shared
The shared host uses security-headers. knixl writes one file for it. The Nix below is the golden test output, so it is exactly what knixl emits.
// Demonstrates let-hoisting: the same security-headers block is applied to two// virtual hosts, so the generated file binds it once as _knixl0 and references it// at both vhosts.
host "shared" { system "x86_64-linux" nixpkgs release="25.05"
security-headers { vhost "a.example.com" vhost "b.example.com" }}Generated
Section titled “Generated”# Generated by knixl 1.5.2 from hosts/shared.kdl# Do NOT edit. Regenerate from the KDL source.# Overrides: add a sibling module and use lib.mkForce / lib.mkAfter.{ config, lib, pkgs, ...}:let _knixl0 = '' add_header X-Frame-Options "SAMEORIGIN" always; add_header X-Content-Type-Options "nosniff" always; add_header Referrer-Policy "strict-origin-when-cross-origin" always; '';in{ nixpkgs.hostPlatform = "x86_64-linux"; networking.hostName = "shared"; services.nginx.virtualHosts."a.example.com".extraConfig = _knixl0; services.nginx.virtualHosts."b.example.com".extraConfig = _knixl0;}