Gitlab-runner setup problems

I’m having problems setting up a gitlab+gitlab-runner server with nixos. i’ve followed the wiki/manual and whatever google gave me - yet i still get this error:

Nov 14 13:32:04 example gitlab-runner[481]: ERROR: Checking for jobs... forbidden               runner=XXXXXXXX
Nov 14 13:32:04 example gitlab-runner[481]: ERROR: Runner https://gitlab.example.com/XXXXXXXXXXXXXXXXXXXX is not healthy and will be disabled!

does someone have any idea what i am missing? To me this seems to be the simplest single-server gitlab with gitlab-runner config there is:

{ config, lib, pkgs, ... }:

let

  baseUrl = "example.com";
  gitlabUrl = "gitlab.${baseUrl}";  
  
in {
  services.gitlab = {
    enable = true;
    initialRootPasswordFile = "/gitlab.pw";
    secrets = {
      dbFile = "/gitlab.pw";
      otpFile = "/gitlab.pw";
      secretFile = "/gitlab.pw";
      jwsFile = "/gitlab.jws";
    };
    host = "${gitlabUrl}";
    port = 443;
    https = true;
  };

  services.nginx = {
    enable = true;
    recommendedGzipSettings = true;
    recommendedOptimisation = true;
    recommendedProxySettings = true;
    recommendedTlsSettings = true;
    virtualHosts."${gitlabUrl}" = {
      enableACME = true;
      forceSSL = true;
      locations."/".proxyPass = "http://unix:/run/gitlab/gitlab-workhorse.socket";
    };
  };

  networking.firewall.allowedTCPPorts = [ 80 443 ];

  services.gitlab-runner = {
    enable = true;
    configOptions = {
      concurrent = 1;
      runners = [
        {
          builds_dir = "";
          docker = {
            cache_dir = "";
            disable_cache = true;
            host = "";
            image = "nixos/nix:2.3";
            privileged = true;
          };
          executor = "docker";
          name = "docker-nix-2.3";
          token = "XXXXXXXXXXXXXXXXXXXX";
          url = "https://${gitlabUrl}/";
        }
      ];
    };
  };
}

is the statement from
README.md · master · Serhii Khoma / nixos-gitlab-runner · GitLab still true, that nixos’ gitlab runners are broken?

Thanks,
ikervagyok