{ lib, config }: { root = "/data/nginx/secrets"; #use ip from ens18 listenAddresses = [ (lib.head config.networking.interfaces.ens18.ipv4.addresses).address ]; locations = { "/" = { extraConfig = "autoindex on;" + "allow 192.168.1.0/24;" + "allow 127.0.0.1;" + "deny all;" ; }; "^~ /.well-known/acme-challenge/" = { root = "/var/lib/acme/acme-challenge"; }; }; }