| options/nixos/services.thanos.store.objstore.config | Object store configuration
|
| options/nixos/services.mysql.galeraCluster.package | The MariaDB Galera package that provides the shared library 'libgalera_smm.so' required for cluster functionality.
|
| options/nixos/services.pgbackrest.commands.info | Options for the 'info' command
|
| options/nixos/services.pihole-ftl.piholePackage | The pihole package to use.
|
| options/nixos/services.postfix.submissionsOptions | Options for the submission config via smtps in master.cf.
smtpd_tls_security_level will be set to encrypt, if it is missing
or has one of the values "may" or "none".
smtpd_tls_wrappermode with value "yes" will be added automatically.
|
| options/nixos/services.prometheus.exporters.varnish.enable | Whether to enable the prometheus varnish exporter.
|
| options/nixos/services.mautrix-meta.instances.<name>.registrationServiceUnit | The registration service that generates the registration file
|
| options/nixos/services.picom.fade | Fade windows in and out.
|
| options/nixos/services.tor.settings.HSLayer3Nodes | See torrc manual.
|
| options/nixos/services.prometheus.scrapeConfigs.*.consul_sd_configs.*.authorization.type | Sets the authentication type
|
| options/nixos/services.radicle.httpd.nginx.forceSSL | Whether to add a separate nginx server block that redirects (defaults
to 301, configurable with redirectCode) all plain HTTP traffic to
HTTPS
|
| options/nixos/services.mainsail.nginx.sslCertificate | Path to server SSL certificate.
|
| options/nixos/services.misskey.reverseProxy.webserver.caddy.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| options/nixos/services.moosefs.master.openFirewall | Whether to automatically open required firewall ports for master service.
|
| options/nixos/services.nextcloud.settings.mail_send_plaintext_only | Email will be sent by default with an HTML and a plain text body
|
| options/nixos/services.opencloud.idpWebPackage | The idp-web package to use.
|
| options/nixos/services.prometheus.exporters.ipmi.firewallFilter | Specify a filter for iptables to use when
services.prometheus.exporters.ipmi.openFirewall
is true
|
| options/nixos/services.prometheus.remoteWrite.*.write_relabel_configs.*.target_label | Label to which the resulting value is written in a replace action
|
| options/nixos/services.prometheus.scrapeConfigs.*.http_sd_configs.*.tls_config.cert_file | Certificate file for client cert authentication to the server.
|
| options/nixos/services.meshtasticd.port | Port to listen on
|
| options/nixos/services.pykms.openFirewallPort | Whether the listening port should be opened automatically.
|
| options/nixos/services.ttyd.interface | Network interface to bind.
|
| options/nixos/services.nagios.virtualHost.listen.*.ssl | Whether to enable SSL (https) support.
|
| options/nixos/services.nginx.virtualHosts.<name>.sslCertificateKey | Path to server SSL certificate key.
|
| options/nixos/services.prometheus.exporters.artifactory.firewallFilter | Specify a filter for iptables to use when
services.prometheus.exporters.artifactory.openFirewall
is true
|
| options/nixos/services.prometheus.package | The prometheus package to use.
|
| options/nixos/services.trilium-server.port | The port number to bind to.
|
| options/nixos/services.twingate.enable | Whether to enable Twingate Client daemon.
|
| options/nixos/services.liquidsoap.streams | Set of Liquidsoap streams to start,
one systemd service per stream.
|
| options/nixos/services.monero.environmentFile | Path to an EnvironmentFile for the monero service as defined in systemd.exec(5)
|
| options/nixos/services.mongodb.replSetName | If this instance is part of a replica set, set its name here
|
| options/nixos/services.openvscode-server.withoutConnectionToken | Run without a connection token
|
| options/nixos/services.movim.podConfig.timezone | The server timezone
|
| options/nixos/services.prometheus.exporters.mysqld.openFirewall | Open port in firewall for incoming connections.
|
| options/nixos/services.prosody.modules.bosh | Enable BOSH clients, aka 'Jabber over HTTP'
|
| options/nixos/services.slskd.nginx.listen.*.port | Port number to listen on
|
| options/nixos/services.postgrest.jwtSecretFile | The secret or JSON Web Key (JWK) (or set) used to decode JWT tokens clients provide for authentication
|
| options/nixos/services.pretix.settings.pretix.registration | Whether to allow registration of new admin users.
|
| options/nixos/services.qui.openFirewall | Whether or not to open ports in the firewall for qui.
|
| options/nixos/services.tomcat.virtualHosts.*.name | name of the virtualhost
|
| options/nixos/services.prometheus.scrapeConfigs.*.dockerswarm_sd_configs.*.oauth2.client_secret | OAuth client secret.
|
| options/nixos/services.serviio.dataDir | The directory where serviio stores its state, data, etc.
|
| options/nixos/services.strongswan-swanctl.swanctl.secrets.ecdsa.<name>.file | File name in the ecdsa folder for which this
passphrase should be used.
|
| options/nixos/services.suwayomi-server.settings.server.extensionRepos | URL of repositories from which the extensions can be installed.
|
| options/nixos/services.prefect.databaseHost | database host for postgres only
|
| options/nixos/services.pufferpanel.enable | Whether to enable PufferPanel game management server
|
| options/nixos/services.realmd.enable | Whether to enable realmd service for managing system enrollment in Active Directory domains.
|
| options/nixos/services.rsyslogd.extraConfig | Additional text appended to syslog.conf,
i.e. the contents of defaultConfig.
|
| options/nixos/services.tor.settings.ServerTransportPlugin | See torrc manual.
|
| options/nixos/services.mediawiki.httpd.virtualHost.sslServerCert | Path to server SSL certificate.
|
| options/nixos/services.prometheus.remoteRead.*.tls_config | Configures the remote read request's TLS settings.
|
| options/nixos/services.trafficserver.plugins | Controls run-time loadable plugins available to Traffic Server, as
well as their configuration
|
| options/nixos/services.trilium-server.dataDir | The directory storing the notes database and the configuration.
|
| options/nixos/services.oncall.settings | Extra configuration options to append or override
|
| options/nixos/services.openssh.moduliFile | Path to moduli file to install in
/etc/ssh/moduli
|
| options/nixos/services.prometheus.exporters.shelly.port | Port to listen on.
|
| options/nixos/services.prometheus.exporters.kea.user | User name under which the kea exporter shall be run.
|
| options/nixos/services.tor.settings.KeyDirectory | See torrc manual.
|
| options/nixos/services.prometheus.exporters.unbound.openFirewall | Open port in firewall for incoming connections.
|
| options/nixos/services.pretalx.gunicorn.extraArgs | Extra arguments to pass to gunicorn
|
| options/nixos/services.spice-autorandr.enable | Whether to enable spice-autorandr service that will automatically resize display to match SPICE client window size.
|
| options/nixos/services.systembus-notify.enable | Whether to enable System bus notification support
WARNING: enabling this option (while convenient) should not be done on a
machine where you do not trust the other users as it allows any other
local user to DoS your session by spamming notifications
.
|
| options/nixos/services.szurubooru.database.host | Host on which the PostgreSQL database runs.
|
| options/nixos/services.shorewall6.enable | Whether to enable Shorewall IPv6 Firewall.
Enabling this service WILL disable the existing NixOS
firewall! Default firewall rules provided by packages are not
considered at the moment.
|
| options/nixos/services.pantheon.parental-controls.enable | Whether to enable Pantheon parental controls daemon.
|
| options/nixos/services.monica.nginx.listen.*.port | Port number to listen on
|
| options/nixos/services.prometheus.exporters.nextcloud.passwordFile | File containing the password for connecting to Nextcloud
|
| options/nixos/services.prometheus.exporters.py-air-control.extraFlags | Extra commandline options to pass to the py-air-control exporter.
|
| options/nixos/services.mqtt2influxdb.influxdb.port | InfluxDB server port
|
| options/nixos/services.prometheus.scrapeConfigs.*.docker_sd_configs.*.authorization.type | Sets the authentication type
|
| options/nixos/services.moodle.virtualHost | Apache configuration can be done by adapting services.httpd.virtualHosts
|
| options/nixos/services.transmission.extraFlags | Extra flags passed to the transmission command in the service definition.
|
| options/nixos/services.strongswan-swanctl.swanctl.connections.<name>.children | CHILD_SA configuration sub-section
|
| options/nixos/services.nsd.bind8Stats | Whether to enable BIND8 like statistics.
|
| options/nixos/services.mosquitto.bridges.<name>.addresses | Remote endpoints for the bridge.
|
| options/nixos/services.syncoid.commands.<name>.sendOptions | Advanced options to pass to zfs send
|
| options/nixos/services.prometheus.exporters.varnish.noExit | Do not exit server on Varnish scrape errors.
|
| options/nixos/services.syncthing.settings | Extra configuration options for Syncthing
|
| options/nixos/services.netbird.tunnels.<name>.openInternalFirewall | Opens up internal firewall ports for the NetBird's network interface.
|
| options/nixos/services.suricata.settings.run-as.user | Run Suricata with a specific user-id.
|
| options/nixos/services.monica.nginx.sslCertificate | Path to server SSL certificate.
|
| options/nixos/services.tt-rss.email.password | SMTP authentication password used when sending outgoing mail.
|
| options/nixos/services.trafficserver.cache | Caching rules that overrule the origin's caching policy
|
| options/nixos/services.tor.settings.HidServAuth | See torrc manual.
|
| options/nixos/services.mainsail.nginx.listen.*.ssl | Enable SSL.
|
| options/nixos/services.neo4j.https.sslPolicy | Neo4j SSL policy for HTTPS traffic
|
| options/nixos/services.opensearch.user | The user OpenSearch runs as
|
| options/nixos/services.taskchampion-sync-server.dataDir | Directory in which to store data
|
| options/nixos/services.octoprint.stateDir | State directory of the daemon.
|
| options/nixos/services.prometheus.scrapeConfigs.*.kubernetes_sd_configs.*.oauth2.client_secret_file | Read the client secret from a file
|
| options/nixos/services.multipath.devices.*.delay_watch_checks | This option is deprecated, and mapped to san_path_err_forget_rate
|
| options/nixos/services.oauth2-proxy.customTemplatesDir | Path to custom HTML templates.
|
| options/nixos/services.prometheus.exporters.mqtt.extraFlags | Extra commandline options to pass to the mqtt exporter.
|
| options/nixos/services.prometheus.scrapeConfigs.*.lightsail_sd_configs.*.role_arn | AWS Role ARN, an alternative to using AWS API keys.
|
| options/nixos/services.slskd.settings.retention.files.incomplete | Lifespan of incomplete downloading files in minutes.
|
| options/nixos/services.slskd.nginx.acmeFallbackHost | Host which to proxy requests to if ACME challenge is not found
|
| options/nixos/services.strongswan-swanctl.swanctl.connections.<name>.local.<name>.pubkeys | List of raw public key candidates to use for
authentication
|
| options/nixos/services.mihomo.package | The mihomo package to use.
|
| options/nixos/services.sonarr.settings.update.automatically | Automatically download and install updates.
|
| options/nixos/services.statsd.graphitePort | Port of Graphite server (i.e. carbon-cache).
|