| options/nixos/services.desktopManager.budgie.sessionPath | Additional list of packages to be added to the session search path
|
| options/nixos/services.discourse.sslCertificate | The path to the server SSL certificate
|
| options/nixos/services.sharkey.settings.mediaDirectory | Path to the folder where Sharkey stores uploaded media such as images and attachments.
|
| options/nixos/services.meilisearch.masterKeyFile | Path to file which contains the master key
|
| options/nixos/services.netbird.useRoutingFeatures | Enables settings required for NetBird's routing features: Network Resources, Network Routes & Exit Nodes
|
| options/nixos/services.suricata.settings.default-log-dir | The default logging directory
|
| options/nixos/services.routinator.settings.log-file | A string value containing the path to a file to which log messages will be appended if the log configuration value is set to file
|
| options/nixos/services.openvscode-server.extraPackages | Additional packages to add to the openvscode-server PATH.
|
| options/nixos/services.prometheus.exporters.lnd.lndTlsPath | Path to lnd TLS certificate.
|
| options/home-manager/services.protonmail-bridge.extraPackages | List of derivations to place in ProtonMail Bridge's service path.
|
| options/home-manager/programs.desktoppr.settings.picture | The path to the desktop picture/wallpaper to set
|
| options/home-manager/services.restic.backups.<name>.repositoryFile | Path to a file containing the repository location to backup to
|
| options/home-manager/xsession.windowManager.xmonad.config | The configuration file to be used for xmonad
|
| options/nixos/services.wordpress.sites.<name>.virtualHost.sslServerKey | Path to server SSL certificate key.
|
| options/nixos/services.postsrsd.settings.secrets-file | Path to the file containing the secret keys.
Secrets are passed using LoadCredential= on the systemd unit,
so this options is read-only
|
| options/nixos/services.zabbixWeb.httpd.virtualHost.documentRoot | The path of Apache's document root directory
|
| options/darwin/launchd.agents.<name>.serviceConfig.Sockets.<name>.SockPathName | This optional key implies SockFamily is set to "Unix"
|
| options/nixos/image.repart.partitions.<name>.nixStorePrefix | The prefix to use for store paths
|
| options/nixos/services.karakeep.environmentFile | An optional path to an environment file that will be used in the web and workers
services
|
| options/nixos/security.pam.yubico.challengeResponsePath | If not null, set the path used by yubico pam module where the challenge expected response is stored
|
| options/nixos/services.beszel.agent.environmentFile | File path containing environment variables for configuring the beszel-agent service in the format of an EnvironmentFile
|
| options/nixos/services.homer.settings | Settings serialized into config.yml before build
|
| options/nixos/services.thanos.store.objstore.config | Object store configuration
|
| options/nixos/services.networking.websockify.sslCert | Path to the SSL certificate.
|
| options/nixos/services.mediawiki.httpd.virtualHost.sslServerChain | Path to server SSL chain file.
|
| options/nixos/services.taskserver.pki.manual.server.crl | Fully qualified path to the server certificate revocation list.
Setting this option will prevent automatic CA creation and handling.
|
| options/nixos/services.taskserver.pki.manual.server.cert | Fully qualified path to the server certificate.
Setting this option will prevent automatic CA creation and handling.
|
| options/nixos/services.thanos.query.web.external-prefix | Static prefix for all HTML links and redirect URLs in the UI query web
interface
|
| options/nixos/services.neo4j.directories.data | Path of the data directory
|
| options/nixos/services.opensnitch.settings.Rules.Path | Path to the directory where firewall rules can be found and will
get stored by the NixOS module.
|
| options/nixos/services.mastodon.vapidPrivateKeyFile | Path to file containing the private key used for Web Push
Voluntary Application Server Identification
|
| options/nixos/services.thanos.query-frontend.tracing.config-file | Path to YAML file that contains tracing configuration
|
| options/nixos/services.plausible.server.secretKeybaseFile | Path to the secret used by the phoenix-framework
|
| options/nixos/services.xserver.xkb.extraLayouts.<name>.symbolsFile | The path to the xkb symbols file
|
| options/nixos/services.wordpress.sites.<name>.virtualHost.sslServerCert | Path to server SSL certificate.
|
| options/nixos/services.kanidm.provision.adminPasswordFile | Path to a file containing the admin password for kanidm
|
| options/nixos/environment.profileRelativeEnvVars | Attribute set of environment variable
|
| options/nixos/services.chatgpt-retrieval-plugin.bearerTokenPath | Path to the secret bearer token used for the http api authentication.
|
| options/nixos/services.sourcehut.settings."todo.sr.ht::mail".sock | Path for the lmtp daemon's unix socket
|
| options/nixos/services.librenms.nginx.sslCertificateKey | Path to server SSL certificate key.
|
| options/nixos/services.agorakit.nginx.sslCertificateKey | Path to server SSL certificate key.
|
| options/nixos/services.fediwall.nginx.sslCertificateKey | Path to server SSL certificate key.
|
| options/nixos/services.kanboard.nginx.sslCertificateKey | Path to server SSL certificate key.
|
| options/nixos/services.dependency-track.ldap.bindPasswordFile | The path to a file containing the LDAP bind password.
|
| options/nixos/services.dolibarr.nginx.sslCertificateKey | Path to server SSL certificate key.
|
| options/nixos/services.drupal.sites.<name>.virtualHost.documentRoot | The path of Apache's document root directory
|
| options/nixos/services.n8n.environment.N8N_USER_FOLDER | Provide the path where n8n will create the .n8n folder
|
| options/nixos/services.pixelfed.nginx.sslCertificateKey | Path to server SSL certificate key.
|
| options/nixos/services.mainsail.nginx.sslCertificateKey | Path to server SSL certificate key.
|
| options/nixos/services.radicle.httpd.nginx.sslCertificate | Path to server SSL certificate.
|
| options/home-manager/services.xidlehook.timers.*.canceller | Command executed when the user becomes active again
|
| options/nixos/services.vsftpd.userDbPath | Only applies if enableVirtualUsers is true
|
| options/nixos/services.mediawiki.extensions | Attribute set of paths whose content is copied to the extensions
subdirectory of the MediaWiki installation and enabled in configuration
|
| options/nixos/services.pretalx.settings.filesystem.data | Base path for all other storage paths.
|
| options/nixos/services.discourse.sslCertificateKey | The path to the server SSL certificate key
|
| options/nixos/security.acme.certs.<name>.environmentFile | Path to an EnvironmentFile for the cert's service containing any required and
optional environment variables for your selected dnsProvider
|
| options/nixos/hardware.graphics.extraPackages | Additional packages to add to the default graphics driver lookup path
|
| options/nixos/services.davis.nginx.sslTrustedCertificate | Path to root SSL certificate for stapling and client certificates.
|
| options/nixos/services.thanos.receive.tracing.config | Tracing configuration
|
| options/nixos/services.openvpn.servers.<name>.authUserPass | This option can be used to store the username / password credentials
with the "auth-user-pass" authentication method
|
| options/nixos/services.thanos.compact.tracing.config | Tracing configuration
|
| options/nixos/services.postfix-tlspol.settings.server.address | Path or address/port where postfix-tlspol binds its socket to.
|
| options/nixos/services.pufferpanel.extraPackages | Packages to add to the PATH environment variable
|
| options/nixos/services.movim.nginx.sslTrustedCertificate | Path to root SSL certificate for stapling and client certificates.
|
| options/nixos/services.thanos.sidecar.tracing.config | Tracing configuration
|
| options/nixos/services.slskd.nginx.sslTrustedCertificate | Path to root SSL certificate for stapling and client certificates.
|
| options/nixos/virtualisation.diskImage | Path to the disk image containing the root filesystem
|
| options/nixos/services.gitlab-runner.services.<name>.registrationConfigFile | Absolute path to a file with environment variables
used for gitlab-runner registration with runner registration
tokens
|
| options/nixos/services.grafana.settings.server.serve_from_sub_path | Serve Grafana from subpath specified in the root_url setting
|
| options/nixos/services.simplesamlphp.<name>.configDir | Path to the SimpleSAMLphp config directory.
|
| options/nixos/services.bitmagnet.settings.postgres.host | Address, hostname or Unix socket path of the database server
|
| options/nixos/security.tpm2.tctiEnvironment.deviceConf | Configuration part of the device TCTI, e.g. the path to the TPM device
|
| options/nixos/services.apache-kafka.configFiles.log4jProperties | Kafka log4j property configuration file path
|
| options/nixos/services.anuko-time-tracker.nginx.sslCertificate | Path to server SSL certificate.
|
| options/nixos/services.step-ca.settings | Settings that go into ca.json
|
| options/nixos/services.limesurvey.httpd.virtualHost.sslServerKey | Path to server SSL certificate key.
|
| options/nixos/services.snipe-it.nginx.sslTrustedCertificate | Path to root SSL certificate for stapling and client certificates.
|
| options/nixos/services.prometheus.exporters.mqtt.mqttTopic | Topic path to subscribe to.
|
| options/nixos/services.nginx.virtualHosts.<name>.sslCertificate | Path to server SSL certificate.
|
| options/nixos/services.sabnzbd.settings.misc.https_key | Path to the TLS key for the web UI
|
| options/nixos/services.gitlab.secrets.activeRecordSaltFile | A file containing the salt for active record encryption in the DB
|
| options/nixos/services.grafana.settings.server.cert_file | Path to the certificate file (if protocol is set to https or h2).
|
| options/nixos/services.misskey.reverseProxy.webserver.nginx.root | The path of the web root directory.
|
| options/nixos/services.radicle.httpd.nginx.sslCertificateKey | Path to server SSL certificate key.
|
| options/nixos/services.pretalx.settings.filesystem.logs | Path to the log directory, that pretalx logs message to.
|
| options/nixos/services.limesurvey.httpd.virtualHost.sslServerCert | Path to server SSL certificate.
|
| options/home-manager/programs.streamlink.plugins.<name>.src | Source of the custom plugin
|
| options/nixos/virtualisation.bootLoaderDevice | The path (inside th VM) to the device to boot from when legacy booting.
|
| options/nixos/services.xserver.windowManager.bspwm.sxhkd.configFile | Path to the sxhkd configuration file
|
| options/nixos/services.wordpress.sites.<name>.virtualHost.sslServerChain | Path to server SSL chain file.
|
| options/darwin/launchd.daemons.<name>.serviceConfig.Sockets.<name>.SockPathName | This optional key implies SockFamily is set to "Unix"
|
| options/nixos/services.matrix-synapse.settings.tls_private_key_path | PEM encoded private key for TLS
|
| options/nixos/services.gitlab-runner.services.<name>.authenticationTokenConfigFile | Absolute path to a file containing environment variables used for
gitlab-runner registrations with runner authentication tokens
|
| options/nixos/services.sourcehut.settings."pages.sr.ht".gemini-certs | An absolute file path (which should be outside the Nix-store)
to Gemini certificates.
|
| options/nixos/nixpkgs.flake.setFlakeRegistry | Whether to pin nixpkgs in the system-wide flake registry (/etc/nix/registry.json) to the
store path of the sources of nixpkgs used to build the NixOS system
|
| options/nixos/boot.binfmt.registrations.<name>.openBinary | Whether to pass the binary to the interpreter as an open
file descriptor, instead of a path.
|
| options/nixos/services.bookstack.nginx.sslCertificate | Path to server SSL certificate.
|
| options/nixos/services.unbound.localControlSocketPath | When not set to null this option defines the path
at which the unbound remote control socket should be created at
|
| options/nixos/services.openbao.settings.listener.<name>.address | The TCP address or UNIX socket path to listen on.
|
| options/nixos/services.openssh.authorizedKeysCommand | Specifies a program to be used to look up the user's public
keys
|