1{ nodes, ... }:
2let
3 caCert = nodes.acme.test-support.acme.caCert;
4 caDomain = nodes.acme.test-support.acme.caDomain;
5
6in
7{
8 security.acme = {
9 acceptTerms = true;
10 defaults = {
11 server = "https://${caDomain}/dir";
12 email = "hostmaster@example.test";
13 };
14 };
15
16 security.pki.certificateFiles = [ caCert ];
17}