# Bootstrap this virtual host only after thought.stream resolves to this nginx # host. It exists only so Certbot can prove domain control. It deliberately does # not expose the password proxy over plaintext HTTP. server { listen 80; listen [::]:80; server_name thought.stream www.thought.stream; location / { return 404; } }