Good news. Now they should add ACME support directly to nginx so it can get and manage TLS certificates seamlessly for you.
services.nginx = {
enable = true;
virtualHosts."example.com" = {
root = "/webroot";
enableACME = true;
};
};
http://nixos.org/nixos/options.html#services.nginx