{config, ...}: { services.invidious = { enable = true; database = { createLocally = true; }; domain = "invidious.vhack.eu"; nginx.enable = true; extraSettingsFile = "$CREDENTIALS_DIRECTORY/hmac"; settings = { check_tables = true; }; }; systemd.services.invidious.serviceConfig = { LoadCredential = "hmac:${config.age.secrets.invidiousHmac.path}"; }; }