{website, ...}: { networking.firewall.allowedTCPPorts = [80 443]; services.nginx = { virtualHosts."buffet.sh" = { useACMEHost = "buffet.sh"; forceSSL = true; root = "${website}"; }; }; }