| options/nixos/services.tor.settings.CacheDirectory | See torrc manual.
|
| options/nixos/services.mediawiki.httpd.virtualHost.robotsEntries | Specification of pages to be ignored by web crawlers
|
| options/nixos/services.mediawiki.httpd.virtualHost.enableACME | Whether to ask Let's Encrypt to sign a certificate for this vhost
|
| options/nixos/services.openvscode-server.serverDataDir | Specifies the directory that server data is kept in.
|
| options/nixos/services.mattermost.socket.enable | Whether to enable Mattermost control socket.
|
| options/nixos/services.ncps.cache.lock.lruTTL | TTL for LRU lock (global exclusive lock).
|
| options/nixos/services.lk-jwt-service.keyFile | Path to a file containing the credential mapping (<keyname>: <secret>) to access LiveKit
|
| options/nixos/services.ncps.cache.upstream.publicKeys | A list of public keys of upstream caches in the format
host[-[0-9]*]:public-key
|
| options/nixos/services.mediawiki.httpd.virtualHost.enableUserDir | Whether to enable serving ~/public_html as
/~«username».
|
| options/nixos/services.resilio.downloadLimit | Download speed limit. 0 is unlimited (default).
|
| options/nixos/services.rebuilderd.package | The rebuilderd package to use.
|
| options/nixos/services.prometheus.exporters.zfs.listenAddress | Address to listen on.
|
| options/nixos/services.squid.proxyPort | TCP port on which squid will listen.
|
| options/nixos/services.reposilite.settings.idleTimeout | Default idle timeout used by Jetty.
|
| options/nixos/services.owncast.listen | The IP address to bind the owncast web server to.
|
| options/nixos/services.prometheus.exporters.exportarr-sonarr.enable | Whether to enable the prometheus exportarr-sonarr exporter.
|
| options/nixos/services.speechd.config | System wide configuration file for Speech Dispatcher
|
| options/nixos/services.pixelfed.nginx.http3 | Whether to enable the HTTP/3 protocol
|
| options/nixos/services.portunus.port | Port where the Portunus webserver should listen on
|
| options/nixos/services.oncall.secretFile | A YAML file containing secrets such as database or user passwords
|
| options/nixos/services.radicle.ci.adapters.native.instances.<name>.name | Adapter name that is used in the radicle-ci-broker configuration
|
| options/nixos/services.prometheus.globalConfig.scrape_timeout | How long until a scrape request times out
|
| options/nixos/services.slskd.settings.soulseek.description | The user description for the Soulseek network.
|
| options/nixos/services.prometheus.remoteWrite.*.sigv4.region | The AWS region.
|
| options/nixos/services.monica.nginx.locations.<name>.tryFiles | Adds try_files directive.
|
| options/nixos/services.radarr.enable | Whether to enable Radarr, a UsetNet/BitTorrent movie downloader.
|
| options/nixos/services.pdns-recursor.resolveNamecoin | Resolve .bit top-level domains using ncdns and namecoin.
|
| options/nixos/services.linkwarden.database.user | The database user for Linkwarden.
|
| options/nixos/services.strongswan-swanctl.swanctl.secrets.pkcs8.<name>.secret | Value of decryption passphrase for PKCS#8 key.
|
| options/nixos/services.suricata.settings.stats.interval | The interval field (in seconds) controls the interval at
which stats are updated in the log.
|
| options/nixos/services.prometheus.scrapeConfigs.*.ec2_sd_configs.*.refresh_interval | Refresh interval to re-read the instance list
|
| options/nixos/services.prometheus.pushgateway.package | The prometheus-pushgateway package to use.
|
| options/nixos/services.prometheus.exporters.mail.firewallFilter | Specify a filter for iptables to use when
services.prometheus.exporters.mail.openFirewall
is true
|
| options/nixos/services.skydns.etcd.tlsPem | Skydns path of TLS client certificate - public key.
|
| options/nixos/services.suricata.settings.classification-file | Suricata classification configuration file.
|
| options/nixos/services.nzbget.group | Group under which NZBGet runs
|
| options/nixos/services.munin-node.extraPluginConfig | plugin-conf.d extra plugin configuration
|
| options/nixos/services.prometheus.exporters.fastly.firewallFilter | Specify a filter for iptables to use when
services.prometheus.exporters.fastly.openFirewall
is true
|
| options/nixos/services.postgrey.enable | Whether to run the Postgrey daemon
|
| options/nixos/services.teamspeak3.queryPort | TCP port opened for ServerQuery connections using the raw telnet protocol.
|
| options/nixos/services.snapserver.settings.http.port | Port to listen on for snapclient connections.
|
| options/nixos/services.onlyoffice.postgresPasswordFile | Path to a file that contains the password OnlyOffice should use to connect to Postgresql
|
| options/nixos/services.snipe-it.nginx.listen | Listen addresses and ports for this virtual host
|
| options/nixos/services.nagios.virtualHost.locations.<name>.proxyPass | Sets up a simple reverse proxy as described by https://httpd.apache.org/docs/2.4/howto/reverse_proxy.html#simple.
|
| options/nixos/services.pfix-srsd.configurePostfix | Whether to configure the required settings to use pfix-srsd in the local Postfix instance.
|
| options/nixos/services.prometheus.scrapeConfigs.*.dockerswarm_sd_configs.*.tls_config.insecure_skip_verify | Disable validation of the server certificate.
|
| options/nixos/services.ndppd.proxies.<name>.rules | This is a rule that the target address is to match against
|
| options/nixos/services.prometheus.scrapeConfigs.*.consul_sd_configs.*.oauth2.scopes | Scopes for the token request.
|
| options/nixos/services.timesyncd.extraConfig | Extra config options for systemd-timesyncd
|
| options/nixos/services.step-ca.package | The step-ca package to use.
|
| options/nixos/services.prometheus.exporters.nvidia-gpu.firewallRules | Specify rules for nftables to add to the input chain
when services.prometheus.exporters.nvidia-gpu.openFirewall is true.
|
| options/nixos/services.stunnel.user | The user under which stunnel runs.
|
| options/nixos/services.taler.settings | Global configuration options for the taler config file
|
| options/nixos/services.omnom.user | The Omnom service user.
|
| options/nixos/services.sympa.listMasters | The list of the email addresses of the listmasters
(users authorized to perform global server commands).
|
| options/nixos/services.snipe-it.mail.port | Mail host port.
|
| options/nixos/services.pgadmin.emailServer.useSSL | Whether to enable SSL for connecting to the SMTP server.
|
| options/nixos/services.strongswan-swanctl.swanctl.connections.<name>.remote.<name>.cacert.<name>.handle | Hex-encoded CKA_ID or handle of the certificate on a token or TPM,
respectively
|
| options/nixos/services.strongswan-swanctl.swanctl.connections.<name>.children.<name>.priority | Optional fixed priority for IPsec policies
|
| options/nixos/services.syncthing.relay.extraOptions | Extra command line arguments to pass to strelaysrv.
|
| options/nixos/services.rspamd.workers.<name>.includes | List of files to include in configuration
|
| options/nixos/services.u9fs.listenStreams | Sockets to listen for clients on
|
| options/nixos/services.limesurvey.httpd.virtualHost.servedFiles | This option provides a simple way to serve individual, static files.
This option has been deprecated and will be removed in a future
version of NixOS
|
| options/nixos/services.prometheus.exporters.opnsense.opnsenseServerProtocol | Opnsense metrics scraper protocol to use
|
| options/nixos/services.pretix.settings.celery.backend | URI to the celery backend used for the asynchronous job queue.
|
| options/nixos/services.prometheus.exporters.idrac.port | Port to listen on.
|
| options/nixos/services.misskey.reverseProxy.webserver.nginx.onlySSL | Whether to enable HTTPS and reject plain HTTP connections
|
| options/nixos/services.nvme-rs.settings.email | Email notification configuration
|
| options/nixos/services.osrm.algorithm | Algorithm to use for the data
|
| options/nixos/services.tor.torsocks.enable | Whether to build /etc/tor/torsocks.conf
containing the specified global torsocks configuration.
|
| options/nixos/services.portunus.group | Group account under which Portunus runs its webserver.
|
| options/nixos/services.prometheus.exporters.scaphandre.port | Port to listen on.
|
| options/nixos/services.pangolin.dnsProvider | The DNS provider Traefik will request wildcard certificates from
|
| options/nixos/services.prometheus.alertmanagerGotify.gotifyEndpoint.host | The hostname or ip your gotify endpoint is running.
|
| options/nixos/services.prometheus.exporters.fritzbox.firewallFilter | Specify a filter for iptables to use when
services.prometheus.exporters.fritzbox.openFirewall
is true
|
| options/nixos/services.skydns.domain | Skydns default domain if not specified by etcd config.
|
| options/nixos/services.nix-store-gcs-proxy.<name>.bucketName | Name of Google storage bucket
|
| options/nixos/services.strongswan-swanctl.swanctl.connections.<name>.remote.<name>.cert.<name>.module | Optional PKCS#11 module name.
|
| options/nixos/services.tor.settings.ClientAutoIPv6ORPort | See torrc manual.
|
| options/nixos/services.prometheus.exporters.unpoller.loki.user | Username for Loki.
|
| options/nixos/services.openvscode-server.group | The group to run openvscode-server under
|
| options/nixos/services.prometheus.exporters.dmarc.enable | Whether to enable the prometheus dmarc exporter.
|
| options/nixos/services.moosefs.metalogger.enable | Whether to enable MooseFS metalogger daemon that maintains a backup copy of the master's metadata.
|
| options/nixos/services.taler.settings.taler.CURRENCY_ROUND_UNIT | Smallest amount in this currency that can be transferred using the underlying RTGS
|
| options/nixos/services.minio.rootCredentialsFile | File containing the MINIO_ROOT_USER, default is "minioadmin", and
MINIO_ROOT_PASSWORD (length >= 8), default is "minioadmin"; in the format of
an EnvironmentFile=, as described by systemd.exec(5).
|
| options/nixos/services.munge.password | The path to a daemon's secret key.
|
| options/nixos/services.suricata.settings.outputs.*.<name>.enabled | Whether to enable .
|
| options/nixos/services.murmur.sslCert | Path to your SSL certificate.
|
| options/nixos/services.monero.mining.enable | Whether to mine monero.
|
| options/nixos/services.nexus.listenPort | Port to listen on.
|
| options/nixos/services.pixelfed.nginx.redirectCode | HTTP status used by globalRedirect and forceSSL
|
| options/nixos/services.nginx.virtualHosts.<name>.locations.<name>.proxyWebsockets | Whether to support proxying websocket connections with HTTP/1.1.
|
| options/nixos/services.microsocks.group | Group microsocks runs as.
|
| options/nixos/services.salt.master.enable | Whether to enable Salt configuration management system master service.
|
| options/nixos/services.prometheus.exporters.mailman3.mailman.addr | Mailman3 Core REST API address.
|
| options/nixos/services.stunnel.clients | Define the client configurations
|
| options/nixos/services.tailscale.derper.domain | Domain name under which the derper server is reachable.
|
| options/nixos/services.misskey.settings.id | The ID generation method to use
|
| options/nixos/services.offlineimap.package | The offlineimap package to use.
|
| options/nixos/services.postgres-websockets.pgpassFile | The password to authenticate to PostgreSQL with
|