| options/nixos/security.pam.services.<name>.gnupg.enable | If enabled, pam_gnupg will attempt to automatically unlock the
user's GPG keys with the login password via
gpg-agent
|
| options/nixos/hardware.fw-fanctrl.package | The fw-fanctrl package to use.
|
| options/nixos/services.geoclue2.enableNmea | Whether to fetch location from NMEA sources on local network.
|
| options/nixos/services.firezone.server.api.trustedProxies | A list of trusted proxies
|
| options/nixos/programs.zsh.histSize | Change history size.
|
| options/nixos/services.ebusd.mqtt.password | The MQTT password.
|
| options/nixos/services.foundationdb.extraReadWritePaths | An extra set of filesystem paths that FoundationDB can read to
and write from
|
| options/nixos/services.beszel.agent.extraPath | Extra packages to add to beszel path (such as nvidia-smi or rocm-smi).
|
| options/nixos/services.headscale.settings.database.postgres.name | Database name.
|
| options/nixos/documentation.man.mandoc.cachePath | Change the paths where mandoc makewhatis(8)generates the
manual page index caches. documentation.man.generateCaches
should be enabled to allow cache generation
|
| options/nixos/services.lavalink.plugins.*.dependency | The coordinates of the plugin.
|
| options/nixos/security.tpm2.applyUdevRules | Whether to make the /dev/tpm[0-9] devices accessible by the tssUser, or
the /dev/tpmrm[0-9] by tssGroup respectively
|
| options/nixos/boot.initrd.luks.devices.<name>.keyFileOffset | The offset of the key file
|
| options/nixos/services.auto-epp.enable | Whether to enable auto-epp for amd active pstate.
|
| options/nixos/services.cfssl.metadata | Metadata file for root certificate presence
|
| options/nixos/services.dae.configFile | The path of dae config file, end with .dae.
|
| options/nixos/services.fedimintd.<name>.nginx.config.reuseport | Create an individual listening socket
|
| options/nixos/services.firewalld.settings.LogDenied | Add logging rules right before reject and drop rules in the INPUT, FORWARD and OUTPUT chains for the default rules and also final reject and drop rules in zones for the configured link-layer packet type.
|
| options/nixos/services.foundationdb.enable | Whether to enable FoundationDB Server.
|
| options/nixos/services.fedimintd.<name>.nginx.config.basicAuthFile | Basic Auth password file for a vhost
|
| options/nixos/services.bookstack.nginx.http3 | Whether to enable the HTTP/3 protocol
|
| options/nixos/services.gitDaemon.basePath | Remap all the path requests as relative to the given path
|
| options/nixos/services.gotenberg.enableBasicAuth | HTTP Basic Authentication
|
| options/nixos/services.headscale.settings.tls_letsencrypt_listen | When HTTP-01 challenge is chosen, letsencrypt must set up a
verification endpoint, and it will be listening on:
:http = port 80.
|
| options/nixos/services.jotta-cli.package | The jotta-cli package to use.
|
| options/nixos/networking.nat.forwardPorts.*.loopbackIPs | Public IPs for NAT reflection; for connections to loopbackip:sourcePort from the host itself and from other hosts behind NAT
|
| options/nixos/services.alps.bindIP | The IP the service should listen on.
|
| options/nixos/services.autorandr.profiles.<name>.hooks.preswitch | Preswitch hook executed before mode switch.
|
| options/nixos/services.bee.enable | Whether to enable Ethereum Swarm Bee.
|
| options/nixos/services.cfssl.intBundle | Path to intermediate certificate store.
|
| options/nixos/services.fcgiwrap.instances.<name>.socket.mode | Mode to be set on the UNIX socket
|
| options/nixos/programs.nano.syntaxHighlight | Whether to enable syntax highlight for various languages.
|
| options/nixos/services.akkoma.nginx.locations.<name>.root | Root directory for requests.
|
| options/nixos/services.h2o.defaultTLSRecommendations | By default, H2O, without prejudice, will use as many TLS versions &
cipher suites as it & the TLS library (OpenSSL) can support
|
| options/nixos/services.cook-cli.basePath | Path to the directory cook-cli will look for recipes.
|
| options/nixos/services.dolibarr.h2o.host | Set the host address for this virtual host
|
| options/nixos/services.jellyfin.transcoding.hardwareEncodingCodecs | Which codecs to enable for hardware encoding. h264 is always enabled.
|
| options/nixos/services.fediwall.settings.hideBots | Hide posts from bot accounts
|
| options/nixos/services.clatd.package | The clatd package to use.
|
| options/nixos/services.hadoop.hbase.thrift.openFirewall | Open firewall ports for HBase thrift.
|
| options/nixos/services.hologram-server.groupClassAttr | The objectclass attribute to search for groups when enableLdapRoles is true
|
| options/nixos/services.couchdb.enable | Whether to enable CouchDB Server.
|
| options/nixos/services.librespeed.downloadIPDB | Whether to download the IP info database before starting librespeed
|
| options/nixos/services.librespeed.settings | LibreSpeed configuration written as Nix expression
|
| options/nixos/services.athens.traceExporterURL | URL endpoint that traces will be sent to.
|
| options/nixos/services.buildbot-master.user | User the buildbot server should execute under.
|
| options/nixos/security.pam.mount.additionalSearchPaths | Additional programs to include in the search path of pam_mount
|
| options/nixos/programs.zsh.ohMyZsh.enable | Enable oh-my-zsh.
|
| options/nixos/security.tpm2.fapi.ekCertLess | A switch to disable Endorsement Key (EK) certificate verification
|
| options/nixos/services.ax25.axports.<name>.tty | Location of hardware kiss tnc for this interface.
|
| options/nixos/services.etcd.peerClientCertAuth | Whether to check all incoming peer requests from the cluster for valid client certificates signed by the supplied CA
|
| options/nixos/services.fedimintd.<name>.nginx.config.locations.<name>.uwsgiPass | Adds uwsgi_pass directive and sets recommended proxy headers if
recommendedUwsgiSettings is enabled.
|
| options/nixos/services.fediwall.nginx.rejectSSL | Whether to listen for and reject all HTTPS connections to this vhost
|
| options/nixos/services.gotosocial.enable | Whether to enable ActivityPub social network server.
|
| options/nixos/services.jitsi-meet.enable | Whether to enable Jitsi Meet - Secure, Simple and Scalable Video Conferences.
|
| options/nixos/services.bitwarden-directory-connector-cli.ldap.port | Port LDAP is accessible on.
|
| options/nixos/services.dysnomia.containers | An attribute set in which each key represents a container and each value an attribute set providing its configuration properties
|
| options/nixos/services.firezone.server.api.address | The address to listen on
|
| options/nixos/services.gitDaemon.listenAddress | Listen on a specific IP address or hostname.
|
| options/nixos/services.grafana.settings.security.cookie_samesite | Sets the SameSite cookie attribute and prevents the browser from sending this cookie along with cross-site requests
|
| options/nixos/services.influxdb2.provision.organizations.<name>.auths.<name>.present | Whether to ensure that this user is present or absent.
|
| options/nixos/programs.proxychains.proxies.<name>.port | Proxy port
|
| options/nixos/services.convos.reverseProxy | Enables reverse proxy support
|
| options/nixos/hardware.deviceTree.overlays.*.dtsFile | Path to .dts overlay file, overlay is applied to
each .dtb file matching "compatible" of the overlay.
|
| options/nixos/security.auditd.settings.space_left | If the free space in the filesystem containing log_file drops below this value, the audit daemon takes the action specified by
space_left_action
|
| options/nixos/services.cgminer.pools | List of pools where to mine
|
| options/nixos/services.disnix.profiles | Names of the Disnix profiles to expose in the system's PATH
|
| options/nixos/services.heisenbridge.namespaces | Configure the 'namespaces' section of the registration.yml for the bridge and the server
|
| options/nixos/services.kanboard.nginx.locations.<name>.basicAuth | Basic Auth protection for a vhost
|
| options/nixos/programs.hyprland.package | The hyprland package to use
|
| options/nixos/services.go-httpbin.package | The go-httpbin package to use.
|
| options/nixos/boot.zfs.forceImportRoot | Forcibly import the ZFS root pool(s) during early boot
|
| options/nixos/services.bonsaid.configFile | Path to a .json file specifying the state transitions
|
| options/nixos/services.borgmatic.configurations | Set of borgmatic configurations, see https://torsion.org/borgmatic/docs/reference/configuration/
|
| options/nixos/services.foundationdb.locality | FoundationDB locality settings.
|
| options/nixos/services.gemstash.settings.db_url | The database to connect to when using postgres, mysql, or mysql2.
|
| options/nixos/services.hadoop.yarn.resourcemanager.extraFlags | Extra command line flags to pass to the service
|
| options/nixos/hardware.sane.brscan5.netDevices.<name>.name | The friendly name you give to the network device
|
| options/nixos/programs.chromium.extraOpts | Extra chromium policy options
|
| options/nixos/services.komodo-periphery.logging.level | Logging verbosity level.
|
| options/nixos/services.gns3-server.auth.enable | Whether to enable password based HTTP authentication to access the GNS3 Server.
|
| options/nixos/environment.extraOutputsToInstall | Entries listed here will be appended to the meta.outputsToInstall attribute for each package in environment.systemPackages, and the files from the corresponding derivation outputs symlinked into /run/current-system/sw
|
| options/nixos/services.buildbot-master.titleUrl | Specifies the Buildbot TitleURL.
|
| options/nixos/services.bookstack.nginx.http3_hq | Whether to enable the HTTP/0.9 protocol negotiation used in QUIC interoperability tests
|
| options/nixos/services.calibre-web.options.calibreLibrary | Path to Calibre library.
|
| options/nixos/services.gancio.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| options/nixos/programs.neovim.runtime | Set of files that have to be linked in runtime.
|
| options/nixos/programs.regreet.settings | ReGreet configuration file
|
| options/nixos/services.bepasty.servers.<name>.defaultPermissions | default permissions for all unauthenticated accesses.
|
| options/nixos/services.cntlm.netbios_hostname | The hostname of your machine.
|
| options/nixos/services.grav.package | The grav package to use.
|
| options/nixos/services.lavalink.group | The group of the service.
|
| options/nixos/security.acme.certs.<name>.csrKey | Path to the private key to the matching certificate signing request.
|
| options/nixos/services.akkoma.nginx.locations.<name>.priority | Order of this location block in relation to the others in the vhost
|
| options/nixos/services.code-server.host | The host name or IP address the server should listen to.
|
| options/nixos/services.druid.middleManager.openFirewall | Open firewall ports for Druid middleManager.
|
| options/nixos/networking.jool.siit.<name>.framework | The framework to use for attaching Jool's translation to the exist
kernel packet processing rules
|
| options/nixos/programs.dublin-traceroute.package | The dublin-traceroute package to use.
|
| options/nixos/services.dovecot2.imapsieve.mailbox.*.causes | Only execute the administrator Sieve scripts for the mailbox configured with services.dovecot2.imapsieve.mailbox..name when one of the listed IMAPSIEVE causes apply
|
| options/nixos/services.grafana.settings.database.query_retries | This setting applies to sqlite3 only and controls the number of times the system retries a query when the database is locked.
|