{ pkgs, ... }: { imports = [ ./hardware-configuration.nix ../../modules ]; sbruder = { nginx.hardening.enable = true; full = false; wireguard.home.enable = true; }; networking.hostName = "yuzuru"; system.stateVersion = "23.11"; services.nginx = { enable = true; virtualHosts."yuzuru.sbruder.de" = { enableACME = true; forceSSL = true; root = pkgs.sbruder.imprint; }; }; networking.firewall.allowedTCPPorts = [ 80 443 ]; }