{ services.caddy = { enable = true; #globalConfig = '' # pki { # ca local { # name "Distrust CA" # } # } #''; }; networking.firewall.allowedTCPPorts = [80 443]; }