| options/nixos/services.healthchecks.settings.REGISTRATION_OPEN | A boolean that controls whether site visitors can create new accounts
|
| options/nixos/services.sourcehut.settings."hg.sr.ht".srhtext | Path to the srht mercurial extension
(defaults to where the hgsrht code is)
|
| options/nixos/services.tor.settings.WarnPlaintextPorts | See torrc manual.
|
| options/nixos/services.murmur.welcometext | Welcome message for connected clients.
|
| options/nixos/services.anuko-time-tracker.nginx.rejectSSL | Whether to listen for and reject all HTTPS connections to this vhost
|
| options/nixos/services.zabbixWeb.nginx.virtualHost.rejectSSL | Whether to listen for and reject all HTTPS connections to this vhost
|
| options/nixos/services.bacula-sd.director.<name>.tls.enable | Specifies if TLS should be enabled
|
| options/nixos/services.bacula-fd.director.<name>.tls.enable | Specifies if TLS should be enabled
|
| options/home-manager/accounts.email.accounts.<name>.jmap.sessionUrl | URL for the JMAP Session resource
|
| options/nixos/services.sharkey.settings.fulltextSearch.provider | Which provider to use for full text search
|
| options/nixos/services.filebeat.inputs | Inputs specify how Filebeat locates and processes input data
|
| options/nixos/services.bookstack.nginx.rejectSSL | Whether to listen for and reject all HTTPS connections to this vhost
|
| options/home-manager/programs.qutebrowser.quickmarks | Quickmarks to add to qutebrowser's quickmarks file
|
| options/home-manager/programs.gemini-cli.commands.<name>.prompt | The prompt that will be sent to the Gemini model when the command is executed
|
| options/nixos/services.tor.settings.RejectPlaintextPorts | See torrc manual.
|
| options/nixos/services.jirafeau.nginxConfig.rejectSSL | Whether to listen for and reject all HTTPS connections to this vhost
|
| options/nixos/programs.tsmClient.servers.<name>.inclexcl | Text lines with include.* and exclude.* directives
to be used when sending files to the IBM TSM server,
or an absolute path pointing to a file with such lines.
|
| options/nixos/services.nginx.virtualHosts.<name>.rejectSSL | Whether to listen for and reject all HTTPS connections to this vhost
|
| options/nixos/services.postgresql.systemCallFilter | Configures the syscall filter for postgresql.service
|
| options/home-manager/programs.gnome-terminal.profile.<name>.allowBold | If true, allow applications in the
terminal to make text boldface.
|
| options/home-manager/programs.gnome-terminal.profile.<name>.boldIsBright | Whether bold text is shown in bright colors.
|
| options/nixos/services.umurmur.settings.welcometext | Welcome message for connected clients.
|
| options/nixos/services.fedimintd.<name>.nginx.config.rejectSSL | Whether to listen for and reject all HTTPS connections to this vhost
|
| options/nixos/services.bacula-fd.director.<name>.tls.allowedCN | Common name attribute of allowed peer certificates
|
| options/nixos/services.bacula-sd.director.<name>.tls.allowedCN | Common name attribute of allowed peer certificates
|
| options/home-manager/programs.kakoune.config.keyMappings.*.docstring | Optional documentation text to display in info boxes.
|
| options/nixos/services.filebeat.modules | Filebeat modules provide a quick way to get started
processing common log formats
|
| options/nixos/services.metricbeat.modules | Metricbeat modules are responsible for reading metrics from the various sources
|
| options/nixos/services.traefik.dynamic.dir | Path to the directory Traefik should watch for configuration files.
Files in this directory matching the glob _nixos-* (reserved for Nix-managed dynamic configurations) will be deleted as part of
systemd-tmpfiles-resetup.service, regardless of their origin..
|
| options/nixos/services.limesurvey.nginx.virtualHost.rejectSSL | Whether to listen for and reject all HTTPS connections to this vhost
|
| options/nixos/services.nncp.daemon.socketActivation.listenStreams | TCP sockets to bind to
|
| options/home-manager/accounts.email.accounts.<name>.mujmap.settings.username | Username for basic HTTP authentication
|
| options/nixos/services.misskey.reverseProxy.webserver.nginx.rejectSSL | Whether to listen for and reject all HTTPS connections to this vhost
|
| options/nixos/services.openssh.authorizedKeysInHomedir | Enables the use of the ~/.ssh/authorized_keys file
|
| options/home-manager/programs.ripgrep-all.custom_adapters.*.name | The unique identifier and name of this adapter; must only include a-z, 0-9, _
|
| options/nixos/boot.kernel.sysctl | Runtime parameters of the Linux kernel, as set by
sysctl(8)
|
| options/nixos/services.syncthing.overrideFolders | Whether to delete the folders which are not configured via the
folders option
|
| options/nixos/services.monado.defaultRuntime | Whether to enable Monado as the default OpenXR runtime on the system
|
| options/nixos/services.wivrn.defaultRuntime | Whether to enable WiVRn as the default OpenXR runtime on the system
|
| options/nixos/networking.tempAddresses | Whether to enable IPv6 Privacy Extensions for interfaces not
configured explicitly in
networking.interfaces._name_.tempAddress
|
| options/nixos/services.postsrsd.settings.chroot-dir | Path to chroot into at runtime as an additional layer of protection.
We confine the runtime environment through systemd hardening instead, so this option is read-only.
|
| options/nixos/services.matrix-synapse.log | Default configuration for the loggers used by matrix-synapse and its workers
|
| options/nixos/services.galene.keyFile | Path to the server's private key
|
| options/nixos/services.scx.extraArgs | Parameters passed to the chosen scheduler at runtime.
Run chosen-scx-scheduler --help to see the available options
|
| options/home-manager/services.colima.enable | Whether to enable Colima, a container runtime.
|
| options/nixos/services.pgbackrest.stanzas.<name>.settings | An attribute set of options as described in:
https://pgbackrest.org/configuration.html
All options can be used
|
| options/nixos/services.node-red.withNpmAndGcc | Give Node-RED access to NPM and GCC at runtime, so 'Nodes' can be
downloaded and managed imperatively via the 'Palette Manager'.
|
| options/home-manager/programs.gemini-cli.commands.<name>.description | A brief, one-line description of what the command does
|
| options/nixos/services.galene.certFile | Path to the server's certificate
|
| options/nixos/services.traefik.dynamic.files | Dynamic configuration files to write
|
| options/nixos/services.bacula-sd.director.<name>.tls.certificate | The full path to the PEM encoded TLS certificate
|
| options/nixos/services.bacula-fd.director.<name>.tls.certificate | The full path to the PEM encoded TLS certificate
|
| options/nixos/virtualisation.rosetta.mountTag | The VirtioFS mount tag for the Rosetta runtime, exposed by the host's virtualisation software
|
| options/nixos/services.bacula-fd.director.<name>.tls.caCertificateFile | The path specifying a PEM encoded TLS CA certificate(s)
|
| options/nixos/services.bacula-sd.director.<name>.tls.caCertificateFile | The path specifying a PEM encoded TLS CA certificate(s)
|
| options/home-manager/programs.qutebrowser.keyBindings | Key bindings mapping keys to commands in different modes
|
| options/nixos/hardware.amdgpu.opencl.enable | Whether to enable OpenCL support using ROCM runtime library.
|
| options/nixos/services.wiki-js.settings.logLevel | Define how much detail is supposed to be logged at runtime.
|
| options/nixos/services.linyaps.enable | Whether to enable linyaps, a cross-distribution package manager with sandboxed apps and shared runtime.
|
| options/nixos/services.bird.preCheckConfig | Commands to execute before the config file check
|
| options/nixos/services.athens.goBinary | The Go package used by Athens at runtime
|
| options/nixos/services.couchdb.configFile | Configuration file for persisting runtime changes
|
| options/home-manager/services.activitywatch.watchers.<name>.settings | The settings for the individual watcher in TOML format
|
| options/home-manager/programs.borgmatic.backups.<name>.location.repositories.*.label | Short text describing the repository
|
| options/nixos/services.maddy.tls.loader | TLS certificates are obtained by modules called "certificate
loaders"
|
| options/nixos/services.forgejo.customDir | Base directory for custom templates and other options
|
| options/nixos/services.zitadel.settings | Contents of the runtime configuration file
|
| options/nixos/services.lighttpd.cgit.configText | Verbatim contents of the cgit runtime configuration file
|
| options/nixos/services.unifi.maximumJavaHeapSize | Set the maximum heap size for the JVM in MB
|
| options/nixos/services.unifi.initialJavaHeapSize | Set the initial heap size for the JVM in MB
|
| options/nixos/hardware.amdgpu.amdvlk.settings | Runtime settings for AMDVLK to be configured /etc/amd/amdVulkanSettings.cfg
|
| options/nixos/system.nixos.label | NixOS version name to be used in the names of generated
outputs and boot labels
|
| options/nixos/boot.plymouth.font | Font file made available for displaying text on the splash screen.
|
| options/nixos/services.prometheus.rules | Alerting and/or Recording rules to evaluate at runtime.
|
| options/nixos/nix.extraOptions | Additional text appended to nix.conf.
|
| options/home-manager/nix.extraOptions | Additional text appended to nix.conf.
|
| options/darwin/nix.extraOptions | Additional text appended to nix.conf.
|
| options/nixos/services.wivrn.config.json | Configuration for WiVRn
|
| options/nixos/services.riemann.configFiles | Extra files containing Riemann configuration
|
| options/nixos/services.rkvm.server.settings.switch-keys | A key list specifying a host switch combination.
A list of key names is available in https://github.com/htrefil/rkvm/blob/master/switch-keys.md.
|
| options/nixos/services.jupyter.extraPackages | Extra packages to be available in the jupyter runtime environment
|
| options/home-manager/accounts.email.accounts.<name>.mujmap.settings.password_command | Shell command which will print a password to stdout for basic HTTP
authentication
|
| options/nixos/services.flannel.storageBackend | Determines where flannel stores its configuration at runtime
|
| options/nixos/services.apcupsd.configText | Contents of the runtime configuration file, apcupsd.conf
|
| options/nixos/hardware.alsa.defaultDevice.capture | The default capture device (i.e. microphone)
|
| options/nixos/services.netdata.python.extraPackages | Extra python packages available at runtime
to enable additional python plugins.
|
| options/nixos/services.deluge.extraPackages | Extra packages available at runtime to enable Deluge's plugins
|
| options/nixos/services.activemq.extraJavaOptions | Add extra options here that you want to be sent to the
Java runtime when the broker service is started.
|
| options/nixos/services.moonraker.analysis.enable | Whether to enable Runtime analysis with klipper-estimator.
|
| options/nixos/hardware.alsa.defaultDevice.playback | The default playback device
|
| options/nixos/services.gotify.stateDirectoryName | The name of the directory below /var/lib where
gotify stores its runtime data.
|
| options/nixos/services.nginx.uwsgiResolveWhileRunning | Resolves domains of uwsgi targets at runtime
and not only at start, you have to set
services.nginx.resolver, too.
|
| options/nixos/services.userdbd.enableSSHSupport | Whether to enable exposing OpenSSH public keys defined in userdb
|
| options/nixos/services.monado.forceDefaultRuntime | Whether to ensure that Monado is the active runtime set for the current
user
|
| options/nixos/services.nextcloud.settings.mail_send_plaintext_only | Email will be sent by default with an HTML and a plain text body
|
| options/nixos/boot.loader.grub.splashImage | Background image used for GRUB
|
| options/nixos/services.rabbitmq.config | Verbatim advanced configuration file contents using the Erlang syntax
|
| options/nixos/services.dae.config | WARNING: This option will expose store your config unencrypted world-readable in the nix store
|
| options/nixos/services.evcc.environmentFile | File with environment variables to pass into the runtime environment
|
| options/nixos/services.firewalld.settings.FlushAllOnReload | Whether to flush all runtime rules on a reload.
|