| options/nixos/services.monica.nginx.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| options/nixos/services.matter-server.package | The python-matter-server package to use.
|
| options/nixos/services.nginx.virtualHosts.<name>.redirectCode | HTTP status used by globalRedirect and forceSSL
|
| options/nixos/services.strongswan-swanctl.swanctl.authorities.<name>.ocsp_uris | List of OCSP URIs
|
| options/nixos/services.moonraker.enable | Whether to enable Moonraker, an API web server for Klipper.
|
| options/nixos/services.prometheus.exporters.ecoflow.firewallFilter | Specify a filter for iptables to use when
services.prometheus.exporters.ecoflow.openFirewall
is true
|
| options/nixos/services.paisa.host | Host bind IP address.
|
| options/nixos/services.strongswan-swanctl.swanctl.connections.<name>.dscp | Differentiated Services Field Codepoint to set on outgoing IKE packets for
this connection
|
| options/nixos/services.prometheus.exporters.mqtt.prometheusPrefix | Prefix added to the metric name.
|
| options/nixos/services.prometheus.scrapeConfigs.*.openstack_sd_configs.*.refresh_interval | Refresh interval to re-read the instance list
|
| options/nixos/services.prometheus.exporters.exportarr-sonarr.extraFlags | Extra commandline options to pass to the exportarr-sonarr exporter.
|
| options/nixos/services.prometheus.scrapeConfigs.*.gce_sd_configs.*.filter | Filter can be used optionally to filter the instance list by other
criteria Syntax of this filter string is described here in the filter
query parameter section: https://cloud.google.com/compute/docs/reference/latest/instances/list.
|
| options/nixos/services.schleuder.listDefaults | Default settings for lists (list-defaults.yml)
|
| options/nixos/services.multipath.devices.*.user_friendly_names | If set to "yes", using the bindings file /etc/multipath/bindings
to assign a persistent and unique alias to the multipath, in the
form of mpath
|
| options/nixos/services.oauth2-proxy.cookie.httpOnly | Set HttpOnly cookie flag.
|
| options/nixos/services.subsonic.defaultMusicFolder | Configure Subsonic to use this folder for music
|
| options/nixos/services.prometheus.exporters.pihole.listenAddress | Address to listen on.
|
| options/nixos/services.netbird.server.management.dnsDomain | Domain used for peer resolution.
|
| options/nixos/services.prometheus.scrapeConfigs.*.uyuni_sd_configs.*.tls_config.ca_file | CA certificate to validate API server certificate with.
|
| options/nixos/services.prometheus.exporters.blackbox.enableConfigCheck | Whether to run a correctness check for the configuration file
|
| options/nixos/services.nginx.statusPage | Enable status page reachable from localhost on http://127.0.0.1/nginx_status.
|
| options/nixos/services.pixelfed.nginx.listen.*.addr | Listen address.
|
| options/nixos/services.tor.settings.ReducedExitPolicy | See torrc manual.
|
| options/nixos/services.mtr-exporter.jobs.*.name | Name of ICMP pinging job.
|
| options/nixos/services.openafsClient.cellServDB | This cell's database server records, added to the global
CellServDB
|
| options/nixos/services.prometheus.exporters.script.settings | Free-form configuration for script_exporter, expressed as a Nix attrset and rendered to YAML.
Migration note:
The previous format using script = "sleep 5" is no longer supported
|
| options/nixos/services.limesurvey.httpd.virtualHost.adminAddr | E-mail address of the server administrator.
|
| options/nixos/services.nebula.networks | Nebula network definitions.
|
| options/nixos/services.minecraft-server.serverProperties | Minecraft server properties for the server.properties file
|
| options/nixos/services.snipe-it.nginx.addSSL | Whether to enable HTTPS in addition to plain HTTP
|
| options/nixos/services.prometheus.scrapeConfigs.*.static_configs.*.targets | The targets specified by the target group.
|
| options/nixos/services.taskchampion-sync-server.host | Host address on which to serve
|
| options/nixos/services.prometheus.exporters.wireguard.enable | Whether to enable the prometheus wireguard exporter.
|
| options/nixos/services.mediawiki.httpd.virtualHost.listenAddresses | Listen addresses for this virtual host
|
| options/nixos/services.terraria.noUPnP | Disables automatic Universal Plug and Play.
|
| options/nixos/services.ombi.enable | Whether to enable Ombi, a web application that automatically gives your shared Plex or
Emby users the ability to request content by themselves!
Optionally see https://docs.ombi.app/info/reverse-proxy
on how to set up a reverse proxy
.
|
| options/nixos/services.prometheus.scrapeConfigs.*.consul_sd_configs.*.proxy_url | Optional proxy URL.
|
| options/nixos/services.pinchflat.logLevel | Log level for Pinchflat.
|
| options/nixos/services.prometheus.remoteWrite.*.metadata_config.send_interval | How frequently metric metadata is sent to remote storage.
|
| options/nixos/services.snapraid.scrub.olderThan | Number of days since data was last scrubbed before it can be scrubbed again.
|
| options/nixos/services.stunnel.enable | Whether to enable the stunnel TLS tunneling service.
|
| options/nixos/services.nextcloud.notify_push.dbtableprefix | Table prefix in Nextcloud's database.
Note: since Nextcloud 20 it's not an option anymore to create a database
schema with a custom table prefix
|
| options/nixos/services.openafsClient.inumcalc | Inode calculation method. compat is
computationally less expensive, but md5 greatly
reduces the likelihood of inode collisions in larger scenarios
involving multiple cells mounted into one AFS space.
|
| options/nixos/services.maubot.settings.homeservers.<name>.url | Client-server API URL
|
| options/nixos/services.tor.settings.ServerDNSAllowBrokenConfig | See torrc manual.
|
| options/nixos/services.movim.nginx.listen.*.port | Port number to listen on
|
| options/nixos/services.opensnitch.settings.Rules.Path | Path to the directory where firewall rules can be found and will
get stored by the NixOS module.
|
| options/nixos/services.opensearch.extraCmdLineOptions | Extra command line options for the OpenSearch launcher.
|
| options/nixos/services.prometheus.exporters.restic.port | Port to listen on.
|
| options/nixos/services.privatebin.group | Group under which privatebin runs
|
| options/nixos/services.toxvpn.enable | Whether to enable toxvpn running on startup.
|
| options/nixos/services.nsd.ratelimit.ratelimit | Max qps allowed from any query source.
0 means unlimited
|
| options/nixos/services.neo4j.directories.certificates | Directory for storing certificates to be used by Neo4j for
TLS connections
|
| options/nixos/services.prometheus.exporters.mqtt.group | Group under which the mqtt exporter shall be run.
|
| options/nixos/services.prometheus.scrapeConfigs.*.scaleway_sd_configs.*.tls_config.server_name | ServerName extension to indicate the name of the server.
http://tools.ietf.org/html/rfc4366#section-3.1
|
| options/nixos/services.shiori.package | The shiori package to use.
|
| options/nixos/services.prosody.modules.server_contact_info | Publish contact information for this service
|
| options/nixos/services.prometheus.exporters.nginx.firewallFilter | Specify a filter for iptables to use when
services.prometheus.exporters.nginx.openFirewall
is true
|
| options/nixos/services.prometheus.scrapeConfigs.*.eureka_sd_configs.*.proxy_url | Optional proxy URL.
|
| options/nixos/services.prowlarr.settings.update.mechanism | which update mechanism to use
|
| options/nixos/services.opengfw.settings.ruleset.geoip | Path to geoip.dat.
|
| options/nixos/services.pixelfed.settings | .env settings for Pixelfed
|
| options/nixos/services.salt.minion.configuration | Salt minion configuration as Nix attribute set
|
| options/nixos/services.resolved.enable | Whether to enable the Systemd DNS resolver daemon (systemd-resolved).
|
| options/nixos/services.oink.domains | List of attribute sets containing configuration for each domain
|
| options/nixos/services.slskd.settings.shares.filters | Regular expressions of files to exclude from sharing.
|
| options/nixos/services.prometheus.exporters.ecoflow.listenAddress | Address to listen on.
|
| options/nixos/services.prometheus.scrapeConfigs.*.openstack_sd_configs.*.project_name | The project_id and project_name fields are optional for the Identity V2 API
|
| options/nixos/services.prometheus.scrapeConfigs.*.linode_sd_configs.*.tls_config | TLS configuration.
|
| options/nixos/services.prometheus.exporters.zfs.firewallFilter | Specify a filter for iptables to use when
services.prometheus.exporters.zfs.openFirewall
is true
|
| options/nixos/services.terraria.secure | Adds additional cheat protection to the server.
|
| options/nixos/services.ntopng.extraConfig | Configuration lines that will be appended to the generated ntopng
configuration file
|
| options/nixos/services.matrix-tuwunel.settings.global.unix_socket_path | Listen on a UNIX socket at the specified path
|
| options/nixos/services.redsocks.redsocks.*.ip | IP on which redsocks should listen
|
| options/nixos/services.prometheus.exporters.mikrotik.user | User name under which the mikrotik exporter shall be run.
|
| options/nixos/services.suricata.settings.vars.address-groups.DNS_SERVERS | DNS_SERVERS variable.
|
| options/nixos/services.nitter.preferences.squareAvatars | Square profile pictures.
|
| options/nixos/services.prosody.authentication | Authentication mechanism used for logins.
|
| options/nixos/services.nostr-rs-relay.enable | Whether to enable nostr-rs-relay.
|
| options/nixos/services.ncps.cache.databaseURL | The URL of the database (currently only SQLite is supported)
|
| options/nixos/services.strongswan-swanctl.swanctl.connections.<name>.mediated_by | The name of the connection to mediate this connection through
|
| options/nixos/services.strongswan-swanctl.swanctl.authorities | Section defining complementary attributes of certification authorities, each
in its own subsection with an arbitrary yet unique name
|
| options/nixos/services.mediawiki.httpd.virtualHost.adminAddr | E-mail address of the server administrator.
|
| options/nixos/services.mycelium.enable | Whether to enable mycelium network.
|
| options/nixos/services.system76-scheduler.settings.cfsProfiles.default.nr-latency | sched_nr_latency.
|
| options/nixos/services.tlsrpt.package | The tlsrpt-reporter package to use.
|
| options/nixos/services.lokinet.settings.dns.upstream | Upstream resolver(s) to use as fallback for non-loki addresses
|
| options/nixos/services.tor.relay.onionServices.<name>.settings.HiddenServiceAllowUnknownPorts | See torrc manual.
|
| options/nixos/services.netdata.python.recommendedPythonPackages | Whether to enable a set of recommended Python plugins
by installing extra Python packages.
|
| options/nixos/services.readeck.enable | Whether to enable Readeck.
|
| options/nixos/services.snapserver.settings.http.doc_root | Path to serve from the HTTP servers root.
|
| options/nixos/services.prometheus.exporters.keylight.firewallRules | Specify rules for nftables to add to the input chain
when services.prometheus.exporters.keylight.openFirewall is true.
|
| options/nixos/services.photoprism.settings | See the getting-started guide for available options.
|
| options/nixos/services.suwayomi-server.enable | Whether to enable Suwayomi, a free and open source manga reader server that runs extensions built for Tachiyomi.
|
| options/nixos/services.spiped.config.<name>.timeout | Timeout, in seconds, after which an attempt to connect to
the target or a protocol handshake will be aborted (and the
connection dropped) if not completed
|
| options/nixos/services.netbird.tunnels.<name>.openFirewall | Opens up firewall port for communication between NetBird peers directly over LAN or public IP,
without using (internet-hosted) TURN servers as intermediaries.
|
| options/nixos/services.trickster.origin-url | URL to the Origin
|
| options/nixos/services.sshwifty.sharedKeyFile | Path to a file containing the shared key.
|
| options/nixos/services.tayga.ipv4.router.address | The IPv4 address of the router.
|
| options/nixos/services.prometheus.exporters.rtl_433.group | Group under which the rtl_433 exporter shall be run.
|