| options/nixos/services.healthchecks.settings.SECRET_KEY_FILE | Path to a file containing the secret key.
|
| options/nixos/services.rosenpass.settings.peers.*.public_key | Path to a file containing the public key of the remote Rosenpass peer.
|
| options/nixos/services.nextcloud.settings."profile.enabled" | Makes user-profiles globally available under nextcloud.tld/u/user.name
|
| options/home-manager/programs.intelli-shell.shellHotkeys | Settings for customizing the keybinding to integrate your shell with intelli-shell
|
| options/nixos/services.snapserver.settings.tcp-streaming.enabled | Whether to enable streaming via TCP.
|
| options/nixos/virtualisation.xen.store.settings.enableMerge | Whether to enable transaction merge support.
|
| options/nixos/services.grafana.provision.alerting.policies.settings | Grafana notification policies configuration in Nix
|
| options/nixos/services.dendrite.settings.sync_api.search.index_path | The path the search index will be created in.
|
| options/nixos/services.crowdsec-firewall-bouncer.settings.api_url | URL of the local API.
|
| options/nixos/services.logrotate.settings.<name>.frequency | How often to rotate the logs
|
| options/nixos/services.anubis.defaultOptions.settings.WEBMASTER_EMAIL | If set, shows a contact email address when rendering error pages
|
| options/nixos/services.dendrite.settings.global.private_key | The path to the signing private key file, used to sign
requests and events.
nix-shell -p dendrite --command "generate-keys --private-key matrix_key.pem"
|
| options/nixos/services.reposilite.settings.defaultFrontend | Whether to enable the default included frontend with a dashboard.
|
| options/nixos/services.libeufin.bank.settings.libeufin-bankdb-postgres.CONFIG | The database connection string for the libeufin-bank database.
|
| options/nixos/boot.initrd.systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.age | Delete a file when it reaches a certain age
|
| options/nixos/services.grafana.settings.security.admin_email | The email of the default Grafana Admin, created on startup.
|
| options/nixos/hardware.tuxedo-drivers.settings.charging-profile | The maximum charge level to help reduce battery wear:
high_capacity charges to 100% (driver default)
balanced charges to 90%
stationary charges to 80% (maximum lifespan)
Note: Regardless of the configured charging profile, the operating system will always report the battery as being charged to 100%.
|
| options/nixos/services.matrix-synapse.settings.log_config | The file that holds the logging configuration.
|
| options/nixos/services.headscale.settings.dns.base_domain | Defines the base domain to create the hostnames for MagicDNS
|
| options/nixos/services.tor.settings.DoSRefuseSingleHopClientRendezvous | See torrc manual.
|
| options/nixos/services.kanidm.server.settings.online_backup.path | Path to the output directory for backups.
|
| options/nixos/services.nextcloud-whiteboard-server.settings | Settings to configure backend server
|
| options/nixos/services.grafana.provision.dashboards.settings | Grafana dashboard configuration in Nix
|
| options/nixos/services.pid-fan-controller.settings.fans.*.heatPressureSrcs | Heat pressure sources affected by the fan.
|
| options/nixos/services.stash.settings.stash_boxes.*.endpoint | URL to the Stash Box graphql api
|
| options/nixos/services.etebase-server.settings.global.secret_file | The path to a file containing the secret
used as django's SECRET_KEY.
|
| options/nixos/services.grafana.settings.database.log_queries | Set to true to log the sql calls and execution times
|
| options/nixos/services.anubis.defaultOptions.settings.METRICS_BIND_NETWORK | The network family that the metrics server should bind to
|
| options/nixos/services.routinator.settings.repository-dir | The path where the collected RPKI data is stored.
|
| options/nixos/services.printing.cups-pdf.instances.<name>.settings.Anonuser | User for anonymous PDF creation
|
| options/nixos/services.prometheus.exporters.fritz.settings.devices.*.name | Name to use for the device.
|
| options/nixos/networking.networkmanager.ensureProfiles.profiles | Declaratively define NetworkManager profiles
|
| options/nixos/services.omnom.settings.server.secure_cookie | Whether to limit cookies to a secure channel.
|
| options/nixos/services.matrix-tuwunel.settings.global.server_name | The server_name is the name of this server
|
| options/nixos/services.matrix-conduit.settings.global.server_name | The server_name is the name of this server
|
| options/nixos/services.zeronsd.servedNetworks.<name>.settings.wildcard | Whether to serve a wildcard record for ZeroTier Nodes.
|
| options/nixos/services.grafana-image-renderer.settings.rendering.height | Height of the PNG used to display the alerting graph.
|
| options/nixos/virtualisation.xen.store.settings.xenstored.log.file | Path to the Xen Store log file.
|
| options/nixos/services.syncthing.settings.options.limitBandwidthInLan | Whether to apply bandwidth limits to devices in the same broadcast domain as the local device.
|
| options/nixos/services.nextcloud-spreed-signaling.settings.grpc.listen | IP and port to listen on for GRPC requests
|
| options/home-manager/services.syncthing.settings.options.limitBandwidthInLan | Whether to apply bandwidth limits to devices in the same broadcast domain as the local device.
|
| options/nixos/services.tor.settings.ClientDNSRejectInternalAddresses | See torrc manual.
|
| options/nixos/services.tor.settings.DormantTimeoutDisabledByIdleStreams | See torrc manual.
|
| options/nixos/services.tor.settings.DisableDebuggerAttachment | See torrc manual.
|
| options/nixos/services.vmalert.instances.<name>.settings."notifier.url" | Prometheus Alertmanager URL
|
| options/nixos/services.sourcehut.settings."pages.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| options/nixos/services.sourcehut.settings."paste.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| options/nixos/services.sourcehut.settings."lists.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| options/nixos/virtualisation.xen.store.settings.quota.maxWatchEvents | Maximum number of outstanding watch events per watch.
|
| options/nixos/services.suricata.settings.app-layer.protocols.<name>.enabled | The option "enabled" takes 3 values - "yes", "no", "detection-only".
"yes" enables both detection and the parser, "no" disables both, and
"detection-only" enables protocol detection only (parser disabled).
|
| options/nixos/services.ocsinventory-agent.settings | Configuration for /etc/ocsinventory-agent/ocsinventory-agent.cfg
|
| options/home-manager/programs.keepassxc.enable | Whether to enable KeePassXC.
When this flag is set, KeePassXC' builtin native messaging manifest for
communication with its browser extension is automatically installed
|
| options/nixos/services.hddfancontrol.settings | Parameter-sets for each instance of hddfancontrol.
|
| options/nixos/documentation.man.mandoc.settings.manpath | Override the default search path for man(1),
apropos(1), and makewhatis(8)
|
| options/nixos/services.draupnir.settings.managementRoom | The room ID or alias where moderators can use the bot's functionality
|
| options/nixos/services.ocsinventory-agent.settings.server | The URI of the OCS Inventory server where to send the inventory file
|
| options/nixos/boot.initrd.systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.user | The user of the file
|
| options/nixos/services.system76-scheduler.settings.cfsProfiles.enable | Tweak CFS latency parameters when going on/off battery
|
| options/nixos/services.tor.relay.onionServices.<name>.settings.HiddenServiceSingleHopMode | See torrc manual.
|
| options/nixos/services.sourcehut.settings."sr.ht".environment | Values other than "production" adds a banner to each page.
|
| options/nixos/services.angrr.settings.temporary-root-policies.<name>.enable | Whether to enable this angrr policy.
|
| options/nixos/services.angrr.settings.profile-policies.<name>.keep-booted-system | Whether to keep the last booted system generation
|
| options/nixos/services.matrix-appservice-irc.settings.ircService.mediaProxy.publicUrl | URL under which the media proxy is publicly acccessible.
|
| options/nixos/services.slskd.settings.retention.transfers.download.errored | Lifespan of errored download tasks.
|
| options/nixos/services.fastnetmon-advanced.traffic_db.settings | Additional settings for /etc/fastnetmon/traffic_db.conf
|
| options/nixos/services.globalprotect.settings | GlobalProtect-openconnect configuration
|
| options/nixos/services.nextcloud-spreed-signaling.settings.http.listen | IP and port to listen on for HTTP requests, in the format of ip:port
|
| options/nixos/services.epgstation.settings.clientSocketioPort | Socket.io port that the web client is going to connect to
|
| options/nixos/services.maubot.settings.database_opts | Additional arguments for asyncpg.create_pool() or sqlite3.connect()
|
| options/nixos/programs.chromium.initialPrefs | Initial preferences are used to configure the browser for the first run
|
| options/nixos/systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.mode | The file access mode to use when creating this file or directory.
|
| options/nixos/services.nextcloud.settings.mail_domain | The return address that you want to appear on emails sent by the Nextcloud server, for example nc-admin@example.com, substituting your own domain, of course.
|
| options/nixos/services.easytier.instances.<name>.settings.hostname | Hostname shown in peer list and web console.
|
| options/nixos/services.angrr.settings.temporary-root-policies.<name>.period | Retention period for the GC roots matched by this policy.
|
| options/nixos/services.angrr.settings.temporary-root-policies.<name>.path-regex | Regex pattern to match the GC root path.
|
| options/nixos/services.tor.relay.onionServices.<name>.settings.HiddenServiceMaxStreams | See torrc manual.
|
| options/nixos/services.dependency-track.settings."alpine.database.driver" | Specifies the JDBC driver class to use.
|
| options/nixos/services.grafana.provision.alerting.muteTimings.settings.muteTimes.*.name | Name of the mute time interval, must be unique
|
| options/nixos/services.transmission.settings.message-level | Set verbosity of transmission messages.
|
| options/nixos/services.grafana.settings.smtp.ehlo_identity | Name to be used as client identity for EHLO in SMTP dialog.
|
| options/nixos/services.postfix.settings.main.relay_domains | List of domains delivered via the relay transport.
https://www.postfix.org/postconf.5.html#relay_domains
|
| options/nixos/services.pretix.settings.pretix.instance_name | The name of this installation.
|
| options/nixos/virtualisation.xen.store.settings.xenstored.log.level | Logging level for the Xen Store.
|
| options/nixos/boot.initrd.systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.type | The type of operation to perform on the file
|
| options/home-manager/programs.codex.enableMcpIntegration | Whether to integrate the MCP server config from
programs.mcp.servers into
programs.codex.settings.mcp_servers
|
| options/nixos/services.pid-fan-controller.settings.fans.*.wildcardPath | Wildcard path of the hwmon pwm file
|
| options/nixos/services.mchprs.settings.auto_redpiler | Use redpiler automatically
|
| options/nixos/services.transmission.settings.rpc-bind-address | Where to listen for RPC connections
|
| options/nixos/services.warpgate.settings.database_url | Database connection string
|
| options/darwin/services.aerospace.settings.on-focused-monitor-changed | Commands to run every time focused monitor changes.
|
| options/nixos/services.omnom.settings.app.disable_signup | Whether to enable restricting user creation.
|
| options/nixos/services.prometheus.exporters.script.settings | Free-form configuration for script_exporter, expressed as a Nix attrset and rendered to YAML.
Migration note:
The previous format using script = "sleep 5" is no longer supported
|
| options/nixos/services.angrr.settings.temporary-root-policies.<name>.filter | External filter program to further filter GC roots matched by this policy.
|
| options/nixos/services.reposilite.settings.bypassExternalCache | Add cache bypass headers to responses from /api/* to avoid issues with proxies such as Cloudflare.
|
| options/nixos/hardware.tuxedo-drivers.settings.charging-priority | These options manage the trade-off between battery charging and CPU performance when the USB-C power supply cannot provide sufficient power for both simultaneously:
charge_battery prioritizes battery charging (driver default)
performance prioritizes maximum CPU performance
|
| options/nixos/services.authelia.instances.<name>.settings.log.file_path | File path where the logs will be written
|
| options/home-manager/accounts.email.accounts.<name>.lieer.settings.ignore_tags | Set labels to ignore when syncing from local tags to
remote labels (after translations).
|
| options/nixos/services.prometheus.exporters.script.settings.scripts.*.name | Name of the script.
|
| options/nixos/services.grafana.provision.alerting.muteTimings.settings.apiVersion | Config file version.
|
| options/nixos/services.transmission.settings.download-dir | Directory where to download torrents.
|