inputs: { config, ... }: { services.radicale = { enable = true; settings = { # Bind address on VPN interface only server.hosts = "[${config.topology.mainVpn.currentNodeIP}]:5232"; }; }; networking.firewall.interfaces.${config.topology.mainVpn.interfaceName}.allowedTCPPorts = [ 5232 ]; }