diff --git a/machines/chungus/configuration.nix b/machines/chungus/configuration.nix
index 2948810..461e172 100644
--- a/machines/chungus/configuration.nix
+++ b/machines/chungus/configuration.nix
@@ -45,9 +45,11 @@
 
     ./service-atuin.nix
     ./service-forgejo.nix
+
     ./service-paperless-backup.nix
     ./service-paperless-tika.nix
     ./service-paperless.nix
+
     ./service-s3.nix
     #./service-taskwarrior.nix
     ./service-vault.nix
diff --git a/machines/chungus/service-paperless.nix b/machines/chungus/service-paperless.nix
index 532e0ed..6fa164c 100644
--- a/machines/chungus/service-paperless.nix
+++ b/machines/chungus/service-paperless.nix
@@ -9,7 +9,7 @@
 
   services.paperless = {
     enable = true;
-    address = "[::]";
+    #address = "[::]";
     port = 28981;
     package = pkgs.paperless-ngx;
     settings = {
@@ -42,24 +42,13 @@
     80 # nginx
   ];
 
-  healthchecks.http.paperless-private = {
-    url = "http://paperless.chungus.private/accounts/login/?next=/";
-    expectedContent = "paperless.chungus.private";
-  };
-  healthchecks.http.paperless-port = {
-    url = "http://paperless.ingolf-wagner.de:${toString config.services.paperless.port}/accounts/login/?next=/";
-    expectedContent = "paperless.chungus.private";
-  };
   healthchecks.http.paperless = {
     url = "http://paperless.ingolf-wagner.de/accounts/login/?next=/";
     expectedContent = "paperless.chungus.private";
   };
 
-  services.nginx.virtualHosts."paperless.${config.networking.hostName}.private" = {
-    serverAliases = [ "paperless.ingolf-wagner.de" ];
+  services.nginx.virtualHosts."paperless.ingolf-wagner.de" = {
     extraConfig = ''
-      allow ${config.tinc.private.subnet};
-      allow ${config.wireguard.wg0.subnet};
       allow ${config.clan.core.networking.zerotier.subnet};
       deny all;
     '';