{ config, ... }: { services.paperless = { enable = true; }; services.nginx.virtualHosts."paperless.${config.networking.hostName}.private" = { extraConfig = '' allow ${config.tinc.private.subnet}; deny all; ''; locations."/" = { proxyPass = "http://localhost:${toString config.services.paperless.port}"; proxyWebsockets = true; }; }; }