Add a 443 listener on the tailscale IP for the opencode vhost, alongside the existing port 80. The name resolves to a CGNAT tailscale IP so Let's Encrypt HTTP-01 can't validate it and there's no DNS-01 provider here; the vhost is tailnet-only, so a self-signed cert (out-of-band at /etc/nginx/oc-selfsigned.*, like oc-htpasswd) is acceptable. addSSL=true is required so the NixOS nginx module actually renders ssl_certificate — without it nginx -t fails and takes the atproto vhost down too. Rationale + regen command documented inline. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016L6nYYwkCWnrEFKTnKAfet