{ ... }: {
  services.nginx = {
    enable = true;
    user = "navidrome";
    virtualHosts."navidrome.grzb.de" = {
      forceSSL = true;
      enableACME = true;
      listen = [
        {
          addr = "0.0.0.0";
          port = 80;
        }
        {
          addr = "0.0.0.0";
          port = 443;
          ssl = true;
        }
      ];
      locations."/" = {
        proxyPass = "http://unix:/run/navidrome/navidrome.socket";
      };
    };
  };
}