| options/nixos/security.wrappers | This option effectively allows adding setuid/setgid bits, capabilities,
changing file ownership and permissions of a program without directly
modifying it
|
| options/nixos/services.qbittorrent.serverConfig | Free-form settings mapped to the qBittorrent.conf file in the profile
|
| options/home-manager/programs.thunderbird.profiles.<name>.search.order | The order the search engines are listed in
|
| options/nixos/security.loginDefs.settings.UMASK | The file mode creation mask is initialized to this value.
|
| options/nixos/services.gitea.database.socket | Path to the unix socket file to use for authentication.
|
| options/nixos/services.ttyd.passwordFile | File containing the password to use for basic http authentication
|
| options/nixos/services.longview.apiKeyFile | A file containing the Longview API key
|
| options/nixos/system.nssDatabases.shadow | List of shadow entries to configure in /etc/nsswitch.conf
|
| options/nixos/services.forgejo.database.path | Path to the sqlite3 database file.
|
| options/nixos/services.vikunja.database.path | Path to the sqlite3 database file.
|
| options/home-manager/programs.thunderbird.profiles.<name>.userContent | Custom Thunderbird user content CSS.
|
| options/home-manager/services.kanshi.settings.*.profile.outputs.*.adaptiveSync | Enables or disables adaptive synchronization
(aka
|
| options/nixos/services.openafsServer.roles.fileserver.salvagerArgs | Arguments to the dasalvager process
|
| options/nixos/services.terraria.worldPath | The path to the world file (.wld) which should be loaded
|
| options/nixos/services.phpfpm.pools.<name>.socket | Path to the unix socket file on which to accept FastCGI requests.
This option is read-only and managed by NixOS.
|
| options/home-manager/programs.pandoc.defaults | Options to set by default
|
| options/home-manager/programs.fuzzel.settings | Configuration for fuzzel written to
$XDG_CONFIG_HOME/fuzzel/fuzzel.ini
|
| options/nixos/meta.maintainers | List of maintainers of each module
|
| options/home-manager/meta.maintainers | List of maintainers of each module
|
| options/nixos/services.mysql.initialScript | A file containing SQL statements to be executed on the first startup
|
| options/nixos/services.prometheus.remoteRead.*.bearer_token_file | Sets the Authorization header on every remote read request with the bearer token
read from the configured file
|
| options/nixos/security.pam.services.<name>.unixAuth | Whether users can log in with passwords defined in
/etc/shadow.
|
| options/nixos/services.nezha-agent.settings | Generate to config.json as a Nix attribute set
|
| options/nixos/services.privoxy.userActions | Actions to be included in a user.action file
|
| options/nixos/services.gns3-server.settings | The global options in config file in ini format
|
| options/nixos/services.diod.statfsPassthru | This option configures statfs to return the host file system's type
rather than V9FS_MAGIC.
|
| options/nixos/services.listmonk.secretFile | A file containing secrets as environment variables
|
| options/nixos/services.goeland.settings | Configuration of goeland
|
| options/home-manager/programs.ghostty.settings | Configuration written to $XDG_CONFIG_HOME/ghostty/config
|
| options/home-manager/programs.wallust.settings | Configuration written to $XDG_CONFIG_HOME/wallust/wallust.toml
|
| options/home-manager/programs.vinegar.settings | Configuration written to $XDG_CONFIG_HOME/vinegar/config.toml
|
| options/home-manager/programs.hexchat.settings | Configuration for $XDG_CONFIG_HOME/hexchat/hexchat.conf, see
https://hexchat.readthedocs.io/en/latest/settings.html#list-of-settings
for supported values.
|
| options/home-manager/programs.earthly.settings | Configuration written to ~/.earthly/config.yml file
|
| options/home-manager/xresources.extraConfig | Additional X server resources contents
|
| options/home-manager/programs.neovim.coc.settings | Extra configuration lines to add to
$XDG_CONFIG_HOME/nvim/coc-settings.json
See
https://github.com/neoclide/coc.nvim/wiki/Using-the-configuration-file
for options.
|
| options/nixos/image.repart.mkfsOptions | Specify extra options for created file systems
|
| options/nixos/services.cassandra.extraEnvSh | Extra shell lines to be appended onto cassandra-env.sh.
|
| options/nixos/services.pdns-recursor.luaConfig | The content Lua configuration file for PowerDNS Recursor
|
| options/nixos/services.prometheus.scrapeConfigs.*.docker_sd_configs.*.oauth2.client_secret_file | Read the client secret from a file
|
| options/nixos/services.prometheus.scrapeConfigs.*.eureka_sd_configs.*.oauth2.client_secret_file | Read the client secret from a file
|
| options/nixos/services.prometheus.scrapeConfigs.*.consul_sd_configs.*.oauth2.client_secret_file | Read the client secret from a file
|
| options/nixos/services.prometheus.scrapeConfigs.*.linode_sd_configs.*.oauth2.client_secret_file | Read the client secret from a file
|
| options/nixos/services.gnome.gnome-user-share.enable | Whether to enable GNOME User Share, a user-level file sharing service for GNOME.
|
| options/home-manager/programs.claude-code.memory.source | Path to a file containing memory content for CLAUDE.md
|
| options/nixos/services.siproxd.passwordFile | Path to per-user password file.
|
| options/nixos/programs.neovim.runtime.<name>.source | Path of the source file.
|
| options/nixos/services.asusd.auraConfigs.<name>.source | Path of the source file.
|
| options/nixos/services.opengfw.settingsFile | Path to file containing OpenGFW settings.
|
| options/nixos/services.opentelemetry-collector.configFile | Specify a path to a configuration file that Opentelemetry Collector should use.
|
| options/nixos/services.forgejo.customDir | Base directory for custom templates and other options
|
| options/nixos/services.ncdns.settings | ncdns settings
|
| options/nixos/services.radicle.publicKey | An SSH public key (as an absolute file path or directly as a string),
usually generated by rad auth
|
| options/home-manager/services.grobi.executeAfter | Commands to be run after an output configuration was
changed
|
| options/nixos/services.davis.nginx.basicAuthFile | Basic Auth password file for a vhost
|
| options/nixos/services.movim.nginx.basicAuthFile | Basic Auth password file for a vhost
|
| options/nixos/services.slskd.nginx.basicAuthFile | Basic Auth password file for a vhost
|
| options/nixos/services.tarsnap.archives.<name>.keyfile | Set a specific keyfile for this archive
|
| options/nixos/services.athens.storage.gcp.jsonKey | Base64 encoded GCP service account key
|
| options/nixos/services.linkwarden.environmentFile | Path of a file with extra environment variables to be loaded from disk
|
| options/nixos/services.prometheus.scrapeConfigs.*.uyuni_sd_configs.*.authorization.credentials_file | Sets the credentials to the credentials read from the configured file
|
| options/nixos/services.sks.extraDbConfig | Set contents of the files "KDB/DB_CONFIG" and "PTree/DB_CONFIG" within
the ${dataDir} directory
|
| options/home-manager/home.stateVersion | It is occasionally necessary for Home Manager to change
configuration defaults in a way that is incompatible with
stateful data
|
| options/home-manager/programs.gnome-terminal.profile.<name>.scrollbackLines | The number of scrollback lines to keep, null for infinite.
|
| options/nixos/services.kubernetes.kubelet.kubeconfig.caFile | Kubelet certificate authority file used to connect to kube-apiserver.
|
| options/nixos/services.mastodon.configureNginx | Configure nginx as a reverse proxy for mastodon
|
| options/nixos/services.prosody.extraConfig | Additional prosody configuration
The generated file is processed by envsubst to allow secrets to be passed securely via environment variables.
|
| options/nixos/services.privoxy.userFilters | Filters to be included in a user.filter file
|
| options/nixos/services.prometheus.remoteWrite.*.bearer_token_file | Sets the Authorization header on every remote write request with the bearer token
read from the configured file
|
| options/nixos/services.pixelfed.secretFile | A secret file to be sourced for the .env settings
|
| options/nixos/services.lubelogger.environmentFile | Path to a file containing extra LubeLogger config options in the systemd EnvironmentFile format
|
| options/nixos/services.postfix.virtualMapType | What type of virtual alias map file to use
|
| options/nixos/services.xonotic.settings | Generates the server.cfg file
|
| options/nixos/virtualisation.containerd.configFile | Path to containerd config file
|
| options/nixos/services.athens.storage.mongo.certPath | Path to the certificate file for the mongo database.
|
| options/nixos/services.xserver.windowManager.herbstluftwm.configFile | Path to the herbstluftwm configuration file
|
| options/darwin/security.sandbox.profiles.<name>.allowLocalNetworking | Whether to allow localhost network access inside the sandbox.
|
| options/nixos/services.drupal.sites.<name>.phpOptions | Options for PHP's php.ini file for this Drupal site.
|
| options/nixos/services.munin-node.extraPluginConfig | plugin-conf.d extra plugin configuration
|
| options/home-manager/programs.asciinema.enable | Whether to enable Enable installing asciinema and writing configuration file.
|
| options/nixos/services.bacula-dir.port | Specify the port (a positive integer) on which the Director daemon
will listen for Bacula Console connections
|
| options/nixos/services.wakapi.passwordSaltFile | The path to a file containing the password salt to use for Wakapi.
|
| options/nixos/services.jicofo.userPasswordFile | Path to file containing password for XMPP user connection.
|
| options/nixos/services.jigasi.userPasswordFile | Path to file containing password for XMPP user connection.
|
| options/nixos/services.rmfakecloud.environmentFile | Path to an environment file loaded for the rmfakecloud service
|
| options/nixos/services.mycelium.keyFile | Optional path to a file containing the mycelium key material
|
| options/nixos/users.ldap.bind.policy | Specifies the policy to use for reconnecting to an unavailable
LDAP server
|
| options/home-manager/programs.firefox.profiles.<name>.search.engines | Attribute set of search engine configurations
|
| options/nixos/services.kubernetes.kubelet.kubeconfig.keyFile | Kubelet client key file used to connect to kube-apiserver.
|
| options/nixos/services.slskd.settings.retention.files.incomplete | Lifespan of incomplete downloading files in minutes.
|
| options/nixos/services.pihole-ftl.macvendorURL | URL from which to download the macvendor.db file.
|
| options/home-manager/pam.yubico.authorizedYubiKeys.path | File path to write the authorized YubiKeys,
relative to HOME.
|
| options/nixos/services.dovecot2.extraConfig | Additional entries to put verbatim into Dovecot's config file.
|
| options/nixos/services.monica.mail.passwordFile | A file containing the password corresponding to
|
| options/nixos/services.snipe-it.nginx.basicAuthFile | Basic Auth password file for a vhost
|
| options/nixos/services.atd.allowEveryone | Whether to make /var/spool/at{jobs,spool}
writeable by everyone (and sticky)
|
| options/home-manager/wayland.windowManager.sway.checkConfig | If enabled, validates the generated config file.
|
| options/nixos/nix.buildMachines.*.sshKey | The path to the SSH private key with which to authenticate on
the build machine
|
| options/home-manager/nix.buildMachines.*.sshKey | The path to the SSH private key with which to authenticate on
the build machine
|
| options/darwin/nix.buildMachines.*.sshKey | The path to the SSH private key with which to authenticate on
the build machine
|
| options/nixos/services.actkbd.bindings | Key bindings for actkbd
|