| options/nixos/services.openssh.settings.AuthorizedPrincipalsFile | Specifies a file that lists principal names that are accepted for certificate authentication
|
| options/nixos/services.prowlarr.settings.update.automatically | Automatically download and install updates.
|
| options/nixos/services.taler.exchange.settings.exchangedb-postgres.CONFIG | Database connection URI.
|
| options/nixos/services.taler.merchant.settings.merchantdb-postgres.CONFIG | Database connection URI.
|
| options/nixos/services.whisparr.settings.update.automatically | Automatically download and install updates.
|
| options/nixos/services.grafana.provision.alerting.rules.settings.deleteRules.*.orgId | Organization ID, default = 1
|
| options/nixos/services.anubis.defaultOptions.settings.OG_PASSTHROUGH | Whether to enable Open Graph tag passthrough
|
| options/nixos/documentation.man.mandoc.settings.output.man | A template for linked manuals (usually via the Xr macro) in HTML
output
|
| options/nixos/services.tor.relay.onionServices.<name>.settings.HiddenServiceAllowUnknownPorts | See torrc manual.
|
| options/nixos/services.prometheus.exporters.script.settings | Free-form configuration for script_exporter, expressed as a Nix attrset and rendered to YAML.
Migration note:
The previous format using script = "sleep 5" is no longer supported
|
| options/nixos/services.headscale.settings.oidc.allowed_users | Users allowed to authenticate even if not in allowedDomains.
|
| options/nixos/services.suricata.settings.exception-policy | Define a common behavior for all exception policies
|
| options/nixos/services.anubis.instances.<name>.settings.OG_PASSTHROUGH | Whether to enable Open Graph tag passthrough
|
| options/nixos/services.biboumi.settings.xmpp_server_ip | The IP address to connect to the XMPP server on
|
| options/nixos/services.grafana-image-renderer.settings.rendering.mode | Rendering mode of grafana-image-renderer:
default: Creates on browser-instance
per rendering request.
reusable: One browser instance
will be started and reused for each rendering request.
clustered: allows to precisely
configure how many browser-instances are supposed to be used
|
| options/nixos/services.grafana.provision.dashboards.settings.apiVersion | Config file version.
|
| options/nixos/services.nextcloud-spreed-signaling.settings.backend.timeout | Timeout in seconds for requests to the backend
|
| options/nixos/services.kerberos_server.settings.module | Modules to obtain Kerberos configuration from.
|
| options/nixos/services.kerberos_server.settings.realms | The realm(s) to serve keys for.
|
| options/home-manager/programs.khard.settings.general.default_action | The default action to execute.
|
| options/nixos/services.nextcloud-spreed-signaling.settings.https.listen | IP and port to listen on for HTTPS requests, in the format of ip:port
|
| options/nixos/services.autosuspend.settings.wakeup_cmd | The command to execute for scheduling a wake up of the system
|
| options/nixos/security.agnos.settings.accounts.*.certificates.*.domains | Domains the certificate represents
|
| options/nixos/services.tor.relay.onionServices.<name>.settings.HiddenServiceDirGroupReadable | See torrc manual.
|
| options/nixos/services.opensearch.settings."plugins.security.disabled" | Whether to enable the security plugin,
plugins.security.ssl.transport.keystore_filepath or
plugins.security.ssl.transport.server.pemcert_filepath and
plugins.security.ssl.transport.client.pemcert_filepath
must be set for this plugin to be enabled.
|
| options/nixos/services.public-inbox.settings.publicinbox.imapserver | IMAP URLs to this public-inbox instance
|
| options/nixos/services.public-inbox.settings.publicinbox.pop3server | POP3 URLs to this public-inbox instance
|
| options/nixos/services.public-inbox.settings.publicinbox.nntpserver | NNTP URLs to this public-inbox instance
|
| options/nixos/services.hddfancontrol.settings.<drive-bay-name>.pwmPaths | PWM filepath(s) to control fan speed (under /sys), followed by initial and fan-stop PWM values
Can also use command substitution to ensure the correct hwmonX is selected on every boot
|
| options/nixos/services.sabnzbd.settings.misc.bandwidth_perc | Percentage of bandwidth_max that sabnzbd is allowed to use.
0 means no limit.
|
| options/nixos/services.minidlna.settings.root_container | Use a different container as the root of the directory tree presented to clients.
|
| options/nixos/services.chhoto-url.settings.redirect_method | The redirect method to use.
|
| options/nixos/services.grafana.provision.alerting.contactPoints.settings | Grafana contact points configuration in Nix
|
| options/nixos/services.journald.upload.settings.Upload.NetworkTimeoutSec | When network connectivity to the server is lost, this option
configures the time to wait for the connectivity to get restored
|
| options/home-manager/gtk.gtk3.extraConfig | Extra settings for $XDG_CONFIG_HOME/gtk-3.0/settings.ini.
|
| options/home-manager/gtk.gtk4.extraConfig | Extra settings for $XDG_CONFIG_HOME/gtk-4.0/settings.ini.
|
| options/nixos/services.headscale.settings.dns.extra_records.*.name | DNS record name.
|
| options/nixos/services.headscale.settings.dns.extra_records.*.type | DNS record type.
|
| options/nixos/services.nextcloud-spreed-signaling.settings.etcd.endpoints | List of static etcd endpoints to connect to.
|
| options/nixos/services.lasuite-docs.collaborationServer.settings.PORT | Port used by collaboration server to listen to
|
| options/nixos/virtualisation.xen.store.settings.ringScanInterval | Perodic scanning for all the rings as a safenet for lazy clients
|
| options/nixos/services.grafana.provision.alerting.muteTimings.settings.muteTimes | List of mute time intervals to import or update.
|
| options/nixos/services.sabnzbd.settings.ntfosd.ntfosd_enable | Whether to enable NotifyOSD alerts
|
| options/nixos/services.suricata.settings.classification-file | Suricata classification configuration file.
|
| options/nixos/services.dependency-track.settings."alpine.database.mode" | Defines the database mode of operation
|
| options/nixos/services.anubis.instances.<name>.settings.METRICS_BIND | The address Anubis' metrics server listens to
|
| options/nixos/services.sourcehut.settings."lists.sr.ht::worker".reject-mimetypes | Comma-delimited list of Content-Types to reject
|
| options/nixos/services.libeufin.nexus.settings.libeufin-nexusdb-postgres.CONFIG | The database connection string for the libeufin-nexus database.
|
| options/nixos/services.grafana.provision.alerting.rules.settings.groups.*.folder | Name of the folder the rule group will be stored in
|
| options/nixos/services.prometheus.exporters.fritz.settings.log_level | Log level to use for the exporter.
|
| options/nixos/services.nipap.settings.auth.default_backend | Name of auth backend to use by default.
|
| options/nixos/virtualisation.xen.store.settings.persistent | Whether to activate the filed base backend.
|
| options/nixos/services.grafana.provision.alerting.templates.settings | Grafana templates configuration in Nix
|
| options/nixos/services.suricata.settings.dpdk.interfaces.*.interface | See upstream docs: docs/capture-hardware/dpdk and docs/configuration/suricata-yaml.html#data-plane-development-kit-dpdk.
|
| options/nixos/services.postfix-tlspol.settings.server.socket-permissions | Permissions to the UNIX socket, if configured.
Due to hardening on the systemd unit the socket can never be created world readable/writable.
|
| options/nixos/services.grafana.provision.datasources.settings.prune | When true, provisioned datasources from this file will be deleted
automatically when removed from
services.grafana.provision.datasources.settings.datasources.
|
| options/nixos/virtualisation.docker.daemon.settings.live-restore | Allow dockerd to be restarted without affecting running container
|
| options/nixos/services.wgautomesh.settings.lan_discovery | Enable discovery of peers on the same LAN using UDP broadcast.
|
| options/nixos/services.public-inbox.settings.publicinbox.wwwlisting | Controls which lists (if any) are listed for when the root
public-inbox URL is accessed over HTTP.
|
| options/nixos/services.matrix-appservice-irc.settings.homeserver.domain | The 'domain' part for user IDs on this home server
|
| options/nixos/services.archisteamfarm.settings | The ASF.json file, all the options are documented here
|
| options/nixos/services.crowdsec.settings.console.configuration | Attributes inside the console.yaml file.
|
| options/nixos/services.warpgate.settings.http.cookie_max_age | How long until logged in cookie expires.
|
| options/nixos/services.matrix-synapse.settings.enable_metrics | Enable collection and rendering of performance metrics
|
| options/nixos/services.transmission.settings.script-torrent-done-enabled | Whether to run
services.transmission.settings.script-torrent-done-filename
at torrent completion.
|
| options/home-manager/programs.librewolf.profiles.<name>.extensions.settings.<name>.force | Forcibly override any existing configuration for
this extension.
|
| options/nixos/services.bonsaid.settings.*.delay_duration | Nanoseconds to wait after the previous state change before performing this transition
|
| options/nixos/services.headscale.settings.prefixes.allocation | Strategy used for allocation of IPs to nodes, available options:
- sequential (default): assigns the next free IP from the previous given IP.
- random: assigns the next free IP from a pseudo-random IP generator (crypto/rand).
|
| options/nixos/services.prometheus.alertmanager-ntfy.settings.http.addr | The address to listen on.
|
| options/nixos/virtualisation.xen.store.settings.xenstored.log.file | Path to the Xen Store log file.
|
| options/nixos/services.prometheus.exporters.nginxlog.settings.consul | Consul integration options
|
| options/nixos/services.pgbouncer.settings.pgbouncer.listen_port | Which port to listen on
|
| options/nixos/virtualisation.docker.rootless.daemon.settings | Configuration for docker daemon
|
| options/nixos/services.grafana.settings.database.max_open_conn | The maximum number of open connections to the database.
|
| options/nixos/services.tlsrpt.reportd.settings.sender_address | Sender address used for reports.
|
| options/nixos/services.authelia.instances.<name>.settings.log.keep_stdout | Whether to also log to stdout when a file_path is defined.
|
| options/nixos/services.transmission.settings.incomplete-dir | When enabled with
services.transmission.home
services.transmission.settings.incomplete-dir-enabled,
new torrents will download the files to this directory
|
| options/nixos/services.transmission.settings.incomplete-dir-enabled | |
| options/nixos/services.kerberos_server.settings.include | Files to include in the Kerberos configuration.
|
| options/nixos/documentation.man.mandoc.settings.output.includes | A string of relative path used as a template for the output path of
linked header files (usually via the In macro) in HTML output
|
| options/nixos/services.matrix-synapse.settings.listeners.*.x_forwarded | Use the X-Forwarded-For (XFF) header as the client IP and not the
actual client IP.
|
| options/nixos/security.auditd.settings.space_left | If the free space in the filesystem containing log_file drops below this value, the audit daemon takes the action specified by
space_left_action
|
| options/nixos/services.system76-scheduler.settings.cfsProfiles.default.latency | sched_latency_ns.
|
| options/nixos/services.grafana.settings.security.cookie_secure | Set to true if you host Grafana behind HTTPS.
|
| options/nixos/services.grafana.settings.database.max_idle_conn | The maximum number of connections in the idle connection pool.
|
| options/nixos/services.slskd.settings.retention.transfers.download.errored | Lifespan of errored download tasks.
|
| options/nixos/services.maubot.settings.crypto_database | Separate database URL for the crypto database
|
| options/nixos/virtualisation.containers.storage.settings | storage.conf configuration
|
| options/nixos/services.matrix-continuwuity.settings.global.address | Addresses (IPv4 or IPv6) to listen on for connections by the reverse proxy/tls terminator
|
| options/nixos/services.umurmur.settings.default_channel | The channel in which users will appear in when connecting.
|
| options/nixos/security.agnos.settings.dns_listen_addr | Address for agnos to listen on
|
| options/nixos/services.system76-scheduler.settings.cfsProfiles.default.preempt | Preemption mode.
|
| options/nixos/services.transmission.settings.script-torrent-done-filename | Executable to be run at torrent completion.
|
| options/nixos/services.headscale.settings.dns.extra_records.*.value | DNS record value (IP address).
|
| options/nixos/services.matrix-appservice-irc.settings.ircService.mediaProxy.signingKeyPath | Path to the signing key file for authenticated media.
|
| options/nixos/services.matrix-synapse.settings.public_baseurl | The public-facing base URL for the client API (not including _matrix/...)
|
| options/nixos/services.mpd.settings.music_directory | The directory or URI where MPD reads music from
|
| options/nixos/services.mchprs.settings.block_in_hitbox | Allow placing blocks inside of players
(hitbox logic is simplified)
|
| options/nixos/services.system76-scheduler.settings.cfsProfiles.default.nr-latency | sched_nr_latency.
|
| options/nixos/documentation.man.mandoc.settings.output.indent | Number of blank characters at the left margin for normal text,
default of 5 for mdoc(7) and 7 for
man(7)
|