security.acme.certs."${domain}" = {
postRun = "systemctl reload nginx";
};
-systemd.services.nginx.serviceConfig = {
- UMask = "0066";
-};
systemd.services.nginx = {
wants = [ "acme-selfsigned-${domain}.service" "acme-${domain}.service"];
after = [ "acme-selfsigned-${domain}.service" ];