| users.mysql.host | The hostname of the MySQL/MariaDB server
|
| services.h2o.hosts.<name>.host | Set the host address for this virtual host
|
| services.honk.host | The host name or IP address the server should listen to.
|
| services.flood.host | Host to bind webserver.
|
| services.db-rest.host | The host address the db-rest server should listen on.
|
| services.paisa.host | Host bind IP address.
|
| services.ympd.mpd.host | The host where MPD is listening.
|
| services.movim.h2o.host | Set the host address for this virtual host
|
| services.bcg.mqtt.host | Host where MQTT server is running.
|
| services.atuin.host | The host address the atuin server should listen on.
|
| services.zammad.host | Host address.
|
| services.hoogle.host | Set the host to bind on.
|
| services.immich.host | The host that immich will listen on.
|
| services.rustus.host | The host that rustus will connect to.
|
| services.tremor-rs.host | The host tremor should be listening on
|
| services.db-rest.redis.host | Redis host.
|
| services.ebusd.mqtt.host | Connect to MQTT broker on HOST.
|
| services.snipe-it.mail.host | Mail host address.
|
| services.ollama.host | The host address which the ollama server HTTP interface listens to.
|
| services.send.host | The hostname or IP address for Send to bind to.
|
| services.gitlab.host | GitLab host name
|
| services.open-webui.host | The host address which the Open-WebUI server HTTP interface listens to.
|
| services.prefect.host | Prefect server host
|
| services.beszel.hub.host | Host or address this beszel hub listens on.
|
| services.monica.mail.host | Mail host address.
|
| services.nipap.nipap-www.host | Host to bind to.
|
| services.code-server.host | The host name or IP address the server should listen to.
|
| services.etesync-dav.host | The server host address.
|
| services.dgraph.zero.host | The host which dgraph zero will be run on.
|
| services.litellm.host | The host address which the LiteLLM server HTTP interface listens to.
|
| security.sudo.extraRules.*.host | For what host this rule should apply.
|
| services.tabby.host | Specifies the hostname on which the tabby server HTTP interface listens.
|
| services.tmate-ssh-server.host | External host name
|
| services.immich.redis.host | The host that redis will listen on.
|
| security.sudo-rs.extraRules.*.host | For what host this rule should apply.
|
| services.dolibarr.h2o.host | Set the host address for this virtual host
|
| services.dgraph.alpha.host | The host which dgraph alpha will be run on.
|
| services.docuseal.host | DocuSeal host.
|
| security.duosec.host | Duo API hostname.
|
| services.llama-cpp.host | IP address the LLaMA C++ server listens on.
|
| services.outline.smtp.host | Host name or IP address of the SMTP server.
|
| services.weblate.smtp.host | SMTP host used when sending emails to users.
|
| services.alps.imaps.host | The IMAPS server address.
|
| services.alps.smtps.host | The SMTPS server address.
|
| services.send.redis.host | Redis server address.
|
| services.cachix-watch-store.host | Cachix host to connect to
|
| services.mame.hostAddr | IP address of the host system
|
| services.qui.settings.host | The host address qui listens on.
|
| services.docling-serve.host | The host address which the Docling Serve server HTTP interface listens to.
|
| services.agorakit.mail.host | Mail host address.
|
| services.avahi.hostName | Host name advertised on the LAN
|
| services.murmur.hostName | Host to bind to
|
| services.athens.index.mysql.host | Host for the MySQL database.
|
| services.trilium-server.host | The host address to bind to (defaults to localhost).
|
| services.octoprint.host | Host to bind OctoPrint to.
|
| services.hledger-web.host | Address to listen on.
|
| services.surrealdb.host | The host that surrealdb will connect to.
|
| services.dawarich.smtp.host | SMTP host used when sending emails to users.
|
| services.mastodon.smtp.host | SMTP host used when sending emails to users.
|
| services.peertube.redis.host | Redis host.
|
| services.mastodon.redis.host | Redis host.
|
| services.tt-rss.database.host | Host of the database
|
| services.cachix-agent.host | Cachix uri to use.
|
| services.bluemap.host | Domain on which nginx will serve the bluemap webapp
|
| services.gitea.database.host | Database host address.
|
| services.crabfit.api.host | The hostname of the API.
|
| services.devpi-server.host | domain/ip address to listen on
|
| services.snipe-it.database.host | Database host address.
|
| services.dawarich.redis.host | The redis host Dawarich will connect to.
|
| services.zammad.redis.host | Redis server address.
|
| services.soju.hostName | Server hostname.
|
| programs.ssh.knownHosts.<name>.hostNames | A list of host names and/or IP numbers used for accessing
the host's ssh service
|
| services.ente.api.settings.db.host | The database host
|
| services.uptermd.hostKey | Path to SSH host key
|
| services.bookstack.mail.host | Mail host address.
|
| services.moodle.database.host | Database host address.
|
| services.monica.database.host | Database host address.
|
| services.zammad.database.host | Database host address.
|
| services.h2o.hosts | The hosts config to be merged with the settings
|
| services.artalk.settings.host | Artalk server listen host
|
| services.gitlab.registry.host | GitLab container registry host name.
|
| services.headphones.host | Host to listen on.
|
| services.zabbixWeb.database.host | Database host address.
|
| services.phylactery.host | Listen host for Phylactery
|
| services.chisel-server.host | Address to listen on, falls back to 0.0.0.0
|
| services.smokeping.host | Host/IP to bind to for the web server
|
| services.linkwarden.host | The host that Linkwarden will listen on.
|
| services.chromadb.host | Defines the IP address by which ChromaDB will be accessible.
|
| services.mattermost.host | Host or address that this Mattermost instance listens on.
|
| services.pdfding.database.host | PostgreSQL host
|
| services.broadcast-box.web.host | Host address the HTTP server listens on
|
| services.forgejo.database.host | Database host address.
|
| services.redmine.database.host | Database host address.
|
| services.grocy.hostName | FQDN for the grocy instance.
|
| services.firezone.server.smtp.host | Outbound SMTP host
|
| services.snipe-it.hostName | The hostname to serve Snipe-IT on.
|
| services.livekit.redis.host | Address to bind local redis instance to.
|
| services.selfoss.database.host | Host of the database (has no effect if type is "sqlite").
|
| nix.buildMachines.*.hostName | The hostname of the build machine.
|
| services.misskey.settings.db.host | The PostgreSQL host.
|
| services.zabbixProxy.database.host | Database host address.
|
| services.vikunja.database.host | Database host address
|
| services.guacamole-server.host | The host name or IP address the server should listen to.
|
| services.legit.settings.server.host | Host address.
|
| services.zfs.autoReplication.host | Remote host where snapshots should be sent. lz4 is expected to be installed on this host.
|
| services.kimai.sites.<name>.database.host | Database host address.
|
| services.athens.index.postgres.host | Host for the Postgres database.
|
| services.openssh.knownHosts.<name>.hostNames | A list of host names and/or IP numbers used for accessing
the host's ssh service
|
| services.grafana.settings.smtp.host | Host to connect to.
|
| services.coder.database.host | Hostname hosting the database.
|
| services.fluidd.hostName | Hostname to serve fluidd on
|
| containers.<name>.hostBridge | Put the host-side of the veth-pair into the named bridge
|
| services.agorakit.database.host | Database host address.
|
| services.cloudlog.database.host | MySQL database host
|
| services.freshrss.database.host | Database host for FreshRSS.
|
| services.dolibarr.database.host | Database host address.
|
| services.zabbixServer.database.host | Database host address.
|
| services.docuseal.redis.host | Redis server address.
|
| services.nominatim.database.host | Host of the postgresql server
|
| services.openssh.hostKeys | NixOS can automatically generate SSH host keys
|
| services.writefreely.host | The public host name to serve.
|
| services.calibre-server.host | The interface on which to listen for connections
|
| services.stash.settings.host | The ip address that Stash should bind to.
|
| services.drupal.sites.<name>.database.host | Database host address.
|
| services.mastodon.database.host | Database host address or unix socket.
|
| services.peertube.database.host | Database host address or unix socket.
|
| services.jitsi-meet.hostName | FQDN of the Jitsi Meet instance.
|
| services.adguardhome.host | Host address to bind HTTP server to.
|
| boot.initrd.network.ssh.hostKeys | Specify SSH host keys to import into the initrd
|
| services.wiki-js.settings.db.host | Hostname or socket-path to connect to.
|
| services.ethercalc.host | Address to listen on (use 0.0.0.0 to allow access from any address).
|
| services.misskey.settings.redis.host | The Redis host.
|
| services.mpdscribble.host | Host for the mpdscribble daemon to search for a mpd daemon on.
|
| services.gammu-smsd.backend.sql.host | Database server address
|
| services.grafana.settings.database.host | Only applicable to MySQL or Postgres
|
| services.pihole-web.hostName | Domain name for the website.
|
| services.anuko-time-tracker.database.host | Database host.
|
| services.openvscode-server.host | The host name or IP address the server should listen to.
|
| services.pgbackrest.repos.<name>.host | Repository host when operating remotely
|
| services.szurubooru.server.host | The host address for Szurubooru to bind to.
|
| containers.<name>.hostAddress | The IPv4 address assigned to the host interface.
(Not used when hostBridge is set.)
|
| containers.<name>.hostAddress6 | The IPv6 address assigned to the host interface.
(Not used when hostBridge is set.)
|
| services.sympa.database.host | Database host address
|
| services.bookstack.database.host | Database host address.
|
| services.mediawiki.database.host | Database host address.
|
| services.omnom.settings.smtp.host | SMTP server hostname.
|
| services.discourse.redis.host | Redis server hostname.
|
| services.pdfding.hostName | Listen address for PdfDing
|
| services.warpgate.settings.ssh.host_key_verification | Specify host key verification action when connecting to a SSH target with unknown/differing host key.
|
| services.oncall.settings.db.conn.kwargs.host | Database host.
|
| services.gancio.settings.db.host | Connection string for the PostgreSQL database
|
| services.jupyterhub.host | Bind IP JupyterHub will be listening on
|
| services.crabfit.frontend.host | The hostname of the frontend.
|
| nixpkgs.hostPlatform | Specifies the platform where the NixOS configuration will run
|
| services.sourcehut.hg.redis.host | The redis host URL
|
| services.ncps.cache.hostName | The hostname of the cache server. This is used to generate the
private key used for signing store paths (.narinfo)
|
| services.tinc.networks.<name>.hostSettings | The name of the host in the network as well as the configuration for that host
|
| services.sourcehut.git.redis.host | The redis host URL
|
| services.sourcehut.hub.redis.host | The redis host URL
|
| services.sourcehut.man.redis.host | The redis host URL
|
| services.immich.database.host | Hostname or address of the postgresql server
|
| services.roundcube.database.host | Host of the postgresql server
|
| services.misskey.settings.redisForJobQueue.host | The Redis host.
|
| services.pretix.settings.database.host | Database host or socket path.
|
| services.invidious.database.host | The database host Invidious should use
|
| containers.<name>.bindMounts.<name>.hostPath | Location of the host path to be mounted.
|
| services.h2o.hosts.<name>.tls | TLS options for virtual host
|
| services.molly-brown.hostName | The hostname to respond to requests for
|
| services.sourcehut.meta.redis.host | The redis host URL
|
| services.sourcehut.todo.redis.host | The redis host URL
|
| services.pretix.settings.mail.host | Hostname of the SMTP server use for mail delivery.
|
| services.limesurvey.database.host | Database host address.
|
| services.misskey.settings.redisForPubsub.host | The Redis host.
|
| services.reposilite.database.host | Database host address.
|
| services.szurubooru.database.host | Host on which the PostgreSQL database runs.
|
| networking.hostId | The 32-bit host ID of the machine, formatted as 8 hexadecimal characters
|
| networking.hostFiles | Files that should be concatenated together to form /etc/hosts.
|
| services.nfs.server.hostName | Hostname or address on which NFS requests will be accepted
|
| services.plausible.mail.smtp.hostAddr | The host address of your smtp server.
|
| programs.ssh.hostKeyAlgorithms | Specifies the host key algorithms that the client wants to use in order of preference.
|
| services.sourcehut.pages.redis.host | The redis host URL
|
| services.sourcehut.paste.redis.host | The redis host URL
|
| services.sourcehut.lists.redis.host | The redis host URL
|
| services.mediawiki.nginx.hostName | The hostname to use for the nginx virtual host
|
| services.agorakit.hostName | The hostname to serve agorakit on.
|
| services.fediwall.hostName | The hostname to serve fediwall on.
|
| services.mainsail.hostName | Hostname to serve mainsail on
|
| services.h2o.hosts.<name>.acme | ACME options for virtual host.
|
| services.h2o.hosts.<name>.http | HTTP options for virtual host
|
| services.frigate.settings.mqtt.host | MQTT server hostname
|
| services.hedgedoc.settings.host | Address to listen on.
|
| services.pretalx.settings.database.host | Database host or socket path.
|
| services.sftpgo.settings.smtp.host | Location of SMTP email server
|
| services.tahoe.nodes.<name>.sftpd.hostPublicKeyFile | Path to the SSH host public key.
|
| containers.<name>.forwardPorts.*.hostPort | Source port of the external interface on host
|
| services.wordpress.sites.<name>.database.host | Database host address.
|
| services.misskey.reverseProxy.host | The fully qualified domain name to bind to
|
| users.mysql.pam.logging.hostColumn | The name of the column in the log table to which the name of the user
being authenticated is stored.
|
| services.jirafeau.hostName | URL of instance
|
| services.keter.globalKeterConfig.listeners.*.host | host
|
| services.glance.settings.server.host | Glance bind address
|
| services.sabnzbd.settings.misc.host | Address for the Web UI to listen on for incoming connections.
|
| services.sourcehut.builds.redis.host | The redis host URL
|
| services.bitlbee.hostName | Normally, BitlBee gets a hostname using getsockname()
|
| services.mattermost.database.host | Host to use for the database
|
| programs.proxychains.proxies.<name>.host | Proxy host or IP address.
|
| containers.<name>.extraVeths.<name>.hostBridge | Put the host-side of the veth-pair into the named bridge
|
| services.h2o.hosts.<name>.acme.enable | Whether to ask Let’s Encrypt to sign a certificate for this
virtual host
|
| services.librenms.database.host | Hostname or IP of the MySQL/MariaDB server
|
| services.writefreely.database.host | The database host to connect to.
|
| services.tahoe.nodes.<name>.sftpd.hostPrivateKeyFile | Path to the SSH host private key.
|
| services.taskchampion-sync-server.host | Host address on which to serve
|
| services.nebula.networks.<name>.listen.host | IP address to listen on.
|
| virtualisation.host.pkgs | Package set to use for the host-specific packages of the VM runner
|
| services.dawarich.database.host | Hostname or address of the postgresql server
|
| services.mqtt2influxdb.mqtt.host | Host where MQTT server is running.
|
| services.froide-govplan.hostName | FQDN for the froide-govplan instance.
|
| services.h2o.hosts.<name>.tls.port | Override the default TLS port for this virtual host.
|
| containers.<name>.extraVeths.<name>.hostAddress | The IPv4 address assigned to the host interface.
(Not used when hostBridge is set.)
|
| services.pgbackrest.repos.<name>.sftp-host | SFTP repository host
|
| services.munin-cron.hosts | Definitions of hosts of nodes to collect data from
|
| containers.<name>.extraVeths.<name>.hostAddress6 | The IPv6 address assigned to the host interface.
(Not used when hostBridge is set.)
|
| services.wstunnel.servers.<name>.listen.host | The hostname.
|
| services.nominatim.hostName | Hostname to use for the nginx vhost.
|
| services.roundcube.hostName | Hostname to use for the nginx vhost
|
| services.nextcloud.hostName | FQDN for the nextcloud instance.
|
| services.rutorrent.hostName | FQDN for the ruTorrent instance.
|
| services.h2o.hosts.<name>.http.port | Override the default HTTP port for this virtual host.
|
| services.nextcloud-spreed-signaling.hostName | The host name to bind the nginx virtual host to, if
config.services.nextcloud-spreed-signaling.configureNginx is set to true.
|
| services.armagetronad.servers.<name>.host | Host to listen on
|
| services.smokeping.hostName | DNS name for the urls generated in the cgi.
|
| services.tsidp.settings.hostName | The hostname to use for the tsnet node.
|
| services.misskey.settings.redisForTimelines.host | The Redis host.
|
| services.audiobookshelf.host | The host Audiobookshelf binds to.
|
| services.discourse.database.host | Discourse database hostname. null means
“prefer local unix socket connection”.
|
| services.xandikos.nginx.hostName | The hostname use to setup the virtualhost configuration
|
| services.tinc.networks.<name>.hosts | The name of the host in the network as well as the configuration for that host
|
| services.chatgpt-retrieval-plugin.host | The hostname or IP address for chatgpt-retrieval-plugin to bind to.
|
| services.nagios.virtualHost.hostName | Canonical hostname for the server.
|
| services.moodle.virtualHost.hostName | Canonical hostname for the server.
|
| services.collabora-online.aliasGroups.*.host | Hostname to allow or deny.
|
| services.zoneminder.database.host | Hostname hosting the database.
|
| services.scrutiny.collector.settings.host.id | Host ID for identifying/labelling groups of disks
|
| services.szurubooru.server.settings.smtp.host | Host of the SMTP server used to send reset password.
|
| services.sabnzbd.settings.servers.<name>.host | Hostname of the server
|
| services.keycloak.database.host | Hostname of the database to connect to
|
| services.scanservjs.settings.host | The IP to listen on.
|
| services.prometheus.scrapeConfigs.*.docker_sd_configs.*.host_networking_host | The host to use if the container is in host networking mode
|
| services.firefox-syncserver.database.host | Database host name. localhost is treated specially and inserts
systemd dependencies, other hostnames or IP addresses of the local machine do not.
|
| services.httpd.virtualHosts.<name>.hostName | Canonical hostname for the server.
|
| services.caddy.virtualHosts.<name>.hostName | Canonical hostname for the server.
|
| virtualisation.forwardPorts.*.host.port | The host port to be mapped.
|
| services.davis.hostname | Domain of the host to serve davis under
|
| services.postfixadmin.database.host | Host of the postgresql server
|
| networking.hostName | The name of the machine
|
| services.sourcehut.settings.mail.smtp-host | Outgoing SMTP host.
|
| services.misskey.settings.meilisearch.host | The Meilisearch host.
|
| services.scrutiny.settings.web.listen.host | Interface address for web application to bind to.
|
| services.trilium-server.nginx.hostName | The hostname use to setup the virtualhost configuration
|
| containers.<name>.extraVeths.<name>.forwardPorts.*.hostPort | Source port of the external interface on host
|
| services.wstunnel.servers.<name>.restrictTo.*.host | The hostname.
|
| services.linkwarden.database.host | Hostname or address of the postgresql server
|
| services.mqtt2influxdb.influxdb.host | Host where InfluxDB server is running.
|
| services.parsedmarc.settings.imap.host | The IMAP server hostname or IP address.
|
| services.parsedmarc.settings.smtp.host | The SMTP server hostname or IP address.
|
| services.invoiceplane.sites.<name>.database.host | Database host address.
|
| services.h2o.hosts.<name>.serverName | Server name to be used for this virtual host
|
| services.pgbackrest.stanzas.<name>.instances.<name>.host | PostgreSQL host for operating remotely.
|
| services.tinc.networks.<name>.hostSettings.<name>.addresses | The external address where the host can be reached
|
| services.matomo.hostname | URL of the host, without https prefix
|
| services.plausible.mail.smtp.hostPort | The port of your smtp server.
|
| services.teeworlds.server.hostName | Hostname for the server.
|
| services.mastodon.elasticsearch.host | Elasticsearch host
|
| hardware.nvidia-container-toolkit.mounts.*.hostPath | Host path.
|
| services.mollysocket.settings.host | Listening address of the web server
|
| virtualisation.forwardPorts.*.host.address | The IPv4 address of the host.
|
| services.zabbixWeb.httpd.virtualHost.hostName | Canonical hostname for the server.
|
| services.scrutiny.settings.web.influxdb.host | IP or hostname of the InfluxDB instance.
|
| services.headscale.settings.database.postgres.host | Database host address.
|
| virtualisation.vmware.host.extraPackages | Extra packages to be used with VMware host.
|
| services.listmonk.database.settings.smtp.*.host | Hostname for the SMTP server
|
| services.buildbot-worker.hostMessage | Description of this worker
|
| services.drupal.sites.<name>.virtualHost.hostName | Canonical hostname for the server.
|
| services.znapzend.zetup.<name>.destinations.<name>.host | Host to use for the destination dataset
|
| virtualisation.vmware.host.enable | This enables VMware host virtualisation for running VMs.
vmware-vmx will cause kcompactd0 due to
Transparent Hugepages feature in kernel
|
| services.bitmagnet.settings.postgres.host | Address, hostname or Unix socket path of the database server
|
| services.icecast.hostname | DNS name or IP address that will be used for the stream directory lookups or possibly the playlist generation if a Host header is not provided.
|
| services.libretranslate.host | The address the application should listen on.
|
| services.keycloak.settings.http-host | On which address Keycloak should accept new connections.
|
| services.h2o.hosts.<name>.tls.identity | Key / certificate pairs for the virtual host.
|
| services.awstats.configs.<name>.hostAliases | List of aliases the site has.
|
| services.tinc.networks.<name>.hostSettings.<name>.settings | Configuration for this host
|
| services.prometheus.exporters.dmarc.imap.host | Hostname of IMAP server to connect to.
|
| services.botamusique.settings.server.host | Hostname of the mumble server to connect to.
|
| services.h2o.hosts.<name>.settings | Attrset to be transformed into YAML for host config
|
| services.akkoma.config.":pleroma"."Pleroma.Web.Endpoint".url.host | Domain name of the instance.
|
| virtualisation.virtualbox.host.enable | Whether to enable VirtualBox.
In order to pass USB devices from the host to the guests, the user
needs to be in the vboxusers group.
|
| services.h2o.hosts.<name>.serverAliases | Additional names of virtual hosts served by this virtual host
configuration.
|
| services.tinc.networks.<name>.hostSettings.<name>.rsaPublicKey | Legacy RSA public key of the host in PEM format, including start and
end markers
|
| virtualisation.vmware.host.package | The vmware-workstation package to use.
|
| services.sogo.vhostName | Name of the nginx vhost
|
| services.wstunnel.servers.<name>.settings.restrict-to.*.host | The hostname.
|
| services.tinc.networks.<name>.hostSettings.<name>.subnets | The subnets which this tinc daemon will serve
|
| virtualisation.vmware.host.extraConfig | Add extra config to /etc/vmware/config
|
| services.postfixadmin.hostName | Hostname to use for the nginx vhost
|
| services.h2o.hosts.<name>.acme.useHost | An existing Let’s Encrypt certificate to use for this virtual
host
|
| services.limesurvey.virtualHost.hostName | Canonical hostname for the server.
|
| services.gitea-actions-runner.instances.<name>.hostPackages | List of packages, that are available to actions, when the runner is configured
with a host execution label.
|
| services.mediawiki.httpd.virtualHost.hostName | Canonical hostname for the server.
|
| services.nebula.networks.<name>.lighthouse.dns.host | IP address on which nebula lighthouse should serve DNS.
'localhost' is a good default to ensure the service does not listen on public interfaces;
use a Nebula address like 10.0.0.5 to make DNS resolution available to nebula hosts only.
|
| services.tinc.networks.<name>.hostSettings.<name>.addresses.*.port | The port where the host can be reached
|
| services.suricata.settings.host-mode | If the Suricata box is a router for the sniffed networks, set it to 'router'
|
| services.wordpress.sites.<name>.virtualHost.hostName | Canonical hostname for the server.
|
| services.sourcehut.settings."hg.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."man.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."git.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."hub.sr.ht".debug-host | Address to bind the debug server to.
|
| networking.hosts | Locally defined maps of hostnames to IP addresses.
|
| services.sourcehut.settings."meta.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."todo.sr.ht".debug-host | Address to bind the debug server to.
|
| services.icingaweb2.modules.monitoring.transports.<name>.host | Host for the api or remote transport
|
| services.limesurvey.httpd.virtualHost.hostName | Canonical hostname for the server.
|
| services.tinc.networks.<name>.hostSettings.<name>.addresses.*.address | The external IP address or hostname where the host can be reached.
|
| services.maddy.hostname | Hostname to use
|
| services.sourcehut.settings."paste.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."pages.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."lists.sr.ht".debug-host | Address to bind the debug server to.
|
| services.prometheus.exporters.unbound.unbound.host | Path to the unbound control socket
|
| virtualisation.virtualbox.host.addNetworkInterface | Automatically set up a vboxnet0 host-only network interface.
|
| virtualisation.virtualbox.host.package | The virtualbox package to use.
|
| services.sourcehut.settings."builds.sr.ht".debug-host | Address to bind the debug server to.
|
| services.openssh.settings.UseDns | Specifies whether sshd(8) should look up the remote host name, and to check that the resolved host name for
the remote IP address maps back to the very same IP address
|
| services.postgrest.settings.server-host | Where to bind the PostgREST web server.
The admin server will also bind here, but potentially exposes sensitive information
|
| services.seafile.seafileSettings.fileserver.host | The bind address used by seafile fileserver
|
| services.opensearch.settings."network.host" | Which port this service should listen on.
|
| services.lldap.settings.ldap_host | The host address that the LDAP server will be bound to.
|
| services.lldap.settings.http_host | The host address that the HTTP server will be bound to.
|
| services.monica.hostname | The hostname to serve monica on.
|
| services.nipap.settings.nipapd.db_host | PostgreSQL host to connect to
|
| services.nextcloud.config.dbhost | Database host (+port) or socket path
|
| services.hostapd.package | The hostapd package to use.
|
| services.r53-ddns.hostname | Manually specify the hostname
|
| services.samba-wsdd.hostname | Override (NetBIOS) hostname to be used (default hostname).
|
| services.mackerel-agent.settings.host_status.on_stop | Host status after agent shutdown.
|
| services.misskey.reverseProxy.webserver.caddy.hostName | Canonical hostname for the server.
|
| virtualisation.virtualbox.host.enableKvm | Enable KVM support for VirtualBox
|
| services.zabbixWeb.hostname | Hostname for either nginx or httpd.
|
| services.tinc.networks.<name>.hostSettings.<name>.subnets.*.address | The subnet of this host
|
| services.h2o.hosts.<name>.acme.root | Directory for the ACME challenge, which is public
|
| services.jitsi-videobridge.xmppConfigs.<name>.hostName | Hostname of the XMPP server to connect to
|
| services.kanboard.nginx | With this option, you can customize an NGINX virtual host which already
has sensible defaults for Kanboard
|
| services.h2o.hosts.<name>.tls.quic | Enables HTTP/3 over QUIC on the UDP port for TLS
|
| services.siproxd.hostsDenySip | Access control list for denying incoming
SIP registrations and traffic.
|
| virtualisation.virtualbox.host.headless | Use VirtualBox installation without GUI and Qt dependency
|
| services.mackerel-agent.settings.host_status.on_start | Host status after agent startup.
|
| services.agate.hostnames | Domain name of this Gemini server, enables checking hostname and port
in requests. (multiple occurrences means basic vhosts)
|
| <imports = [ pkgs.ghostunnel.services.default ]>.ghostunnel.target | Address to forward connections to (can be HOST:PORT or unix:PATH).
|
| <imports = [ pkgs.ghostunnel.services.default ]>.ghostunnel.listen | Address and port to listen on (can be HOST:PORT, unix:PATH).
|
| services.siproxd.hostsAllowSip | Access control list for incoming SIP traffic.
|
| services.siproxd.hostsAllowReg | Access control list for incoming SIP registrations.
|
| <imports = [ pkgs.ghostunnel.services.default ]>.ghostunnel.key | Path to certificate private key (PEM with private key)
|
| <imports = [ pkgs.ghostunnel.services.default ]>.ghostunnel.cert | Path to certificate (PEM with certificate chain)
|
| services.i2pd.proto.http.hostname | Expected hostname for WebUI.
|
| <imports = [ pkgs.ghostunnel.services.default ]>.ghostunnel.allowCN | Allow client if common name appears in the list.
|
| virtualisation.virtualbox.host.enableWebService | Build VirtualBox web service tool (vboxwebsrv) to allow managing VMs via other webpage frontend tools
|
| services.hitch.backend | The host and port Hitch connects to when receiving
a connection in the form [HOST]:PORT
|
| services.akkoma.nginx | Extra configuration for the nginx virtual host of Akkoma
|
| <imports = [ pkgs.ghostunnel.services.default ]>.ghostunnel.allowOU | Allow client if organizational unit name appears in the list.
|
| services.postfix.hostname | Hostname to use
|
| <imports = [ pkgs.ghostunnel.services.default ]>.ghostunnel.allowAll | If true, allow all clients, do not check client cert subject.
|
| <imports = [ pkgs.ghostunnel.services.default ]>.ghostunnel.allowDNS | Allow client if DNS subject alternative name appears in the list.
|
| <imports = [ pkgs.ghostunnel.services.default ]>.ghostunnel.allowURI | Allow client if URI subject alternative name appears in the list.
|
| services.frigate.hostname | Hostname of the nginx vhost to configure
|
| services.ghostunnel.enable | Whether to enable ghostunnel.
|
| <imports = [ pkgs.ghostunnel.services.default ]>.ghostunnel.package | Package to use for ghostunnel
|
| services.prometheus.alertmanagerGotify.gotifyEndpoint.host | The hostname or ip your gotify endpoint is running.
|
| fonts.enableGhostscriptFonts | Whether to add the fonts provided by Ghostscript (such as
various URW fonts and the “Base-14” Postscript fonts) to the
list of system fonts, making them available to X11
applications.
|
| <imports = [ pkgs.ghostunnel.services.default ]>.ghostunnel.cacert | Path to CA bundle file (PEM/X509)
|
| services.librenms.hostname | The hostname to serve LibreNMS on.
|
| services.geth.<name>.authrpc.vhosts | List of virtual hostnames from which to accept requests.
|
| services.ncdns.identity.hostmaster | An email address for the SOA record at the bit zone
|
| services.nitter.server.hostname | Hostname of the instance.
|
| services.movim.h2o | With this option, you can customize an H2O virtual host which already
has sensible defaults for Movim
|
| system.nssDatabases.hosts | List of hosts entries to configure in /etc/nsswitch.conf
|
| services.hostapd.enable | Whether to enable hostapd, a user space daemon for access point and
authentication servers
|
| services.mobilizon.settings.":mobilizon"."Mobilizon.Web.Endpoint".url.host | Your instance's hostname for generating URLs throughout the app
|
| services.mailman.enable | Enable Mailman on this host
|
| services.radicle.httpd.nginx | With this option, you can customize an nginx virtual host which already has sensible defaults for radicle-httpd
|
| services.firefox-syncserver.singleNode.hostname | Host name to use for this service.
|
| services.h2o.hosts.<name>.tls.policy | add will additionally listen for TLS connections. only will
disable TLS connections. force will redirect non-TLS traffic
to the TLS connection.
|
| services.vwifi.server.ports.vhost | The vhost port
|
| services.datadog-agent.hostname | The hostname to show in the Datadog dashboard (optional)
|
| services.tinc.networks.<name>.hostSettings.<name>.subnets.*.weight | Indicates the priority over identical Subnets owned by different nodes
|
| services.hostapd.radios.<name>.noScan | Disables scan for overlapping BSSs in HT40+/- mode
|
| virtualisation.virtualbox.host.enableExtensionPack | Whether to install the Oracle Extension Pack for VirtualBox.
You must set nixpkgs.config.allowUnfree = true in
order to use this
|
| services.ghostunnel.package | The ghostunnel package to use.
|
| services.tinc.networks.<name>.hostSettings.<name>.subnets.*.prefixLength | The prefix length of the subnet
|
| services.pingvin-share.hostname | The domain name of your instance
|
| services.hostapd.radios.<name>.band | Specifies the frequency band to use, possible values are 2g for 2.4 GHz,
5g for 5 GHz, 6g for 6 GHz and 60g for 60 GHz.
|
| services.anuko-time-tracker.hostname | The hostname to serve Anuko Time Tracker on.
|
| <imports = [ pkgs.ghostunnel.services.default ]>.ghostunnel.unsafeTarget | If set, does not limit target to localhost, 127.0.0.1, [::1], or UNIX sockets
|
| virtualisation.virtualbox.host.enableHardening | Enable hardened VirtualBox, which ensures that only the binaries in the
system path get access to the devices exposed by the kernel modules
instead of all users in the vboxusers group.
Disabling this can put your system's security at risk, as local users
in the vboxusers group can tamper with the VirtualBox device files.
|
| services.discourse.hostname | The hostname to serve Discourse on.
|
| services.bookstack.hostname | The hostname to serve BookStack on.
|
| services.ghostunnel.servers | Server mode ghostunnels (TLS listener -> plain TCP/UNIX target)
|
| services.movim.nginx | With this option, you can customize an Nginx virtual host which
already has sensible defaults for Movim
|
| <imports = [ pkgs.ghostunnel.services.default ]>.ghostunnel.keystore | Path to keystore (combined PEM with cert/key, or PKCS12 keystore)
|
| <imports = [ pkgs.ghostunnel.services.default ]>.ghostunnel.extraArguments | Extra arguments to pass to ghostunnel server
|
| services.lemmy.settings.hostname | The domain name of your instance (eg 'lemmy.ml').
|
| services.movim.h2o.acme.enable | Whether to ask Let’s Encrypt to sign a certificate for this
virtual host
|
| services.httpd.logPerVirtualHost | If enabled, each virtual host gets its own
access.log and
error.log, namely suffixed by the
hostName of the virtual host.
|
| services.hostapd.radios.<name>.wifi6.enable | Enables support for IEEE 802.11ax (WiFi 6, HE)
|
| services.tomcat.virtualHosts | List consisting of a virtual host name and a list of web applications to deploy on each virtual host
|
| services.actual.settings.hostname | The address to listen on
|
| services.hostapd.radios.<name>.wifi5.enable | Enables support for IEEE 802.11ac (WiFi 5, VHT)
|
| services.h2o.hosts.<name>.tls.identity.*.key-file | Path to key file
|
| services.gancio.settings.hostname | The domain name under which the server is reachable.
|
| services.nextcloud.notify_push.dbhost | Database host (+port) or socket path
|
| programs.ssh.knownHosts | The set of system-wide known SSH hosts
|
| services.zoneminder.hostname | The hostname on which to listen.
|
| services.etebase-server.settings.allowed_hosts.allowed_host1 | The main host that is allowed access.
|
| services.ghostunnel.servers.<name>.key | Path to certificate private key (PEM with private key)
|
| services.ghostunnel.servers.<name>.target | Address to forward connections to (can be HOST:PORT or unix:PATH).
|
| services.ghostunnel.servers.<name>.listen | Address and port to listen on (can be HOST:PORT, unix:PATH).
|
| services.onlyoffice.hostname | FQDN for the OnlyOffice instance.
|
| services.h2o.hosts.<name>.tls.extraSettings | Additional TLS/SSL-related configuration options
|
| services.ghostunnel.servers.<name>.cert | Path to certificate (PEM with certificate chain)
|
| services.fastnetmon-advanced.hostgroups | Hostgroups to declaratively load into FastNetMon Advanced
|
| services.bitwarden-directory-connector-cli.ldap.hostname | The host the LDAP is accessible on.
|
| services.hostapd.radios.<name>.driver | The driver hostapd will use.
nl80211 is used with all Linux mac80211 drivers.
none is used if building a standalone RADIUS server that does
not control any wireless/wired driver
|
| services.home-assistant.config.http.server_host | Only listen to incoming requests on specific IP/host
|
| services.icecream.daemon.hostname | Hostname of the daemon in the icecream infrastructure
|
| services.hostapd.radios.<name>.wifi7.enable | Enables support for IEEE 802.11be (WiFi 7, EHT)
|
| services.hostapd.radios.<name>.networks | This defines a BSS, colloquially known as a WiFi network
|
| services.slurm.enableStools | Whether to provide a slurm.conf file
|
| services.hostapd.radios.<name>.wifi6.require | Require stations (clients) to support WiFi 6 (HE) and disassociate them if they don't.
|
| services.ghostunnel.servers.<name>.allowCN | Allow client if common name appears in the list.
|
| services.hostapd.radios.<name>.wifi4.enable | Enables support for IEEE 802.11n (WiFi 4, HT)
|
| services.hostapd.radios.<name>.channel | The channel to operate on
|
| services.dolibarr.h2o | With this option, you can customize an H2O virtual host which already
has sensible defaults for Dolibarr
|
| services.nullmailer.config.defaulthost | The content of this attribute is appended to any address that
is missing a host name
|
| services.ghostunnel.servers.<name>.allowOU | Allow client if organizational unit name appears in the list.
|
| services.hostapd.radios.<name>.wifi4.require | Require stations (clients) to support WiFi 4 (HT) and disassociate them if they don't.
|
| services.hostapd.radios.<name>.wifi5.require | Require stations (clients) to support WiFi 5 (VHT) and disassociate them if they don't.
|
| services.ghostunnel.servers.<name>.allowAll | If true, allow all clients, do not check client cert subject.
|
| services.prometheus.scrapeConfigs.*.docker_sd_configs.*.host | Address of the Docker daemon.
|
| services.ghostunnel.servers.<name>.allowURI | Allow client if URI subject alternative name appears in the list.
|
| services.ghostunnel.servers.<name>.allowDNS | Allow client if DNS subject alternative name appears in the list.
|
| services.prometheus.exporters.fritz.settings.devices.*.host_info | Enable extended host info for this device. Warning: This will heavily increase scrape time.
|
| services.xonotic.settings.hostname | The name that will appear in the server list. $g_xonoticversion
gets replaced with the current version.
|
| services.castopod.database.hostname | Database hostname.
|
| services.biboumi.settings.hostname | The hostname served by the XMPP gateway
|
| services.h2o.hosts.<name>.tls.redirectCode | HTTP status used by globalRedirect & forceSSL
|
| services.ghostunnel.servers.<name>.cacert | Path to CA bundle file (PEM/X509)
|
| services.kubernetes.proxy.hostname | Kubernetes proxy hostname override.
|
| services.multipath.devices.*.ghost_delay | Sets the number of seconds that multipath will wait after creating a device with only ghost paths before marking it ready for use in systemd
|
| services.pixelfed.nginx | With this option, you can customize an nginx virtual host which already has sensible defaults for Pixelfed
|
| services.vsmartcard-vpcd.hostname | Hostname of a waiting vpicc server vpcd will be connecting to
|
| services.maubot.settings.server.hostname | The IP to listen on
|
| services.nextjs-ollama-llm-ui.hostname | The hostname under which the Ollama UI interface should be accessible
|
| services.hostapd.radios.<name>.networks.<name>.ssid | SSID to be used in IEEE 802.11 management frames.
|
| services.hostapd.radios | This option allows you to define APs for one or multiple physical radios
|
| <imports = [ pkgs.ghostunnel.services.default ]> | This is a modular service, which can be imported into a NixOS configuration using the system.services option.
|
| programs.ssh.knownHosts.<name>.publicKey | The public key data for the host
|
| services.ncdns.identity.hostname | The hostname of this ncdns instance, which defaults to the machine
hostname
|
| services.dolibarr.h2o.acme.enable | Whether to ask Let’s Encrypt to sign a certificate for this
virtual host
|
| services.hostapd.radios.<name>.settings | Extra configuration options to put at the end of global initialization, before defining BSSs
|
| services.inadyn.settings.custom.<name>.hostname | Hostname alias(es).
|
| services.hostapd.radios.<name>.networks.<name>.group | Members of this group can access the control socket for this interface.
|
| services.keycloak.settings.hostname | The hostname part of the public URL used as base for
all frontend requests
|
| services.hostapd.radios.<name>.networks.<name>.utf8Ssid | Whether the SSID is to be interpreted using UTF-8 encoding.
|
| virtualisation.forwardPorts.*.from | Controls the direction in which the ports are mapped:
"host" means traffic from the host ports
is forwarded to the given guest port.
"guest" means traffic from the guest ports
is forwarded to the given host port.
|
| services.dolibarr.nginx | With this option, you can customize an nginx virtual host which already has sensible defaults for Dolibarr
|
| services.openssh.generateHostKeys | Whether to generate SSH host keys
|
| services.kubernetes.kubelet.hostname | Kubernetes kubelet hostname override.
|
| services.movim.h2o.tls | TLS options for virtual host
|
| services.nullmailer.config.idhost | The content of this attribute is used when building the message-id
string for the message
|
| services.awstats.configs.<name>.webService.hostname | The hostname the web service appears under.
|
| services.bind.ipv4Only | Only use ipv4, even if the host supports ipv6.
|
| services.ghostunnel.servers.<name>.unsafeTarget | If set, does not limit target to localhost, 127.0.0.1, [::1], or UNIX sockets
|
| services.pinchflat.selfhosted | Use a weak secret
|
| services.redmine.components.ghostscript | Whether to enable exporting Gant diagrams as PDF..
|
| <imports = [ pkgs.ghostunnel.services.default ]>.ghostunnel.disableAuthentication | Disable client authentication, no client certificate will be required.
|
| services.hostapd.radios.<name>.networks.<name>.logLevel | Levels (minimum value for logged events):
0 = verbose debugging
1 = debugging
2 = informational messages
3 = notification
4 = warning
|
| services.filesender.database.hostname | Database hostname.
|
| services.movim.h2o.http | HTTP options for virtual host
|
| services.odoo.domain | Domain to host Odoo with nginx
|
| services.nifi.proxyHost | Allow requests from a specific host.
|
| services.rqbit.httpHost | The listen host for the HTTP API.
|
| services.movim.h2o.acme | ACME options for virtual host.
|
| services.nextcloud.settings.mail_smtphost | This depends on mail_smtpmode
|
| services.hostapd.radios.<name>.networks.<name>.apIsolate | Isolate traffic between stations (clients) and prevent them from
communicating with each other.
|
| services.ghostunnel.servers.<name>.keystore | Path to keystore (combined PEM with cert/key, or PKCS12 keystore)
|
| services.hostapd.radios.<name>.networks.<name>.macDeny | Specifies the MAC addresses to deny if macAcl is set to "deny" or "radius"
|
| services.pgpkeyserver-lite.hostname | Which hostname to set the vHost to that is proxying to sks.
|
| services.cjdns.ETHInterface.connectTo.<name>.hostname | Optional hostname to add to /etc/hosts; prevents reverse lookup failures.
|
| services.cjdns.UDPInterface.connectTo.<name>.hostname | Optional hostname to add to /etc/hosts; prevents reverse lookup failures.
|
| services.inadyn.settings.provider.<name>.hostname | Hostname alias(es).
|
| services.prosody.httpFileShare.http_host | To avoid an additional DNS record and certificate, you may set this option to your primary domain (e.g. "example.com")
or use a reverse proxy to handle the HTTP for that domain.
|
| services.davis.nginx.acmeFallbackHost | Host which to proxy requests to if ACME challenge is not found
|
| services.slskd.nginx.acmeFallbackHost | Host which to proxy requests to if ACME challenge is not found
|
| services.movim.nginx.acmeFallbackHost | Host which to proxy requests to if ACME challenge is not found
|
| services.snipe-it.nginx.acmeFallbackHost | Host which to proxy requests to if ACME challenge is not found
|
| services.hostapd.radios.<name>.networks.<name>.macAllow | Specifies the MAC addresses to allow if macAcl is set to "allow" or "radius"
|
| services.reposilite.settings.hostname | The hostname to bind to
|
| services.slskd.nginx | This option customizes the nginx virtual host set up for slskd.
|
| services.snipe-it.mail.port | Mail host port.
|
| services.openssh.knownHosts.<name>.publicKey | The public key data for the host
|
| services.ghostunnel.servers.<name>.extraArguments | Extra arguments to pass to ghostunnel server
|
| services.postfix.settings.main.myhostname | The internet hostname of this mail system
|
| services.akkoma.nginx.acmeFallbackHost | Host which to proxy requests to if ACME challenge is not found
|
| services.gancio.nginx.acmeFallbackHost | Host which to proxy requests to if ACME challenge is not found
|
| services.fluidd.nginx.acmeFallbackHost | Host which to proxy requests to if ACME challenge is not found
|
| services.monica.nginx.acmeFallbackHost | Host which to proxy requests to if ACME challenge is not found
|
| services.matomo.nginx.acmeFallbackHost | Host which to proxy requests to if ACME challenge is not found
|
| services.pgbackrest.repos | An attribute set of repositories as described in:
https://pgbackrest.org/configuration.html#section-repository
Each repository defaults to set repo-host to the attribute's name
|
| services.trafficserver.hosting | Partition the cache according to origin server or domain
Consult the
upstream documentation for more details.
|
| services.hostapd.radios.<name>.networks.<name>.settings | Extra configuration options to put at the end of this BSS's defintion in the
hostapd.conf for the associated interface
|
| containers.<name>.privateNetwork | Whether to give the container its own private virtual
Ethernet interface
|
| virtualisation.useHostCerts | If enabled, when NIX_SSL_CERT_FILE is set on the host,
pass the CA certificates from the host to the VM.
|
| services.hostapd.radios.<name>.wifi6.multiUserBeamformer | HE multi user beamformee support
|
| services.hostapd.radios.<name>.wifi7.multiUserBeamformer | EHT multi user beamformee support
|
| services.hostapd.radios.<name>.networks.<name>.bssid | Specifies the BSSID for this BSS
|
| services.nebula.networks.<name>.staticHostMap | The static host map defines a set of hosts with fixed IP addresses on the internet (or any network)
|
| services.fluidd.nginx | Extra configuration for the nginx virtual host of fluidd.
|
| services.gancio.nginx | Extra configuration for the nginx virtual host of gancio.
|
| services.davis.nginx | Use this option to customize an nginx virtual host
|
| services.monica.mail.port | Mail host port.
|
| services.hostapd.radios.<name>.dynamicConfigScripts | All of these scripts will be executed in lexicographical order before hostapd
is started, right after the global segment was generated and may dynamically
append global options the generated configuration file
|
| services.oncall.settings.oncall_host | FQDN for the Oncall instance.
|
| services.nullmailer.config.helohost | Sets the environment variable $HELOHOST which is used by the
SMTP protocol module to set the parameter given to the HELO command
|
| services.hostapd.radios.<name>.countryCode | Country code (ISO/IEC 3166-1)
|
| services.postfix.settings.main.relayhost | List of hosts to use for relaying outbound mail.
Putting the hostname in angled brackets, e.g. [relay.example.com], turns off MX and SRV lookups for the hostname.
https://www.postfix.org/postconf.5.html#relayhost
|
| services.etesync-dav.port | The server host port.
|
| services.patroni.name | The name of the host
|
| services.movim.h2o.tls.port | Override the default TLS port for this virtual host.
|
| services.hostapd.radios.<name>.wifi6.singleUserBeamformee | HE single user beamformee support
|
| services.hostapd.radios.<name>.wifi6.singleUserBeamformer | HE single user beamformer support
|
| services.spacecookie.settings.hostname | The hostname the service is reachable via
|
| services.hostapd.radios.<name>.wifi7.singleUserBeamformer | EHT single user beamformer support
|
| services.hostapd.radios.<name>.wifi7.singleUserBeamformee | EHT single user beamformee support
|
| services.caddy.virtualHosts.<name>.listenAddresses | A list of host interfaces to bind to for this virtual host.
|
| programs.ssh.knownHosts.<name>.publicKeyFile | The path to the public key file for the host
|
| services.bosun.influxHost | Host and port of the influxdb database.
|
| services.hostapd.radios.<name>.networks.<name>.macDenyFile | Specifies a file containing the MAC addresses to deny if macAcl is set to "deny" or "radius"
|
| services.hostapd.radios.<name>.networks.<name>.macAcl | Station MAC address -based authentication
|
| services.movim.h2o.http.port | Override the default HTTP port for this virtual host.
|
| services.prometheus.scrapeConfigs.*.dockerswarm_sd_configs.*.host | Address of the Docker daemon.
|
| services.agorakit.nginx.acmeFallbackHost | Host which to proxy requests to if ACME challenge is not found
|
| services.librenms.nginx.acmeFallbackHost | Host which to proxy requests to if ACME challenge is not found
|
| services.kanboard.nginx.acmeFallbackHost | Host which to proxy requests to if ACME challenge is not found
|
| services.dolibarr.nginx.acmeFallbackHost | Host which to proxy requests to if ACME challenge is not found
|
| services.fediwall.nginx.acmeFallbackHost | Host which to proxy requests to if ACME challenge is not found
|
| services.pixelfed.nginx.acmeFallbackHost | Host which to proxy requests to if ACME challenge is not found
|
| services.mainsail.nginx.acmeFallbackHost | Host which to proxy requests to if ACME challenge is not found
|
| services.hostapd.radios.<name>.networks.<name>.macAllowFile | Specifies a file containing the MAC addresses to allow if macAcl is set to "allow" or "radius"
|
| services.easytier.instances.<name>.settings.hostname | Hostname shown in peer list and web console.
|
| services.elasticsearch-curator.hosts | a list of elasticsearch hosts to connect to
|
| services.nghttpx.frontends.*.params.sni-fwd | When performing a match to select a backend server, SNI host
name received from the client is used instead of the request
host
|
| services.radicle.httpd.nginx.acmeFallbackHost | Host which to proxy requests to if ACME challenge is not found
|
| services.h2o.hosts.<name>.tls.identity.*.certificate-file | Path to certificate file
|
| services.anuko-time-tracker.nginx.acmeFallbackHost | Host which to proxy requests to if ACME challenge is not found
|
| services.nginx.virtualHosts.<name>.acmeFallbackHost | Host which to proxy requests to if ACME challenge is not found
|
| networking.ucarp.srcIp | Source (real) IP address of this host.
|
| services.slskd.domain | If non-null, enables an nginx reverse proxy virtual host at this FQDN,
at the path configurated with services.slskd.web.url_base.
|
| services.parsedmarc.provision.localMail.hostname | The hostname to use when configuring Postfix
|
| services.nghttpx.backends.*.params.dns | Name resolution of a backends host name is done at start up,
or configuration reload
|
| services.bookstack.nginx.acmeFallbackHost | Host which to proxy requests to if ACME challenge is not found
|
| services.prosody.admins | List of administrators of the current host
|
| containers | A set of NixOS system configurations to be run as lightweight
containers
|
| services.hostapd.radios.<name>.wifi5.capabilities | VHT (Very High Throughput) capabilities given as a list of flags
|
| services.dolibarr.h2o.tls | TLS options for virtual host
|
| services.cntlm.netbios_hostname | The hostname of your machine.
|
| services.open-web-calendar.settings.ALLOWED_HOSTS | The hosts that the Open Web Calendar permits
|
| services.h2o.hosts.<name>.tls.recommendations | By default, H2O, without prejudice, will use as many TLS versions &
cipher suites as it & the TLS library (OpenSSL) can support
|
| services.nextcloud.config.objectstore.s3.hostname | Required for some non-Amazon implementations.
|
| services.hostapd.radios.<name>.wifi4.capabilities | HT (High Throughput) capabilities given as a list of flags
|
| services.jirafeau.nginxConfig.acmeFallbackHost | Host which to proxy requests to if ACME challenge is not found
|
| services.openssh.knownHosts.<name>.publicKeyFile | The path to the public key file for the host
|
| services.nitter.cache.redisHost | Redis host.
|
| services.unpoller.loki.url | URL of the Loki host.
|
| security.ipa.ipaHostname | Fully-qualified hostname used to identify this host in the IPA domain.
|
| services.hostapd.radios.<name>.wifi6.operatingChannelWidth | Determines the operating channel width for HE.
- "20or40": 20 or 40 MHz operating channel width
- "80": 80 MHz channel width
- "160": 160 MHz channel width
- "80+80": 80+80 MHz channel width
|
| services.hostapd.radios.<name>.wifi5.operatingChannelWidth | Determines the operating channel width for VHT.
- "20or40": 20 or 40 MHz operating channel width
- "80": 80 MHz channel width
- "160": 160 MHz channel width
- "80+80": 80+80 MHz channel width
|
| services.hostapd.radios.<name>.wifi7.operatingChannelWidth | Determines the operating channel width for EHT.
- "20or40": 20 or 40 MHz operating channel width
- "80": 80 MHz channel width
- "160": 160 MHz channel width
- "80+80": 80+80 MHz channel width
|
| services.zabbixWeb.nginx.virtualHost.acmeFallbackHost | Host which to proxy requests to if ACME challenge is not found
|
| services.dolibarr.h2o.acme | ACME options for virtual host.
|
| services.dolibarr.h2o.http | HTTP options for virtual host
|
| services.tayga.mappings | Static IPv4 -> IPv6 host mappings.
|
| services.movim.h2o.serverName | Server name to be used for this virtual host
|
| services.agorakit.mail.port | Mail host port.
|
| services.flannel.iface | Interface to use (IP or name) for inter-host communication
|
| services.mainsail.nginx | Extra configuration for the nginx virtual host of mainsail.
|
| services.saunafs.masterHost | IP or hostname name of master host.
|
| services.prometheus.exporters.smokeping.hosts | List of endpoints to probe.
|
| services.pretix.nginx.enable | Whether to set up an nginx virtual host.
|
| services.pretix.nginx.domain | The domain name under which to set up the virtual host.
|
| services.lasuite-meet.bind | The path, host/port or file descriptior to bind the gunicorn socket to
|
| services.lasuite-docs.bind | The path, host/port or file descriptior to bind the gunicorn socket to
|
| services.firezone.server.provision.accounts.<name>.features.self_hosted_relays | Whether to enable the self_hosted_relays feature for this account.
|
| services.printing.cups-pdf.instances.<name>.settings.GhostScript | location of GhostScript binary
|
| services.openssh.authorizedKeysFiles | Specify the rules for which files to read on the host
|
| programs.ssh.extraConfig | Extra configuration text prepended to ssh_config
|
| nix.settings.extra-sandbox-paths | Directories from the host filesystem to be included
in the sandbox.
|
| services.hitch.frontend | The port and interface of the listen endpoint in the
form [HOST]:PORT[+CERT].
|
| services.mobilizon.settings.":mobilizon".":instance".hostname | Your instance's hostname
|
| nix.buildMachines.*.sshUser | The username to log in as on the remote host
|
| services.davis.nginx.serverName | Name of this virtual host
|
| services.gitea.database.port | Database host port.
|
| services.slskd.nginx.serverName | Name of this virtual host
|
| services.movim.nginx.serverName | Name of this virtual host
|
| services.mailman.ldap.serverUri | LDAP host to connect against.
|
| services.keycloak.settings.hostname-backchannel-dynamic | Enables dynamic resolving of backchannel URLs,
including hostname, scheme, port and context path
|
| services.flannel.publicIp | IP accessible by other nodes for inter-host communication
|
| services.snipe-it.nginx.serverName | Name of this virtual host
|
| services.snipe-it.appURL | The root URL that you want to host Snipe-IT on
|
| services.snipe-it.database.port | Database host port.
|
| programs.ssh.knownHostsFiles | Files containing SSH host keys to set as global known hosts.
/etc/ssh/ssh_known_hosts (which is
generated by programs.ssh.knownHosts) is
always included.
|
| services.fedimintd.<name>.nginx.config.acmeFallbackHost | Host which to proxy requests to if ACME challenge is not found
|
| virtualisation.forwardPorts | When using the SLiRP user networking (default), this option allows to
forward ports to/from the host/guest.
If the NixOS firewall on the virtual machine is enabled, you also
have to open the guest ports to enable the traffic between host and
guest.
Currently QEMU supports only IPv4 forwarding.
|
| services.strongswan-swanctl.swanctl.connections.<name>.children.<name>.hostaccess | Hostaccess variable to pass to updown script
|
| services.hostapd.radios.<name>.networks.<name>.dynamicConfigScripts | All of these scripts will be executed in lexicographical order before hostapd
is started, right after the bss segment was generated and may dynamically
append bss options to the generated configuration file
|
| services.echoip.virtualHost | Name of the nginx virtual host to use and setup
|
| services.dolibarr.h2o.tls.port | Override the default TLS port for this virtual host.
|
| services.sunshine.enable | Whether to enable Sunshine, a self-hosted game stream host for Moonlight.
|
| services.jibri.enable | Whether to enable Jitsi BRoadcasting Infrastructure
|
| networking.useHostResolvConf | In containers, whether to use the
resolv.conf supplied by the host.
|
| services.pretalx.nginx.enable | Whether to set up an nginx virtual host.
|
| services.tomcat.logPerVirtualHost | Whether to enable logging per virtual host.
|
| services.pretalx.nginx.domain | The domain name under which to set up the virtual host.
|
| services.httpd.virtualHosts | Specification of the virtual hosts served by Apache
|
| services.nagios.objectDefs | A list of Nagios object configuration files that must define
the hosts, host groups, services and contacts for the
network that you want Nagios to monitor.
|
| services.bookstack.mail.port | Mail host port.
|
| services.fail2ban.bantime | Number of seconds that a host is banned.
|
| services.fluidd.nginx.serverName | Name of this virtual host
|
| services.bosun.listenAddress | The host address and port that bosun's web interface will listen on.
|
| services.akkoma.nginx.serverName | Name of this virtual host
|
| services.gancio.nginx.serverName | Name of this virtual host
|
| services.dolibarr.h2o.http.port | Override the default HTTP port for this virtual host.
|
| services.moodle.database.port | Database host port.
|
| services.matomo.nginx.serverName | Name of this virtual host
|
| services.monica.database.port | Database host port.
|
| services.movim.h2o.tls.identity | Key / certificate pairs for the virtual host.
|
| services.oauth2-proxy.passHostHeader | Pass the request Host Header to upstream.
|
| services.monica.nginx.serverName | Name of this virtual host
|
| services.warpgate.settings.external_host | Configure the domain name of this Warpgate instance
|
| services.convos.listenAddress | Address or host the web interface should listen on
|
| services.doh-server.useACMEHost | A host of an existing Let's Encrypt certificate to use.
Note that this option does not create any certificates, nor it does add subdomains to existing ones – you will need to create them manually using security.acme.certs.
|
| networking.ucarp.neutral | Do not run downscript at start if the host is the backup.
|
| virtualisation.restrictNetwork | If this option is enabled, the guest will be isolated, i.e. it will
not be able to contact the host and no guest IP packets will be
routed over the host to the outside
|
| services.samba-wsdd.enable | Whether to enable Web Services Dynamic Discovery host daemon
|
| services.nullmailer.config.adminaddr | If set, all recipients to users at either "localhost" (the literal string)
or the canonical host name (from the me control attribute) are remapped to this address
|
| virtualisation.libvirtd.qemu.vhostUserPackages | Packages containing out-of-tree vhost-user drivers.
|
| services.prometheus.exporters.fritz.settings.devices.*.hostname | Hostname under which the target device is reachable.
|
| services.hardware.lcd.serverHost | Host on which LCDd is listening.
|
| services.ntopng.redis.address | Redis address - may be a Unix socket or a network host and port.
|
| services.zabbixWeb.database.port | Database host port.
|
| services.pgbackrest.stanzas.<name>.instances | An attribute set of database instances as described in:
https://pgbackrest.org/configuration.html#section-stanza
Each instance defaults to set pg-host to the attribute's name
|
| services.fakeroute.route | Fake route that will appear after the real
one to any host running a traceroute.
|
| services.anki-sync-server.address | IP address anki-sync-server listens to
|
| services.monica.appURL | The root URL that you want to host monica on
|
| services.nebula.networks.<name>.key | Path or reference to the host key.
|
| services.prefect.databaseHost | database host for postgres only
|
| services.lxd-image-server.nginx.domain | Domain to use for nginx virtual host.
|
| services.movim.h2o.serverAliases | Additional names of virtual hosts served by this virtual host
configuration.
|
| services.ghostunnel.servers.<name>.disableAuthentication | Disable client authentication, no client certificate will be required.
|
| services.limesurvey.nginx.virtualHost.acmeFallbackHost | Host which to proxy requests to if ACME challenge is not found
|
| services.ente.web.domains.api | The domain under which the api is served
|
| services.flannel.subnetLen | The size of the subnet allocated to each host
|
| services.dockerRegistry.redisUrl | Set redis host and port.
|
| services.bosun.opentsdbHost | Host and port of the OpenTSDB database that stores bosun data
|
| services.nebula.networks.<name>.cert | Path to the host certificate.
|
| services.jirafeau.nginxConfig | Extra configuration for the nginx virtual host of Jirafeau.
|
| services.forgejo.database.port | Database host port.
|
| services.diod.statfsPassthru | This option configures statfs to return the host file system's type
rather than V9FS_MAGIC.
|
| services.go-httpbin.settings.HOST | The host to listen on.
|
| services.redmine.database.port | Database host port.
|
| services.part-db.enableNginx | Whether to enable nginx or not
|
| networking.ucarp.preempt | Enable preemptive failover
|
| services.movim.h2o.settings | Attrset to be transformed into YAML for host config
|
| services.moonraker.address | The IP or host to listen on.
|
| users.mysql.pam.logging.rHostColumn | The name of the column in the log table to which the name of the remote
host that initiates the session is stored
|
| services.pcscd.extendReaderNames | String to append to every reader name
|
| services.misskey.reverseProxy.webserver.caddy.listenAddresses | A list of host interfaces to bind to for this virtual host.
|
| services.fail2ban.maxretry | Number of failures before a host gets banned.
|
| services.riemann-tools.riemannHost | Address of the host riemann node
|
| services.zabbixProxy.database.port | Database host port.
|
| services.dolibarr.h2o.serverName | Server name to be used for this virtual host
|
| nix.buildMachines.*.publicHostKey | The (base64-encoded) public host key of this builder
|
| services.hostapd.radios.<name>.networks.<name>.ignoreBroadcastSsid | Send empty SSID in beacons and ignore probe request frames that do not
specify full SSID, i.e., require stations to know SSID
|
| services.documize.db | Database specific connection string for example:
- MySQL/Percona/MariaDB:
user:password@tcp(host:3306)/documize
- MySQLv8+:
user:password@tcp(host:3306)/documize?allowNativePasswords=true
- PostgreSQL:
host=localhost port=5432 dbname=documize user=admin password=secret sslmode=disable
- MSSQL:
sqlserver://username:password@localhost:1433?database=Documize or
sqlserver://sa@localhost/SQLExpress?database=Documize
|
| services.plantuml-server.listenHost | Host to listen on.
|
| services.davis.nginx.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.slskd.nginx.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.movim.nginx.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| networking.fqdn | The fully qualified domain name (FQDN) of this host
|
| services.snipe-it.nginx.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.graphite.seyren.seyrenUrl | Host where seyren is accessible.
|
| services.kimai.sites.<name>.database.port | Database host port.
|
| boot.initrd.network.ssh.ignoreEmptyHostKeys | Allow leaving config.boot.initrd.network.ssh.hostKeys empty,
to deploy ssh host keys out of band.
|
| services.davis.nginx.listen | Listen addresses and ports for this virtual host
|
| services.i2pd.proto.http.strictHeaders | Enable strict host checking on WebUI.
|
| services.unpoller.influxdb.url | URL of the influxdb host.
|
| services.movim.nginx.listen | Listen addresses and ports for this virtual host
|
| services.slskd.nginx.listen | Listen addresses and ports for this virtual host
|
| services.youtrack.virtualHost | Name of the nginx virtual host to use and setup
|
| programs.ssh.knownHosts.<name>.extraHostNames | A list of additional host names and/or IP numbers used for
accessing the host's ssh service
|
| services.parsedmarc.settings.elasticsearch.hosts | A list of Elasticsearch hosts to push parsed reports
to.
|
| networking.fqdnOrHostName | Either the fully qualified domain name (FQDN), or just the host name if
it does not exist
|
| services.cadvisor.listenAddress | Cadvisor listening host
|
| services.static-web-server.listen | The systemd.socket(5) "ListenStream" used in static-web-server.socket
|
| services.snipe-it.nginx.listen | Listen addresses and ports for this virtual host
|
| services.lasuite-meet.settings.DB_HOST | Host of the database
|
| services.lasuite-docs.settings.DB_HOST | Host of the database
|
| services.misskey.reverseProxy.webserver.nginx.acmeFallbackHost | Host which to proxy requests to if ACME challenge is not found
|
| services.seafile.seahubAddress | Which address to bind the seahub server to, of the form:
|
| virtualisation.oci-containers.containers.<name>.hostname | The hostname of the container.
|
| services.nextcloud.notify_push.bendDomainToLocalhost | Whether to add an entry to /etc/hosts for the configured nextcloud domain to point to localhost and add localhost to nextcloud's trusted_proxies config option
|
| services.nextcloud-spreed-signaling.settings.backend.connectionsperhost | Maximum number of concurrent backend connections per host
|
| services.fedimintd.<name>.nginx.path | Path to host the API on and forward to the daemon's api port
|
| services.dolibarr.database.port | Database host port.
|
| services.agorakit.nginx.serverName | Name of this virtual host
|
| services.agorakit.database.port | Database host port.
|
| services.dolibarr.nginx.serverName | Name of this virtual host
|
| services.librenms.nginx.serverName | Name of this virtual host
|
| services.kanboard.nginx.serverName | Name of this virtual host
|
| services.fediwall.nginx.serverName | Name of this virtual host
|
| services.peertube.database.port | Database host port.
|
| services.pixelfed.nginx.serverName | Name of this virtual host
|
| services.mastodon.database.port | Database host port.
|
| services.mainsail.nginx.serverName | Name of this virtual host
|
| containers.<name>.macvlans | The list of host interfaces from which macvlans will be
created
|
| services.zabbixServer.database.port | Database host port.
|
| services.boinc.allowRemoteGuiRpc | If set to true, any remote host can connect to and control this BOINC
client (subject to password authentication)
|
| services.gancio.nginx.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.fluidd.nginx.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.akkoma.nginx.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.matomo.nginx.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.monica.nginx.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.umami.settings.BASE_PATH | Allows you to host Umami under a subdirectory
|
| services.akkoma.nginx.listen | Listen addresses and ports for this virtual host
|
| services.drupal.sites.<name>.database.port | Database host port.
|
| services.gancio.nginx.listen | Listen addresses and ports for this virtual host
|
| services.fluidd.nginx.listen | Listen addresses and ports for this virtual host
|
| networking.ucarp.deadratio | Ratio to consider a host as dead.
|
| services.gemstash.settings.bind | Host and port combination for the server to listen on.
|
| services.monica.nginx.listen | Listen addresses and ports for this virtual host
|
| services.matomo.nginx.listen | Listen addresses and ports for this virtual host
|
| services.resolved.llmnr | Controls Link-Local Multicast Name Resolution support
(RFC 4795) on the local host
|
| services.agorakit.appURL | The root URL that you want to host agorakit on
|
| services.scollector.bosunHost | Host and port of the bosun server that will store the collected
data.
|
| services.mobilizon.nginx.enable | Whether an Nginx virtual host should be
set up to serve Mobilizon.
|
| services.radicle.httpd.nginx.serverName | Name of this virtual host
|
| services.kanidm.provision.systems.oauth2.<name>.enableLocalhostRedirects | Allow localhost redirects
|
| containers.<name>.forwardPorts | List of forwarded ports from host to container
|
| services.fail2ban.ignoreIP | "ignoreIP" can be a list of IP addresses, CIDR masks or DNS hosts
|
| services.dolibarr.h2o.tls.identity | Key / certificate pairs for the virtual host.
|
| services.cadvisor.storageDriverHost | Cadvisor storage driver host.
|
| services.davis.nginx.globalRedirect | If set, all requests for this host are redirected (defaults to 301,
configurable with redirectCode) to the given hostname.
|
| services.slskd.nginx.globalRedirect | If set, all requests for this host are redirected (defaults to 301,
configurable with redirectCode) to the given hostname.
|
| services.movim.nginx.globalRedirect | If set, all requests for this host are redirected (defaults to 301,
configurable with redirectCode) to the given hostname.
|
| services.homer.virtualHost.domain | Domain to use for the virtual host
|
| services.anuko-time-tracker.nginx.serverName | Name of this virtual host
|
| services.dashy.virtualHost.domain | Domain to use for the virtual host
|
| services.nginx.virtualHosts.<name>.serverName | Name of this virtual host
|
| services.snipe-it.nginx.globalRedirect | If set, all requests for this host are redirected (defaults to 301,
configurable with redirectCode) to the given hostname.
|
| services.firefly-iii.enableNginx | Whether to enable nginx or not
|
| services.nominatim.enable | Whether to enable nominatim
|
| systemd.sysupdate.enable | Atomically update the host OS, container images, portable service
images or other sources
|
| services.hostapd.radios.<name>.networks.<name>.authentication.saeAddToMacAllow | If set, all sae password entries that have a non-wildcard MAC associated to
them will additionally be used to populate the MAC allow list
|
| services.filebeat.settings.output.elasticsearch.hosts | The list of Elasticsearch nodes to connect to
|
| services.dolibarr.h2o.serverAliases | Additional names of virtual hosts served by this virtual host
configuration.
|
| services.bookstack.database.port | Database host port.
|
| services.bookstack.nginx.serverName | Name of this virtual host
|
| services.hatsu.settings.HATSU_LISTEN_HOST | Host where hatsu should listen for incoming requests.
|
| programs.extra-container.enable | Whether to enable extra-container, a tool for running declarative NixOS containers
without host system rebuilds
.
|
| services.oauth2-proxy.cookie.domain | Optional cookie domains to force cookies to (ie: .yourcompany.com)
|
| services.mediawiki.database.port | Database host port.
|
| services.roundcube.enable | Whether to enable roundcube
|
| services.warpgate.settings.ssh.keys | Path to store SSH host & client keys.
|
| services.bookstack.appURL | The root URL that you want to host BookStack on
|
| services.davis.nginx.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.movim.nginx.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.slskd.nginx.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.movim.h2o.acme.useHost | An existing Let’s Encrypt certificate to use for this virtual
host
|
| services.nullmailer.config.me | The fully-qualifiled host name of the computer running nullmailer
|
| services.akkoma.nginx.globalRedirect | If set, all requests for this host are redirected (defaults to 301,
configurable with redirectCode) to the given hostname.
|
| services.fluidd.nginx.globalRedirect | If set, all requests for this host are redirected (defaults to 301,
configurable with redirectCode) to the given hostname.
|
| services.gancio.nginx.globalRedirect | If set, all requests for this host are redirected (defaults to 301,
configurable with redirectCode) to the given hostname.
|
| services.monica.nginx.globalRedirect | If set, all requests for this host are redirected (defaults to 301,
configurable with redirectCode) to the given hostname.
|
| services.matomo.nginx.globalRedirect | If set, all requests for this host are redirected (defaults to 301,
configurable with redirectCode) to the given hostname.
|
| services.bitlbee.interface | The interface the BitlBee daemon will be listening to
|
| services.snipe-it.nginx.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.wordpress.sites.<name>.fontsDir | This directory is used to download fonts from a remote location, e.g.
to host google fonts locally.
|
| services.awstats.configs.<name>.logFormat | The log format being used
|
| services.ncps.upstream.publicKeys | A list of public keys of upstream caches in the format
host[-[0-9]*]:public-key
|
| services.caddy.virtualHosts.<name>.extraConfig | Additional lines of configuration appended to this virtual host in the
automatically generated Caddyfile.
|
| services.dolibarr.h2o.settings | Attrset to be transformed into YAML for host config
|
| services.discourse.nginx.enable | Whether an nginx virtual host should be
set up to serve Discourse
|
| services.librespeed.useACMEHost | Use a certificate generated by the NixOS ACME module for the given host
|
| services.hedgedoc.settings.path | Path to UNIX domain socket to listen on
If specified, host and port will be ignored.
|
| services.graphite.seyren.graphiteUrl | Host where graphite service runs.
|
| programs.browserpass.enable | Whether to enable Browserpass native messaging host.
|
| services.nagios.virtualHost.listen | Listen addresses and ports for this virtual host.
This option overrides addSSL, forceSSL and onlySSL
|
| services.moodle.virtualHost.listen | Listen addresses and ports for this virtual host.
This option overrides addSSL, forceSSL and onlySSL
|
| services.sourcehut.nginx.virtualHost | Virtual-host configuration merged with all Sourcehut's virtual-hosts.
|
| services.jirafeau.nginxConfig.serverName | Name of this virtual host
|
| services.openssh.knownHosts.<name>.extraHostNames | A list of additional host names and/or IP numbers used for
accessing the host's ssh service
|
| services.hostapd.radios.<name>.networks.<name>.authentication.saePasswords.*.id | If this attribute is given with non-zero length, it will set the password identifier
for this entry
|
| services.dolibarr.nginx.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.librenms.nginx.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.kanboard.nginx.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.fediwall.nginx.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.agorakit.nginx.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.mainsail.nginx.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.pixelfed.nginx.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.akkoma.nginx.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.gancio.nginx.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.fedimintd.<name>.nginx.path_ws | Path to host the API on and forward to the daemon's api port
|
| services.fluidd.nginx.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.dockerRegistry.listenAddress | Docker registry host or ip to bind to.
|
| services.prosody.virtualHosts.<name>.enabled | Whether to enable the virtual host
|
| services.matomo.nginx.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.monica.nginx.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.nextjs-ollama-llm-ui.ollamaUrl | The address (including host and port) under which we can access the Ollama backend server.
!Note that if the the UI service is running under a domain "https://ui.example.org",
the Ollama backend service must allow "CORS" requests from this domain, e.g. by adding
"services.ollama.environment
|
| services.hostapd.radios.<name>.networks.<name>.authentication.wpaPasswordFile | Sets the password for WPA-PSK
|
| services.kanboard.nginx.listen | Listen addresses and ports for this virtual host
|
| services.httpd.virtualHosts.<name>.listen | Listen addresses and ports for this virtual host.
This option overrides addSSL, forceSSL and onlySSL
|
| services.dolibarr.nginx.listen | Listen addresses and ports for this virtual host
|
| services.librenms.nginx.listen | Listen addresses and ports for this virtual host
|
| services.fediwall.nginx.listen | Listen addresses and ports for this virtual host
|
| services.fedimintd.<name>.nginx.path_ui | Path to host the built-in UI on and forward to the daemon's api port
|
| services.agorakit.nginx.listen | Listen addresses and ports for this virtual host
|
| services.mainsail.nginx.listen | Listen addresses and ports for this virtual host
|
| services.pixelfed.nginx.listen | Listen addresses and ports for this virtual host
|
| services.tomcat.virtualHosts.*.webapps | List containing web application WAR files and/or directories containing
web applications and configuration files for the virtual host.
|
| services.zabbixWeb.nginx.virtualHost.serverName | Name of this virtual host
|
| services.nagios.virtualHost.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.moodle.virtualHost.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.openssh.listenAddresses.*.addr | Host, IPv4 or IPv6 address to listen to.
|
| services.radicle.httpd.nginx.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.hostapd.radios.<name>.networks.<name>.authentication.saePasswords.*.mac | If this attribute is not included, or if is set to the wildcard address (ff:ff:ff:ff:ff:ff),
the entry is available for any station (client) to use
|
| services.limesurvey.database.port | Database host port.
|
| services.prosody.virtualHosts.<name>.extraConfig | Additional virtual host specific configuration
|
| services.hostapd.radios.<name>.networks.<name>.authentication.saePasswords.*.pk | If this attribute is given, SAE-PK will be enabled for this connection
|
| services.hostapd.radios.<name>.networks.<name>.authentication.saePasswords.*.vlanid | If this attribute is given, all clients using this entry will get tagged with the given VLAN ID.
|
| services.drupal.webserver | Whether to use nginx or caddy for virtual host management
|
| services.dependency-track.nginx.enable | Whether to set up an nginx virtual host.
|
| services.dependency-track.nginx.domain | The domain name under which to set up the virtual host.
|
| services.radicle.httpd.nginx.listen | Listen addresses and ports for this virtual host
|
| services.rkvm.server.settings.switch-keys | A key list specifying a host switch combination.
A list of key names is available in https://github.com/htrefil/rkvm/blob/master/switch-keys.md.
|
| services.httpd.virtualHosts.<name>.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.anuko-time-tracker.nginx.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.caddy.virtualHosts.<name>.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.nginx.virtualHosts.<name>.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.firewalld.settings.IPv6_rpfilter | Performs reverse path filtering (RPF) on IPv6 packets as per RFC 3704
|
| services.quassel.interfaces | The interfaces the Quassel daemon will be listening to
|
| containers.<name>.forwardPorts.*.protocol | The protocol specifier for port forwarding between host and container
|
| services.wstunnel.servers.<name>.useACMEHost | Use a certificate generated by the NixOS ACME module for the given host
|
| services.warpgate.databaseUrlFile | Path to file containing database connection string with credentials
|
| services.jitsi-meet.nginx.enable | Whether to enable nginx virtual host that will serve the javascript application and act as
a proxy for the XMPP server
|
| services.anuko-time-tracker.nginx.listen | Listen addresses and ports for this virtual host
|
| services.davis.nginx.listenAddresses | Listen addresses for this virtual host
|
| services.SystemdJournal2Gelf.graylogServer | Host and port of your graylog2 input
|
| services.nginx.virtualHosts.<name>.listen | Listen addresses and ports for this virtual host
|
| services.movim.nginx.listenAddresses | Listen addresses for this virtual host
|
| services.livekit.settings.redis.address | Host and port used to connect to a redis instance.
|
| services.slskd.nginx.listenAddresses | Listen addresses for this virtual host
|
| services.nghttpx.backends.*.params.sni | Override the TLS SNI field value
|
| services.bookstack.nginx.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| security.pam.u2f.settings.origin | By default pam-u2f module sets the origin
to pam://$HOSTNAME
|
| services.ncps.cache.upstream.publicKeys | A list of public keys of upstream caches in the format
host[-[0-9]*]:public-key
|
| services.postgrey.greylistHeader | Prepend header to greylisted mails; use %%t for seconds delayed due to greylisting, %%v for the version of postgrey, %%d for the date, and %%h for the host
|
| services.rutorrent.nginx.enable | Whether to enable nginx virtual host management
|
| services.subsonic.listenAddress | The host name or IP address on which to bind Subsonic
|
| services.snipe-it.nginx.listenAddresses | Listen addresses for this virtual host
|
| services.dolibarr.nginx.globalRedirect | If set, all requests for this host are redirected (defaults to 301,
configurable with redirectCode) to the given hostname.
|
| services.fediwall.nginx.globalRedirect | If set, all requests for this host are redirected (defaults to 301,
configurable with redirectCode) to the given hostname.
|
| services.kanboard.nginx.globalRedirect | If set, all requests for this host are redirected (defaults to 301,
configurable with redirectCode) to the given hostname.
|
| services.agorakit.nginx.globalRedirect | If set, all requests for this host are redirected (defaults to 301,
configurable with redirectCode) to the given hostname.
|
| services.librenms.nginx.globalRedirect | If set, all requests for this host are redirected (defaults to 301,
configurable with redirectCode) to the given hostname.
|
| services.mainsail.nginx.globalRedirect | If set, all requests for this host are redirected (defaults to 301,
configurable with redirectCode) to the given hostname.
|
| services.pixelfed.nginx.globalRedirect | If set, all requests for this host are redirected (defaults to 301,
configurable with redirectCode) to the given hostname.
|
| services.bookstack.nginx.listen | Listen addresses and ports for this virtual host
|
| services.nagios.virtualHost.globalRedirect | If set, all requests for this host are redirected permanently to
the given URL.
|
| services.moodle.virtualHost.globalRedirect | If set, all requests for this host are redirected permanently to
the given URL.
|
| services.wordpress.sites.<name>.database.port | Database host port.
|
| services.nghttpx.frontends.*.server | Frontend server interface binding specification as either a
host:port pair or a unix domain docket
|
| services.zabbixWeb.httpd.virtualHost.listen | Listen addresses and ports for this virtual host.
This option overrides addSSL, forceSSL and onlySSL
|
| services.vwifi.client.serverAddress | The address of the server
|
| services.hostapd.radios.<name>.networks.<name>.authentication.saePasswords | Sets allowed passwords for WPA3-SAE
|
| networking.nat.forwardPorts.*.loopbackIPs | Public IPs for NAT reflection; for connections to loopbackip:sourcePort from the host itself and from other hosts behind NAT
|
| services.hylafax.userAccessFile | The hosts.hfaxd
file entry in the spooling area
will be symlinked to the location given here
|
| services.fluidd.nginx.listenAddresses | Listen addresses for this virtual host
|
| services.caddy.virtualHosts.<name>.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.akkoma.nginx.listenAddresses | Listen addresses for this virtual host
|
| services.gancio.nginx.listenAddresses | Listen addresses for this virtual host
|
| services.monica.nginx.listenAddresses | Listen addresses for this virtual host
|
| services.matomo.nginx.listenAddresses | Listen addresses for this virtual host
|
| virtualisation.cores | Specify the number of cores the guest is permitted to use
|
| services.jirafeau.nginxConfig.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.radicle.httpd.nginx.globalRedirect | If set, all requests for this host are redirected (defaults to 301,
configurable with redirectCode) to the given hostname.
|
| services.spiped.config.<name>.source | Address on which spiped should listen for incoming
connections
|
| services.resolved.domains | A list of domains
|
| services.librenms.nginx.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.dolibarr.h2o.acme.useHost | An existing Let’s Encrypt certificate to use for this virtual
host
|
| services.httpd.virtualHosts.<name>.globalRedirect | If set, all requests for this host are redirected permanently to
the given URL.
|
| services.bookstack.settings.APP_URL | The root URL that you want to host BookStack on
|
| services.kanboard.nginx.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.agorakit.nginx.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.dolibarr.nginx.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.gitlab.databaseCreateLocally | Whether a database should be automatically created on the
local host
|
| services.drupal.sites.<name>.virtualHost.listen | Listen addresses and ports for this virtual host.
This option overrides addSSL, forceSSL and onlySSL
|
| services.fediwall.nginx.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.privatebin.enableNginx | Whether to enable nginx or not
|
| services.pixelfed.nginx.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.mainsail.nginx.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.hostapd.radios.<name>.networks.<name>.authentication.wpaPassword | Sets the password for WPA-PSK that will be converted to the pre-shared key
|
| containers.<name>.extraVeths.<name>.forwardPorts | List of forwarded ports from host to container
|
| services.fedimintd.<name>.nginx.config.serverName | Name of this virtual host
|
| services.scrutiny.influxdb.enable | Enables InfluxDB on the host system using the services.influxdb2 NixOS module
with default options
|
| services.mackerel-agent.autoRetirement | Whether to enable retiring the host upon OS shutdown
.
|
| services.jirafeau.nginxConfig.listen | Listen addresses and ports for this virtual host
|
| services.zabbixWeb.httpd.virtualHost.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.zabbixWeb.nginx.virtualHost.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.anuko-time-tracker.nginx.globalRedirect | If set, all requests for this host are redirected (defaults to 301,
configurable with redirectCode) to the given hostname.
|
| services.nginx.virtualHosts.<name>.globalRedirect | If set, all requests for this host are redirected (defaults to 301,
configurable with redirectCode) to the given hostname.
|
| services.moodle.virtualHost.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.misskey.database.createLocally | Create the PostgreSQL database locally
|
| services.nagios.virtualHost.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.hostapd.radios.<name>.networks.<name>.authentication.saePasswordsFile | Sets the password for WPA3-SAE
|
| programs.schroot.profiles.<name>.copyfiles | A list of files to copy into the chroot from the host system.
|
| services.radicle.httpd.nginx.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.zabbixWeb.nginx.virtualHost.listen | Listen addresses and ports for this virtual host
|
| services.writefreely.database.port | The port used when connecting to the database host.
|
| services.hostapd.radios.<name>.networks.<name>.authentication.wpaPskFile | Sets the password(s) for WPA-PSK
|
| services.hostapd.radios.<name>.networks.<name>.authentication.saePasswords.*.passwordFile | The password for this entry, read from the given file when starting hostapd
|
| services.hostapd.radios.<name>.networks.<name>.authentication.pairwiseCiphers | Set of accepted cipher suites (encryption algorithms) for pairwise keys (unicast packets)
|
| services.drupal.sites.<name>.virtualHost.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.bookstack.nginx.globalRedirect | If set, all requests for this host are redirected (defaults to 301,
configurable with redirectCode) to the given hostname.
|
| services.freshrss.webserver | Whether to use nginx or caddy for virtual host management
|
| services.gitlab-runner.services.<name>.dockerExtraHosts | Add a custom host-to-IP mapping.
|
| services.dokuwiki.webserver | Whether to use nginx or caddy for virtual host management
|
| services.libeufin.nexus.settings.nexus-ebics.HOST_ID | Name of the EBICS host.
|
| services.gotosocial.settings | Contents of the GoToSocial YAML config
|
| services.httpd.virtualHosts.<name>.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.airsonic.listenAddress | The host name or IP address on which to bind Airsonic
|
| services.anuko-time-tracker.nginx.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.nginx.virtualHosts.<name>.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| virtualisation.mountHostNixStore | Mount the host Nix store as a 9p mount.
|
| services.hostapd.radios.<name>.networks.<name>.authentication.mode | Selects the authentication mode for this AP.
- "none": Don't configure any authentication
|
| services.reposilite.useACMEHost | Host of an existing Let's Encrypt certificate to use for SSL
|
| services.self-deploy.repository | The repository to fetch from
|
| services.zfs.autoReplication.username | Username used by SSH to login to remote host.
|
| services.hostapd.radios.<name>.networks.<name>.authentication.saePasswords.*.password | The password for this entry
|
| services.bookstack.nginx.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.librespeed.frontend.enable | Enables the LibreSpeed frontend and adds a nginx virtual host if
not explicitly disabled and services.librespeed.domain is not null.
|
| services.tinc.networks.<name>.chroot | Change process root directory to the directory where the config file is located (/etc/tinc/netname/), for added security
|
| services.znapzend.zetup.<name>.mbuffer.port | Port to use for mbuffer
|
| services.jirafeau.nginxConfig.globalRedirect | If set, all requests for this host are redirected (defaults to 301,
configurable with redirectCode) to the given hostname.
|
| services.miniflux.createDatabaseLocally | Whether a PostgreSQL database should be automatically created and
configured on the local host
|
| services.moodle.virtualHost.listenAddresses | Listen addresses for this virtual host
|
| services.nagios.virtualHost.listenAddresses | Listen addresses for this virtual host
|
| services.zabbixWeb.httpd.virtualHost.globalRedirect | If set, all requests for this host are redirected permanently to
the given URL.
|
| services._3proxy.services.*.acl.*.targets | List of target IP ranges, use empty list for any
|
| services.zabbixWeb.nginx.virtualHost.globalRedirect | If set, all requests for this host are redirected (defaults to 301,
configurable with redirectCode) to the given hostname.
|
| services.drupal.sites.<name>.virtualHost.globalRedirect | If set, all requests for this host are redirected permanently to
the given URL.
|
| services.librenms.nginx.listenAddresses | Listen addresses for this virtual host
|
| services.fediwall.nginx.listenAddresses | Listen addresses for this virtual host
|
| services.kanboard.nginx.listenAddresses | Listen addresses for this virtual host
|
| services.firefox-syncserver.singleNode.url | URL of the host
|
| services.agorakit.nginx.listenAddresses | Listen addresses for this virtual host
|
| services.dolibarr.nginx.listenAddresses | Listen addresses for this virtual host
|
| services.mainsail.nginx.listenAddresses | Listen addresses for this virtual host
|
| services.pixelfed.nginx.listenAddresses | Listen addresses for this virtual host
|
| services.postfixadmin.enable | Whether to enable postfixadmin
|
| services.httpd.virtualHosts.<name>.listenAddresses | Listen addresses for this virtual host
|
| networking.interfaces.<name>.virtual | Whether this interface is virtual and should be created by tunctl
|
| services.librespeed.frontend.useNginx | Configure nginx for the LibreSpeed frontend
|
| services.jirafeau.nginxConfig.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.wordpress.webserver | Whether to use apache2 or nginx for virtual host management
|
| services.keycloak.database.createLocally | Whether a database should be automatically created on the
local host
|
| services.slurm.enableSrunX11 | If enabled srun will accept the option "--x11" to allow for X11 forwarding
from within an interactive session or a batch job
|
| services.fedimintd.<name>.nginx.config.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.limesurvey.virtualHost.listen | Listen addresses and ports for this virtual host.
This option overrides addSSL, forceSSL and onlySSL
|
| services.firefly-iii-data-importer.enableNginx | Whether to enable nginx or not
|
| services.misskey.reverseProxy.webserver.caddy | Extra configuration for the caddy virtual host of Misskey
|
| services.misskey.reverseProxy.webserver.nginx | Extra configuration for the nginx virtual host of Misskey
|
| services.radicle.httpd.nginx.listenAddresses | Listen addresses for this virtual host
|
| services.zabbixWeb.httpd.virtualHost.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.wastebin.settings.WASTEBIN_BASE_URL | Base URL for the QR code display
|
| services.zabbixWeb.nginx.virtualHost.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.invoiceplane.webserver | Which webserver to use for virtual host management.
|
| services.fedimintd.<name>.nginx.config.listen | Listen addresses and ports for this virtual host
|
| services.gnome.gnome-browser-connector.enable | Whether to enable native host connector for the GNOME Shell browser extension, a DBus service
allowing to install GNOME Shell extensions from a web browser
.
|
| services.mediawiki.httpd.virtualHost.listen | Listen addresses and ports for this virtual host.
This option overrides addSSL, forceSSL and onlySSL
|
| services.limesurvey.nginx.virtualHost.serverName | Name of this virtual host
|
| services.zfs.autoReplication.identityFilePath | Path to SSH key used to login to host.
|
| containers.<name>.extraVeths.<name>.forwardPorts.*.protocol | The protocol specifier for port forwarding between host and container
|
| services.anuko-time-tracker.nginx.listenAddresses | Listen addresses for this virtual host
|
| services.keycloak.database.passwordFile | The path to a file containing the database password
|
| services.drupal.sites.<name>.virtualHost.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.nginx.virtualHosts.<name>.listenAddresses | Listen addresses for this virtual host
|
| services.prometheus.exporters.jitsi.url | Jitsi Videobridge metrics URL to monitor
|
| services.limesurvey.virtualHost.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.bookstack.nginx.listenAddresses | Listen addresses for this virtual host
|
| services.openssh.authorizedKeysCommandUser | Specifies the user under whose account the AuthorizedKeysCommand
is run
|
| services.mediawiki.httpd.virtualHost.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.prometheus.exporters.bitcoin.rpcHost | RPC host.
|
| services.wordpress.sites.<name>.virtualHost.listen | Listen addresses and ports for this virtual host.
This option overrides addSSL, forceSSL and onlySSL
|
| services.your_spotify.nginxVirtualHost | If set creates an nginx virtual host for the client
|
| services.sslh.settings.protocols | List of protocols sslh will probe for and redirect
|
| services.globalprotect.csdWrapper | A script that will produce a Host Integrity Protection (HIP) report,
as described at https://www.infradead.org/openconnect/hip.html
|
| services.nextjs-ollama-llm-ui.enable | Whether to enable Simple Ollama web UI service; an easy to use web frontend for a Ollama backend service
|
| services.zabbixWeb.httpd.virtualHost.listenAddresses | Listen addresses for this virtual host
|
| services.varnish.listen.*.address | If given an IP address, it can be a host name ("localhost"), an IPv4 dotted-quad
("127.0.0.1") or an IPv6 address enclosed in square brackets ("[::1]").
(VCL4.1 and higher) If given an absolute Path ("/path/to/listen.sock") or "@"
followed by the name of an abstract socket ("@myvarnishd") accept connections
on a Unix domain socket
|
| virtualisation.oci-containers.containers.<name>.ports | Network ports to publish from the container to the outer host
|
| services.discourse.database.createLocally | Whether a database should be automatically created on the
local host
|
| services.snips-sh.environmentFile | Additional environment file as defined in systemd.exec(5)
|
| services.journald.remote.settings.Remote.SplitMode | With "host", a separate output file is used, based on the
hostname of the other endpoint of a connection
|
| services.fedimintd.<name>.nginx.config.globalRedirect | If set, all requests for this host are redirected (defaults to 301,
configurable with redirectCode) to the given hostname.
|
| services.drupal.sites.<name>.virtualHost.listenAddresses | Listen addresses for this virtual host
|
| services.jirafeau.nginxConfig.listenAddresses | Listen addresses for this virtual host
|
| services.wordpress.sites.<name>.virtualHost.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.wstunnel.clients.<name>.httpProxy | Proxy to use to connect to the wstunnel server (USER:PASS@HOST:PORT).
Passwords specified here will be world-readable in the Nix store!
To pass a password to the service, point the environmentFile option
to a file containing PROXY_PASSWORD=<your-password-here> and set
this option to <user>:$PROXY_PASSWORD@<host>:<port>
|
| services.limesurvey.httpd.virtualHost.listen | Listen addresses and ports for this virtual host.
This option overrides addSSL, forceSSL and onlySSL
|
| services.limesurvey.virtualHost.globalRedirect | If set, all requests for this host are redirected permanently to
the given URL.
|
| services.firewalld.zones.<name>.sources.*.address | An IP address or a network IP address with a mask for IPv4 or IPv6
|
| virtualisation.nixStore9pCache | Type of 9p cache to use when mounting host nix store. "none" provides
no caching. "loose" enables Linux's local VFS cache. "fscache" uses Linux's
fscache subsystem
|
| services.zabbixWeb.nginx.virtualHost.listenAddresses | Listen addresses for this virtual host
|
| services.invoiceplane.sites.<name>.database.port | Database host port.
|
| services.fedimintd.<name>.nginx.config.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.mediawiki.httpd.virtualHost.globalRedirect | If set, all requests for this host are redirected permanently to
the given URL.
|
| virtualisation.writableStore | If enabled, the Nix store in the VM is made writable by
layering an overlay filesystem on top of the host's Nix
store
|
| services.misskey.meilisearch.createLocally | Create and use a local Meilisearch instance
|
| services.yggdrasil.settings.PrivateKeyPath | Path to the private key file on the host system
|
| services.limesurvey.nginx.virtualHost.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.limesurvey.httpd.virtualHost.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.prometheus.exporters.unpoller.loki.url | URL of the Loki host.
|
| services.limesurvey.nginx.virtualHost.listen | Listen addresses and ports for this virtual host
|
| services.misskey.reverseProxy.webserver.nginx.serverName | Name of this virtual host
|
| services.limesurvey.virtualHost.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.wordpress.sites.<name>.virtualHost.globalRedirect | If set, all requests for this host are redirected permanently to
the given URL.
|
| services.hostapd.radios.<name>.networks.<name>.authentication.enableRecommendedPairwiseCiphers | Additionally enable the recommended set of pairwise ciphers
|
| services.mediawiki.httpd.virtualHost.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.murmur.environmentFile | Environment file as defined in systemd.exec(5)
|
| containers.<name>.ephemeral | Runs container in ephemeral mode with the empty root filesystem at boot
|
| services.dependency-track.database.createLocally | Whether a database should be automatically created on the
local host
|
| services.nullmailer.config.remotes | A list of remote servers to which to send each message
|
| services.headscale.settings.database.postgres.port | Database host port.
|
| services.limesurvey.httpd.virtualHost.globalRedirect | If set, all requests for this host are redirected permanently to
the given URL.
|
| services.misskey.reverseProxy.webserver.caddy.extraConfig | Additional lines of configuration appended to this virtual host in the
automatically generated Caddyfile.
|
| services.wordpress.sites.<name>.virtualHost.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| containers.<name>.privateUsers | Whether to give the container its own private UIDs/GIDs space (user namespacing)
|
| services.limesurvey.nginx.virtualHost.globalRedirect | If set, all requests for this host are redirected (defaults to 301,
configurable with redirectCode) to the given hostname.
|
| services.limesurvey.virtualHost.listenAddresses | Listen addresses for this virtual host
|
| services.healthchecks.settings.ALLOWED_HOSTS | The host/domain names that this site can serve.
|
| services.fedimintd.<name>.nginx.config.listenAddresses | Listen addresses for this virtual host
|
| services.pinchflat.secretsFile | Secrets like SECRET_KEY_BASE and BASIC_AUTH_PASSWORD
should be passed to the service without adding them to the world-readable Nix store
|
| programs.schroot.profiles.<name>.nssdatabases | System databases (as described in /etc/nsswitch.conf on GNU/Linux systems) to copy into the chroot from the host.
|
| services.static-web-server.configuration | Configuration for Static Web Server
|
| services.mediawiki.httpd.virtualHost.listenAddresses | Listen addresses for this virtual host
|
| services.limesurvey.nginx.virtualHost.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| services.limesurvey.httpd.virtualHost.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| programs.chromium.enablePlasmaBrowserIntegration | Whether to enable Native Messaging Host for Plasma Browser Integration.
|
| services.prometheus.exporters.dnssec.listenAddress | Listen address as host IP and port definition.
|
| services.misskey.reverseProxy.webserver.caddy.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.misskey.reverseProxy.webserver.nginx.serverAliases | Additional names of virtual hosts served by this virtual host configuration.
|
| services.wordpress.sites.<name>.virtualHost.listenAddresses | Listen addresses for this virtual host
|
| services.nextcloud-whiteboard-server.settings | Settings to configure backend server
|
| services.misskey.reverseProxy.webserver.nginx.listen | Listen addresses and ports for this virtual host
|
| virtualisation.rosetta.enable | Whether to enable Rosetta support
|
| services.matrix-hookshot.serviceDependencies | List of Systemd services to require and wait for when starting the application service,
such as the Matrix homeserver if it's running on the same host.
|
| virtualisation.libvirtd.onBoot | Specifies the action to be done to / on the guests when the host boots
|
| services.headscale.settings.tls_letsencrypt_hostname | Domain name to request a TLS certificate for.
|
| services.limesurvey.httpd.virtualHost.listenAddresses | Listen addresses for this virtual host
|
| services.misskey.reverseProxy.webserver.caddy.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| virtualisation.libvirtd.qemu.package | The qemu package to use. pkgs.qemu can emulate alien architectures (e.g. aarch64 on x86)
pkgs.qemu_kvm saves disk space allowing to emulate only host architectures.
|
| services.hedgedoc.environmentFile | Environment file as defined in systemd.exec(5)
|
| services.nextcloud-spreed-signaling.configureNginx | Whether to set up and configure an nginx virtual host according to upstream's recommendations
|
| services.misskey.reverseProxy.webserver.nginx.globalRedirect | If set, all requests for this host are redirected (defaults to 301,
configurable with redirectCode) to the given hostname.
|
| services.limesurvey.nginx.virtualHost.listenAddresses | Listen addresses for this virtual host
|
| services.matrix-appservice-discord.settings | config.yaml configuration as a Nix attribute set
|
| services.cloudflared.tunnels.<name>.originRequest.httpHostHeader | Sets the HTTP Host header on requests sent to the local service.
|
| services.teeworlds.environmentFile | Environment file as defined in systemd.exec(5)
|
| virtualisation.credentials.<name>.source | Source file on the host containing the credential data.
|
| services.matrix-synapse.settings.listeners.*.resources.*.names | List of resources to host on this listener.
|
| services.dendrite.environmentFile | Environment file as defined in systemd.exec(5)
|
| services.misskey.reverseProxy.webserver.nginx.useACMEHost | A host of an existing Let's Encrypt certificate to use
|
| virtualisation.libvirtd.onShutdown | When shutting down / restarting the host what method should
be used to gracefully halt the guests
|
| services.livebook.environment | Environment variables to set
|
| services.peering-manager.environmentFile | Environment file as defined in systemd.exec(5)
|
| services.autosuspend.settings.suspend_cmd | The command to execute in case the host shall be suspended
|
| services.prometheus.exporters.klipper.moonrakerApiKey | API Key to authenticate with the Moonraker APIs
|
| services.heisenbridge.registrationUrl | The URL where the application service is listening for HS requests, from the Matrix HS perspective.#
The default value assumes the bridge runs on the same host as the home server, in the same network.
|
| services.biboumi.settings.xmpp_server_ip | The IP address to connect to the XMPP server on
|
| services.waagent.settings.Provisioning.Enable | Whether to enable provisioning functionality in the agent
|
| services.misskey.reverseProxy.webserver.nginx.listenAddresses | Listen addresses for this virtual host
|
| virtualisation.virtualbox.guest.seamless | Whether to enable seamless mode
|
| virtualisation.additionalPaths | A list of paths whose closure should be made available to
the VM
|
| services.grafana.settings.security.cookie_secure | Set to true if you host Grafana behind HTTPS.
|
| services.nullmailer.config.defaultdomain | The content of this attribute is appended to any host name that
does not contain a period (except localhost), including defaulthost
and idhost
|
| services.livebook.environmentFile | Additional environment file as defined in systemd.exec(5)
|
| services.grafana.settings.server.enforce_domain | Redirect to correct domain if the host header does not match the domain
|
| services.cloudflared.tunnels.<name>.edgeIPVersion | Specifies the IP address version (IPv4 or IPv6) used to establish a connection between cloudflared and the Cloudflare global network
|
| services.matrix-appservice-discord.serviceDependencies | List of Systemd services to require and wait for when starting the application service,
such as the Matrix homeserver if it's running on the same host.
|
| programs.tsmClient.servers.<name>.tcpserveraddress | Host/domain name or IP address of the IBM TSM server.
|
| services.easytier.instances.<name>.settings.instance_name | Identify different instances on same host
|
| services.vaultwarden.environmentFile | Additional environment file or files as defined in systemd.exec(5)
|
| services.litestream.environmentFile | Environment file as defined in systemd.exec(5)
|
| security.virtualisation.flushL1DataCache | Whether the hypervisor should flush the L1 data cache before
entering guests
|
| programs.pay-respects.aiIntegration | Whether to enable pay-respects' LLM integration
|
| services.veilid.settings.core.network.routing_table.bootstrap | Host name of existing well-known Veilid bootstrap servers for the network to connect to.
|
| services.xserver.displayManager.lightdm.greeters.gtk.indicators | List of allowed indicator modules to use for the lightdm gtk
greeter panel
|
| services.prometheus.exporters.snmp.environmentFile | EnvironmentFile as defined in systemd.exec(5)
|
| services.prometheus.exporters.php-fpm.environmentFile | Environment file as defined in systemd.exec(5)
|
| services.matrix-synapse.workers.<name>.worker_listeners.*.resources.*.names | List of resources to host on this listener.
|
| services.prometheus.exporters.postgres.environmentFile | Environment file as defined in systemd.exec(5)
|
| services.movim.h2o.tls.recommendations | By default, H2O, without prejudice, will use as many TLS versions &
cipher suites as it & the TLS library (OpenSSL) can support
|
| services.h2o.defaultTLSRecommendations | By default, H2O, without prejudice, will use as many TLS versions &
cipher suites as it & the TLS library (OpenSSL) can support
|
| services.dolibarr.h2o.tls.recommendations | By default, H2O, without prejudice, will use as many TLS versions &
cipher suites as it & the TLS library (OpenSSL) can support
|
| services.headscale.settings.dns.base_domain | Defines the base domain to create the hostnames for MagicDNS
|
| containers.<name>.localAddress6 | The IPv6 address assigned to the interface in the container
|
| containers.<name>.localAddress | The IPv4 address assigned to the interface in the container
|
| containers.<name>.extraVeths.<name>.localAddress6 | The IPv6 address assigned to the interface in the container
|
| services.journald.remote.output | The location of the output journal
|
| containers.<name>.extraVeths.<name>.localAddress | The IPv4 address assigned to the interface in the container
|
| services.polipo.parentProxy | Hostname and port number of an HTTP parent proxy;
it should have the form ‘host:port’.
|
| services.polipo.socksParentProxy | Hostname and port number of an SOCKS parent proxy;
it should have the form ‘host:port’.
|
| services.tinc.networks.<name>.name | The name of the node which is used as an identifier when communicating
with the remote nodes in the mesh
|
| services.hadoop.hbase.regionServer.overrideHosts | Remove /etc/hosts entries for "127.0.0.2" and "::1" defined in nixos/modules/config/networking.nix
Regionservers must be able to resolve their hostnames to their IP addresses, through PTR records
or /etc/hosts entries.
|
| services.cjdns.addExtraHosts | Whether to add cjdns peers with an associated hostname to
/etc/hosts
|
| services.livekit.settings.rtc.use_external_ip | When set to true, attempts to discover the host's public IP via STUN
|
| services.bookstack.settings.DB_HOST | The IP or hostname which hosts your database.
|
| services.dnscache.domainServers | Table of {hostname: server} pairs to use as authoritative servers for hosts (and subhosts)
|
| services.firezone.server.clusterHosts | A list of components and their hosts that are part of this cluster
|
| services.livekit.ingress.settings.rtc_config.use_external_ip | When set to true, attempts to discover the host's public IP via STUN
|
| services.tt-rss.sphinx.server | Hostname:port combination for the Sphinx server.
|
| services.tt-rss.email.server | Hostname:port combination to send outgoing mail
|
| nixpkgs.crossSystem | Systems with a recently generated hardware-configuration.nix
may instead specify only nixpkgs.buildPlatform,
or fall back to removing the nixpkgs.hostPlatform line from the generated config
|
| services.pghero.listenAddress | hostname:port to listen for HTTP traffic
|
| services.gerrit.listenAddress | hostname:port to listen for HTTP traffic
|
| nixpkgs.localSystem | Systems with a recently generated hardware-configuration.nix
do not need to specify this option, unless cross-compiling, in which case
you should set only nixpkgs.buildPlatform
|
| services.dawarich.enable | Whether to enable Dawarich, a self-hostable alternative to Google Location History.
|
| networking.search | The list of domain search paths that are considered for resolving
hostnames with fewer dots than configured in the ndots option,
which defaults to 1 if unset.
|
| services.certmgr.defaultRemote | The default CA host:port to use.
|
| services.thanos.rule.http-address | Listen host:port for HTTP endpoints
|
| services.thanos.store.http-address | Listen host:port for HTTP endpoints
|
| services.thanos.query.http-address | Listen host:port for HTTP endpoints
|
| services.tor.torsocks.server | IP/Port of the Tor SOCKS server
|
| services.sslh.listenAddresses | Listening addresses or hostnames.
|
| services.oauth2-proxy.loginURL | Authentication endpoint
|
| programs.ssh.knownHosts.<name>.certAuthority | This public key is an SSH certificate authority, rather than an
individual host's key.
|
| security.acme.certs.<name>.dnsResolver | Set the resolver to use for performing recursive DNS queries
|
| services.thanos.compact.http-address | Listen host:port for HTTP endpoints
|
| services.thanos.receive.http-address | Listen host:port for HTTP endpoints
|
| services.thanos.sidecar.http-address | Listen host:port for HTTP endpoints
|
| services.castopod.enable | Whether to enable Castopod, a hosting platform for podcasters.
|
| services.mailman.webHosts | The list of hostnames and/or IP addresses from which the Mailman Web
UI will accept requests
|
| services.oauth2-proxy.redeemURL | Token redemption endpoint
|
| services.nghttpx.backends.*.server | Backend server location specified as either a host:port pair
or a unix domain docket.
|
| services.ncps.cache.redis.addresses | A list of host:port for the Redis servers that are part of a cluster
|
| services.sshguard.whitelist | Whitelist a list of addresses, hostnames, or address blocks.
|
| security.acme.defaults.dnsResolver | Set the resolver to use for performing recursive DNS queries
|
| services.openssh.knownHosts.<name>.certAuthority | This public key is an SSH certificate authority, rather than an
individual host's key.
|
| services.tor.torsocks.fasterServer | IP/Port of the Tor SOCKS server for torsocks-faster wrapper suitable for HTTP
|
| services.thanos.query-frontend.http-address | Listen host:port for HTTP endpoints
|
| services.github-runners.<name>.enable | Whether to enable GitHub Actions runner
|
| services.oauth2-proxy.validateURL | Access token validation endpoint
|
| services.synergy.client.serverAddress | The server address is of the form: [hostname][:port]
|
| services.sourcehut.enable | Whether to enable sourcehut - git hosting, continuous integration, mailing list, ticket tracking, wiki
and account management services
.
|
| services.kubo.localDiscovery | Whether to enable local discovery for the Kubo daemon
|
| services.mlmmj.mailLists | The collection of hosted maillists
|
| networking.extraHosts | Additional verbatim entries to be appended to /etc/hosts
|
| boot.loader.initScript.enable | Some systems require a /sbin/init script which is started
|
| services.hedgedoc.settings.urlPath | URL path for the website
|
| services.gitDaemon.enable | Enable Git daemon, which allows public hosting of git repositories
without any access controls
|
| services.mysql.galeraCluster.nodeAddresses | IP addresses or hostnames of all nodes in the cluster, including this node
|
| services.pretix.settings.memcached.location | The host:port combination or the path to the UNIX socket of a memcached instance
|
| services.hatsu.enable | Whether to enable Self-hosted and fully-automated ActivityPub bridge for static sites.
|
| virtualisation.kvmgt.enable | Whether to enable KVMGT (iGVT-g) VGPU support
|
| services.tabby.enable | Whether to enable Self-hosted AI coding assistant using large language models.
|
| virtualisation.rosetta.mountTag | The VirtioFS mount tag for the Rosetta runtime, exposed by the host's virtualisation software
|
| services.snips-sh.settings | The configuration of snips-sh is done through environment variables,
therefore you must use upper snake case (e.g. SNIPS_HTTP_INTERNAL)
|
| services.slurm.dbdserver.dbdHost | Hostname of the machine where slurmdbd
is running (i.e. name returned by hostname -s).
|
| programs.xfs_quota.projects.<name>.fileSystem | XFS filesystem hosting the xfs_quota project.
|
| services.dashy.enable | Whether to enable Dashy, a highly customizable, easy to use, privacy-respecting dashboard app
|
| services.slurm.controlMachine | The short hostname of the machine where SLURM control functions are
executed (i.e. the name returned by the command "hostname -s", use "tux001"
rather than "tux001.my.com").
|
| services.jibri.xmppEnvironments.<name>.xmppServerHosts | Hostnames of the XMPP servers to connect to.
|
| services.podgrab.enable | Whether to enable Podgrab, a self-hosted podcast manager.
|
| hardware.sane.netConf | Network hosts that should be probed for remote scanners.
|
| services.snapserver.streams.<name>.location | For type pipe or file, the path to the pipe or file
|
| services.slurm.rest.environment.SLURMRESTD_LISTEN | Comma-delimited list of host:port pairs or unix sockets to listen on.
|
| services.tailscale.serve.services.<name>.endpoints | Map of incoming traffic patterns to local targets
|
| virtualisation.credentials.<name>.text | Text content of the credential
|
| security.ipa.server | IPA Server hostname.
|
| services.postsrsd.settings.srs-domain | Dedicated mail domain used for ephemeral SRS envelope addresses
|
| virtualisation.useNixStoreImage | Build and use a disk image for the Nix store, instead of
accessing the host's one through 9p
|
| services.pingvin-share.enable | Whether to enable Pingvin Share, a self-hosted file sharing platform.
|
| services.murmur.registerHostname | DNS hostname where your server can be reached
|
| services.hydra.smtpHost | Hostname of the SMTP server to use to send email.
|
| networking.dhcpcd.setHostname | Whether to set the machine hostname based on the information
received from the DHCP server.
The hostname will be changed only if the current one is
the empty string, localhost or nixos
|
| services.mycelium.peers | List of peers to connect to, in the formats:
quic://[2001:0db8::1]:9651
quic://192.0.2.1:9651
tcp://[2001:0db8::1]:9651
tcp://192.0.2.1:9651
If addHostedPublicNodes is set to true, the hosted public nodes will also be added.
|
| services.jicofo.xmppHost | Hostname of the XMPP server to connect to.
|
| services.jigasi.xmppHost | Hostname of the XMPP server to connect to.
|
| services.i2pd.address | Your external IP or hostname.
|
| services.syncthing.enable | Whether to enable Syncthing, a self-hosted open-source alternative to Dropbox and Bittorrent Sync.
|
| services.cachix-agent.name | Agent name, usually same as the hostname
|
| services.suwayomi-server.settings.server.basicAuthEnabled | Whether to enable basic access authentication for Suwayomi-Server
|
| services.hydra.listenHost | The hostname or address to listen on or * to listen
on all interfaces.
|
| networking.ucarp.vhId | Virtual IP identifier shared between CARP hosts.
|
| services.mycelium.addHostedPublicNodes | Adds the hosted peers from https://github.com/threefoldtech/mycelium#hosted-public-nodes.
|
| services.ceph.global.monHost | List of hostname shortnames/IP addresses of the initial monitors.
|
| services.shellhub-agent.preferredHostname | Set the device preferred hostname
|
| services.epmd.enable | Whether to enable socket activation for Erlang Port Mapper Daemon (epmd),
which acts as a name server on all hosts involved in distributed
Erlang computations.
|
| services.leaps.address | Hostname or IP-address to listen to
|
| security.ipa.dyndns.enable | Whether to enable FreeIPA automatic hostname updates.
|
| services.polaris.port | The port which the Polaris REST api and web UI should listen to
|
| services.lubelogger.enable | Whether to enable LubeLogger, a self-hosted, open-source, web-based vehicle maintenance and fuel milage tracker.
|
| services.torque.mom.serverNode | Hostname running pbs server.
|
| services.nezha-agent.genUuid | Whether to generate uuid from fqdn automatically
|
| services.rmfakecloud.enable | Whether to enable rmfakecloud remarkable self-hosted cloud.
|
| services.caddy.virtualHosts | Declarative specification of virtual hosts served by Caddy.
|
| services.zabbixAgent.server | The IP address or hostname of the Zabbix server to connect to.
|
| services.zabbixProxy.server | The IP address or hostname of the Zabbix server to connect to.
|
| services.netbird.clients | Attribute set of NetBird client daemons, by default each one will:
- be manageable using dedicated tooling:
netbird-<name> script,
NetBird - netbird-<name> graphical interface when appropriate (see ui.enable),
- run as a
netbird-<name>.service,
- listen for incoming remote connections on the port
51820 (openFirewall by default),
- manage the
netbird-<name> wireguard interface,
- use the /var/lib/netbird-/config.json configuration file,
- override /var/lib/netbird-/config.json with values from /etc/netbird-/config.d/*.json,
- (
hardened) be locally manageable by netbird-<name> system group,
With following caveats:
- multiple daemons will interfere with each other's DNS resolution of
netbird.cloud, but
should remain fully operational otherwise
|
| services.printing.allowFrom | From which hosts to allow unconditional access.
|
| services.postfix.domain | Domain to use
|
| services.postfix.origin | Origin to use in outgoing e-mail
|
| services.slurm.nodeName | Name that SLURM uses to refer to a node (or base partition for BlueGene
systems)
|
| services.cassandra.listenAddress | Address or interface to bind to and tell other Cassandra nodes
to connect to
|
| services.ntfy-sh.settings.base-url | Public facing base URL of the service
This setting is required for any of the following features:
- attachments (to return a download URL)
- e-mail sending (for the topic URL in the email footer)
- iOS push notifications for self-hosted servers
(to calculate the Firebase poll_request topic)
- Matrix Push Gateway (to validate that the pushkey is correct)
|
| services.h2o.defaultTLSListenPort | If hosts do not specify listen.port, use these ports for SSL by default.
|
| services.prosody.virtualHosts | Define the virtual hosts
|
| services.statsd.graphiteHost | Hostname or IP of Graphite server
|
| services.ente.api.settings.apps.public-albums | If you're running a self hosted instance and wish to serve public links,
set this to the URL where your albums web app is running.
|
| services.avahi.publish.domain | Whether to announce the locally used domain name for browsing by other hosts.
|
| services.h2o.defaultHTTPListenPort | If hosts do not specify listen.port, use these ports for HTTP by default.
|
| services.kismet.httpd.address | The address to listen on
|
| power.ups.upsmon.monitor.<name>.system | Identifier of the UPS to monitor, in this form: <upsname>[@<hostname>[:<port>]]
See upsmon.conf for details.
|
| services.resolved.dnsovertls | If set to
"true":
all DNS lookups will be encrypted
|
| services.gitDaemon.listenAddress | Listen on a specific IP address or hostname.
|
| services.usbrelayd.broker | Hostname or IP address of your MQTT Broker.
|
| services.outline.cdnUrl | If using a Cloudfront/Cloudflare distribution or similar it can be set
using this option
|
| services.netbird.clients.<name>.openFirewall | Opens up firewall port for communication between NetBird peers directly over LAN or public IP,
without using (internet-hosted) TURN servers as intermediaries.
|
| services.pangolin.dashboardDomain | The domain where the application will be hosted
|
| services.netbird.tunnels.<name>.openFirewall | Opens up firewall port for communication between NetBird peers directly over LAN or public IP,
without using (internet-hosted) TURN servers as intermediaries.
|
| services.silverbullet.enable | Whether to enable Silverbullet, an open-source, self-hosted, offline-capable Personal Knowledge Management (PKM) web application.
|
| services.github-runners.<name>.name | Name of the runner to configure
|
| services.iodine.clients.<name>.server | Hostname of server running iodined
|
| services.gitlab.databaseHost | GitLab database hostname
|
| services.zabbixWeb.server.address | The IP address or hostname of the Zabbix server to connect to.
|
| security.ipa.dyndns.interface | Network interface to perform hostname updates through.
|
| services.firefly-iii.virtualHost | The hostname at which you wish firefly-iii to be served
|
| services.pdns-recursor.exportHosts | Whether to export names and IP addresses defined in /etc/hosts.
|
| services.archisteamfarm.web-ui | The Web-UI hosted on 127.0.0.1:1242.
|
| services.synergy.client.screenName | Use the given name instead of the hostname to identify
ourselves to the server.
|
| services.davis.nginx.reuseport | Create an individual listening socket
|
| services.slskd.nginx.reuseport | Create an individual listening socket
|
| services.movim.nginx.reuseport | Create an individual listening socket
|
| services.synergy.server.screenName | Use the given name instead of the hostname to identify
this screen in the configuration.
|
| services.caddy.openFirewall | Whether to enable opening the specified http(s) ports in the firewall
|
| networking.ucarp.passwordFile | File containing shared password between CARP hosts.
|
| services.snipe-it.nginx.reuseport | Create an individual listening socket
|
| services.github-runners.<name>.tokenType | Type of token to use for runner registration
|
| services.postfix.networks | Net masks for trusted - allowed to relay mail to third parties -
hosts
|
| services.quicktun.<name>.localAddress | IP address or hostname of the local end.
|
| services.gancio.nginx.reuseport | Create an individual listening socket
|
| services.fluidd.nginx.reuseport | Create an individual listening socket
|
| services.ceph.global.monInitialMembers | List of hosts that will be used as monitors at startup.
|
| services.akkoma.nginx.reuseport | Create an individual listening socket
|
| services.matomo.nginx.reuseport | Create an individual listening socket
|
| services.monica.nginx.reuseport | Create an individual listening socket
|
| services.pds.settings.PDS_HOSTNAME | Instance hostname (base domain name)
|
| security.pam.dp9ik.authserver | This controls the hostname for the 9front authentication server
that users will be authenticated against.
|
| services.buildkite-agents | Attribute set of buildkite agents
|
| services.audiobookshelf.enable | Whether to enable Audiobookshelf, self-hosted audiobook and podcast server.
|
| services.wstunnel.clients.<name>.tlsSNI | Use this as the SNI while connecting via TLS
|
| services.athens.storage.cdn.endpoint | hostname of the CDN server.
|
| services.thanos.query.grpc-client-server-name | Server name to verify the hostname on the returned gRPC certificates
|
| services.ncdns.identity.address | The IP address the hostname specified in
services.ncdns.identity.hostname should resolve to
|
| services.dependency-track.oidc.teams.claim | Defines the name of the claim that contains group memberships or role assignments in the provider's userinfo endpoint
|
| services.miredo.serverAddress | The hostname or primary IPv4 address of the Teredo server
|
| services.karma.settings.listen.address | Hostname or IP to listen on.
|
| services.vikunja.frontendHostname | The Hostname under which the frontend is running.
|
| services.ntp.restrictDefault | The restriction flags to be set by default
|
| services.quicktun.<name>.remoteAddress | IP address or hostname of the remote end (use 0.0.0.0 for a floating/dynamic remote endpoint).
|
| services.oauth2-proxy.nginx.virtualHosts | Nginx virtual hosts to put behind the oauth2 proxy
|
| services.portunus.ldap.tls | Whether to enable LDAPS protocol
|
| services.fediwall.nginx.reuseport | Create an individual listening socket
|
| services.kanboard.nginx.reuseport | Create an individual listening socket
|
| services.dolibarr.nginx.reuseport | Create an individual listening socket
|
| services.librenms.nginx.reuseport | Create an individual listening socket
|
| services.agorakit.nginx.reuseport | Create an individual listening socket
|
| services.public-inbox.inboxes.<name>.inboxdir | The absolute path to the directory which hosts the public-inbox.
|
| services.mainsail.nginx.reuseport | Create an individual listening socket
|
| services.pixelfed.nginx.reuseport | Create an individual listening socket
|
| services.netdata.enableAnalyticsReporting | Enable reporting of anonymous usage statistics to Netdata Inc. via either
Google Analytics (in versions prior to 1.29.4), or Netdata Inc.'s
self-hosted PostHog (in versions 1.29.4 and later)
|
| services.privatebin.virtualHost | The hostname at which you wish privatebin to be served
|
| services.radicle.httpd.nginx.reuseport | Create an individual listening socket
|
| services.onlyoffice.postgresHost | The Postgresql hostname or socket path OnlyOffice should connect to.
|
| services.zipline.settings.CORE_HOSTNAME | The hostname to listen on.
|
| services.anuko-time-tracker.settings.email.smtpHost | MTA hostname.
|
| services.mysql.galeraCluster.localAddress | IP address or hostname of this node that will be used for cluster communication
|
| services.mysql.replication.slaveHost | Hostname of the MySQL slave server.
|
| services.anuko-time-tracker.nginx.reuseport | Create an individual listening socket
|
| services.firefly-iii.settings.DB_HOST | The machine which hosts your database
|
| services.nginx.tailscaleAuth.virtualHosts | A list of nginx virtual hosts to put behind tailscale.nginx-auth
|
| services.nginx.virtualHosts.<name>.reuseport | Create an individual listening socket
|
| services.metricbeat.settings.name | Name of the beat
|
| services.bluesky-pds.settings.PDS_HOSTNAME | Instance hostname (base domain name)
|
| services.kubernetes.masterAddress | Clusterwide available network address or hostname for the kubernetes master server.
|
| services.bookstack.nginx.reuseport | Create an individual listening socket
|
| services.openssh.settings.GatewayPorts | Specifies whether remote hosts are allowed to connect to
ports forwarded for the client
|
| services.mysql.replication.masterHost | Hostname of the MySQL master server.
|
| networking.stevenblack.enable | Whether to enable the stevenblack hosts file blocklist.
|
| services.jirafeau.nginxConfig.reuseport | Create an individual listening socket
|
| services.zabbixWeb.nginx.virtualHost.reuseport | Create an individual listening socket
|
| services.i2pd.inTunnels.<name>.destination | Remote endpoint, I2P hostname or b32.i2p address.
|
| services.firefly-iii-data-importer.virtualHost | The hostname at which you wish firefly-iii-data-importer to be served
|
| services.cassandra.seedAddresses | The addresses of hosts designated as contact points in the cluster
|
| services.i2pd.outTunnels.<name>.destination | Remote endpoint, I2P hostname or b32.i2p address.
|
| services.echoip.enableReverseHostnameLookups | Whether to enable reverse hostname lookups.
|
| services.icecream.daemon.schedulerHost | Explicit scheduler hostname, useful in firewalled environments
|
| services.tor.relay.onionServices.<name>.secretKey | Secret key of the onion service
|
| services.dependency-track.settings."alpine.oidc.teams.claim" | Defines the name of the claim that contains group memberships or role assignments in the provider's userinfo endpoint
|
| services.lasuite-docs.settings.DJANGO_ALLOWED_HOSTS | Comma-separated list of hosts that are able to connect to the server
|
| services.lasuite-meet.settings.DJANGO_ALLOWED_HOSTS | Comma-separated list of hosts that are able to connect to the server
|
| services.silverbullet.listenAddress | Address or hostname to listen on
|
| services.livekit.ingress.settings.redis.address | Address or hostname and port for redis connection
|
| services.homepage-dashboard.allowedHosts | Hosts that homepage-dashboard will be running under
|
| services.prometheus.exporters.nut.nutServer | Hostname or address of the NUT server
|
| services.fedimintd.<name>.nginx.config.reuseport | Create an individual listening socket
|
| services.journaldriver.logName | Configures the name of the target log in Stackdriver Logging
|
| services.meilisearch.listenAddress | The IP address that Meilisearch will listen on
|
| services.biboumi.settings.password | The password used to authenticate the XMPP component to your XMPP server
|
| services.cassandra.rpcAddress | The address or interface to bind the native transport server to
|
| programs.firefox.nativeMessagingHosts.packages | Additional packages containing native messaging hosts that should be made available to Firefox extensions.
|
| services.dsnet.settings.ExternalHostname | The hostname that clients should use to connect to this server
|
| services.jitsi-videobridge.xmppConfigs.<name>.domain | Domain part of JID of the XMPP user, if it is different from hostName.
|
| services.borgbackup.jobs.<name>.archiveBaseName | How to name the created archives
|
| services.prometheus.exporters.mqtt.mqttAddress | IP or hostname of MQTT broker.
|
| services.nebula.networks.<name>.lighthouses | List of IPs of lighthouse hosts this node should report to and query from
|
| services.prometheus.exporters.deluge.delugeHost | Hostname where deluge server is running.
|
| services.limesurvey.nginx.virtualHost.reuseport | Create an individual listening socket
|
| services.easytier.instances.<name>.configServer | Configure the instance from config server
|
| services.graylog.elasticsearchHosts | List of valid URIs of the http ports of your elastic nodes
|
| networking.wg-quick.interfaces.<name>.peers.*.endpoint | Endpoint IP or hostname of the peer, followed by a colon,
and then a port number of the peer.
|
| services.unpoller.prometheus.http_listen | Bind the prometheus exporter to this IP or hostname.
|
| services.firezone.server.settingsSecret.TOKENS_SALT | A file containing a unique base64 encoded secret for the
TOKENS_SALT
|
| virtualisation.libvirtd.nss.enable | This option enables the older libvirt NSS module
|
| services.misskey.reverseProxy.webserver.nginx.reuseport | Create an individual listening socket
|
| services.firezone.server.settingsSecret.TOKENS_KEY_BASE | A file containing a unique base64 encoded secret for the
TOKENS_KEY_BASE
|
| services.firezone.server.settingsSecret.SECRET_KEY_BASE | A file containing a unique base64 encoded secret for the
SECRET_KEY_BASE
|
| networking.resolvconf.dnsSingleRequest | Recent versions of glibc will issue both ipv4 (A) and ipv6 (AAAA)
address queries at the same time, from the same port
|
| services.librenms.distributedPoller.rrdcachedHost | Hostname or IP of the rrdcached server.
|
| services.jitsi-videobridge.xmppConfigs.<name>.mucNickname | Videobridges use the same XMPP account and need to be distinguished by the
nickname (aka resource part of the JID)
|
| services.librenms.distributedPoller.memcachedHost | Hostname or IP of the memcached server.
|
| networking.interfaces.<name>.proxyARP | Turn on proxy_arp for this device
|
| virtualisation.libvirtd.nss.enableGuest | This option enables the newer libvirt_guest NSS module
|
| services.prometheus.exporters.pihole.piholeHostname | Hostname or address where to find the Pi-Hole webinterface
|
| security.pam.sshAgentAuth.authorizedKeysFiles | A list of paths to files in OpenSSH's authorized_keys format, containing
the keys that will be trusted by the pam_ssh_agent_auth module
|
| services.changedetection-io.environmentFile | Securely pass environment variables to changedetection-io
|
| services.github-runners.<name>.tokenFile | The full path to a file which contains either
- a fine-grained personal access token (PAT),
- a classic PAT
- or a runner registration token
Changing this option or the tokenFile’s content triggers a new runner registration
|
| services.firezone.server.settingsSecret.RELEASE_COOKIE | A file containing a unique secret identifier for the Erlang
cluster
|
| services.your_spotify.settings.API_ENDPOINT | The endpoint of your server
This api has to be reachable from the device you use the website from not from the server
|
| services.prometheus.exporters.surfboard.modemAddress | The hostname or IP of the cable modem.
|
| services.firezone.server.settingsSecret.LIVE_VIEW_SIGNING_SALT | A file containing a unique base64 encoded secret for the
LIVE_VIEW_SIGNING_SALT
|
| services.prometheus.exporters.py-air-control.deviceHostname | The hostname of the air purification device from which to scrape the metrics.
|
| services.prometheus.exporters.fritzbox.gatewayAddress | The hostname or IP of the FRITZ!Box.
|
| services.cloudflared.tunnels.<name>.originRequest.originServerName | Hostname that cloudflared should expect from your origin server certificate.
|
| services.firezone.server.settingsSecret.COOKIE_SIGNING_SALT | A file containing a unique base64 encoded secret for the
COOKIE_SIGNING_SALT
|
| services.tor.relay.onionServices.<name>.authorizeClient.clientNames | Only clients that are listed here are authorized to access the hidden service
|
| services.strongswan-swanctl.swanctl.pools.<name>.addrs | Addresses allocated in pool
|
| services.dependency-track.settings."alpine.database.mode" | Defines the database mode of operation
|
| services.nextcloud-spreed-signaling.settings.backend.allowall | Allow any hostname as backend endpoint
|
| services.firezone.server.settingsSecret.COOKIE_ENCRYPTION_SALT | A file containing a unique base64 encoded secret for the
COOKIE_ENCRYPTION_SALT
|
| services.prometheus.exporters.mail.configuration.servers.*.server | Hostname of the server that should be probed.
|
| networking.wireguard.interfaces.<name>.peers.*.endpoint | Endpoint IP or hostname of the peer, followed by a colon,
and then a port number of the peer
|
| networking.wireguard.interfaces.<name>.dynamicEndpointRefreshSeconds | Periodically refresh the endpoint hostname or address for all peers
|
| security.pam.rssh.settings.auth_key_file | Path to file with trusted public keys in OpenSSH's authorized_keys format
|
| networking.wireguard.interfaces.<name>.peers.*.dynamicEndpointRefreshSeconds | Periodically re-execute the wg utility every
this many seconds in order to let WireGuard notice DNS / hostname
changes
|
| services.matrix-synapse.settings.trusted_key_servers.*.server_name | Hostname of the trusted server.
|