{ pkgs, ... }: { imports = [ ./hardware-configuration.nix ../../modules ./services/proxy.nix ]; sbruder = { nginx.hardening.enable = true; full = false; wireguard.home.enable = true; }; networking.hostName = "okarin"; system.stateVersion = "22.11"; services.nginx = { enable = true; recommendedGzipSettings = true; recommendedOptimisation = true; recommendedProxySettings = true; recommendedTlsSettings = true; virtualHosts."okarin.sbruder.xyz" = { enableACME = true; forceSSL = true; root = pkgs.sbruder.imprint; }; }; networking.firewall.allowedTCPPorts = [ 80 443 ]; }