk1lyf80mdav3shkaxfyzhfrka5zkfq-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/6x8vlzfw6a1jwykqww188jzl2wgvirva-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/znkkq5v4lfmsl9a3bjahlhlrw5d9vrxw-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/07182vp9nm48fkgibfn911dbhlvs6isg-vars-check-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/znkkq5v4lfmsl9a3bjahlhlrw5d9vrxw-users-groups.json.drv' building '/nix/store/3v4bg9a3qamb0bm2ziqm6cc7bzf4issj-user-generators.drv' building '/nix/store/w7nqaqnlj2zf8lbzf5qy6i2yx8hrw8hs-unit-script-acme-order-renew-test.foo-start.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/036blsc4zrqllkxan7f78dh9gd9ch2zr-unit-script-acme-order-renew-ca.foo-start.drv' building '/nix/store/ynfyapp5cancgb9wh78nfp5pzxpbjjxn-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/07182vp9nm48fkgibfn911dbhlvs6isg-vars-check-certificates.drv' vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully building '/nix/store/1nk8gzqdwcbys8cscgg83vgibcwy841s-unit-acme-renew-test.foo.timer.drv' unit-acme-renew-test.foo.timer> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/j06h07j5hl1jqwhfrjy1bd3dm5y6ypr3-unit-script-acme-ca.foo-start.drv' building '/nix/store/qmyis2dzw5mgw8xrk10l8p0yr3v98z34-users-groups.json.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/7cv835y8lfj1ahd75a2kl0gwg1igckv8-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/7cv835y8lfj1ahd75a2kl0gwg1igckv8-dry-activate.drv' building '/nix/store/ynfyapp5cancgb9wh78nfp5pzxpbjjxn-dry-activate.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/hyz198np31gbamdizdi0qba1b6zvh6x7-user-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/h7c9v4lnmls01zx9587yy0wvdr953bvn-unit-acme-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/35a5msij0380fgxm7ckwqrc2hd9rg2za-unit-acme-order-renew-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/71znniis8d1lbkvb02h5s9pchz895fcx-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p3bvivbjsggzi4ffpblddgslgf0f7qc2-unit-acme-order-renew-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/35a5msij0380fgxm7ckwqrc2hd9rg2za-unit-acme-order-renew-test.foo.service.drv' unit-acme-order-renew-test.foo.service> structuredAttrs is enabled building '/nix/store/h7c9v4lnmls01zx9587yy0wvdr953bvn-unit-acme-ca.foo.service.drv' unit-acme-ca.foo.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/71znniis8d1lbkvb02h5s9pchz895fcx-system-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/p3bvivbjsggzi4ffpblddgslgf0f7qc2-unit-acme-order-renew-ca.foo.service.drv' unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled building '/nix/store/jaxldl2h85gp6ah03fla3598jh2fidbz-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5vm9ymzdliqg7fqxcr150mp4646d3dp9-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/5vm9ymzdliqg7fqxcr150mp4646d3dp9-system-units.drv' building '/nix/store/34n4l0kvqaj7d5jqdxqm3rz74vx2m3v3-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/abr5z01d6mwmrlvclmg3j0f9w7bhxmgf-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jaxldl2h85gp6ah03fla3598jh2fidbz-etc.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/3k8w6v5bh2l8x1ksgqskszjimpx6fm28-activate.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/abr5z01d6mwmrlvclmg3j0f9w7bhxmgf-etc.drv' building '/nix/store/34n4l0kvqaj7d5jqdxqm3rz74vx2m3v3-system-units.drv' building '/nix/store/mnxm53c04agddk613sh0ab17nb09b4yv-etc.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/dyw3dw9hw5qh54y477rag02ll36dm2y7-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3k8w6v5bh2l8x1ksgqskszjimpx6fm28-activate.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/vaxw5cmffhzd42qhfdvy6ilr0yis3qq9-nixos-system-client-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dyw3dw9hw5qh54y477rag02ll36dm2y7-activate.drv' building '/nix/store/xj7qx7q0h1b7by56ffrm2zprl7py7xri-nixos-system-server-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/mnxm53c04agddk613sh0ab17nb09b4yv-etc.drv' building '/nix/store/d2qdsqfgwcxy9vyx9dbi4mbcxzmipx7q-activate.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/d2qdsqfgwcxy9vyx9dbi4mbcxzmipx7q-activate.drv' building '/nix/store/vaxw5cmffhzd42qhfdvy6ilr0yis3qq9-nixos-system-client-test.drv' nixos-system-client-test> structuredAttrs is enabled building '/nix/store/dya6b4ghpxwjfhhgxwl35z8f92hfs3a9-run-client-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/xj7qx7q0h1b7by56ffrm2zprl7py7xri-nixos-system-server-test.drv' nixos-system-server-test> structuredAttrs is enabled building '/nix/store/rh0xz77dx4ngjzr60z6c9p7jm4r2n4mi-nixos-system-ca-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/80a3zk5r7mr5jmbdljv398qcmb380hwr-run-server-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/80a3zk5r7mr5jmbdljv398qcmb380hwr-run-server-nspawn.drv' building '/nix/store/dya6b4ghpxwjfhhgxwl35z8f92hfs3a9-run-client-nspawn.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/rh0xz77dx4ngjzr60z6c9p7jm4r2n4mi-nixos-system-ca-test.drv' nixos-system-ca-test> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/57vprx6r7pik8x0if7xi9hbf8fn8ldzq-run-ca-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/57vprx6r7pik8x0if7xi9hbf8fn8ldzq-run-ca-nspawn.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/4aw9bbwjacr50dnzhpm7jsms130s47wn-driverConfiguration.json.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/4aw9bbwjacr50dnzhpm7jsms130s47wn-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/k3vnxkrnp5vdhgcf7kbjqdysqv856zcr-nixos-test-driver-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/k3vnxkrnp5vdhgcf7kbjqdysqv856zcr-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/mh2xw6jxhr5538fjby9rsq6klc6pd19w-container-test-run-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/mh2xw6jxhr5538fjby9rsq6klc6pd19w-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> ca: systemd-nspawn running (pid 52) container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> server: systemd-nspawn running (pid 57) container-test-run-certificates> client: systemd-nspawn running (pid 55) container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.00 seconds) container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> server # [27732.532758] server systemd-journald[69]: Journal started container-test-run-certificates> server # [27732.532815] server systemd-journald[69]: Runtime Journal (/run/log/journal/6b5f57384d89440e8044ed61e9078250) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> server # [27732.537055] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> client # [27732.531911] client systemd-journald[69]: Journal started container-test-run-certificates> server # [27732.548063] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [27732.531969] client systemd-journald[69]: Runtime Journal (/run/log/journal/2a709b1c49914f43b6a56d3cecf2acf4) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> server # [27732.549016] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [27732.535325] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> server # [27732.549928] server systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [27732.544712] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> server # [27732.557226] server systemd-journald[69]: Time spent on flushing to /var/log/journal/6b5f57384d89440e8044ed61e9078250 is 2.763ms for 6 entries. container-test-run-certificates> client # [27732.546007] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [27732.546991] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [27732.555368] client systemd-journald[69]: Time spent on flushing to /var/log/journal/2a709b1c49914f43b6a56d3cecf2acf4 is 1.528ms for 6 entries. container-test-run-certificates> client # [27732.555368] client systemd-journald[69]: System Journal (/var/log/journal/2a709b1c49914f43b6a56d3cecf2acf4) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [27732.562474] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [27732.562722] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [27732.562819] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [27732.563566] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [27732.563614] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [27732.564518] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> client # [27732.564549] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> client # [27732.590603] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [27732.592214] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [27732.531896] ca systemd-journald[79]: Journal started container-test-run-certificates> ca # [27732.531959] ca systemd-journald[79]: Runtime Journal (/run/log/journal/4334bc2b675e4b41bf01b3d2df8e1f83) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> ca # [27732.534862] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> ca # [27732.544307] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [27732.545177] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [27732.546496] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [27732.557502] ca systemd-journald[79]: Time spent on flushing to /var/log/journal/4334bc2b675e4b41bf01b3d2df8e1f83 is 1.767ms for 6 entries. container-test-run-certificates> client # [27732.607774] client systemd-tmpfiles[124]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [27732.608337] client systemd-tmpfiles[124]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [27732.608617] client systemd-tmpfiles[124]: fchmod() of /var/log/journal/2a709b1c49914f43b6a56d3cecf2acf4 failed: Operation not permitted container-test-run-certificates> client # [27732.608827] client systemd-tmpfiles[124]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [27732.557226] server systemd-journald[69]: System Journal (/var/log/journal/6b5f57384d89440e8044ed61e9078250) is 8M, max 4G, 3.9G free. container-test-run-certificates> server # [27732.570880] server systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> server # [27732.571580] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> server # [27732.571705] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> server # [27732.572553] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> server # [27732.572602] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [27732.573442] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [27732.573477] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [27732.595850] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [27732.596913] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> server # [27732.612202] server systemd-tmpfiles[129]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [27732.612422] server systemd-tmpfiles[129]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [27732.612572] server systemd-tmpfiles[129]: fchmod() of /var/log/journal/6b5f57384d89440e8044ed61e9078250 failed: Operation not permitted container-test-run-certificates> server # [27732.612789] server systemd-tmpfiles[129]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> ca # [27732.557502] ca systemd-journald[79]: System Journal (/var/log/journal/4334bc2b675e4b41bf01b3d2df8e1f83) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [27732.562498] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [27732.562761] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> ca # [27732.562848] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [27732.563582] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [27732.563630] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [27732.564495] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [27732.564533] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [27732.602599] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> ca # [27732.604178] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [27732.619579] ca systemd-tmpfiles[140]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> ca # [27732.619786] ca systemd-tmpfiles[140]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> ca # [27732.619926] ca systemd-tmpfiles[140]: fchmod() of /var/log/journal/4334bc2b675e4b41bf01b3d2df8e1f83 failed: Operation not permitted container-test-run-certificates> ca # [27732.620141] ca systemd-tmpfiles[140]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [27732.610184] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> client # [27732.611250] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> client # [27732.612057] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> client # [27732.620710] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> client # [27732.624989] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> client # [27732.631908] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> client # [27732.632992] client systemd[1]: Starting Update is Completed... container-test-run-certificates> client # [27732.641857] client systemd[1]: Finished Update is Completed. container-test-run-certificates> client # [27732.679976] client systemd[1]: Finished Firewall. container-test-run-certificates> client # [27732.680138] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [27732.680349] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [27732.681332] client systemd[1]: Starting Network Management... container-test-run-certificates> ca # [27732.620720] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> ca # [27732.621119] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> ca # [27732.622827] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> ca # [27732.623612] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [27732.634809] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [27732.641134] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> ca # [27732.642103] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> ca # [27732.652145] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> ca # [27732.684368] ca systemd[1]: Finished Firewall. container-test-run-certificates> ca # [27732.684924] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [27732.685202] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> ca # [27732.686230] ca systemd[1]: Starting Network Management... container-test-run-certificates> server # [27732.615250] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [27732.616582] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [27732.617304] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [27732.620703] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [27732.631500] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [27732.636862] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [27732.638226] server systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [27732.647402] server systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [27732.679291] server systemd[1]: Finished Firewall. container-test-run-certificates> server # [27732.679443] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> server # [27732.679658] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [27732.680732] server systemd[1]: Starting Network Management... container-test-run-certificates> client # [27733.055491] client systemd-networkd[183]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [27733.055581] client systemd-networkd[183]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [27733.063839] client systemd-networkd[183]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [27733.064016] client systemd-networkd[183]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [27733.064166] client systemd-networkd[183]: lo: Link UP container-test-run-certificates> client # [27733.064169] client systemd-networkd[183]: lo: Gained carrier container-test-run-certificates> client # [27733.064362] client systemd-networkd[183]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [27733.064733] client systemd[1]: Started Network Management. container-test-run-certificates> client # [27733.064822] client systemd-networkd[183]: eth1: Link UP container-test-run-certificates> client # [27733.065139] client systemd-networkd[183]: eth1: Gained carrier container-test-run-certificates> client # [27733.065805] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> client # [27733.109371] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> client # [27733.210435] client systemd-resolved[92]: Positive Trust Anchors: container-test-run-certificates> client # [27733.210446] client systemd-resolved[92]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> client # [27733.210448] client systemd-resolved[92]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [27733.210484] client systemd-resolved[92]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [27733.232050] client systemd-resolved[92]: Using system hostname 'client'. container-test-run-certificates> client # [27733.233357] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> client # [27733.233437] client systemd[1]: Reached target Network. container-test-run-certificates> client # [27733.233503] client systemd[1]: Reached target System Initialization. container-test-run-certificates> client # [27733.233555] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [27733.233589] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> client # [27733.233607] client systemd[1]: Reached target Timer Units. container-test-run-certificates> client # [27733.233742] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [27733.233858] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> client # [27733.233969] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> client # [27733.233996] client systemd[1]: Reached target Socket Units. container-test-run-certificates> client # [27733.234030] client systemd[1]: Reached target Basic System. container-test-run-certificates> client # [27733.272500] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> client # [27733.273763] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> client # [27733.275176] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> client # [27733.295136] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> ca # [27733.067118] ca systemd-networkd[197]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [27733.067208] ca systemd-networkd[197]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [27733.074940] ca systemd-networkd[197]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [27733.075109] ca systemd-networkd[197]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [27733.075236] ca systemd-networkd[197]: lo: Link UP container-test-run-certificates> ca # [27733.075239] ca systemd-networkd[197]: lo: Gained carrier container-test-run-certificates> ca # [27733.075387] ca systemd-networkd[197]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> ca # [27733.075750] ca systemd[1]: Started Network Management. container-test-run-certificates> ca # [27733.100356] ca systemd-networkd[197]: eth1: Link UP container-test-run-certificates> ca # [27733.100704] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [27733.100721] ca systemd-networkd[197]: eth1: Gained carrier container-test-run-certificates> ca # [27733.134478] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> ca # [27733.200191] ca systemd-resolved[102]: Positive Trust Anchors: container-test-run-certificates> ca # [27733.200202] ca systemd-resolved[102]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [27733.200205] ca systemd-resolved[102]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [27733.200239] ca systemd-resolved[102]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [27733.222047] ca systemd-resolved[102]: Using system hostname 'ca'. container-test-run-certificates> ca # [27733.223948] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [27733.224099] ca systemd[1]: Reached target Network. container-test-run-certificates> ca # [27733.224218] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [27733.224299] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [27733.225163] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> ca # [27733.225233] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [27733.225285] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [27733.225327] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> ca # [27733.225772] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> ca # [27733.225966] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [27733.226194] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [27733.226242] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [27733.226334] ca systemd[1]: Reached target Basic System. container-test-run-certificates> ca # [27733.228938] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> ca # [27733.230231] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [27733.230299] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> ca # [27733.231772] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [27733.233535] ca systemd[1]: Starting step-ca service... container-test-run-certificates> ca # [27733.273540] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> ca # [27733.291389] ca systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [27733.066764] server systemd-networkd[187]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [27733.066852] server systemd-networkd[187]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [27733.074545] server systemd-networkd[187]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [27733.074711] server systemd-networkd[187]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [27733.074839] server systemd-networkd[187]: lo: Link UP container-test-run-certificates> server # [27733.074844] server systemd-networkd[187]: lo: Gained carrier container-test-run-certificates> server # [27733.075023] server systemd-networkd[187]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [27733.075375] server systemd[1]: Started Network Management. container-test-run-certificates> server # [27733.100276] server systemd-networkd[187]: eth1: Link UP container-test-run-certificates> server # [27733.100704] server systemd-networkd[187]: eth1: Gained carrier container-test-run-certificates> server # [27733.100898] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> server # [27733.134487] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [27733.214451] server systemd-resolved[95]: Positive Trust Anchors: container-test-run-certificates> server # [27733.214462] server systemd-resolved[95]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [27733.214465] server systemd-resolved[95]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [27733.214499] server systemd-resolved[95]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [27733.236683] server systemd-resolved[95]: Using system hostname 'server'. container-test-run-certificates> server # [27733.238020] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [27733.238152] server systemd[1]: Reached target Network. container-test-run-certificates> server # [27733.238259] server systemd[1]: Reached target Network is Online. container-test-run-certificates> server # [27733.238338] server systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [27733.238717] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> server # [27733.238778] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [27733.238832] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [27733.238879] server systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [27733.239094] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [27733.239285] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [27733.239498] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [27733.239546] server systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [27733.239626] server systemd[1]: Reached target Basic System. container-test-run-certificates> server # [27733.273634] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> server # [27733.275003] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [27733.275069] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> server # [27733.276445] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [27733.278706] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [27733.297790] server systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [27733.370337] server acme-setup-privileged[192]: + set -euo pipefail container-test-run-certificates> server # [27733.370337] server acme-setup-privileged[192]: + cd /var/lib/acme container-test-run-certificates> server # [27733.370337] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> server # [27733.372166] server acme-setup-privileged[192]: + chown -R acme .lego/accounts container-test-run-certificates> server # [27733.374293] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [27733.374293] server acme-setup-privileged[192]: + '[' -d test.foo ']' container-test-run-certificates> server # [27733.374409] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [27733.374409] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']' container-test-run-certificates> server # [27733.399549] server nsncd[194]: Sep 04 15:09:13.385 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> server # [27733.399533] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> server # [27733.399632] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> server # [27733.399731] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [27733.449270] server systemd[1]: Starting User Login Management... container-test-run-certificates> server # [27733.450392] server systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [27733.461678] server systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [27733.463597] server systemd[1]: Started Console Getty. container-test-run-certificates> server # [27733.463667] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [27733.463709] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [27733.510487] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [27733.528197] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [27733.530255] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [27733.530255] server dbus-broker-launch[195]: Invalid user-name in /nix/store/xamxpwkpq9pj51cyi13j1rn4cfjsvpj5-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [27733.530712] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [27733.539271] server dbus-broker-launch[195]: Ready container-test-run-certificates> client # [27733.413718] client nsncd[189]: Sep 04 15:09:13.399 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [27733.413794] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [27733.413887] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [27733.413994] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> client # [27733.449680] client systemd[1]: Starting User Login Management... container-test-run-certificates> client # [27733.451199] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> client # [27733.461734] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> client # [27733.463449] client systemd[1]: Started Console Getty. container-test-run-certificates> client # [27733.463529] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> client # [27733.463571] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> client # [27733.515061] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> client # [27733.527796] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> client # [27733.529903] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [27733.529903] client dbus-broker-launch[190]: Invalid user-name in /nix/store/hcmnwjy5lp6bjqw8pvq2l5h1hh90qrh4-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [27733.530335] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> client # [27733.538130] client dbus-broker-launch[190]: Ready container-test-run-certificates> ca # [27733.396856] ca acme-setup-privileged[202]: + set -euo pipefail container-test-run-certificates> ca # [27733.396856] ca acme-setup-privileged[202]: + cd /var/lib/acme container-test-run-certificates> ca # [27733.396856] ca acme-setup-privileged[202]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> ca # [27733.398778] ca acme-setup-privileged[202]: + chown -R acme .lego/accounts container-test-run-certificates> ca # [27733.400621] ca acme-setup-privileged[202]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [27733.400700] ca acme-setup-privileged[202]: + '[' -d ca.foo ']' container-test-run-certificates> ca # [27733.400700] ca acme-setup-privileged[202]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [27733.400700] ca acme-setup-privileged[202]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> ca # [27733.426334] ca nsncd[204]: Sep 04 15:09:13.412 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [27733.449262] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [27733.449425] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [27733.449489] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [27733.450875] ca systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [27733.451748] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [27733.463060] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [27733.464738] ca systemd[1]: Started Console Getty. container-test-run-certificates> ca # [27733.464806] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> ca # [27733.464844] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca # [27733.525605] ca dbus-broker-launch[209]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [27733.527913] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [27733.530138] ca dbus-broker-launch[209]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> ca # [27733.530138] ca dbus-broker-launch[209]: Invalid user-name in /nix/store/kb2b8z8qy8fbf7i5cavy9vvn05jlnfay-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> ca # [27733.530559] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [27733.539465] ca dbus-broker-launch[209]: Ready container-test-run-certificates> server # [27733.932717] server systemd-logind[220]: New seat seat0. container-test-run-certificates> server # [27733.932957] server systemd[1]: Started User Login Management. container-test-run-certificates> server # [27733.935397] server systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [27733.949567] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> server # [27733.949847] server systemd[1]: Finished linger-users.service. container-test-run-certificates> server # [27734.009101] server acme-setup-start[208]: + set -euo pipefail container-test-run-certificates> server # [27734.009101] server acme-setup-start[208]: + test -e ca/key.pem container-test-run-certificates> server # [27734.009101] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> server # [27734.030291] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> server # [27734.081373] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> client # [27733.941807] client systemd-logind[205]: New seat seat0. container-test-run-certificates> client # [27733.942050] client systemd[1]: Started User Login Management. container-test-run-certificates> client # [27733.944405] client systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [27733.958270] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> client # [27733.958426] client systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [27733.959227] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> client # [27733.959529] client systemd[1]: Startup finished in 1.878s. container-test-run-certificates> ca # [27733.932782] ca systemd-logind[231]: New seat seat0. container-test-run-certificates> ca # [27733.933194] ca systemd[1]: Started User Login Management. container-test-run-certificates> ca # [27733.935051] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> ca # [27733.949632] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [27733.949883] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [27734.000832] ca acme-setup-start[220]: + set -euo pipefail container-test-run-certificates> ca # [27734.000832] ca acme-setup-start[220]: + test -e ca/key.pem container-test-run-certificates> ca # [27734.000832] ca acme-setup-start[220]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [27734.020961] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [27734.022952] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> ca # [27734.124358] ca step-ca[205]: badger 2026/09/04 15:09:14 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [27734.129431] ca step-ca[205]: 2026/09/04 15:09:14 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> ca # [27734.135499] ca step-ca[205]: 2026/09/04 15:09:14 Starting Smallstep CA/0.30.2 (linux/arm64) container-test-run-certificates> ca # [27734.135499] ca step-ca[205]: 2026/09/04 15:09:14 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> ca # [27734.135499] ca step-ca[205]: 2026/09/04 15:09:14 Community Discord: https://u.step.sm/discord container-test-run-certificates> ca # [27734.135499] ca step-ca[205]: 2026/09/04 15:09:14 Config file: /etc/smallstep/ca.json container-test-run-certificates> ca # [27734.135499] ca step-ca[205]: 2026/09/04 15:09:14 The primary server URL is https://ca.foo:1443 container-test-run-certificates> ca # [27734.135624] ca step-ca[205]: 2026/09/04 15:09:14 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [27734.135624] ca step-ca[205]: 2026/09/04 15:09:14 X.509 Root Fingerprint: f0dc1d5e5cc59b71e44fb3e5996d4e2d60a72d6859cf66e500ddfeb7389647da container-test-run-certificates> ca # [27734.136146] ca systemd[1]: Started step-ca service. container-test-run-certificates> ca # [27734.136277] ca step-ca[205]: 2026/09/04 15:09:14 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> server # [27734.464240] server systemd-networkd[187]: eth1: Gained IPv6LL container-test-run-certificates> server # [27734.546387] server acme-test.foo-start[245]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [27734.550037] server acme-test.foo-start[245]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [27734.550037] server acme-test.foo-start[245]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [27734.565871] server acme-test.foo-start[254]: + cd test.foo container-test-run-certificates> server # [27734.566152] server acme-test.foo-start[254]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [27734.567376] server acme-test.foo-start[255]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [27734.567663] server acme-test.foo-start[254]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [27734.568935] server acme-test.foo-start[254]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [27734.569189] server acme-test.foo-start[245]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [27734.570953] server acme-test.foo-start[245]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [27734.572267] server acme-test.foo-start[245]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [27734.574202] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [27734.574202] server acme-test.foo-start[245]: + '[' -d out ']' container-test-run-certificates> server # [27734.574322] server acme-test.foo-start[245]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [27734.575924] server acme-test.foo-start[245]: + chown -R acme:nginx out container-test-run-certificates> server # [27734.578895] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [27734.578950] server acme-test.foo-start[245]: + '[' -d certificates ']' container-test-run-certificates> server # [27734.582518] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [27734.585231] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> ca # [27734.368199] ca systemd-networkd[197]: eth1: Gained IPv6LL container-test-run-certificates> ca # [27734.555797] ca acme-ca.foo-start[262]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [27734.559316] ca acme-ca.foo-start[262]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [27734.559316] ca acme-ca.foo-start[262]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> ca # [27734.575258] ca acme-ca.foo-start[294]: + cd ca.foo container-test-run-certificates> ca # [27734.575823] ca acme-ca.foo-start[294]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> ca # [27734.576681] ca acme-ca.foo-start[295]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [27734.576973] ca acme-ca.foo-start[294]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> ca # [27734.577974] ca acme-ca.foo-start[294]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [27734.578161] ca acme-ca.foo-start[262]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [27734.580006] ca acme-ca.foo-start[262]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [27734.581377] ca acme-ca.foo-start[262]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [27734.582794] ca acme-ca.foo-start[262]: + for fixpath in out certificates container-test-run-certificates> ca # [27734.582824] ca acme-ca.foo-start[262]: + '[' -d out ']' container-test-run-certificates> ca # [27734.582824] ca acme-ca.foo-start[262]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [27734.584427] ca acme-ca.foo-start[262]: + chown -R acme:nginx out container-test-run-certificates> ca # [27734.587742] ca acme-ca.foo-start[262]: + for fixpath in out certificates container-test-run-certificates> ca # [27734.587784] ca acme-ca.foo-start[262]: + '[' -d certificates ']' container-test-run-certificates> ca # [27734.592259] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> ca # [27734.594057] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> client # [27734.656209] client systemd-networkd[183]: eth1: Gained IPv6LL container-test-run-certificates> ca # [27735.087097] ca nginx-pre-start[306]: nginx: the configuration file /nix/store/jwfw4qdij81lq64xr33fi49z93gggc3p-nginx.conf syntax is ok container-test-run-certificates> ca # [27735.087747] ca nginx-pre-start[306]: nginx: configuration file /nix/store/jwfw4qdij81lq64xr33fi49z93gggc3p-nginx.conf test is successful container-test-run-certificates> ca # [27735.120656] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [27735.121428] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [27735.123723] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> server # [27735.077089] server nginx-pre-start[266]: nginx: the configuration file /nix/store/1hcqj3qwgk1l5wg86fhwxyq6ddsn1ggy-nginx.conf syntax is ok container-test-run-certificates> server # [27735.077712] server nginx-pre-start[266]: nginx: configuration file /nix/store/1hcqj3qwgk1l5wg86fhwxyq6ddsn1ggy-nginx.conf test is successful container-test-run-certificates> server # [27735.082654] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [27735.083412] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [27735.085767] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> ca # [27735.623845] ca acme-order-renew-ca.foo-start[309]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [27735.627450] ca acme-order-renew-ca.foo-start[309]: + set -euo pipefail container-test-run-certificates> ca # [27735.627530] ca acme-order-renew-ca.foo-start[309]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [27735.627647] ca acme-order-renew-ca.foo-start[309]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [27735.629255] ca acme-order-renew-ca.foo-start[309]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> ca # [27735.647574] ca acme-order-renew-ca.foo-start[320]: 2026/09/04 15:09:15 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [27735.647889] ca acme-order-renew-ca.foo-start[320]: 2026/09/04 15:09:15 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [27735.672203] ca step-ca[205]: time="2026-09-04T15:09:15Z" level=info duration="172.242µs" duration-ns=172242 fields.time="2026-09-04T15:09:15Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=f0501628-a830-4d0b-bf13-ddc288c844af response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [27735.672564] ca acme-order-renew-ca.foo-start[320]: 2026/09/04 15:09:15 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> ca # [27735.726332] ca step-ca[205]: time="2026-09-04T15:09:15Z" level=info duration=53.559033ms duration-ns=53559033 fields.time="2026-09-04T15:09:15Z" method=HEAD name=ca nonce=RVQ2aWs4a3YxdUhHSldlSEI1cU5BRngxNXdENEs1Vmg path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=7c5d4c9e-15cd-4afe-8f18-797f5d26d5a1 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [27735.739899] ca step-ca[205]: time="2026-09-04T15:09:15Z" level=info duration=12.264332ms duration-ns=12264332 fields.time="2026-09-04T15:09:15Z" method=POST name=ca nonce=cWZQZzBwdDFaWU5uelVnYXFtNzc5eDdEMmRvS3pnUUQ path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=ea56be2d-6550-4673-8295-f22a18265f2e response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/XZUnOf3mK38ebRAStxf2Y8lRpxgofK2K/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [27735.740406] ca acme-order-renew-ca.foo-start[320]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [27735.740406] ca acme-order-renew-ca.foo-start[320]: Your account credentials have been saved in your container-test-run-certificates> ca # [27735.740406] ca acme-order-renew-ca.foo-start[320]: configuration directory at "accounts". container-test-run-certificates> ca # [27735.740406] ca acme-order-renew-ca.foo-start[320]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [27735.740406] ca acme-order-renew-ca.foo-start[320]: configuration directory will also contain private keys container-test-run-certificates> ca # [27735.740406] ca acme-order-renew-ca.foo-start[320]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [27735.740406] ca acme-order-renew-ca.foo-start[320]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [27735.740526] ca acme-order-renew-ca.foo-start[320]: 2026/09/04 15:09:15 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [27735.746709] ca step-ca[205]: time="2026-09-04T15:09:15Z" level=info duration=5.254394ms duration-ns=5254394 fields.time="2026-09-04T15:09:15Z" method=POST name=ca nonce=c3RhMEVvZ2tIc083cW1mSjcwZkRFSUtsRXVmSnVGZ0w path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=d190c1b4-4d08-47d0-b0b9-6829d23b27e4 response="{\"id\":\"U63qXSas76YjObzOIAYLFYYENdYhB3dj\",\"status\":\"pending\",\"expires\":\"2026-09-05T15:09:15Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-09-04T15:08:15Z\",\"notAfter\":\"2026-12-03T15:09:15Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/Q6Q6lvYHJwxmb183XIDM62BwCR4Tigsg\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/U63qXSas76YjObzOIAYLFYYENdYhB3dj/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [27735.811164] ca step-ca[205]: time="2026-09-04T15:09:15Z" level=info duration=6.271648ms duration-ns=6271648 fields.time="2026-09-04T15:09:15Z" method=POST name=ca nonce=RG5udzFWSU9tNUNkVXBLNW1mOHBGWFhYUkFXTkJHd1A path=/acme/acme/authz/Q6Q6lvYHJwxmb183XIDM62BwCR4Tigsg protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=246bc94b-d361-48a7-8098-2209c275fb1e response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"jguzkJte1Ro8MSs1Z8AvXzplV3mC5rau\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/Q6Q6lvYHJwxmb183XIDM62BwCR4Tigsg/uh3cZFQvPmhXn5FfFTR5WCtZWxplCZiD\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"jguzkJte1Ro8MSs1Z8AvXzplV3mC5rau\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/Q6Q6lvYHJwxmb183XIDM62BwCR4Tigsg/xEKSEn4XM6sufX3KrBYRMXYvKuSfmoow\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"jguzkJte1Ro8MSs1Z8AvXzplV3mC5rau\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/Q6Q6lvYHJwxmb183XIDM62BwCR4Tigsg/fq68A8KzSAWmQKeHE9Ag31VNKS077Mkq\"}],\"wildcard\":false,\"expires\":\"2026-09-05T15:09:15Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [27735.811565] ca acme-order-renew-ca.foo-start[320]: 2026/09/04 15:09:15 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/Q6Q6lvYHJwxmb183XIDM62BwCR4Tigsg container-test-run-certificates> ca # [27735.811565] ca acme-order-renew-ca.foo-start[320]: 2026/09/04 15:09:15 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [27735.811565] ca acme-order-renew-ca.foo-start[320]: 2026/09/04 15:09:15 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [27735.811565] ca acme-order-renew-ca.foo-start[320]: 2026/09/04 15:09:15 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> ca # [27735.817891] ca step-ca[205]: time="2026-09-04T15:09:15Z" level=info duration=5.424076ms duration-ns=5424076 fields.time="2026-09-04T15:09:15Z" method=POST name=ca nonce=OHJxYkgyWjNqM2hKZnRCM1JPNWNLT0oweWtBTlFKUXY path=/acme/acme/challenge/Q6Q6lvYHJwxmb183XIDM62BwCR4Tigsg/xEKSEn4XM6sufX3KrBYRMXYvKuSfmoow protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=2cc98ba8-4ad3-409b-9aea-3077d38535e3 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"jguzkJte1Ro8MSs1Z8AvXzplV3mC5rau\",\"validated\":\"2026-09-04T15:09:15Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/Q6Q6lvYHJwxmb183XIDM62BwCR4Tigsg/xEKSEn4XM6sufX3KrBYRMXYvKuSfmoow\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [27735.818251] ca acme-order-renew-ca.foo-start[320]: 2026/09/04 15:09:15 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [27735.818355] ca acme-order-renew-ca.foo-start[320]: 2026/09/04 15:09:15 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [27735.828935] ca step-ca[205]: time="2026-09-04T15:09:15Z" level=info duration=8.871965ms duration-ns=8871965 fields.time="2026-09-04T15:09:15Z" method=POST name=ca nonce=S2Z2UUNOZFJVclNyVWFQMFp0Q0xVVzFBeW1EejA4Rkc path=/acme/acme/order/U63qXSas76YjObzOIAYLFYYENdYhB3dj/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=65edfb7e-e725-45c2-b8f8-f7e68323254d response="{\"id\":\"U63qXSas76YjObzOIAYLFYYENdYhB3dj\",\"status\":\"valid\",\"expires\":\"2026-09-05T15:09:15Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-09-04T15:08:15Z\",\"notAfter\":\"2026-12-03T15:09:15Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/Q6Q6lvYHJwxmb183XIDM62BwCR4Tigsg\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/U63qXSas76YjObzOIAYLFYYENdYhB3dj/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/C31UabbTrX7lV5RjQJE1IEJCqIdDVrTW\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [27735.831689] ca step-ca[205]: time="2026-09-04T15:09:15Z" level=info certificate=MIIB0zCCAXqgAwIBAgIRAPSyRtfviO2ADk1/uDw0mQowCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwOTA0MTUwODE1WhcNMjYxMjAzMTUwOTE1WjARMQ8wDQYDVQQDEwZjYS5mb28wWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAARhPgp3eFzgmKxSRXMmardhwoerbZ2amjltiM3obiZbxBAXd8xjZ7jAqfhHpzxoJCM9H8LcBeYYw4sTh4Wqd05zo4GkMIGhMA4GA1UdDwEB/wQEAwIHgDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwHQYDVR0OBBYEFK/zR8l+veokOoGlGnycfVLqH+axMB8GA1UdIwQYMBaAFNFqRJ1BBy/MzAovHdKP6cHdSJ0SMBEGA1UdEQQKMAiCBmNhLmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDRwAwRAIgfXtPUW2eEv7PxbtLCFPE7wYJHD5KurigGpdM3QtmLW0CIDu1QUTSzJrFmrc7KqBGwXNzuYiE+hnMNyl6ICAwWfO9 duration=1.784985ms duration-ns=1784985 fields.time="2026-09-04T15:09:15Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=WkdrWm95UmY1Z0lxcUdXZ25KSmJOTVlqZnpyejBhb0U path=/acme/acme/certificate/C31UabbTrX7lV5RjQJE1IEJCqIdDVrTW protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=90d8e813-241a-4510-bddb-45a871a74c8b sans="map[dns:[ca.foo]]" serial=325257296689198321312008972827264063754 size=1340 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-09-04T15:08:15Z" valid-to="2026-12-03T15:09:15Z" container-test-run-certificates> ca # [27735.831999] ca acme-order-renew-ca.foo-start[320]: 2026/09/04 15:09:15 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [27735.838494] ca acme-order-renew-ca.foo-start[309]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [27735.840664] ca acme-order-renew-ca.foo-start[309]: + touch out/acme-success container-test-run-certificates> ca # [27735.842525] ca acme-order-renew-ca.foo-start[309]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [27735.843799] ca acme-order-renew-ca.foo-start[309]: + touch out/renewed container-test-run-certificates> ca # [27735.845653] ca acme-order-renew-ca.foo-start[309]: + echo Installing new certificate container-test-run-certificates> ca # [27735.845653] ca acme-order-renew-ca.foo-start[309]: Installing new certificate container-test-run-certificates> ca # [27735.845653] ca acme-order-renew-ca.foo-start[309]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [27735.847259] ca acme-order-renew-ca.foo-start[353]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [27735.847595] ca acme-order-renew-ca.foo-start[309]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [27735.848993] ca acme-order-renew-ca.foo-start[354]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [27735.849288] ca acme-order-renew-ca.foo-start[309]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [27735.850945] ca acme-order-renew-ca.foo-start[355]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [27735.851211] ca acme-order-renew-ca.foo-start[309]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [27735.853086] ca acme-order-renew-ca.foo-start[309]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [27735.854923] ca acme-order-renew-ca.foo-start[309]: + for fixpath in out certificates container-test-run-certificates> ca # [27735.854923] ca acme-order-renew-ca.foo-start[309]: + '[' -d out ']' container-test-run-certificates> ca # [27735.855027] ca acme-order-renew-ca.foo-start[309]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [27735.856520] ca acme-order-renew-ca.foo-start[309]: + chown -R acme:nginx out container-test-run-certificates> ca # [27735.859407] ca acme-order-renew-ca.foo-start[309]: + for fixpath in out certificates container-test-run-certificates> ca # [27735.859459] ca acme-order-renew-ca.foo-start[309]: + '[' -d certificates ']' container-test-run-certificates> ca # [27735.859459] ca acme-order-renew-ca.foo-start[309]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [27735.861396] ca acme-order-renew-ca.foo-start[309]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [27735.864253] ca acme-order-renew-ca.foo-start[309]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> server # [27735.601265] server acme-order-renew-test.foo-start[269]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [27735.604936] server acme-order-renew-test.foo-start[269]: + set -euo pipefail container-test-run-certificates> server # [27735.605015] server acme-order-renew-test.foo-start[269]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [27735.605137] server acme-order-renew-test.foo-start[269]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [27735.606803] server acme-order-renew-test.foo-start[269]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [27735.625559] server acme-order-renew-test.foo-start[280]: 2026/09/04 15:09:15 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [27735.625892] server acme-order-renew-test.foo-start[280]: 2026/09/04 15:09:15 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [27736.028810] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> ca # [27736.033104] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [27736.033312] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> ca # [27736.511428] ca nginx[371]: nginx: the configuration file /nix/store/jwfw4qdij81lq64xr33fi49z93gggc3p-nginx.conf syntax is ok container-test-run-certificates> ca # [27736.511927] ca nginx[371]: nginx: configuration file /nix/store/jwfw4qdij81lq64xr33fi49z93gggc3p-nginx.conf test is successful container-test-run-certificates> server # [27736.678361] server acme-order-renew-test.foo-start[280]: 2026/09/04 15:09:16 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 2 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority container-test-run-certificates> server # [27736.682745] server acme-order-renew-test.foo-start[269]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [27736.682745] server acme-order-renew-test.foo-start[269]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [27736.683012] server acme-order-renew-test.foo-start[269]: + exit 10 container-test-run-certificates> server # [27736.686183] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a container-test-run-certificates> server # [27736.686383] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'. container-test-run-certificates> server # [27736.686775] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [27736.692108] server systemd[1]: Startup finished in 4.608s. container-test-run-certificates> ca # [27737.024649] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [27737.025125] ca systemd[1]: Startup finished in 4.906s. container-test-run-certificates> ca # [27737.249668] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 3.39 seconds) container-test-run-certificates> ca # [27737.748437] ca acme-order-renew-ca.foo-start[386]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [27737.751262] ca acme-order-renew-ca.foo-start[386]: + set -euo pipefail container-test-run-certificates> ca # [27737.751337] ca acme-order-renew-ca.foo-start[386]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [27737.751450] ca acme-order-renew-ca.foo-start[386]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [27737.753021] ca acme-order-renew-ca.foo-start[386]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [27737.753073] ca acme-order-renew-ca.foo-start[386]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [27737.753593] ca acme-order-renew-ca.foo-start[394]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [27737.756674] ca acme-order-renew-ca.foo-start[386]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [27737.756726] ca acme-order-renew-ca.foo-start[386]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [27737.803094] ca step-ca[205]: time="2026-09-04T15:09:17Z" level=info duration="52.841µs" duration-ns=52841 fields.time="2026-09-04T15:09:17Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=2ef48e95-7b70-4b84-ac7c-357d5c876e5a response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [27737.803937] ca acme-order-renew-ca.foo-start[395]: 2026/09/04 15:09:17 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [27737.803937] ca acme-order-renew-ca.foo-start[395]: 2026/09/04 15:09:17 [INFO] [ca.foo] The certificate expires at 2026-12-03T15:09:15Z, the renewal can be performed in 1439h59m37.210737758s: no renewal. container-test-run-certificates> ca # [27737.804186] ca acme-order-renew-ca.foo-start[386]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [27737.806485] ca acme-order-renew-ca.foo-start[386]: + touch out/acme-success container-test-run-certificates> ca # [27737.808301] ca acme-order-renew-ca.foo-start[386]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [27737.809659] ca acme-order-renew-ca.foo-start[386]: + for fixpath in out certificates container-test-run-certificates> ca # [27737.809659] ca acme-order-renew-ca.foo-start[386]: + '[' -d out ']' container-test-run-certificates> ca # [27737.809747] ca acme-order-renew-ca.foo-start[386]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [27737.811504] ca acme-order-renew-ca.foo-start[386]: + chown -R acme:nginx out container-test-run-certificates> ca # [27737.815162] ca acme-order-renew-ca.foo-start[386]: + for fixpath in out certificates container-test-run-certificates> ca # [27737.815162] ca acme-order-renew-ca.foo-start[386]: + '[' -d certificates ']' container-test-run-certificates> ca # [27737.815255] ca acme-order-renew-ca.foo-start[386]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [27737.816928] ca acme-order-renew-ca.foo-start[386]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [27737.819822] ca acme-order-renew-ca.foo-start[386]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [27737.969198] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [27737.969555] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server # [27740.992755] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [27740.993130] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [27740.994386] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [27740.996780] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.55 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1008 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [110 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Sep 4 15:09:14 2026 GMT container-test-run-certificates> * expire date: Oct 4 15:09:14 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 29729b container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [27741.490161] server acme-test.foo-start[314]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [27741.493385] server acme-test.foo-start[314]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [27741.493385] server acme-test.foo-start[314]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [27741.508345] server acme-test.foo-start[324]: + cd test.foo container-test-run-certificates> server # [27741.508801] server acme-test.foo-start[324]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [27741.510108] server acme-test.foo-start[325]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [27741.510419] server acme-test.foo-start[324]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [27741.511824] server acme-test.foo-start[324]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [27741.512090] server acme-test.foo-start[314]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [27741.513901] server acme-test.foo-start[314]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [27741.515541] server acme-test.foo-start[314]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [27741.517390] server acme-test.foo-start[314]: + for fixpath in out certificates container-test-run-certificates> server # [27741.517390] server acme-test.foo-start[314]: + '[' -d out ']' container-test-run-certificates> server # [27741.517484] server acme-test.foo-start[314]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [27741.519141] server acme-test.foo-start[314]: + chown -R acme:nginx out container-test-run-certificates> server # [27741.522223] server acme-test.foo-start[314]: + for fixpath in out certificates container-test-run-certificates> server # [27741.522316] server acme-test.foo-start[314]: + '[' -d certificates ']' container-test-run-certificates> server # [27741.525776] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [27741.530381] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> server # [27742.032096] server acme-order-renew-test.foo-start[332]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [27742.035541] server acme-order-renew-test.foo-start[332]: + set -euo pipefail container-test-run-certificates> server # [27742.035635] server acme-order-renew-test.foo-start[332]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [27742.035728] server acme-order-renew-test.foo-start[332]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [27742.037030] server acme-order-renew-test.foo-start[332]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [27742.092269] server acme-order-renew-test.foo-start[340]: 2026/09/04 15:09:22 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [27742.209008] server acme-order-renew-test.foo-start[340]: !!!! HEADS UP !!!! container-test-run-certificates> server # [27742.209008] server acme-order-renew-test.foo-start[340]: Your account credentials have been saved in your container-test-run-certificates> server # [27742.209008] server acme-order-renew-test.foo-start[340]: configuration directory at "accounts". container-test-run-certificates> server # [27742.209008] server acme-order-renew-test.foo-start[340]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [27742.209008] server acme-order-renew-test.foo-start[340]: configuration directory will also contain private keys container-test-run-certificates> server # [27742.209008] server acme-order-renew-test.foo-start[340]: generated by lego and certificates obtained from the ACME container-test-run-certificates> server # [27742.209008] server acme-order-renew-test.foo-start[340]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [27742.209368] server acme-order-renew-test.foo-start[340]: 2026/09/04 15:09:22 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> server # [27742.280670] server acme-order-renew-test.foo-start[340]: 2026/09/04 15:09:22 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/wsmzM8E4FXvcs2Q07w63pbiYgIbDzjzV container-test-run-certificates> server # [27742.280670] server acme-order-renew-test.foo-start[340]: 2026/09/04 15:09:22 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [27742.280670] server acme-order-renew-test.foo-start[340]: 2026/09/04 15:09:22 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [27742.280670] server acme-order-renew-test.foo-start[340]: 2026/09/04 15:09:22 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [27742.289965] server acme-order-renew-test.foo-start[340]: 2026/09/04 15:09:22 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [27742.290038] server acme-order-renew-test.foo-start[340]: 2026/09/04 15:09:22 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [27742.091675] ca step-ca[205]: time="2026-09-04T15:09:22Z" level=info duration="61.121µs" duration-ns=61121 fields.time="2026-09-04T15:09:22Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=520e6999-600d-4ae6-beb1-671f1da3f397 response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [27742.201217] ca step-ca[205]: time="2026-09-04T15:09:22Z" level=info duration=104.948435ms duration-ns=104948435 fields.time="2026-09-04T15:09:22Z" method=HEAD name=ca nonce=dnRpaGhOZTBYZ0ZDTGZnOUR4ank5cGdoaHhvTUExQzM path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=c8f2bc39-f9a8-48dc-addf-4903e11ceec0 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [27742.208158] ca step-ca[205]: time="2026-09-04T15:09:22Z" level=info duration=2.412114ms duration-ns=2412114 fields.time="2026-09-04T15:09:22Z" method=POST name=ca nonce=eVhQVUdJb0hXdGRDOEVpWnJxOGhacDE5UlZKOGIyT1Y path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=d7841407-5480-4052-bcd6-0665623b0bcb response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/vpSJ6mgGivXKDhKonz0pw2Vk9w9HZGpY/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [27742.217327] ca step-ca[205]: time="2026-09-04T15:09:22Z" level=info duration=4.22266ms duration-ns=4222660 fields.time="2026-09-04T15:09:22Z" method=POST name=ca nonce=VVo4WXpIdkt4dGRmZ1kwVGc4NEJaV1QwQnFscGpMWXY path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=e25e1163-ab06-40fe-b3cc-037dc43cd538 response="{\"id\":\"7q2ErtaHMuUQ4EHF5GKauf1NmsRXG1iu\",\"status\":\"pending\",\"expires\":\"2026-09-05T15:09:22Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-09-04T15:08:22Z\",\"notAfter\":\"2026-12-03T15:09:22Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/wsmzM8E4FXvcs2Q07w63pbiYgIbDzjzV\"],\"finalize\":\"https://ca.foo/acme/acme/order/7q2ErtaHMuUQ4EHF5GKauf1NmsRXG1iu/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [27742.280039] ca step-ca[205]: time="2026-09-04T15:09:22Z" level=info duration=1.947267ms duration-ns=1947267 fields.time="2026-09-04T15:09:22Z" method=POST name=ca nonce=cjhDOUlrUHpYMUxGcmwwc0I2NnY3RlFJdmR1ZUFqY2U path=/acme/acme/authz/wsmzM8E4FXvcs2Q07w63pbiYgIbDzjzV protocol=HTTP/1.1 referer= remote-address="::1" request-id=8fe8c724-8d26-4c75-92a2-4885f53efdf5 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"W5s9LXcUccLnHbQF1tl6OXJxVOUgSbFx\",\"url\":\"https://ca.foo/acme/acme/challenge/wsmzM8E4FXvcs2Q07w63pbiYgIbDzjzV/ZI8EJmomhg0H5dVhT7FgAPvRK8024JMY\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"W5s9LXcUccLnHbQF1tl6OXJxVOUgSbFx\",\"url\":\"https://ca.foo/acme/acme/challenge/wsmzM8E4FXvcs2Q07w63pbiYgIbDzjzV/lpXNSQcTh8XXLkZneoA371RP9mQHxDcb\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"W5s9LXcUccLnHbQF1tl6OXJxVOUgSbFx\",\"url\":\"https://ca.foo/acme/acme/challenge/wsmzM8E4FXvcs2Q07w63pbiYgIbDzjzV/5wJLxzLP7fVS7n5AmCANdfRFPmzRDuit\"}],\"wildcard\":false,\"expires\":\"2026-09-05T15:09:22Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [27742.289297] ca step-ca[205]: time="2026-09-04T15:09:22Z" level=info duration=4.550304ms duration-ns=4550304 fields.time="2026-09-04T15:09:22Z" method=POST name=ca nonce=T0JKeDRJNUtoVHk4aXdrdFYzRFlYVmdCY29na3RSVFc path=/acme/acme/challenge/wsmzM8E4FXvcs2Q07w63pbiYgIbDzjzV/lpXNSQcTh8XXLkZneoA371RP9mQHxDcb protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=45b88d3c-41f7-4b26-ad0c-1e937e2ecf78 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"W5s9LXcUccLnHbQF1tl6OXJxVOUgSbFx\",\"validated\":\"2026-09-04T15:09:22Z\",\"url\":\"https://ca.foo/acme/acme/challenge/wsmzM8E4FXvcs2Q07w63pbiYgIbDzjzV/lpXNSQcTh8XXLkZneoA371RP9mQHxDcb\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [27742.303603] ca step-ca[205]: time="2026-09-04T15:09:22Z" level=info duration=8.647762ms duration-ns=8647762 fields.time="2026-09-04T15:09:22Z" method=POST name=ca nonce=ek9KdXhXaVpaUU1oMGFkMzFoZXh6SmoyODVOVjJqUzk path=/acme/acme/order/7q2ErtaHMuUQ4EHF5GKauf1NmsRXG1iu/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=59485e2d-caba-420e-b11f-91130febfdaf response="{\"id\":\"7q2ErtaHMuUQ4EHF5GKauf1NmsRXG1iu\",\"status\":\"valid\",\"expires\":\"2026-09-05T15:09:22Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-09-04T15:08:22Z\",\"notAfter\":\"2026-12-03T15:09:22Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/wsmzM8E4FXvcs2Q07w63pbiYgIbDzjzV\"],\"finalize\":\"https://ca.foo/acme/acme/order/7q2ErtaHMuUQ4EHF5GKauf1NmsRXG1iu/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/7Mx0G5G9nBf6PYnNLBmaeq5oJ1vG3YoE\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [27742.310158] ca step-ca[205]: time="2026-09-04T15:09:22Z" level=info certificate=MIIB1jCCAX2gAwIBAgIQTY9Bt5L4NhEbs4iM8vVNyjAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA5MDQxNTA4MjJaFw0yNjEyMDMxNTA5MjJaMBMxETAPBgNVBAMTCHRlc3QuZm9vMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE49lh6uG7jTyHDvCtWgKaiHWfAIKL9U7UWiwD4GQgy8nd0Y+IsQDpSFJd/ulO+S94gl03Wfl//Rv49LKASo9xKqOBpjCBozAOBgNVHQ8BAf8EBAMCB4AwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBRTr79qSzOeFD0246wzvrWvzkjzQDAfBgNVHSMEGDAWgBTRakSdQQcvzMwKLx3Sj+nB3UidEjATBgNVHREEDDAKggh0ZXN0LmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDRwAwRAIgX8l/vAA0MWb/LgXLGeBnis2WhBDEI1Mpf06sxUBlBYICIHIYDmSfpXJzB+X2Iy5+lJVyEXX5B/E4r/MQX24nfjbX duration=2.08155ms duration-ns=2081550 fields.time="2026-09-04T15:09:22Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=SWtmVUZ6YzM5ZjVxOXhHeWZSTGxEVHdQYkJXemR4VW0 path=/acme/acme/certificate/7Mx0G5G9nBf6PYnNLBmaeq5oJ1vG3YoE protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=5e97a9f8-a583-4b14-bef1-896637d2de5a sans="map[dns:[test.foo]]" serial=103094387027071860393985962288398814666 size=1344 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-09-04T15:08:22Z" valid-to="2026-12-03T15:09:22Z" container-test-run-certificates> server # [27742.310714] server acme-order-renew-test.foo-start[340]: 2026/09/04 15:09:22 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [27742.315801] server acme-order-renew-test.foo-start[332]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [27742.318067] server acme-order-renew-test.foo-start[332]: + touch out/acme-success container-test-run-certificates> server # [27742.319942] server acme-order-renew-test.foo-start[332]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [27742.321133] server acme-order-renew-test.foo-start[332]: + touch out/renewed container-test-run-certificates> server # [27742.322871] server acme-order-renew-test.foo-start[332]: + echo Installing new certificate container-test-run-certificates> server # [27742.322871] server acme-order-renew-test.foo-start[332]: Installing new certificate container-test-run-certificates> server # [27742.322871] server acme-order-renew-test.foo-start[332]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [27742.324400] server acme-order-renew-test.foo-start[372]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [27742.324764] server acme-order-renew-test.foo-start[332]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [27742.326217] server acme-order-renew-test.foo-start[373]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [27742.326524] server acme-order-renew-test.foo-start[332]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [27742.327953] server acme-order-renew-test.foo-start[374]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [27742.328292] server acme-order-renew-test.foo-start[332]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [27742.329931] server acme-order-renew-test.foo-start[332]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [27742.332179] server acme-order-renew-test.foo-start[332]: + for fixpath in out certificates container-test-run-certificates> server # [27742.332179] server acme-order-renew-test.foo-start[332]: + '[' -d out ']' container-test-run-certificates> server # [27742.332274] server acme-order-renew-test.foo-start[332]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [27742.333837] server acme-order-renew-test.foo-start[332]: + chown -R acme:nginx out container-test-run-certificates> server # [27742.336864] server acme-order-renew-test.foo-start[332]: + for fixpath in out certificates container-test-run-certificates> server # [27742.336864] server acme-order-renew-test.foo-start[332]: + '[' -d certificates ']' container-test-run-certificates> server # [27742.337002] server acme-order-renew-test.foo-start[332]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [27742.338701] server acme-order-renew-test.foo-start[332]: + chown -R acme:nginx certificates container-test-run-certificates> server # [27742.342309] server acme-order-renew-test.foo-start[332]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> server # [27742.485854] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [27742.490612] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [27742.490930] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1008 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Sep 4 15:09:14 2026 GMT container-test-run-certificates> * expire date: Oct 4 15:09:14 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 29729b container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [27743.015968] server nginx[390]: nginx: the configuration file /nix/store/1hcqj3qwgk1l5wg86fhwxyq6ddsn1ggy-nginx.conf syntax is ok container-test-run-certificates> server # [27743.016485] server nginx[390]: nginx: configuration file /nix/store/1hcqj3qwgk1l5wg86fhwxyq6ddsn1ggy-nginx.conf test is successful container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [930 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [80 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Sep 4 15:08:22 2026 GMT container-test-run-certificates> * expire date: Dec 3 15:09:22 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 56148 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 653 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 2.16 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> 4d:8f:41:b7:92:f8:36:11:1b:b3:88:8c:f2:f5:4d:ca container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Sep 4 15:08:22 2026 GMT container-test-run-certificates> Not After : Dec 3 15:09:22 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:e3:d9:61:ea:e1:bb:8d:3c:87:0e:f0:ad:5a:02: container-test-run-certificates> 9a:88:75:9f:00:82:8b:f5:4e:d4:5a:2c:03:e0:64: container-test-run-certificates> 20:cb:c9:dd:d1:8f:88:b1:00:e9:48:52:5d:fe:e9: container-test-run-certificates> 4e:f9:2f:78:82:5d:37:59:f9:7f:fd:1b:f8:f4:b2: container-test-run-certificates> 80:4a:8f:71:2a container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> 53:AF:BF:6A:4B:33:9E:14:3D:36:E3:AC:33:BE:B5:AF:CE:48:F3:40 container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> D1:6A:44:9D:41:07:2F:CC:CC:0A:2F:1D:D2:8F:E9:C1:DD:48:9D:12 container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:44:02:20:5f:c9:7f:bc:00:34:31:66:ff:2e:05:cb:19:e0: container-test-run-certificates> 67:8a:cd:96:84:10:c4:23:53:29:7f:4e:ac:c5:40:65:05:82: container-test-run-certificates> 02:20:72:18:0e:64:9f:a5:72:73:07:e5:f6:23:2e:7e:94:95: container-test-run-certificates> 72:11:75:f9:07:f1:38:af:f3:10:5f:6e:27:7e:36:d7 container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.04 seconds) container-test-run-certificates> (finished: run the VM test script, in 12.14 seconds) container-test-run-certificates> server # [27743.526171] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> test script finished in 12.37s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 52) container-test-run-certificates> kill NspawnMachine (pid 55) container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> kill NspawnMachine (pid 57) container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> Container server terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.54 seconds) warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy post-build step Upload to niks3: ok time=2026-09-04T15:09:26.589Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-09-04T15:09:26.894Z level=INFO msg="Uploading 1 narinfos" time=2026-09-04T15:09:27.703Z level=INFO msg="Upload complete. (1.163s)"