| options/nixos/services.nextcloud-spreed-signaling.settings.sessions.blockkeyFile | The path to the file containing the value for sessions.blockkey
|
| options/nixos/services.oncall.secretFile | A YAML file containing secrets such as database or user passwords
|
| options/nixos/services.murmur.sslKey | Path to your SSL key.
|
| options/nixos/<imports = [ pkgs.ghostunnel.services.default ]>.ghostunnel.keystore | Path to keystore (combined PEM with cert/key, or PKCS12 keystore)
|
| options/nixos/services.misskey.settings.meilisearch.host | The Meilisearch host.
|
| options/nixos/services.misskey.settings.meilisearch.port | The Meilisearch port.
|
| options/nixos/hardware.keyboard.teck.enable | Whether to enable non-root access to the firmware of TECK keyboards.
|
| options/darwin/launchd.daemons.<name>.serviceConfig.UserName | This optional key specifies the user to run the job as
|
| options/nixos/services.xrdp.sslKey | ssl private key path
A self-signed certificate will be generated if file not exists.
|
| options/home-manager/programs.gradle.settings | Key value pairs to write to gradle.properties in the Gradle
home directory.
|
| options/nixos/services.mackerel-agent.apiKeyFile | Path to file containing the Mackerel API key
|
| options/nixos/services.kmonad.keyboards | Keyboard configuration.
|
| options/nixos/services.kanata.keyboards | Keyboard configurations.
|
| options/nixos/services.kubernetes.apiserver.tlsKeyFile | Kubernetes apiserver private key file.
|
| options/darwin/launchd.user.agents.<name>.serviceConfig.MachServices | This optional key is used to specify Mach services to be registered with the Mach bootstrap sub-system
|
| options/nixos/services.xserver.xkb.extraLayouts.<name>.keycodesFile | The path to the xkb keycodes file
|
| options/nixos/services.pgpkeyserver-lite.package | The pgpkeyserver-lite package to use.
|
| options/nixos/services.misskey.reverseProxy.webserver.nginx.quic | Whether to enable the QUIC transport protocol
|
| options/home-manager/programs.mc.keymapSettings | Settings for mc/mc.keymap file
|
| options/nixos/services.yubikey-agent.package | The yubikey-agent package to use.
|
| options/home-manager/services.gnome-keyring.package | The gnome-keyring package to use.
|
| options/home-manager/services.yubikey-agent.package | The yubikey-agent package to use.
|
| options/nixos/boot.initrd.luks.devices.<name>.yubikey | The options to use for this LUKS device in YubiKey-PBA
|
| options/nixos/services.yggdrasil.settings.PrivateKeyPath | Path to the private key file on the host system
|
| options/nixos/services.grafana.settings.database.client_key_path | The path to the client key
|
| options/nixos/services.fwupd.extraTrustedKeys | Installing a public key allows firmware signed with a matching private key to be recognized as trusted, which may require less authentication to install than for untrusted files
|
| options/nixos/services.weblate.djangoSecretKeyFile | Location of the Django secret key
|
| options/nixos/services.nntp-proxy.sslKey | Proxy ssl key path
|
| options/darwin/launchd.daemons.<name>.serviceConfig.MachServices | This optional key is used to specify Mach services to be registered with the Mach bootstrap sub-system
|
| options/nixos/services.misskey.reverseProxy.webserver.nginx.addSSL | Whether to enable HTTPS in addition to plain HTTP
|
| options/darwin/system.keyboard.enableKeyMapping | Whether to enable keyboard mappings.
|
| options/nixos/programs.ssh.knownHosts.<name>.certAuthority | This public key is an SSH certificate authority, rather than an
individual host's key.
|
| options/darwin/programs.ssh.knownHosts.<name>.certAuthority | This public key is an SSH certificate authority, rather than an
individual host's key.
|
| options/nixos/services.misskey.settings.meilisearch.scope | The search scope.
|
| options/nixos/services.hockeypuck.port | HKP port to listen on.
|
| options/nixos/services.misskey.reverseProxy.webserver.nginx.acmeRoot | Directory for the ACME challenge, which is public
|
| options/nixos/services.misskey.reverseProxy.webserver.nginx.onlySSL | Whether to enable HTTPS and reject plain HTTP connections
|
| options/nixos/services.pgpkeyserver-lite.hkpAddress | Which IP address the sks-keyserver is listening on.
|
| options/nixos/services.misskey.settings.meilisearch.index | Meilisearch index to use.
|
| options/nixos/services.mympd.settings | Manages the configuration files declaratively
|
| options/nixos/services.etcd.peerKeyFile | Key file to use for peer to peer communication
|
| options/home-manager/programs.kodi.addonSettings | Attribute set with the plugin namespace as toplevel key and the plugins
settings as lower level key/value pairs
|
| options/nixos/services.misskey.reverseProxy.webserver.nginx.kTLS | Whether to enable kTLS support
|
| options/nixos/services.misskey.reverseProxy.webserver.nginx.listen.*.ssl | Enable SSL.
|
| options/nixos/services.keycloak.settings.http-relative-path | The path relative to / for serving
resources.
In versions of Keycloak using Wildfly (<17),
this defaulted to /auth
|
| options/nixos/services.matrix-synapse.settings.signing_key_path | Path to the signing key to sign messages with.
|
| options/nixos/services.crowdsec-firewall-bouncer.secrets.apiKeyPath | Path to the API key to authenticate with a local CrowdSec API
|
| options/home-manager/launchd.agents.<name>.config.Sockets.<name>.SockType | This optional key tells launchctl what type of socket to create
|
| options/nixos/services.misskey.reverseProxy.webserver.nginx.listen.*.addr | Listen address.
|
| options/nixos/services.misskey.reverseProxy.webserver.nginx.basicAuth | Basic Auth protection for a vhost
|
| options/nixos/services.misskey.reverseProxy.webserver.nginx.default | Makes this vhost the default.
|
| options/nixos/services.gitlab.secrets.jwsFile | A file containing the secret used to encrypt session
keys
|
| options/nixos/services.keycloak.plugins | Keycloak plugin jar, ear files or derivations containing
them
|
| options/nixos/programs.yubikey-manager.enable | Whether to enable yubikey-manager.
|
| options/nixos/services.pgpkeyserver-lite.hostname | Which hostname to set the vHost to that is proxying to sks.
|
| options/nixos/services.nginx.proxyCachePath.<name>.keysZoneName | Set name to shared memory zone.
|
| options/nixos/services.nginx.proxyCachePath.<name>.keysZoneSize | Set size to shared memory zone.
|
| options/nixos/services.misskey.reverseProxy.webserver.caddy.logFormat | Configuration for HTTP request logging (also known as access logs)
|
| options/darwin/launchd.agents.<name>.serviceConfig.GroupName | This optional key specifies the group to run the job as
|
| options/nixos/services.sharkey.openFirewall | Whether to open ports in the NixOS firewall for Sharkey.
|
| options/home-manager/programs.keychain.inheritType | Inherit type to attempt from agent variables from the environment.
|
| options/nixos/services.guix.publish.generateKeyPair | Whether to generate signing keys in /etc/guix which are
required to initialize a substitute server
|
| options/home-manager/programs.tmux.prefix | Set the prefix key
|
| options/nixos/services.oink.settings.secretApiKey | Secret API key to use when modifying DNS records.
|
| options/nixos/services.synergy.server.tls.enable | Whether TLS encryption should be used
|
| options/nixos/networking.wireless.networks.<name>.pskRaw | Either the raw pre-shared key in hexadecimal format
or the name of the secret (as defined inside
networking.wireless.secretsFile and prefixed
with ext:) containing the network pre-shared key.
Be aware that this will be written to the Nix store
in plaintext! Always use an external reference.
The external secret can be either the plaintext
passphrase or the raw pre-shared key.
Mutually exclusive with psk and auth.
|
| options/nixos/programs.wshowkeys.package | The wshowkeys package to use.
|
| options/nixos/services.rauc.slots | RAUC slot definitions
|
| options/nixos/services.misskey.reverseProxy.ssl | Whether to enable SSL for the reverse proxy
|
| options/nixos/services.misskey.reverseProxy.webserver.nginx.extraConfig | These lines go to the end of the vhost verbatim.
|
| options/nixos/services.headscale.settings.noise.private_key_path | Path to noise private key file, generated automatically if it does not exist.
|
| options/home-manager/programs.wlogout.layout.*.keybind | Keyboard character to trigger this action.
|
| options/darwin/launchd.agents.<name>.serviceConfig.Disabled | This optional key is used as a hint to launchctl(1) that it should not submit this job to launchd when
loading a job or jobs
|
| options/nixos/services.misskey.reverseProxy.webserver.nginx.listen.*.port | Port number to listen on
|
| options/home-manager/programs.cudatext.lexerHotkeys | Hotkeys settings specific to each lexer.
|
| options/nixos/services.yubikey-agent.enable | Whether to start yubikey-agent when you log in
|
| options/nixos/services.prometheus.remoteWrite.*.sigv4.access_key | The Access Key ID.
|
| options/nixos/services.prometheus.remoteWrite.*.sigv4.secret_key | The Secret Access Key.
|
| options/nixos/networking.wireguard.interfaces.<name>.peers.*.presharedKey | Base64 preshared key generated by wg genpsk
|
| options/nixos/services.nsd.zones.<name>.dnssecPolicy.keyttl | TTL for dnssec records
|
| options/nixos/services.misskey.reverseProxy.webserver.nginx.enableACME | Whether to ask Let's Encrypt to sign a certificate for this vhost
|
| options/darwin/launchd.user.agents.<name>.serviceConfig.Disabled | This optional key is used as a hint to launchctl(1) that it should not submit this job to launchd when
loading a job or jobs
|
| options/darwin/services.synergy.server.tls.enable | Whether to enable Whether TLS encryption should be used
|
| options/darwin/launchd.agents.<name>.serviceConfig.ServiceIPC | This optional key specifies whether the job participates in advanced
communication with launchd
|
| options/nixos/services.athens.tlsKeyFile | Path to the TLS key file.
|
| options/nixos/services.ircdHybrid.rsaKey | IRCD server RSA key.
|
| options/nixos/services.vsftpd.rsaKeyFile | RSA private key file.
|
| options/nixos/services.misskey.reverseProxy.webserver.caddy.extraConfig | Additional lines of configuration appended to this virtual host in the
automatically generated Caddyfile.
|
| options/nixos/services.postfix.sslKey | SSL key to use.
|
| options/home-manager/programs.cudatext.hotkeys | Hotkeys for Cudatext
|
| options/nixos/services.metabase.ssl.keystore | Java KeyStore file containing the certificates.
|
| options/darwin/launchd.user.agents.<name>.serviceConfig.GroupName | This optional key specifies the group to run the job as
|
| options/nixos/services.misskey.reverseProxy.webserver.nginx.http2 | Whether to enable the HTTP/2 protocol
|
| options/home-manager/launchd.agents.<name>.config.Sockets | This optional key is used to specify launch on demand sockets that can be used to let launchd know when
to run the job
|
| options/nixos/services.kmonad.keyboards.<name>.defcfg.fallthrough | Whether to enable re-emitting unhandled key events.
|
| options/nixos/services.zitadel.settings.TLS.KeyPath | Path to the TLS certificate private key.
|
| options/nixos/services.misskey.reverseProxy.webserver.nginx.listen | Listen addresses and ports for this virtual host
|
| options/nixos/services.postgrest.jwtSecretFile | The secret or JSON Web Key (JWK) (or set) used to decode JWT tokens clients provide for authentication
|
| options/nixos/services.misskey.reverseProxy.host | The fully qualified domain name to bind to
|
| options/home-manager/programs.ne.keybindings | Keybinding file for ne.
|