{ inputs, config, ... }: { services.nginx.virtualHosts."vault.vulpecula.zone" = { addSSL = true; enableACME = true; locations."/" = { proxyPass = "http://127.0.0.1:${toString config.services.vaultwarden.config.ROCKET_PORT}"; }; }; services.vaultwarden.enable = true; services.bitwarden-directory-connector-cli.domain = "vault.vulpecula.zone"; services.vaultwarden.config = { DOMAIN = "https://vault.vulpecula.zone"; SIGNUPS_ALLOWED = false; ROCKET_ADDRESS = "127.0.0.1"; ROCKET_PORT = 62107; ROCKET_LOG = "critical"; }; }