| options/nixos/services.mastodon.activeRecordEncryptionPrimaryKeyFile | This key must be set to enable the Active Record Encryption feature within
Rails that Mastodon uses to encrypt and decrypt some database attributes
|
| options/nixos/services.matterbridge.configFile | WARNING: THIS IS INSECURE, as your password will end up in
/nix/store, thus publicly readable
|
| options/nixos/services.nexus.group | Group which runs Nexus3.
|
| options/nixos/services.snapper.snapshotInterval | Snapshot interval
|
| options/nixos/services.pixelfed.nginx.serverName | Name of this virtual host
|
| options/nixos/services.nats.port | Port on which to listen.
|
| options/nixos/services.prometheus.exporters.tibber.port | Port to listen on.
|
| options/nixos/services.strongswan-swanctl.swanctl.connections.<name>.children.<name>.esp_proposals | ESP proposals to offer for the CHILD_SA
|
| options/nixos/services.prometheus.alertmanager-ntfy.settings.ntfy.baseurl | The base URL of the ntfy.sh instance.
|
| options/nixos/services.tomcat.virtualHosts | List consisting of a virtual host name and a list of web applications to deploy on each virtual host
|
| options/nixos/services.prometheus.scrapeConfigs.*.azure_sd_configs.*.tenant_id | Optional tenant ID
|
| options/nixos/services.maubot.settings.database | The full URI to the database
|
| options/nixos/services.taskchampion-sync-server.dataDir | Directory in which to store data
|
| options/nixos/services.prometheus.exporters.tailscale.firewallFilter | Specify a filter for iptables to use when
services.prometheus.exporters.tailscale.openFirewall
is true
|
| options/nixos/services.renovate.enable | Whether to enable renovate.
|
| options/nixos/services.mysql.galeraCluster.sstMethod | Method for the initial state transfer (wsrep_sst_method) when a node joins the cluster
|
| options/nixos/services.nsd.reuseport | Whether to enable SO_REUSEPORT on all used sockets
|
| options/nixos/services.openafsServer.dottedPrincipals | If enabled, allow principal names containing (.) dots
|
| options/nixos/services.openiscsi.discoverPortal | Portal to discover targets on
|
| options/nixos/services.prometheus.alertmanagerGotify.titleAnnotation | Annotation holding the title of the alert
|
| options/nixos/services.prometheus.exporters.snmp.openFirewall | Open port in firewall for incoming connections.
|
| options/nixos/services.neo4j.directories.certificates | Directory for storing certificates to be used by Neo4j for
TLS connections
|
| options/nixos/services.prometheus.exporters.statsd.firewallFilter | Specify a filter for iptables to use when
services.prometheus.exporters.statsd.openFirewall
is true
|
| options/nixos/services.prometheus.exporters.unpoller.loki.url | URL of the Loki host.
|
| options/nixos/services.rspamd-trainer.secrets | A list of files containing the various secrets
|
| options/nixos/services.nagios.mainConfigFile | If non-null, overrides the main configuration file of Nagios.
|
| options/nixos/services.paperless.dataDir | Directory to store the Paperless data.
|
| options/nixos/services.prometheus.scrapeConfigs.*.linode_sd_configs.*.tls_config.cert_file | Certificate file for client cert authentication to the server.
|
| options/nixos/services.matomo.nginx.listen | Listen addresses and ports for this virtual host
|
| options/nixos/services.mediagoblin.pluginPackages | Plugins to add to the environment of MediaGoblin
|
| options/nixos/services.prometheus.exporters.nut.enable | Whether to enable the prometheus nut exporter.
|
| options/nixos/services.pykms.memoryLimit | How much memory to use at most.
|
| options/nixos/services.tailscale.authKeyFile | A file containing the auth key
|
| options/nixos/services.prometheus.exporters.mikrotik.port | Port to listen on.
|
| options/nixos/services.prometheus.remoteWrite.*.metadata_config.send_interval | How frequently metric metadata is sent to remote storage.
|
| options/nixos/services.nginx.defaultListen | If vhosts do not specify listen, use these addresses by default
|
| options/nixos/services.prometheus.scrapeConfigs.*.consul_sd_configs.*.oauth2.scopes | Scopes for the token request.
|
| options/nixos/services.mtr-exporter.jobs | List of MTR jobs
|
| options/nixos/services.pgbouncer.settings.pgbouncer.default_pool_size | How many server connections to allow per user/database pair
|
| options/nixos/services.tarsnap.archives.<name>.followSymlinks | Whether to follow all symlinks in archive trees.
|
| options/nixos/services.postgresqlWalReceiver.receivers.<name>.synchronous | Flush the WAL data to disk immediately after it has been received
|
| options/nixos/services.mail.sendmailSetuidWrapper.capabilities | A comma-separated list of capability clauses to be given to the
wrapper program
|
| options/nixos/services.prometheus.exporters.lnd.lndHost | lnd instance gRPC address:port.
|
| options/nixos/services.mattermost.telemetry.enableDiagnostics | True if we should enable sending diagnostic data
|
| options/nixos/services.nix-store-gcs-proxy.<name>.enable | Whether to enable proxy for this bucket
|
| options/nixos/services.scrutiny.settings.web.influxdb.org | InfluxDB organisation under which to store data.
|
| options/nixos/services.opentracker.extraOptions | Configuration Arguments for opentracker
See https://erdgeist.org/arts/software/opentracker/ for all params
|
| options/nixos/services.prometheus.scrapeConfigs.*.marathon_sd_configs.*.tls_config | TLS configuration.
|
| options/nixos/services.sftpgo.settings.httpd.bindings | Configure listen addresses and ports for httpd.
|
| options/nixos/services.outline.rateLimiter.durationWindow | Length of a throttling window.
|
| options/nixos/services.rkvm.enable | Whether to enable rkvm, a Virtual KVM switch for Linux machines.
|
| options/nixos/services.taskserver.queueSize | Size of the connection backlog, see listen(2).
|
| options/nixos/services.rsync.jobs.<name>.sources | Source directories.
|
| options/nixos/services.stargazer.user | User account under which stargazer runs.
|
| options/nixos/services.prometheus.scrapeConfigs.*.uyuni_sd_configs.*.oauth2.client_secret_file | Read the client secret from a file
|
| options/nixos/services.pixelfed.group | Group account under which pixelfed runs.
If left as the default value this group will automatically be created
on system activation, otherwise you are responsible for
ensuring the group exists before the pixelfed application starts.
|
| options/nixos/services.thanos.downsample.objstore.config | Object store configuration
|
| options/nixos/services.postfix.settings.main.smtp_tls_CAfile | File containing CA certificates of root CAs trusted to sign either remote SMTP server certificates or intermediate CA certificates
|
| options/nixos/services.mysql.settings | MySQL configuration
|
| options/nixos/services.prometheus.exporters.restic.passwordFile | File containing the password to the repository.
|
| options/nixos/services.prometheus.remoteWrite.*.sigv4.profile | The named AWS profile used to authenticate.
|
| options/nixos/services.mailman.siteOwner | Certain messages that must be delivered to a human, but which can't
be delivered to a list owner (e.g. a bounce from a list owner), will
be sent to this address
|
| options/nixos/services.prometheus.exporters.libvirt.user | User name under which the libvirt exporter shall be run.
|
| options/nixos/services.nginx.recommendedTlsSettings | Enable recommended TLS settings.
|
| options/nixos/services.stalwart.group | Group ownership of service
|
| options/nixos/services.prometheus.exporters.ping.port | Port to listen on.
|
| options/nixos/services.postgresqlWalReceiver.receivers.<name>.statusInterval | Specifies the number of seconds between status packets sent back to the server
|
| options/nixos/services.prometheus.exporters.dovecot.socketPath | Path under which the stats socket is placed
|
| options/nixos/services.redmine.components.minimagick_font_path | MiniMagick font path
|
| options/nixos/services.tt-rss.registration.notifyAddress | Email address to send new user notifications to.
|
| options/nixos/services.openafsClient.cache.directory | Cache directory.
|
| options/nixos/services.lokinet.settings | Configuration for Lokinet
|
| options/nixos/services.monero.extraNodes | List of additional peer IP addresses to add to the local list.
|
| options/nixos/services.twingate.package | The twingate package to use.
|
| options/nixos/services.prometheus.exporters.mikrotik.listenAddress | Address to listen on.
|
| options/nixos/services.loki.extraFlags | Specify a list of additional command line flags,
which get escaped and are then passed to Loki.
|
| options/nixos/services.umurmur.settings.bindaddr | IPv4 address to bind to
|
| options/nixos/services.networkd-dispatcher.rules | Declarative configuration of networkd-dispatcher rules
|
| options/nixos/services.multipath.defaults | This section defines default values for attributes which are used
whenever no values are given in the appropriate device or multipath
sections.
|
| options/nixos/services.undervolt.gpuOffset | The amount of voltage in mV to offset the GPU by.
|
| options/nixos/services.mailman.ldap.attrMap.email | LDAP-attribute that corresponds to the email-attribute in mailman.
|
| options/nixos/services.powerdns.secretFile | Environment variables from this file will be interpolated into the
final config file using envsubst with this syntax: $ENVIRONMENT
or ${VARIABLE}
|
| options/nixos/services.udp-over-tcp.udp2tcp.<name>.fwmark | If given, sets the SO_MARK option on the TCP socket.
|
| options/nixos/services.ollama.syncModels | Synchronize all currently installed models with those declared in services.ollama.loadModels,
removing any models that are installed but not currently declared there.
|
| options/nixos/services.lvm.enable | Whether to enable lvm2.
The lvm2 package contains device-mapper udev rules and without those tools like cryptsetup do not fully function!
|
| options/nixos/services.magnetico.web.credentialsFile | The path to the file holding the credentials to access the web
interface
|
| options/nixos/services.openntpd.extraConfig | Additional text appended to openntpd.conf.
|
| options/nixos/services.terraria.worldPath | The path to the world file (.wld) which should be loaded
|
| options/nixos/services.postgresql.enable | Whether to enable PostgreSQL Server.
|
| options/nixos/services.suricata.settings.stats.enable | Whether to enable suricata global stats.
|
| options/nixos/services.tor.settings.AssumeReachable | See torrc manual.
|
| options/nixos/services.matrix-tuwunel.settings.global.unix_socket_perms | The default permissions (in octal) to create the UNIX socket with.
|
| options/nixos/services.monero.rpc.restricted | Whether to restrict RPC to view only commands.
|
| options/nixos/services.synergy.server.address | Address on which to listen for clients.
|
| options/nixos/services.printing.cups-pdf.instances.<name>.settings.Anonuser | User for anonymous PDF creation
|
| options/nixos/services.prosody.muc.*.roomDefaultMembersOnly | If set, the MUC rooms will only be accessible to the members by default.
|
| options/nixos/services.netbird.clients.<name>.interface | Name of the network interface managed by this client.
|
| options/nixos/services.slskd.nginx.listen.*.proxyProtocol | Enable PROXY protocol.
|
| options/nixos/services.tox-node.lanDiscovery | Enable local network discovery.
|
| options/nixos/services.litestream.settings | See the documentation.
|