Nginx Subdomains are all messed up

My configuration causes no errors or similar but does not follow my expectations at all. The odd behavior might be related to one another.

My configuration


{ config, pkgs, ... }:
  domain = config.networking.domain;
  services.nginx = {
    enable = true;

    package = pkgs.nginxStable.override { openssl = pkgs.libressl; };

    virtualHosts = {
      ${domain} = {
        enableACME = true;
        addSSL = true;
        locations."/" = {
          return = "200 '<html><body>It works</body></html>'";
          extraConfig = ''
            default_type text/html;

      "binarycache.${domain}" = {
        useACMEHost = domain;
        addSSL = true;
        locations."/".extraConfig = ''
          proxy_set_header Host $host;
          proxy_redirect http:// https://;
          proxy_http_version 1.1;
          proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
          proxy_set_header Upgrade $http_upgrade;
          proxy_set_header Connection $connection_upgrade;

      "${}" = {
        useACMEHost = domain;
        addSSL = true;

      "test.${domain}" = {
        useACMEHost = domain;
        locations."/" = {
          return = "200 '<html><body>Test Works</body></html>'";
          extraConfig = ''
            default_type text/html;


{ pkgs, config, ... }:
  domain = config.networking.domain;
  security.acme = {
    acceptTerms = true;
    defaults = {
      email = "redacted";
      dnsProvider = redacted;
      environmentFile = redacted;

    certs = {
      "${domain}" = {
        domain = "*.${domain}";
        extraDomainNames = [ domain ];
        group =;

  systemd.tmpfiles.rules = [ "d /var/lib/acme 0750 acme acme -" ];

  users.groups.acme = {
    members = [ ];

Buildbot Master

{ config, lib, ... }:

  sopsCfg = config.sops;
  services = {
    buildbot-nix.master = {
      enable = true;
      domain = "buildbot.${config.networking.domain}";

      workersFile = sopsCfg.templates."buildbot-workers.json".path;
      admins = [ "malik" ];
      outputsPath = "/var/www/buildbot/nix-outputs";

      authBackend = "gitea";
      gitea = {
        enable = true;
        tokenFile = sopsCfg.secrets."codeberg-token".path;
        instanceUrl = "";
        oauthId = "redacted";
        oauthSecretFile = sopsCfg.secrets."cb-buildbot-secret".path;
        webhookSecretFile = sopsCfg.secrets."buildbot-webhook".path;
        topic = "build-with-buildbot";

    buildbot-master = {
      buildbotUrl = lib.mkForce "https://${}";


1. All unconfigured Subdomains lead to the site of Harmonia

Whatever url I put in my Browser in the form of “https://any letters.domain” cause this behavior.

2. buildbot domain not reachable

I get an error 502 Bad Gateway when trying to reach the buildbot web interface.
Nginx 502 Bad Gateway

For 1. the main question is why all these unconfigured subdomains resolve to your Nginx instance. Nginx will respond with whatever site is configured as default_server when the incoming domain name does not match any configured site. Not sure which one it chooses when no site is configured as default_server.

Still, I’d check why they all resolve to your webserver. And if that is on purpose, please mention what your expectations are.

For 2. that usually means that nginx cannot reach the application server of buildbot. It’s not completely clear to me how the buildbot configuration works, but I’d look at the generated nginx config files if there is a proxy_pass directive and if it is correct. Then you could check if the service that nginx expects to run is actually running and responding properly.

I will propably set the default server to the one behind the topdomain.

Because Harmonia is a binary cache provider I don’t really need the frontend, which makes me wonder why the in the Readme recommended nginx settings cause such behavior.

I already realized that the problem with buildbot is most propably not related to my nginx configuration.