this is my container config for element/matrix
podman containers do not run as root so you have to get the file privileges right on the volumes mapped into the containers. i used top to find out what user the services were running as. you can see there are some settings there where you can change the user if you are having permissions problems
you only need to reboot Nix when something low level has changed. i honestly don't know where that line is drawn so i reboot quite a lot when i'm setting up a Nix server and then hardly reboot it at all from then on even with auto-updates running
oh and if i make small changes to the services i just run sudo nixos-rebuild switch and don't reboot
it was all over italy according to the video but it is fishy
not sure how this aspiration for Circular Economy can only be satisfied by this new system. the usual dodgy comparisons to regular currencies were slipped in the video too. blockchainy things are notoriously easy to trace so not sure if it could be used for money laundering.
seems more like a trade group than a significant fintech endeavour but it's been going for almost 15 years so they've kept under the authorities radar so far
i guess you were able to install the os ok? are you using proxmox or regular servers?
i can post an example configuration.nix for the proxy and container servers that might help. i have to admit debugging issues with configurations can be very tricky.
in terms of security i was always worried about getting hacked. the only protection for that was to make regular backups of data and config so i can restore services, and to create a dmz behind my isp router with a vlan switch and a small router just for my services to protect the rest of my home network
i have found this reference very useful https://mynixos.com/options/