{config, pkgs, ...}: let source = builtins.fetchGit { url = "https://stuebinm.eu/git/picarones/"; rev = "393186f9ebf0bf43a1add8bd8d0e37be566ae8cc"; }; in { imports = [ source.outPath ]; services.picarones = { enable = true; frontend = { enable = true; domain = "picarones.stuebinm.eu"; proxyBackend = true; config = { enableACME = true; forceSSL = true; }; }; }; networking.firewall.allowedTCPPorts = [ 80 443 ]; }