| services.angrr.settings.profile-policies | Profile GC root policies.
|
| services.angrr.settings.profile-policies.<name>.profile-paths | Paths to the Nix profile
|
| services.angrr.settings.profile-policies.<name>.keep-since | Retention period for the GC roots in this profile.
|
| services.angrr.settings.profile-policies.<name>.keep-latest-n | Keep the latest N GC roots in this profile.
|
| hardware.tuxedo-drivers.settings.charging-profile | The maximum charge level to help reduce battery wear:
high_capacity charges to 100% (driver default)
balanced charges to 90%
stationary charges to 80% (maximum lifespan)
Note: Regardless of the configured charging profile, the operating system will always report the battery as being charged to 100%.
|
| services.angrr.settings.profile-policies.<name>.enable | Whether to enable this angrr policy.
|
| services.nextcloud.settings."profile.enabled" | Makes user-profiles globally available under nextcloud.tld/u/user.name
|
| services.angrr.settings.profile-policies.<name>.keep-booted-system | Whether to keep the last booted system generation
|
| services.angrr.settings.profile-policies.<name>.keep-current-system | Whether to keep the current system generation
|
| services.system76-scheduler.settings.processScheduler.pipewireBoost.profile.nice | Niceness.
|
| services.system76-scheduler.settings.processScheduler.pipewireBoost.profile.prio | CPU scheduler priority.
|
| i18n.inputMethod.fcitx5.settings.inputMethod | The input method configure in profile file in ini format.
|
| services.system76-scheduler.settings.processScheduler.pipewireBoost.profile.ioPrio | IO scheduler priority.
|
| services.system76-scheduler.settings.processScheduler.pipewireBoost.profile.class | CPU scheduler class.
|
| services.system76-scheduler.settings.processScheduler.pipewireBoost.profile.ioClass | IO scheduler class.
|
| services.system76-scheduler.settings.processScheduler.pipewireBoost.profile.matchers | Process matchers.
|
| programs.dconf.profiles | Attrset of dconf profiles
|
| services.tuned.settings.profile_dirs | Directories to search for profiles, separated by , or ;.
|
| services.tt-rss.auth.autoLogin | Automatically login user on remote or other kind of externally supplied
authentication, otherwise redirect to login form as normal
|
| services.hedgedoc.settings.allowGravatar | Whether to enable Libravatar as
profile picture source on your instance
|
| networking.networkmanager.ensureProfiles.profiles | Declaratively define NetworkManager profiles
|
| services.freshrss.api.enable | Whether to enable API access for mobile apps and third-party clients (Google Reader API and Fever API)
|
| services.g810-led.profile | Keyboard profile to apply at boot time
|
| programs.schroot.profiles | Custom configuration profiles for schroot.
|
| services.cachix-agent.profile | Profile name, defaults to 'system' (NixOS).
|
| security.acme.certs.<name>.profile | The certificate profile to choose if the CA offers multiple profiles.
|
| services.grafana.settings.security.disable_gravatar | Set to true to disable the use of Gravatar for user profile images.
|
| security.acme.defaults.profile | The certificate profile to choose if the CA offers multiple profiles.
|
| programs.schroot.profiles.<name>.fstab | A file in the format described in fstab(5), used to mount filesystems inside the chroot
|
| security.tpm2.fapi.profileName | Name of the default cryptographic profile chosen from the profile_dir directory.
|
| services.oauth2-proxy.profileURL | Profile access endpoint.
|
| services.tuned.profiles | Profiles for TuneD
|
| services.qbittorrent.serverConfig | Free-form settings mapped to the qBittorrent.conf file in the profile
|
| services.disnix.profiles | Names of the Disnix profiles to expose in the system's PATH
|
| services.autorandr.profiles.<name>.hooks | Profile hook scripts.
|
| programs.schroot.profiles.<name>.copyfiles | A list of files to copy into the chroot from the host system.
|
| security.apparmor.policies.<name>.profile | The profile file contents
|
| services.autorandr.profiles.<name>.config | Per output profile configuration.
|
| security.tpm2.fapi.profileDir | Directory that contains all cryptographic profiles known to FAPI.
|
| services.prometheus.remoteWrite.*.sigv4.profile | The named AWS profile used to authenticate.
|
| services.asusd.profileConfig | The content of /etc/asusd/profile.ron
|
| services.asusd.profileConfig.text | Text of the file.
|
| environment.profiles | A list of profiles used to setup the global environment.
|
| services.qbittorrent.profileDir | the path passed to qbittorrent via --profile.
|
| services.autorandr.profiles | Autorandr profiles specification.
|
| programs.schroot.profiles.<name>.nssdatabases | System databases (as described in /etc/nsswitch.conf on GNU/Linux systems) to copy into the chroot from the host.
|
| services.tuned.ppdSettings.profiles | Map of PPD profiles to native TuneD profiles.
|
| services.asusd.profileConfig.source | Path of the source file.
|
| services.power-profiles-daemon.package | The power-profiles-daemon package to use.
|
| services.power-profiles-daemon.enable | Whether to enable power-profiles-daemon, a DBus daemon that allows
changing system behavior based upon user-selected power profiles.
|
| services.crowdsec.localConfig.profiles | A list of profiles to enable
|
| programs.nncp.settings | NNCP configuration, see
http://www.nncpgo.org/Configuration.html
|
| environment.profileRelativeEnvVars | Attribute set of environment variable
|
| boot.uki.settings | The configuration settings for ukify
|
| programs.rust-motd.settings | Settings on what to generate
|
| services.libinput.mouse.accelProfile | Sets the pointer acceleration profile to the given profile
|
| programs.yazi.settings | Configuration included in $YAZI_CONFIG_HOME.
|
| services.autorandr.profiles.<name>.config.<name>.dpi | Output DPI configuration.
|
| programs.bat.settings | Parameters to be written to the system-wide bat configuration file.
|
| services.autorandr.profiles.<name>.config.<name>.mode | Output resolution.
|
| services.autorandr.profiles.<name>.config.<name>.rate | Output framerate.
|
| programs.atop.settings | Parameters to be written to /etc/atoprc.
|
| services.autorandr.profiles.<name>.config.<name>.crtc | Output video display controller.
|
| services.autorandr.profiles.<name>.config.<name>.scale.y | Vertical scaling factor/pixels.
|
| services.autorandr.profiles.<name>.config.<name>.scale.x | Horizontal scaling factor/pixels.
|
| programs.yazi.settings.vfs | Configuration included in vfs.toml
|
| services.autorandr.profiles.<name>.config.<name>.gamma | Output gamma configuration.
|
| programs.schroot.settings | Schroot configuration settings
|
| programs.yazi.settings.yazi | Configuration included in yazi.toml
|
| services.libinput.touchpad.accelProfile | Sets the pointer acceleration profile to the given profile
|
| services.autorandr.profiles.<name>.config.<name>.enable | Whether to enable the output.
|
| services.autorandr.profiles.<name>.config.<name>.rotate | Output rotate configuration.
|
| programs.foot.settings | Configuration for foot terminal emulator
|
| programs.htop.settings | Extra global default configuration for htop
which is read on first startup only
|
| programs.yazi.settings.theme | Configuration included in theme.toml
|
| services.autorandr.profiles.<name>.config.<name>.scale.method | Output scaling method.
|
| services.autorandr.profiles.<name>.config.<name>.primary | Whether output should be marked as primary
|
| services.lact.settings | Settings for LACT
|
| programs.direnv.settings | Direnv configuration
|
| services.autorandr.profiles.<name>.hooks.preswitch | Preswitch hook executed before mode switch.
|
| services.autorandr.profiles.<name>.hooks.predetect | Predetect hook executed before autorandr attempts to run xrandr.
|
| services.autorandr.profiles.<name>.config.<name>.scale | Output scale configuration
|
| services.mjolnir.settings | Additional settings (see mjolnir default config for available settings)
|
| services.autorandr.profiles.<name>.config.<name>.position | Output position
|
| programs.yazi.settings.keymap | Configuration included in keymap.toml
|
| programs.gamemode.settings | System-wide configuration for GameMode (/etc/gamemode.ini)
|
| services.nitter.settings | Add settings here to override NixOS module generated settings
|
| programs.gnupg.agent.settings | Configuration for /etc/gnupg/gpg-agent.conf
|
| services.autorandr.profiles.<name>.hooks.postswitch | Postswitch hook executed after mode switch.
|
| programs.lazygit.settings | Lazygit configuration
|
| services.prometheus.scrapeConfigs.*.ec2_sd_configs.*.profile | Named AWS profile used to connect to the API.
|
| programs.regreet.settings | ReGreet configuration file
|
| services.autorandr.profiles.<name>.config.<name>.transform | Refer to
xrandr(1)
for the documentation of the transform matrix.
|
| services.autorandr.profiles.<name>.fingerprint | Output name to EDID mapping
|
| services.amule.settings | Free form attribute set for aMule settings
|
| systemd.oomd.settings.OOM | Settings option for systemd-oomd
|
| programs.spacefm.settings | The system-wide spacefm configuration
|
| programs.starship.settings | Configuration included in starship.toml
|
| security.agnos.settings | Settings
|
| services.odoo.settings | Odoo configuration settings
|
| services.ncdns.settings | ncdns settings
|
| environment.profileRelativeSessionVariables | Attribute set of environment variable used in the global
environment
|
| services.sslh.settings | sslh configuration
|
| services.newt.settings | Settings for Newt module, see Newt CLI docs for more information.
|
| services.xray.settings | The configuration object
|
| services.picom.settings | Picom settings
|
| services.davfs2.settings | Extra settings appended to the configuration of davfs2
|
| services.marytts.settings | Settings for MaryTTS
|
| services.ntpd-rs.settings | Settings to write to ntp.toml
See https://docs.ntpd-rs.pendulum-project.org/man/ntp.toml.5
for more information about available options.
|
| services.auto-epp.settings | Settings for the auto-epp application
|
| services.rimgo.settings | Settings for rimgo, see the official documentation for supported options.
|
| services.searx.settings | Searx settings
|
| security.apparmor.policies.<name>.path | A path of a profile file to include
|
| xdg.portal.wlr.settings | Configuration for xdg-desktop-portal-wlr
|
| services.stubby.settings | Content of the Stubby configuration file
|
| services.redlib.settings | See GitHub for available settings.
|
| services.acme-dns.settings | Free-form settings written directly to the acme-dns.cfg file
|
| services.psd.enable | Whether to enable the Profile Sync daemon.
|
| services.hickory-dns.settings | Settings for hickory-dns
|
| services.movim.settings | .env settings for Movim
|
| services.lldap.settings | Free-form settings written directly to the lldap_config.toml file
|
| services.screego.settings | Screego settings passed as Nix attribute set, they will be merged with
the defaults
|
| services.hercules-ci-agent.settings | These settings are written to the agent.toml file
|
| services.wakapi.settings | Settings for Wakapi
|
| programs.openvpn3.netcfg.settings | Options stored in /etc/openvpn3/netcfg.json configuration file
|
| power.ups.upsmon.settings | Additional settings to add to upsmon.conf.
|
| services.logrotate.settings | logrotate freeform settings: each attribute here will define its own section,
ordered by services.logrotate.settings.<name>.priority,
which can either define files to rotate with their settings
or settings common to all further files settings
|
| services.misskey.settings.db | Database settings.
|
| services.opengfw.settings.io | IO settings.
|
| services.g3proxy.settings | Settings of g3proxy.
|
| services.mailman.settings | Settings for mailman.cfg
|
| services.gokapi.settings | Configuration settings for the generated config json file
|
| services.privoxy.settings | This option is mapped to the main Privoxy configuration file
|
| services.h2o.settings | Configuration for H2O (see https://h2o.examp1e.net/configure.html)
|
| services.aria2.settings | Generates the aria2.conf file
|
| services.rauc.slots.<name>.*.settings | Settings for this slot.
|
| services.pgadmin.settings | Settings for pgadmin4.
Documentation
|
| services.sanoid.settings | Free-form settings written directly to the config file
|
| services.draupnir.settings | Free-form settings written to Draupnir's configuration file
|
| services.tor.settings | See torrc manual
for documentation.
|
| services.fluent-bit.settings | See configurationFile.
configurationFile takes precedence over settings.
|
| services.umurmur.settings | Settings of uMurmur
|
| services.maubot.settings | YAML settings for maubot
|
| services.sssd.settings | Contents of sssd.conf.
|
| services.n8n.settings | Configuration for n8n, see https://docs.n8n.io/hosting/environment-variables/configuration-methods/
for supported values.
|
| services.openbao.settings | Settings of OpenBao
|
| services.opengfw.settings | Settings passed to OpenGFW. Example config
|
| nix.settings.max-jobs | This option defines the maximum number of jobs that Nix will try to
build in parallel
|
| services.private-gpt.settings | settings-local.yaml for private-gpt
|
| services.knot.settings | Extra configuration as nix values.
|
| services.tlp.settings | Options passed to TLP
|
| services.pretix.settings | pretix configuration as a Nix attribute set
|
| services.qui.settings.port | The port qui listens on.
|
| services.eintopf.settings | Settings to configure web service
|
| services.evremap.settings | Settings for evremap
|
| services.wiki-js.settings.db.db | Name of the database to use.
|
| services.qui.settings.host | The host address qui listens on.
|
| services.public-inbox.settings | Settings for the public-inbox config file.
|
| services.grafana.settings | Grafana settings
|
| programs.openvpn3.log-service.settings | Options stored in /etc/openvpn3/log-service.json configuration file
|
| services.bee.settings | Ethereum Swarm Bee configuration
|
| services.lemmy.settings | Lemmy configuration
|
| services.aesmd.settings | AESM configuration
|
| services.stash.settings | Stash configuration
|
| services.apache-kafka.settings | Kafka broker configuration
server.properties
|
| hardware.cpu.x86.msr.settings | Parameters for the msr kernel module.
|
| services.ntfy-sh.settings | Configuration for ntfy.sh, supported values are here.
|
| services.turn-rs.settings | Turn-rs server config file
|
| services.suricata.settings | Suricata settings
|
| services.tor.settings.ORPort | See torrc manual.
|
| services.inadyn.settings.custom | Settings for custom DNS providers.
|
| services.ifm.settings | Configuration of the IFM service
|
| services.openssh.settings.Macs | Allowed MACs
Defaults to recommended settings from both
https://stribika.github.io/2015/01/04/secure-secure-shell.html
and
https://infosec.mozilla.org/guidelines/openssh#modern-openssh-67
|
| services.haven.settings | See https://github.com/bitvora/haven for documentation.
|
| services.logind.settings.Login | Settings option for systemd-logind
|
| services.zwave-js.settings | Configuration settings for the generated config file
|
| services.pds.settings.PDS_PORT | Port to listen on
|
| nix.settings.cores | This option defines the maximum number of concurrent tasks during
one build
|
| services.frp.settings | Frp configuration, for configuration options
see the example of client
or server on github.
|
| services.tor.settings.DirPort | See torrc manual.
|
| services.tor.settings.DNSPort | See torrc manual.
|
| services.tor.settings.PidFile | See torrc manual.
|
| services.umami.settings.BASE_PATH | Allows you to host Umami under a subdirectory
|
| services.mpd.settings.port | This setting is the TCP port that is desired for the daemon to get assigned
to.
|
| services.envoy.settings | Specify the configuration for Envoy in Nix.
|
| boot.initrd.unl0kr.settings | Configuration for unl0kr
|
| services.forgejo.settings | Free-form settings written directly to the app.ini configfile file
|
| services.acme-dns.settings.api.ip | IP to bind the HTTP API on.
|
| services.thinkfan.settings | Thinkfan settings
|
| services.rsync.jobs.<name>.settings | Settings that should be passed to rsync via long options
|
| services.ente.api.settings.db.port | The database port
|
| services.ente.api.settings.db.host | The database host
|
| services.ente.api.settings.db.user | The database user
|
| services.ente.api.settings.db.name | The database name
|
| services.wiki-js.settings | Settings to configure wiki-js
|
| services.acme-dns.settings.api.tls | TLS backend to use.
|
| services.isso.settings | Configuration for isso
|
| services.goss.settings | The global options in config file in yaml format
|
| services.kubo.settings | Attrset of daemon configuration
|
| services.nats.settings | Declarative NATS configuration
|
| services.pdns-recursor.settings | PowerDNS Recursor settings
|
| services.dolibarr.settings | Dolibarr settings, see https://github.com/Dolibarr/dolibarr/blob/develop/htdocs/conf/conf.php.example for details.
|
| services.mediamtx.settings | Settings for MediaMTX
|
| services.komga.settings | Komga configuration
|
| services.angrr.settings | Global configuration for angrr in TOML format.
|
| services.dunst.settings | Dunst configuration, see dunst(5)
|
| services.zrepl.settings | Configuration for zrepl
|
| services.tor.settings.IPv6Exit | See torrc manual.
|
| services.tor.settings.ExtORPort | See torrc manual.
|
| services.tor.settings.GeoIPFile | See torrc manual.
|
| services.wiki-js.settings.port | TCP port the process should listen to.
|
| services.actual.settings | Server settings, refer to the documentation for available options
|
| services.wiki-js.settings.db.host | Hostname or socket-path to connect to.
|
| services.pretalx.settings | pretalx configuration as a Nix attribute set
|
| services.lokinet.settings | Configuration for Lokinet
|
| services.wiki-js.settings.bindIP | IPs the service should listen to.
|
| services.nfs.settings | General configuration for NFS daemons and tools
|
| services.oink.settings.apiKey | API key to use when modifying DNS records.
|
| services.canaille.settings | Settings for Canaille
|
| services.howdy.settings | Howdy configuration file
|
| services.gonic.settings | Configuration for Gonic, see https://github.com/sentriz/gonic#configuration-options for supported values.
|
| services.clatd.settings | Configuration of clatd
|
| services.plikd.settings | Configuration for plikd, see https://github.com/root-gg/plik/blob/master/server/plikd.cfg
for supported values.
|
| services.omnom.settings | Configuration options for the /etc/omnom/config.yml file.
|
| services.slskd.settings | Application configuration for slskd
|
| services.nipap.settings | Configuration options to set in /etc/nipap/nipap.conf.
|
| security.pam.u2f.settings.debug | Debug output to stderr.
|
| services.rimgo.settings.PORT | The port to use.
|
| services.umami.settings.PORT | The port to listen on.
|
| services.cross-seed.settingsFile | Path to a JSON file containing settings that will be merged with the
settings option
|
| services.omnom.settings.db.type | Database type.
|
| services.sabnzbd.settings.ntfosd | NotifyOSD settings
|
| services.tor.settings.NATDPort | See torrc manual.
|
| hardware.nfc-nci.settings | Configuration to be written to the libncf-nci configuration files
|
| services.pds.settings | Environment variables to set for the service
|
| services.prometheus.scrapeConfigs.*.lightsail_sd_configs.*.profile | Named AWS profile used to connect to the API.
|
| services.karma.settings | Karma dashboard configuration as nix attributes
|
| services.hatsu.settings | Configuration for Hatsu, see
|
| services.gitea.settings | Gitea configuration
|
| services.tuned.settings | Configuration for TuneD
|
| services.xmrig.settings | XMRig configuration
|
| services.stash.settings.port | The port that Stash should listen on.
|
| services.nvme-rs.settings | Configuration for nvme-rs in TOML format
|
| services.trickster.profiler-port | Port that the /debug/pprof endpoint will listen on.
|
| services.cockpit.settings | Settings for cockpit that will be saved in /etc/cockpit/cockpit.conf
|
| services.opengfw.settings.replay | PCAP replay settings.
|
| services.kanidm.server.settings | Settings for Kanidm, see
the documentation
and example configuration
for possible values.
|
| services.kanboard.settings | Customize the default settings, refer to https://github.com/kanboard/kanboard/blob/main/config.default.php
for details on supported values.
|
| services.dendrite.settings | Configuration for dendrite, see:
https://github.com/matrix-org/dendrite/blob/main/dendrite-sample.yaml
for available options with which to populate settings.
|
| services.pixelfed.settings | .env settings for Pixelfed
|
| services.aria2.settings.dir | Directory to store downloaded files.
|
| services.tsidp.settings.port | Port to listen on (default: 443).
|
| services.tor.settings.DirCache | See torrc manual.
|
| services.tor.settings.GeoIPv6File | See torrc manual.
|
| services.stash.settings.host | The ip address that Stash should bind to.
|
| services.gatus.settings | Configuration for Gatus
|
| services.ulogd.settings | Configuration for ulogd
|
| services.pgscv.settings | Configuration for pgSCV, in YAML format
|
| services.tempo.settings | Specify the configuration for Tempo in Nix
|
| services.acme-dns.settings.api.port | Listen port for the HTTP API.
|
| services.harmonia.settings | Settings to merge with the default configuration
|
| services.paisa.settings.dbFile | Filename of the Paisa database.
|
| services.nvme-rs.settings.email | Email notification configuration
|
| services.crab-hole.settings | Crab-holes config
|
| services.inadyn.settings | See inadyn.conf (5)
|
| services.mbpfan.settings | INI configuration for Mbpfan.
|
| services.slskd.settings.web.port | The HTTP listen port.
|
| services.nvme-rs.settings.email.to | Recipient email address
|
| services.lemmy.settings.port | Port where lemmy should listen for incoming requests.
|
| services.legit.settings | The primary legit configuration
|
| services.umami.settings | Additional configuration (environment variables) for Umami, see
https://umami.is/docs/environment-variables for supported values.
|
| services.mympd.settings.ssl | Whether to enable listening on the SSL port
|
| nix.settings.extra-sandbox-paths | Directories from the host filesystem to be included
in the sandbox.
|
| services.tor.settings.HidServAuth | See torrc manual.
|
| services.rauc.settings | Rauc configuration that will be converted to INI
|
| services.cloud-init.settings | Structured cloud-init configuration.
|
| services.kismet.settings | Options for Kismet
|
| services.vector.settings | Specify the configuration for Vector in Nix.
|
| services.pds.settings.PDS_DID_PLC_URL | URL of DID PLC directory
|
| hardware.amdgpu.amdvlk.settings | Runtime settings for AMDVLK to be configured /etc/amd/amdVulkanSettings.cfg
|
| nix.settings | Configuration for Nix, see
https://nixos.org/manual/nix/stable/command-ref/conf-file.html or
nix.conf(5) for available options
|
| services.stash.settings.cache | Path to cache
|
| services.kea.dhcp-ddns.settings | Kea DHCP-DDNS configuration as an attribute set, see https://kea.readthedocs.io/en/kea-3.0.2/arm/ddns.html.
|
| services.alice-lg.settings | alice-lg configuration, for configuration options see the example on github
|
| services.gatus.settings.web.port | The TCP port to serve the Gatus service at.
|
| services.postfix.settings.main | The main.cf configuration file as key value set
|
| services.atticd.settings | Structured configurations of atticd
|
| security.please.settings | Please configuration
|
| services.garage.settings | Garage configuration, see https://garagehq.deuxfleurs.fr/documentation/reference-manual/configuration/ for reference.
|
| services.paisa.settings.dataDir | Path to paisa data directory.
|
| services.tor.settings.ExitRelay | See torrc manual.
|
| services.tor.settings.SOCKSPort | See torrc manual.
|
| services.tor.settings.TransPort | See torrc manual.
|
| services.tor.settings.PerConnBWRate | See torrc manual.
|
| services.sunshine.settings | Settings to be rendered into the configuration file
|
| services.kea.dhcp4.settings | Kea DHCP4 configuration as an attribute set, see https://kea.readthedocs.io/en/kea-3.0.2/arm/dhcp4-srv.html.
|
| services.kea.dhcp6.settings | Kea DHCP6 configuration as an attribute set, see https://kea.readthedocs.io/en/kea-3.0.2/arm/dhcp6-srv.html.
|
| services.aesmd.settings.proxy | HTTP network proxy.
|
| services.omnom.settings.smtp.host | SMTP server hostname.
|
| services.dsnet.settings.IP | The IPv4 address that the server will use on the network
|
| services.omnom.settings.smtp.tls | Whether to enable Whether TLS encryption should be used..
|
| services.dex.settings | The available options can be found in
the example configuration
|
| services.actual.settings.port | The port to listen on
|
| services.kavita.settings.Port | Port to bind to.
|
| services.nfs.idmapd.settings | libnfsidmap configuration
|
| services.hebbot.settings | Configuration for Hebbot, see, for examples:
|
| services.kavita.settings | Kavita configuration options, as configured in appsettings.json.
|
| services.gancio.settings | Configuration for Gancio, see https://gancio.org/install/config for supported values.
|
| services.dgraph.settings | Contents of the dgraph config
|
| services.rsyncd.settings | Configuration for rsyncd
|
| services.uhub.<name>.plugins.*.settings | Settings specific to this plugin.
|
| services.paperless.settings | Extra paperless config options
|
| services.opengfw.settings.workers | Worker settings.
|
| services.godns.settings | Configuration for GoDNS
|
| services.sympa.settings | The sympa.conf configuration file as key value set
|
| services.part-db.settings | Options for part-db configuration
|
| services.slskd.settings.rooms | Chat rooms to join on startup.
|
| services.tor.settings.AuthDirPinKeys | See torrc manual.
|
| services.omnom.settings.smtp.port | SMTP server port address.
|
| services.xray.settingsFile | The absolute path to the configuration file
|
| services.evcc.settings | evcc configuration as a Nix attribute set
|
| services.sftpgo.settings.smtp | SMTP configuration section.
|
| services.cryptpad.settings | Cryptpad configuration settings
|
| services.gitea.settings.log.LEVEL | General log level.
|
| services.nvme-rs.settings.email.from | Sender email address
|
| services.cgit.<name>.settings | cgit configuration, see cgitrc(5)
|
| services.uhub.<name>.settings | Configuration of uhub
|
| services.dsnet.settings.IP6 | The IPv6 address that the server will use on the network
Leave this empty to let dsnet choose an address.
|
| services.blocky.settings | Blocky configuration
|
| services.erigon.settings | Configuration for Erigon
Refer to https://github.com/ledgerwatch/erigon#usage for details on supported values.
|
| services.greetd.settings | greetd configuration (documentation)
as a Nix attribute set.
|
| services.gobgpd.settings | GoBGP configuration
|
| services.soft-serve.settings | The contents of the configuration file for soft-serve
|
| services.qdrant.settings | Configuration for Qdrant
Refer to https://github.com/qdrant/qdrant/blob/master/config/config.yaml for details on supported values.
|
| services.gerrit.settings | Gerrit configuration
|
| services.zeyple.settings | Zeyple configuration. refer to
https://github.com/infertux/zeyple/blob/master/zeyple/zeyple.conf.example
for details on supported values.
|
| security.pam.u2f.settings | Options to pass to the PAM module
|
| services.neard.settings | Neard INI-style configuration file as a Nix attribute set
|
| security.krb5.settings | Structured contents of the krb5.conf file
|
| services.phpfpm.settings | PHP-FPM global directives
|
| services.qui.settings | qui configuration options
|
| services.renovate.settings | Renovate's global configuration
|
| services.artalk.settings.port | Artalk server listen port
|
| services.artalk.settings.host | Artalk server listen host
|
| services.tsidp.settings.hostName | The hostname to use for the tsnet node.
|
| services.tor.settings.DirPolicy | See torrc manual.
|
| services.rkvm.server.settings | Structured server daemon configuration
|
| services.rkvm.client.settings | Structured client daemon configuration
|
| services.gancio.settings.db.host | Connection string for the PostgreSQL database
|
| services.omnom.settings.app.debug | Whether to enable debug mode.
|
| services.zfs.zed.settings | ZFS Event Daemon /etc/zfs/zed.d/zed.rc content
See
zed(8)
for details on ZED and the scripts in /etc/zfs/zed.d to find the possible variables
|
| security.auditd.settings | auditd configuration file contents
|
| services.mopidy.settings | The configuration that Mopidy should use
|
| services.strfry.settings | Configuration options to set for the Strfry service
|
| services.mchprs.settings | Configuration for MCHPRS via Config.toml
|
| services.zenohd.settings | Config options for zenoh.json5 configuration file
|
| services.nezha-agent.settings.gpu | Enable GPU monitoring.
|
| services.kubo.settings.Mounts.MFS | Where to mount the MFS namespace to
|
| services.wiki-js.settings.logLevel | Define how much detail is supposed to be logged at runtime.
|
| services.chhoto-url.settings.port | The port to listen on.
|
| services.ente.api.settings.apps.cast | Set this to the URL where your cast page is running
|
| services.legit.settings.meta.title | Website title.
|
| services.misskey.settings.db.db | The database name.
|
| services.nostr-rs-relay.settings | See https://git.sr.ht/~gheartsfield/nostr-rs-relay/#configuration for documentation.
|
| services.cross-seed.settings.port | Port the cross-seed daemon listens on.
|
| services.kea.ctrl-agent.settings | Kea Control Agent configuration as an attribute set, see https://kea.readthedocs.io/en/kea-3.0.2/arm/agent.html.
|
| services.homed.settings.Home | Options for systemd-homed
|
| services.ananicy.settings | See https://github.com/Nefelim4ag/Ananicy/blob/master/ananicy.d/ananicy.conf
|
| services.radicle.settings | See https://app.radicle.xyz/nodes/seed.radicle.garden/rad:z3gqcJUoA1n9HaHKufZs5FCSGazv5/tree/radicle/src/node/config.rs#L275
|
| services.sftpgo.settings.smtp.from | From address.
|
| services.clight.settings | Additional configuration to extend clight.conf
|
| services.netbox.settings | Configuration options to set in configuration.py
|
| services.sftpgo.settings | The primary sftpgo configuration
|
| services.porn-vault.settings | Configuration for Porn-Vault
|
| services.pghero.settings | PgHero configuration
|
| services.tor.settings.HidServAuth.*.auth | Authentication cookie.
|
| services.nezha-agent.settings.tls | Enable SSL/TLS encryption.
|
| services.tor.settings.PerConnBWBurst | See torrc manual.
|
| services.zwave-js-ui.settings | Extra environment variables passed to the zwave-js-ui process
|
| services.samba.settings | Configuration file for the Samba suite in ini format
|
| programs.openvpn3.log-service.settings.journald | Use systemd-journald
|
| services.listmonk.settings | Static settings set in the config.toml, see https://github.com/knadh/listmonk/blob/master/config.toml.sample for details
|
| services.pocket-id.settings | Environment variables to be passed
|
| services.postfix.settings.master | The master.cf configuration file as an attribute set of service
defitions
|
| services.mchprs.settings.port | Port for the server
|
| services.mchprs.settings.motd | Message of the day
|
| services.aria2.settings.conf-path | Configuration file path.
|
| services.movim.h2o.settings | Attrset to be transformed into YAML for host config
|
| services.schleuder.settings | Settings for schleuder.yml
|
| services.chhoto-url.settings | Configuration of Chhoto URL
|
| services.doh-server.settings | Configuration of doh-server in toml
|
| services.pihole-ftl.settings | Configuration options for pihole.toml
|
| services.sftpgo.settings.smtp.user | SMTP username.
|
| services.freeciv.settings | Parameters of freeciv-server.
|
| services.openssh.settings | Configuration for sshd_config(5).
|
| services.reaction.settings | Configuration for reaction
|
| services.taler.settings | Global configuration options for the taler config file
|
| services.grafana-to-ntfy.settings.bauthPass | The path to the password you will use in the Grafana webhook settings.
|
| services.openssh.settings.Ciphers | Allowed ciphers
Defaults to recommended settings from both
https://stribika.github.io/2015/01/04/secure-secure-shell.html
and
https://infosec.mozilla.org/guidelines/openssh#modern-openssh-67
|
| services.gitea.settings.log.ROOT_PATH | Root path for log files.
|
| services.doh-server.settings.path | HTTP path for resolve application
|
| services.tor.settings.ExitPolicy | See torrc manual.
|
| services.pocket-id.settings.APP_URL | The URL where you will access the app.
|
| services.displayManager.ly.settings | Extra settings merged in and overwriting defaults in config.ini.
|
| services.invidious.settings | The settings Invidious should use
|
| services.nominatim.settings | Nominatim configuration settings
|
| security.krb5.settings.module | Modules to obtain Kerberos configuration from.
|
| services.oink.settings.ttl | The TTL ("Time to Live") value to set for your DNS records
|
| services.kubo.settings.Mounts.IPNS | Where to mount the IPNS namespace to
|
| services.kubo.settings.Mounts.IPFS | Where to mount the IPFS namespace to
|
| services.sftpgo.settings.smtp.port | Port of the SMTP Server.
|
| services.mpd.settings.db_file | The path to MPD's database.
|
| services.tsidp.settings.localPort | Listen on localhost:.
|
| services.dwm-status.settings | Config options for dwm-status, see https://github.com/Gerschtli/dwm-status#configuration
for available options.
|
| services.mealie.settings | Configuration of the Mealie service
|
| services.veilid.settings | Build veilid-server.conf with nix expression
|
| services.go2rtc.settings | go2rtc configuration as a Nix attribute set
|
| services.litellm.settings | Configuration for LiteLLM
|
| services.openbao.settings.ui | Whether to enable the OpenBao web UI.
|
| services.ente.api.settings | Museum yaml configuration
|
| services.grocy.phpfpm.settings | Options for grocy's PHPFPM pool.
|
| services.tor.settings.Address | See torrc manual.
|
| services.tor.settings.ClientUseIPv6 | See torrc manual.
|
| services.tor.settings.HSLayer3Nodes | See torrc manual.
|
| services.tor.settings.Sandbox | See torrc manual.
|
| services.tor.settings.HSLayer2Nodes | See torrc manual.
|
| services.tor.settings.ClientUseIPv4 | See torrc manual.
|
| services.tsidp.settings.logLevel | Set logging level: debug, info, warn, error.
|
| services.llama-swap.settings | llama-swap configuration
|
| services.mympd.settings | Manages the configuration files declaratively
|
| services.logrotate.settings.<name>.global | Whether this setting is a global option or not: set to have these
settings apply to all files settings with a higher priority.
|
| services.biboumi.settings | See biboumi 9.0
for documentation.
|
| services.waagent.settings | The waagent.conf configuration, see https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/agent-linux for documentation.
|
| services.zipline.settings | Configuration of Zipline
|
| services.molly-brown.settings | molly-brown configuration
|
| systemd.settings.Manager | Options for the global systemd service manager
|
| networking.networkmanager.ensureProfiles.profiles.<name>.connection.id | This is the name that will be displayed by NetworkManager and GUIs.
|
| services.misskey.settings.db.port | The PostgreSQL port.
|
| services.misskey.settings.db.host | The PostgreSQL host.
|
| services.pds.settings.PDS_BSKY_APP_VIEW_DID | DID of bsky frontend
|
| services.freeciv.settings.read | Startup script.
|
| services.sslh.settings.timeout | Timeout in seconds.
|
| services.legit.settings.repo.scanPath | Directory where legit will scan for repositories.
|
| services.glance.settings | Configuration written to a yaml file that is read by glance
|
| services.artalk.settings | The artalk configuration
|
| services.tuned.settings.daemon | Whether to enable the use of a daemon for TuneD.
|
| services.stash.settings.stash.*.path | location of your media files
|
| services.wiki-js.settings.db.type | Database driver to use for persistence
|
| services.oncall.settings.db.conn.str | Database connection scheme
|
| services.amule.settings.eMule.Port | TCP port for eD2k connections
|
| services.tor.settings.HidServAuth.*.onion | Onion address.
|
| services.tor.settings.DirPortFrontPage | See torrc manual.
|
| services.go-csp-collector.settings | Settings for go-csp-collector
|
| security.pam.rssh.settings | Options to pass to the pam_rssh module
|
| services.knot.settingsFile | As alternative to settings, you can provide whole configuration
directly in the almost-YAML format of Knot DNS
|
| nix.settings.require-sigs | If enabled (the default), Nix will only download binaries from binary caches if
they are cryptographically signed with any of the keys listed in
nix.settings.trusted-public-keys
|
| services.pretix.settings.mail.host | Hostname of the SMTP server use for mail delivery.
|
| services.pretix.settings.mail.port | Port of the SMTP server to use for mail delivery.
|
| services.rkvm.server.settings.key | TLS key path.
This should be generated with rkvm-certificate-gen.
|
| services.pds.settings.PDS_BSKY_APP_VIEW_URL | URL of bsky frontend
|
| services.zitadel.settings.Port | The port that ZITADEL listens on.
|
| services.uptime-kuma.settings | Additional configuration for Uptime Kuma, see
https://github.com/louislam/uptime-kuma/wiki/Environment-Variables
for supported values.
|
| security.loginDefs.settings.UMASK | The file mode creation mask is initialized to this value.
|
| services.glance.settings.pages | List of pages to be present on the dashboard
|
| security.pam.u2f.settings.cue | By default pam-u2f module does not inform user
that he needs to use the u2f device, it just waits without a prompt
|
| security.loginDefs.settings.UID_MAX | Range of user IDs used for the creation of regular users by useradd or newusers.
|
| security.loginDefs.settings.UID_MIN | Range of user IDs used for the creation of regular users by useradd or newusers.
|
| services.legit.settings.server.host | Host address.
|
| services.legit.settings.server.name | Server name.
|
| services.legit.settings.server.port | Legit port.
|
| services.legit.settings.repo.ignore | Repositories to ignore.
|
| services.displayManager.sddm.settings | Extra settings merged in and overwriting defaults in sddm.conf.
|
| services.nzbget.settings | NZBGet configuration, passed via command line using switch -o
|
| services.pds.settings.LOG_ENABLED | Enable logging
|
| services.go-httpbin.settings.PORT | The port to listen on.
|
| services.go-httpbin.settings.HOST | The host to listen on.
|
| services.amule.settings.eMule.TempDir | Directory where aMule stores incomplete downloads (.part/.part.met files).
|
| services.phpfpm.pools.<name>.settings | PHP-FPM pool directives
|
| services.autobrr.settings | Autobrr configuration options
|
| services.klipper.settings | Configuration for Klipper
|
| services.readeck.settings | Additional configuration for Readeck, see
https://readeck.org/en/docs/configuration
for supported values.
|
| services.redmine.settings | Redmine configuration (configuration.yml)
|
| services.misskey.settings | Configuration for Misskey, see
example.yml
for all supported options.
|
| services.zitadel.settings | Contents of the runtime configuration file
|
| services.vikunja.settings | Vikunja configuration
|
| services.sharkey.settings.id | The ID generation method for Sharkey to use
|
| services.misskey.settings.db.user | The user used for database authentication.
|
| services.opengfw.settings.io.sndBuf | Netlink send buffer size.
|
| services.misskey.settings.db.pass | The password used for database authentication.
|
| services.opengfw.settings.io.rcvBuf | Netlink receive buffer size.
|
| services.pretix.settings.mail.from | E-Mail address used in the FROM header of outgoing mails.
|
| nix.settings.trusted-users | A list of names of users that have additional rights when
connecting to the Nix daemon, such as the ability to specify
additional binary caches, or to import unsigned NARs
|
| services.freeciv.settings.auth | Whether to enable server authentication.
|
| services.dwm-status.settings.order | List of enabled features in order.
|
| services.freeciv.settings.port | Listen for clients on given port
|
| services.openssh.settings.UsePAM | Whether to enable PAM authentication.
|
| services.tor.settings.TransProxyType | See torrc manual.
|
| services.misskey.settings.port | The port your Misskey server should listen on.
|
| services.tor.settings.SocksPolicy | See torrc manual.
|
| services.tor.settings.BridgeRelay | See torrc manual.
|
| services.tor.settings.LongLivedPorts | See torrc manual.
|
| services.sharkey.settings.port | The port that Sharkey will listen on.
|
| services.xonotic.settings.port | The port Xonotic will listen on.
|
| services.inadyn.settings.provider | Settings for DDNS providers built-in to inadyn
|
| programs.openvpn3.log-service.settings.log_level | How verbose should the logging be
|
| services.lasuite-meet.livekit.settings | Settings to pass to the livekit server
|
| security.loginDefs.settings.GID_MAX | Range of group IDs used for the creation of regular groups by useradd, groupadd, or newusers.
|
| security.loginDefs.settings.GID_MIN | Range of group IDs used for the creation of regular groups by useradd, groupadd, or newusers.
|
| services.legit.settings.repo.readme | Readme files to look for.
|
| services.karma.settings.listen.port | HTTP port to listen on.
|
| services.nipap.settings.nipapd.port | Port to bind nipapd to.
|
| services.paisa.settings | Paisa configuration
|
| nix.settings.system-features | The set of features supported by the machine
|
| networking.networkmanager.ensureProfiles.profiles.<name>.connection.type | The connection type defines the connection kind, like vpn, wireguard, gsm, wifi and more.
|
| services.glpiAgent.settings | GLPI Agent configuration options
|
| security.pam.u2f.settings.appid | By default pam-u2f module sets the application
ID to pam://$HOSTNAME
|
| services.grafana-to-ntfy.settings.bauthUser | The user that you will authenticate with in the Grafana webhook settings
|
| services.corteza.settings | Configuration for Corteza, will be passed as environment variables
|
| services.orthanc.settings | Configuration written to a json file that is read by orthanc
|
| services.zeronet.settings | zeronet.conf configuration
|
| services.misskey.settings.id | The ID generation method to use
|
| services.kanidm.unix.settings | Configure Kanidm unix daemon
|
| services.sing-box.settings | The sing-box configuration, see https://sing-box.sagernet.org/configuration/ for documentation
|
| services.nezha-agent.settings | Generate to config.json as a Nix attribute set
|
| services.maubot.settings.server | Listener config
|
| nix.settings.allowed-users | A list of names of users (separated by whitespace) that are
allowed to connect to the Nix daemon
|
| services.doh-server.settings.tries | Number of tries if upstream DNS fails
|
| services.go-httpbin.settings | Configuration of go-httpbin
|
| programs.openvpn3.log-service.settings.timestamp | Add timestamp log file
|
| hardware.apple.touchBar.settings | Configuration for tiny-dfr
|
| services.stash.settings.stash | Add directories containing your adult videos and images
|
| services.komga.settings.server.port | The port that Komga will listen on.
|
| services.legit.settings.dirs.static | Directories where static files are located.
|
| services.omnom.settings.smtp.sender | Omnom sender e-mail.
|
| services.gns3-server.settings | The global options in config file in ini format
|
| services.tor.settings.HTTPTunnelPort | See torrc manual.
|
| services.tor.settings.CookieAuthFile | See torrc manual.
|
| services.tor.settings.AuthDirListBadExits | See torrc manual.
|
| services.oink.settings.secretApiKey | Secret API key to use when modifying DNS records.
|
| services.spacecookie.settings | Settings for spacecookie
|
| services.goeland.settings | Configuration of goeland
|
| services.corerad.settings | Configuration for CoreRAD, see https://github.com/mdlayher/corerad/blob/main/internal/config/reference.toml
for supported values
|
| services.merecat.settings | Merecat configuration
|
| services.sharkey.settings | Configuration options for Sharkey
|
| services.sabnzbd.settings | The sabnzbd configuration (see also
sabnzbd's wiki
for extra documentation)
|
| services.packagekit.settings | Additional settings passed straight through to PackageKit.conf
|
| services.livekit.settings.port | Main TCP port for RoomService and RTC endpoint.
|
| services.grafana.settings.smtp.host | Host to connect to.
|
| services.lokinet.settings.dns.bind | Address to bind to for handling DNS requests.
|
| services.evremap.settings.remap | List of remappings.
|
| services.rimgo.settings.ADDRESS | The address to listen on.
|
| services.sftpgo.settings.smtp.host | Location of SMTP email server
|
| services.xonotic.settings | Generates the server.cfg file
|
| services.tor.settings.ControlPort | See torrc manual.
|
| services.tor.settings.FetchDirInfoEarly | See torrc manual.
|
| services.tor.settings.ContactInfo | See torrc manual.
|
| services.biboumi.settings.port | The TCP port to use to connect to the local XMPP component.
|
| services.tsidp.settings.enableSts | Enable OAuth token exchange using RFC 8693.
|
| services.amule.settings.WebServer.Port | Web server port
|
| services.grafana.settings.smtp.user | User used for authentication.
|
| services.misskey.settings.db.extra | Extra connection options.
|
| services.frigate.settings.mqtt.host | MQTT server hostname
|
| services.kanidm.client.settings.uri | Address of the Kanidm server.
|
| services.sharkey.settings.url | The full URL that the Sharkey instance will be publically accessible on
|
| services.pretalx.settings.site.url | The base URI below which your pretalx instance will be reachable.
|
| services.peertube.settings | Configuration for peertube.
|
| services.quickwit.settings | Quickwit configuration.
|
| services.warpgate.settings | Warpgate configuration.
|
| services.hound.settings | The full configuration of the Hound daemon
|
| services.memos.settings | The environment variables to configure Memos.
At time of writing, there is no clear documentation about possible values
|
| services.grocy.settings.culture | Display language of the frontend.
|
| services.crowdsec.settings.general | Settings for the main CrowdSec configuration file
|
| security.krb5.settings.include | Files to include in the Kerberos configuration.
|
| services.opengfw.settingsFile | Path to file containing OpenGFW settings.
|
| services.dashy.settings | Settings serialized into user-data/conf.yml before build
|
| security.loginDefs.settings.SYS_UID_MAX | Range of user IDs used for the creation of system users by useradd or newusers.
|
| security.loginDefs.settings.SYS_UID_MIN | Range of user IDs used for the creation of system users by useradd or newusers.
|
| services.opengfw.settings.io.rst | Set to true if you want to send RST for blocked TCP connections, needs local = false.
|
| services.haste-server.settings | Configuration for haste-server
|
| services.zabbixProxy.settings | Zabbix Proxy configuration
|
| services.zabbixAgent.settings | Zabbix Agent configuration
|
| services.homebox.settings | The homebox configuration as environment variables
|
| services.bonsaid.settings | State transition definitions
|
| services.unbound.settings | Declarative Unbound configuration
See the unbound.conf(5) manpage for a list of
available options.
|
| services.osquery.settings | Configuration to be written to the osqueryd JSON configuration file
|
| services.inadyn.settings.allow-ipv6 | Whether to get IPv6 addresses from interfaces.
|
| services.go2rtc.settings.ffmpeg.bin | The ffmpeg package to use for transcoding.
|
| services.opendkim.settings | Additional opendkim configuration
|
| services.freeciv.settings.debug | Set debug log level.
|
| services.tor.settings.V3AuthUseLegacyKey | See torrc manual.
|
| services.forgejo.settings.log.LEVEL | General log level.
|
| services.pretix.settings.tools.pdftk | Path to the pdftk executable.
|
| services.nipap.settings.nipapd.debug | Enable debug logging.
|
| services.oncall.settings | Extra configuration options to append or override
|
| services.tsidp.settings.debugTsnet | For development
|
| services.wiki-js.settings.offline | Disable latest file updates and enable
sideloading.
|
| services.scrutiny.settings | Scrutiny settings to be rendered into the configuration file
|
| security.loginDefs.settings.SYS_GID_MAX | Range of group IDs used for the creation of system groups by useradd, groupadd, or newusers
|
| security.loginDefs.settings.SYS_GID_MIN | Range of group IDs used for the creation of system groups by useradd, groupadd, or newusers
|
| services.kimai.sites.<name>.settings | Structural Kimai's local.yaml configuration
|
| services.chhoto-url.settings.db_url | The path of the sqlite database.
|
| services.apache-kafka.settings."log.dirs" | Log file directories.
|
| services.lidarr.settings.server.port | Port Number
|
| services.maubot.settings.server.port | The port to listen on
|
| services.radarr.settings.server.port | Port Number
|
| services.sonarr.settings.server.port | Port Number
|
| services.vmalert.settings | vmalert configuration, passed via command line flags
|
| hardware.cpu.x86.msr.settings.allow-writes | Whether to allow writes to MSRs ("on") or not ("off").
|
| services.zitadel.settings.TLS.KeyPath | Path to the TLS certificate private key.
|
| services.resolved.settings.Resolve | Settings option for systemd-resolved
|
| services.bluesky-pds.settings.PDS_PORT | Port to listen on
|
| services.nezha-agent.settings.server | Address to the dashboard.
|
| services.zipline.settings.CORE_PORT | The port to listen on.
|
| services.mysql.settings | MySQL configuration
|
| services.influxdb.settings | Extra configuration options for influxdb
|
| services.crowdsec.settings | Set of various configuration attributes
|
| services.openldap.settings | Configuration for OpenLDAP, in OLC format
|
| services.minidlna.settings | Configuration for minidlna.conf(5).
|
| security.loginDefs.settings | Config options for the /etc/login.defs file, that defines
the site-specific configuration for the shadow password suite
|
| services.h2o.hosts.<name>.settings | Attrset to be transformed into YAML for host config
|
| services.aria2.settings.enable-rpc | Enable JSON-RPC/XML-RPC server.
|
| services.lxd-image-server.settings | Configuration for lxd-image-server
|
| services.doh-server.settings.listen | HTTP listen address and port
|
| services.tor.settings.DisableAllSwap | See torrc manual.
|
| services.tor.settings.Nickname | See torrc manual.
|
| services.sonic-server.settings | Sonic Server configuration options
|
| services.glance.settings.server.port | Glance port to listen on
|
| services.glance.settings.server.host | Glance bind address
|
| services.legit.settings.repo.mainBranch | Main branch to look for.
|
| services.zitadel.settings.TLS.CertPath | Path to the TLS certificate.
|
| services.pdns-recursor.yaml-settings | PowerDNS Recursor settings
|
| services.automx2.settings | Bootstrap json to populate database
|
| services.patroni.settings | The primary patroni configuration
|
| services.livekit.settings | LiveKit configuration file expressed in nix
|
| services.clamav.daemon.settings | ClamAV configuration
|
| services.sabnzbd.settings.misc.port | Port for the Web UI to listen on for incoming connections.
|
| services.pretix.settings.pretix.url | The installation’s full URL, without a trailing slash.
|
| services.sabnzbd.settings.misc.host | Address for the Web UI to listen on for incoming connections.
|
| services.hickory-dns.settings.zones | List of zones to serve.
|
| services.misskey.settings.redis.host | The Redis host.
|
| services.omnom.settings.storage.type | Storage type.
|
| services.misskey.settings.redis.port | The Redis port.
|
| services.misskey.settings.redis | ioredis options
|
| services.gitea.settings.server.ROOT_URL | Full public URL of gitea server.
|
| services.homer.settings | Settings serialized into config.yml before build
|
| services.hedgedoc.settings | HedgeDoc configuration, see
https://docs.hedgedoc.org/configuration/
for documentation.
|
| services.olivetin.settings | Configuration of OliveTin
|
| services.routedns.settings | Configuration for RouteDNS, see https://github.com/folbricht/routedns/blob/master/doc/configuration.md
for more information.
|
| services.lidarr.settings | Attribute set of arbitrary config options
|
| services.cross-seed.settings | Configuration options for cross-seed
|
| services.sonarr.settings | Attribute set of arbitrary config options
|
| services.radarr.settings | Attribute set of arbitrary config options
|
| services.cross-seed.settings.linkDirs | List of directories where cross-seed will create links
|
| services.fediwall.settings.tags | Tags to follow
|
| services.hedgedoc.settings.port | Port to listen on.
|
| services.hedgedoc.settings.host | Address to listen on.
|
| services.lasuite-meet.settings.DB_NAME | Name of the database
|
| services.lasuite-docs.settings.DB_NAME | Name of the database
|
| services.lasuite-docs.settings.DB_USER | User of the database
|
| services.lasuite-meet.settings.DB_HOST | Host of the database
|
| services.lasuite-meet.settings.DB_USER | User of the database
|
| services.lasuite-docs.settings.DB_HOST | Host of the database
|
| services.traccar.settingsFile | File used as configuration for traccar
|
| services.wg-access-server.settings | See https://www.freie-netze.org/wg-access-server/2-configuration/ for possible options
|
| services.go2rtc.settings.api.listen | API listen address, conforming to a Go address string.
|
| services.actual.settings.userFiles | The server will put all the budget files in this directory as binary blobs.
|
| services.sslh.settings.numeric | Whether to disable reverse DNS lookups, thus keeping IP
address literals in the log.
|
| services.inadyn.settings.custom.<name>.include | File to include additional settings for this provider from.
|
| services.tor.settings.ClientAutoIPv6ORPort | See torrc manual.
|
| services.step-ca.settings | Settings that go into ca.json
|
| services.freeciv.settings.exit-on-end | Whether to enable exit instead of restarting when a game ends.
|
| services.ergochat.settings | Ergo IRC daemon configuration file.
https://raw.githubusercontent.com/ergochat/ergo/master/default.yaml
|
| services.spotifyd.settings | Configuration for Spotifyd
|
| services.netatalk.settings | Configuration for Netatalk
|
| services.crowdsec.settings.capi | CAPI Configuration attributes
|
| services.crowdsec.settings.lapi | LAPI Configuration attributes
|
| services.amule.settings.eMule.UDPPort | UDP port for eD2k traffic (searches, source exchange) and all Kad network communication
|
| services.bonsaid.settings.*.type | Type of transition
|
| services.polaris.settings | Contents for the TOML Polaris config, applied each start
|
| services.pds.settings.PDS_CRAWLERS | URL of crawlers
|
| services.forgejo.settings.log.ROOT_PATH | Root path for log files.
|
| services.udisks2.settings | Options passed to udisksd
|
| xdg.terminal-exec.settings | Configuration options for the Default Terminal Execution Specification
|
| services.radicle.ci.broker.settings.db | Database file path.
|
| services.peroxide.settings | Configuration for peroxide
|
| services.fediwall.settings | Fediwall configuration
|
| services.ferretdb.settings | Additional configuration for FerretDB, see
https://docs.ferretdb.io/configuration/flags/
for supported values.
|
| services.gancio.settings.db.storage | Location for the SQLite database.
|
| services.gancio.settings.db.dialect | The database dialect to use
|
| services.opengfw.settings.io.queueSize | IO queue size.
|
| services.mpd.settings | Configuration for MPD
|
| services.anubis.defaultOptions.policy.settings | Additional policy settings merged into the policy file
|
| services.tor.settings.ClientOnionAuthDir | See torrc manual.
|
| services.quickwit.settings.rest | Rest server configuration for Quickwit
|
| services.opengfw.settings.io.local | Set to false if you want to run OpenGFW on FORWARD chain. (e.g. on a router)
|
| services.tor.relay.onionServices.<name>.settings | Settings of the onion service
|
| services.firefly-iii.settings.DB_PORT | The port your database is listening at. sqlite does not require
this value to be filled.
|
| services.lasuite-docs.settings.DATA_DIR | Path to the data directory
|
| boot.initrd.network.ifstate.settings | Content of IfState's initrd configuration file
|
| services.oncall.settings.db.conn.kwargs.host | Database host.
|
| services.oncall.settings.db.conn.kwargs.user | Database user.
|
| services.hockeypuck.settings | Configuration file for hockeypuck, here you can override
certain settings (loglevel and
openpgp.db.dsn) by just setting those values
|
| services.nvme-rs.settings.email.use_tls | Use TLS for SMTP connection
|
| services.rkvm.server.settings.listen | An internet socket address to listen on, either IPv4 or IPv6.
|
| services.hatsu.settings.HATSU_DOMAIN | The domain name of your instance (eg 'hatsu.local').
|
| services.gemstash.settings.bind | Host and port combination for the server to listen on.
|
| services.suricata.settings.vars | Variables to be used within the suricata rules.
|
| services.oink.settings.interval | Seconds to wait before sending another request.
|
| services.suricata.settings.pcap | Cross platform libpcap capture support.
|
| services.gitlab-runner.settings | Global gitlab-runner configuration
|
| services.libeufin.settings | Global configuration options for the libeufin bank system config file.
|
| services.temporal.settings | Temporal configuration
|
| services.sshwifty.settings | Configuration for Sshwifty
|
| services.zabbixServer.settings | Zabbix Server configuration
|
| services.cross-seed.settings.outputDir | Directory where cross-seed will place torrent files it finds.
|
| services.auto-cpufreq.settings | Configuration for auto-cpufreq
|
| services.bluesky-pds.settings | Environment variables to set for the service
|
| services.gitlab.pages.settings.pages-root | The directory where pages are stored.
|
| services.gitea.settings.server.DOMAIN | Domain name of your server.
|
| services.rathole.settings | Rathole configuration, for options reference
see the example on GitHub
|
| services.frigate.settings | Frigate configuration as a nix attribute set
|
| services.dnsmasq.settings.server | The DNS servers which dnsmasq should query.
|
| services.grafana-to-ntfy.settings.ntfyUrl | The URL to the ntfy-sh topic.
|
| services.gancio.settings.baseurl | The full URL under which the server is reachable.
|
| services.tor.settings.DisableOOSCheck | See torrc manual.
|
| services.moosefs.master.settings | Master configuration options (mfsmaster.cfg).
|
| services.gitea.settings.server.HTTP_PORT | Listen port
|
| services.firefly-iii.settings.APP_ENV | The app environment
|
| nix.settings.trusted-public-keys | List of public keys used to sign binary caches
|
| services.warpgate.settings.http.key | Path to HTTPS listener private key.
|
| services.rkvm.client.settings.server | An RKVM server's internet socket address, either IPv4 or IPv6.
|
| services.kanidm.server.settings.role | The role of this server
|
| services.castopod.settings | Environment variables used for Castopod
|
| services.radicale.settings | Configuration for Radicale
|
| services.mediagoblin.settings | Settings which are written into mediagoblin.ini.
|
| services.aesmd.settings.proxyType | Type of proxy to use
|
| services.misskey.settings.url | The final user-facing URL
|
| services.sourcehut.settings."meta.sr.ht::settings".user-invites | How many invites each user is issued upon registration
(only applicable if open registration is disabled).
|
| services.doh-server.settings.timeout | Upstream timeout
|
| services.doh-server.settings.verbose | Enable logging
|
| services.umami.settings.HOSTNAME | The address to listen on.
|
| services.nipap.settings.nipapd.listen | IP address to bind nipapd to.
|
| services.gitea.settings.server.HTTP_ADDR | Listen address
|
| services.pds.settings.PDS_HOSTNAME | Instance hostname (base domain name)
|
| services.misskey.settings.socket | The UNIX socket your Misskey server should listen on.
|
| services.paisa.settings.journalFile | Filename of the main journal / ledger file.
|
| services.pocket-id.settings.TRUST_PROXY | Whether the app is behind a reverse proxy.
|
| services.prosody-filer.settings | Configuration for Prosody Filer
|
| services.scion.scion-router.settings | scion-router configuration
|
| services.scion.scion-daemon.settings | scion-daemon configuration
|
| services.warpgate.settings.ssh.keys | Path to store SSH host & client keys.
|
| services.tor.settings.ExtORPortCookieAuthFile | See torrc manual.
|
| services.tor.settings.AuthDirTestEd25519LinkKeys | See torrc manual.
|
| services.gokapi.settingsFile | Path to config file to parse and append to settings
|
| services.buffyboard.settings | Settings to include in /etc/buffyboard.conf
|
| services.readarr.settings.server.port | Port Number
|
| services.pangolin.settings | Additional attributes to be merged with the configuration options and written to Pangolin's config.yml file.
|
| services.pinnwand.settings | Your pinnwand.toml as a Nix attribute set
|
| services.postsrsd.settings | Configuration options for the postsrsd.conf file
|
| i18n.inputMethod.fcitx5.settings.addons | The addon configures in conf folder in ini format with global sections
|
| services.immich-kiosk.settings.kiosk.port | Port on which immich-kiosk will listen.
|
| services.suricata.settings.run-as.user | Run Suricata with a specific user-id.
|
| services.bluesky-pds.settings.PDS_DID_PLC_URL | URL of DID PLC directory
|
| services.openldap.settings.attrs | Attributes of the parent entry.
|
| services.stash.settings.database | Path to the SQLite database
|
| services.listmonk.database.settings | Dynamic settings in the PostgreSQL database, set by a SQL script, see https://github.com/knadh/listmonk/blob/master/schema.sql#L177-L230 for details.
|
| services.immich-kiosk.settings | Configuration for immich-kiosk
|
| services.freeciv.settings.Guests | Whether to enable guests to login if auth is enabled.
|
| services.saunafs.master.settings | Contents of config file (sfsmaster.cfg(5)).
|
| services.radicle.ci.broker.settings | Configuration of radicle-ci-broker
|
| services.firefox-syncserver.settings | Settings for the sync server
|
| services.minidlna.settings.port | Port number for HTTP traffic (descriptions, SOAP, media transfer).
|
| services.pdns-recursor.old-settings | Older PowerDNS Recursor settings
|
| services.scrutiny.settings.log.level | Log level for Scrutiny.
|
| services.kanidm.client.settings | Configure Kanidm clients, needed for the PAM daemon
|
| services.froide-govplan.settings | Configuration options to set in extra_settings.py.
|
| services.pocket-id.settings.PUBLIC_APP_URL | The URL where you will access the app.
|
| services.tor.settings.FetchDirInfoExtraEarly | See torrc manual.
|
| services.tor.settings.ControlSocket | See torrc manual.
|
| services.anubis.instances.<name>.policy.settings | Additional policy settings merged into the policy file
|
| services.clamav.updater.settings | freshclam configuration
|
| services.webdav-server-rs.settings | Attrset that is converted and passed as config file
|
| services.lasuite-docs.settings.REDIS_URL | URL of the redis backend
|
| services.lasuite-meet.settings.REDIS_URL | URL of the redis backend
|
| services.dsnet.settings | The settings to use for dsnet
|
| services.filebrowser.settings | Settings for FileBrowser
|
| services.borgmatic.settings | See https://torsion.org/borgmatic/docs/reference/configuration/
|
| services.sunshine.settings.port | Base port -- others used are offset from this one, see https://docs.lizardbyte.dev/projects/sunshine/en/latest/about/advanced_usage.html#port for details.
|
| services.vmalert.settings.rule | Path to the files with alerting and/or recording rules.
Consider using the services.vmalert.rules option as a convenient alternative for declaring rules
directly in the nix language.
|
| services.aria2.settings.listen-port | Set UDP listening port range used by DHT(IPv4, IPv6) and UDP tracker.
|
| services.microbin.settings | Additional configuration for MicroBin, see
https://microbin.eu/docs/installation-and-configuration/configuration/
for supported values
|
| services.wastebin.settings | Additional configuration for wastebin, see
https://github.com/matze/wastebin#usage for supported values
|
| services.pds.settings.PDS_BLOB_UPLOAD_LIMIT | Size limit of uploaded blobs in bytes
|
| services.lemmy.settings.hostname | The domain name of your instance (eg 'lemmy.ml').
|
| services.grocy.settings.currency | ISO 4217 code for the currency to display.
|
| services.stash.settings.no_proxy | A list of domains for which the proxy must not be used
|
| services.kea.dhcp6.configFile | Kea DHCP6 configuration as a path, see https://kea.readthedocs.io/en/kea-3.0.2/arm/dhcp6-srv.html
|
| services.kea.dhcp4.configFile | Kea DHCP4 configuration as a path, see https://kea.readthedocs.io/en/kea-3.0.2/arm/dhcp4-srv.html
|
| services.readarr.settings | Attribute set of arbitrary config options
|
| services.tlsrpt.fetcher.settings | Flags from tlsrpt-fetcher(1) as key-value pairs.
|
| services.tlsrpt.reportd.settings | Flags from tlsrpt-reportd(1) as key-value pairs.
|
| services.sharkey.settings.socket | If specified, creates a UNIX socket at the given path that Sharkey listens on.
|
| services.openssh.settings.PrintMotd | Whether to enable printing /etc/motd when a user logs in interactively.
|
| services.dsnet.settings.Network | The IPv4 network that the server will use to allocate IPs on the network
|
| services.canaille.settings.CANAILLE_OIDC | OpenID Connect settings
|
| services.fediwall.settings.hideBots | Hide posts from bot accounts
|
| services.cryptpad.settings.httpPort | Port on which the Node.js server should listen
|
| services.inadyn.settings.custom.<name>.ssl | Whether to use HTTPS for this DDNS provider.
|
| services.zwave-js.settings.storage.cacheDir | Cache directory
|
| services.slskd.settings.web.url_base | The base path in the url for web requests.
|
| services.warpgate.settings.mysql.key | Path to MySQL listener private key.
|
| services.sourcehut.settings | The configuration for the sourcehut network.
|
| services.bitmagnet.settings | Bitmagnet configuration (https://bitmagnet.io/setup/configuration.html).
|
| services.tinyproxy.settings | Configuration for tinyproxy.
|
| services.cryptpad.settings.logLevel | Controls log level
|
| services.c2fmzq-server.settings | Configuration for c2FmZQ-server passed as CLI arguments
|
| services.teleport.settings | Contents of the teleport.yaml config file
|
| services.lldap.settings.http_url | The public URL of the server, for password reset links.
|
| services.lasuite-docs.settings | Configuration options of docs
|
| systemd.tmpfiles.settings | Declare systemd-tmpfiles rules to create, delete, and clean up volatile
and temporary files and directories
|
| services.immich.settings | Configuration for Immich
|
| services.freeciv.settings.saves | Save games to given directory,
a sub-directory named after the starting date of the service
will me inserted to preserve older saves.
|
| services.keycloak.settings.http-host | On which address Keycloak should accept new connections.
|
| services.dokuwiki.sites.<name>.settings | Structural DokuWiki configuration
|
| security.pam.u2f.settings.origin | By default pam-u2f module sets the origin
to pam://$HOSTNAME
|
| services.acme-dns.settings.general.nsname | Zone name server.
|
| services.transmission.settings | Settings whose options overwrite fields in
.config/transmission-daemon/settings.json
(each time the service starts)
|
| services.dsnet.settings.Network6 | The IPv6 network that the server will use to allocate IPs on the
network
|
| services.tor.settings.MainloopStats | See torrc manual.
|
| services.tor.settings.NewCircuitPeriod | See torrc manual.
|
| services.tor.settings.OfflineMasterKey | See torrc manual.
|
| services.actual.settings.dataDir | Directory under which Actual runs and saves its data
|
| services.omnom.settings.server.address | Server address.
|
| services.dnsproxy.settings | Contents of the config.yaml config file
|
| services.stalwart.settings | Configuration options for the Stalwart server
|
| services.cross-seed.settings.dataDirs | Paths to be searched for matching data
|
| services.suricata.settings.run-as.group | Run Suricata with a specific group-id.
|
| services.aria2.settings.save-session | Save error/unfinished downloads to FILE on exit.
|
| services.maubot.settings.logging | Python logging configuration
|
| services.sharkey.settings.address | The address that Sharkey binds to.
|
| services.sabnzbd.settings.servers | Usenet provider specification
|
| services.mosquitto.bridges.<name>.settings | Additional settings for this bridge.
|
| services.meilisearch.settings | Configuration settings for Meilisearch
|
| services.mediagoblin.paste.settings | Settings which are written into paste.ini.
|
| services.keycloak.settings.http-port | On which port Keycloak should listen for new HTTP connections.
|
| services.transfer-sh.settings | Additional configuration for transfer-sh, see
https://github.com/dutchcoders/transfer.sh#usage-1
for supported values
|
| services.acme-dns.settings.general.domain | Domain name to serve the requests off of.
|
| services.pretix.settings.pretix.logdir | Directory for storing log files.
|
| services.hedgedoc.settings.urlPath | URL path for the website
|
| boot.initrd.systemd.settings.Manager | Options for the global systemd service manager used in initrd
|
| services.frigate.settings.ffmpeg.path | Package providing the ffmpeg and ffprobe executables below the bin/ directory.
|
| services.paperless.exporter.settings | Settings to pass to the document exporter as CLI arguments.
|
| services.actual.settings.hostname | The address to listen on
|
| services.zitadel.settings.TLS.Key | The TLS certificate private key, as a base64-encoded string
|
| services.dolibarr.h2o.settings | Attrset to be transformed into YAML for host config
|
| services.ntfy-sh.settings.base-url | Public facing base URL of the service
This setting is required for any of the following features:
- attachments (to return a download URL)
- e-mail sending (for the topic URL in the email footer)
- iOS push notifications for self-hosted servers
(to calculate the Firebase poll_request topic)
- Matrix Push Gateway (to validate that the pushkey is correct)
|
| services.hatsu.settings.HATSU_LISTEN_PORT | Port where hatsu should listen for incoming requests.
|
| services.hatsu.settings.HATSU_LISTEN_HOST | Host where hatsu should listen for incoming requests.
|
| services.firezone.server.settings | Environment variables for the Firezone server
|
| services.gancio.settings.db.database | Name of the PostgreSQL database
|
| services.karma.settings.listen.address | Hostname or IP to listen on.
|
| services.glitchtip.settings | Configuration of GlitchTip
|
| services.supergfxd.settings | The content of /etc/supergfxd.conf
|
| services.rosenpass.settings | Configuration for Rosenpass, see https://rosenpass.eu/ for further information.
|
| services.mackerel-agent.settings | Options for mackerel-agent.conf
|
| services.manticore.settings | Configuration for Manticoresearch
|
| services.mosquitto.settings | Global configuration options for the mosquitto broker.
|
| services.librenms.settings | Attrset of the LibreNMS configuration
|
| services.gemstash.settings | Configuration for Gemstash
|
| services.lasuite-meet.settings | Configuration options of meet
|
| services.biboumi.settings.admin | The bare JID of the gateway administrator
|
| services.suricata.settings.af-xdp | Linux high speed af-xdp capture support, see
docs/capture-hardware/af-xdp.
|
| services.ente.api.settings.apps.accounts | Set this to the URL where your accounts page is running
|
| services.tor.settings.ClientPreferIPv6ORPort | See torrc manual.
|
| services.umurmur.settings.ca_path | Path to your SSL CA certificate.
|
| services.gitlab.pages.settings.listen-http | The address(es) to listen on for HTTP requests.
|
| services.gancio.settings.server.socket | The unix socket for the gancio server to listen on.
|
| services.hedgedoc.settings.path | Path to UNIX domain socket to listen on
If specified, host and port will be ignored.
|
| services.gancio.settings.log_path | Directory Gancio logs into
|
| services.fediwall.settings.showMedia | Show media in posts
|
| services.navidrome.settings.Port | Port to run Navidrome on.
|
| services.tinyproxy.settings.Port | Specify which port to listen to.
|
| services.pinnwand.settings.footer | The footer in raw HTML.
|
| services.zitadel.settings.TLS.Cert | The TLS certificate, as a base64-encoded string
|
| services.homepage-dashboard.settings | Homepage settings
|
| services.hickory-dns.settings.zones.*.zone | Zone name, like "example.com", "localhost", or "0.0.127.in-addr.arpa".
|
| services.webdav.settings | Attrset that is converted and passed as config file
|
| services.immich-public-proxy.settings | Configuration for IPP
|
| services.swapspace.settings | Config file for swapspace
|
| services.navidrome.settings | Configuration for Navidrome, see https://www.navidrome.org/docs/usage/configuration-options/ for supported values.
|
| services.nextcloud.settings | Extra options which should be appended to Nextcloud's config.php file.
|
| services.pgbouncer.settings | Configuration for PgBouncer, see https://www.pgbouncer.org/config.html
for supported values.
|
| security.loginDefs.settings.TTYPERM | The terminal permissions: the login tty will be owned by the TTYGROUP group,
and the permissions will be set to TTYPERM
|
| services.etebase-server.settings | Configuration for etebase-server
|
| services.redis.servers.<name>.settings | Redis configuration
|
| services.matrix-tuwunel.settings | Generates the tuwunel.toml configuration file
|
| services.angrr.settings.owned-only | Only monitors owned symbolic link target of GC roots.
- "auto": behaves like true for normal users, false for root.
- "true": only monitor GC roots owned by the current user.
- "false": monitor all GC roots.
|
| nix.settings.auto-optimise-store | If set to true, Nix automatically detects files in the store that have
identical contents, and replaces them with hard links to a single copy
|
| services.frigate.settings.cameras | Attribute set of cameras configurations.
https://docs.frigate.video/configuration/cameras
|
| services.xonotic.settings.sv_motd | Text displayed when players join the server.
|
| services.kubo.settings.Mounts.FuseAllowOther | Allow all users to access the FUSE mount points
|
| services.kanidm.server.settings.origin | The origin of your Kanidm instance
|
| services.apache-kafka.settings."broker.id" | Broker ID. -1 or null to auto-allocate in zookeeper mode.
|
| services.scion.scion-control.settings | scion-control configuration
|
| services.waagent.settings.HttpProxy.Host | If you set http proxy, waagent will use is proxy to access the Internet.
|
| services.waagent.settings.HttpProxy.Port | If you set http proxy, waagent will use this proxy to access the Internet.
|
| services.gancio.settings.hostname | The domain name under which the server is reachable.
|
| services.kanboard.phpfpm.settings | Options for kanboard's PHPFPM pool.
|
| services.inadyn.settings.forced-update | Duration (in seconds) after which an update is forced.
|
| services.tor.settings.KeyDirectory | See torrc manual.
|
| services.tor.settings.ClientPreferIPv6DirPort | See torrc manual.
|
| services.tor.settings.ReducedExitPolicy | See torrc manual.
|
| services.forgejo.settings.server.ROOT_URL | Full public URL of Forgejo server.
|
| services.nipap.settings.nipapd.db_name | Name of database to use on PostgreSQL server.
|
| services.slskd.settings.shares.filters | Regular expressions of files to exclude from sharing.
|
| services.suricata.settings.app-layer | app-layer configuration, see upstream docs.
|
| services.aria2.settings.rpc-listen-port | Specify a port number for JSON-RPC/XML-RPC server to listen to
|
| services.mchprs.settings.address | Address for the server
|
| services.go2rtc.settings.streams | Stream source configuration
|
| services.openssh.settings.LogLevel | Gives the verbosity level that is used when logging messages from sshd(8)
|
| services.firewalld.settings | FirewallD config file
|
| services.moonraker.settings | Configuration for Moonraker
|
| services.mobilizon.settings | Mobilizon Elixir documentation, see
https://docs.joinmobilizon.org/administration/configure/reference/
for supported values.
|
| services.typesense.settings | Typesense configuration
|
| services.firefly-iii.settings | Options for firefly-iii configuration
|
| services.pomerium.settings | The contents of Pomerium's config.yaml, in Nix expressions
|
| services.workout-tracker.settings | Extra config options.
|
| services.warpgate.settings.ssh.enable | Whether to enable SSH listener.
|
| services.warpgate.settings.ssh.listen | Listen endpoint of SSH listener.
|
| security.loginDefs.settings.DEFAULT_HOME | Indicate if login is allowed if we can't cd to the home directory.
|
| services.evremap.settings.phys | The physical device name to listen on
|
| services.acme-dns.settings.general.listen | IP+port combination to bind and serve the DNS server on.
|
| services.pretix.settings.celery.broker | URI to the celery broker used for the asynchronous job queue.
|
| services.part-db.settings.DATABASE_URL | The postgresql database server to connect to
|
| services.maubot.settings.admins | List of administrator users
|
| containers.<name>.path | As an alternative to specifying
config, you can specify the path to
the evaluated NixOS system configuration, typically a
symlink to a system profile.
|
| services.grafana.settings.smtp.enabled | Whether to enable SMTP.
|
| services.saunafs.master.settings.DATA_PATH | Data storage directory.
|
| services.inadyn.settings.provider.<name>.include | File to include additional settings for this provider from.
|
| services.gitea.settings.mailer.ENABLED | Whether to use an email service to send notifications.
|
| services.slskd.settings.global.upload.slots | Limit of the number of concurrent upload slots.
|
| services.veilid.settings.logging.api.level | The minimum priority of api events to be logged.
|
| services.tsidp.settings.enableFunnel | Use Tailscale Funnel to make tsidp available on the public internet so it works with SaaS products.
|
| services.hedgedoc.settings.db | Specify the configuration for sequelize
|
| services.openssh.settings.DenyUsers | If specified, login is denied for all listed users
|
| services.nezha-agent.settings.uuid | Must be set to a unique identifier, preferably a UUID according to
RFC 4122
|
| services.prowlarr.settings.server.port | Port Number
|
| services.pretix.settings.database.user | Database username.
|
| services.pretix.settings.database.name | Database name.
|
| services.whisparr.settings.server.port | Port Number
|
| services.zeronsd.servedNetworks.<name>.settings | Settings for zeronsd
|
| services.peroxide.settings.UserPortImap | The port on which to listen for IMAP connections.
|
| services.peroxide.settings.UserPortSmtp | The port on which to listen for SMTP connections.
|
| services.tor.settings.ControlPortWriteToFile | See torrc manual.
|
| services.tor.settings.ServerDNSResolvConfFile | See torrc manual.
|
| services.tor.settings.DisableNetwork | See torrc manual.
|
| services.gitea.settings.server.SSH_PORT | SSH port displayed in clone URL
|
| services.stash.settings.ui.frontPageContent | Search filters to display on the front page.
|
| services.livekit.ingress.settings | LiveKit Ingress configuration
|
| services.umami.settings.DATABASE_URL | Connection string for the database
|
| services.rspamd-trainer.settings | IMAP authentication configuration for rspamd-trainer
|
| services.openssh.settings.AllowUsers | If specified, login is allowed only for the listed users
|
| services.bookstack.settings.DB_PORT | The port your database is listening at.
|
| services.gitlab.pages.settings.pages-domain | The domain to serve static pages on.
|
| services.moosefs.master.settings.DATA_PATH | Directory for storing master metadata.
|
| services.frigate.settings.mqtt.enabled | Whether to enable MQTT support.
|
| services.keycloak.settings.https-port | On which port Keycloak should listen for new HTTPS connections.
|
| services.gemstash.settings.db_url | The database to connect to when using postgres, mysql, or mysql2.
|
| services.nomad.settings | Configuration for Nomad
|
| services.rkvm.server.settings.switch-keys | A key list specifying a host switch combination.
A list of key names is available in https://github.com/htrefil/rkvm/blob/master/switch-keys.md.
|
| services.pds.settings.PDS_REPORT_SERVICE_DID | DID of mod service
|
| services.bluesky-pds.settings.PDS_BSKY_APP_VIEW_DID | DID of bsky frontend
|
| services.go-csp-collector.settings.port | The port to listen on.
|
| services.dsnet.settings.Networks | The CIDR networks that should route through this server
|
| services.knot-resolver.settings | Nix-based (RFC 42) configuration for Knot Resolver
|
| services.misskey.settings.chmodSocket | The file access mode of the UNIX socket.
|
| services.suricata.settings.af-packet | Linux high speed capture support.
|
| services.veilid.settings.core.network.upnp | Should the app try to improve its incoming network connectivity using UPnP?
|
| services.create_ap.settings | Configuration for create_ap
|
| services.watchdogd.settings | Configuration to put in watchdogd.conf
|
| services.misskey.settings.redisForJobQueue.port | The Redis port.
|
| services.misskey.settings.redisForJobQueue.host | The Redis host.
|
| services.bookstack.settings.DB_HOST | The IP or hostname which hosts your database.
|
| services.anuko-time-tracker.settings.helpLink | Help link from the main menu.
|
| services.tor.settings.DownloadExtraInfo | See torrc manual.
|
| services.tor.settings.DataDirectory | See torrc manual.
|
| services.tor.settings.BandwidthRate | See torrc manual.
|
| services.postfix.settings.master.<name>.type | The type of the service
|
| services.slskd.settings.web.https.disabled | Disable the built-in HTTPS server
|
| services.gitlab.pages.settings.listen-https | The address(es) to listen on for HTTPS requests.
|
| services.amule.settings.WebServer.Enabled | Set to 1 to enable the web server
|
| services.gitlab.pages.settings.listen-proxy | The address(es) to listen on for proxy requests.
|
| services.nipap.settings.nipapd.db_host | PostgreSQL host to connect to
|
| services.minidlna.settings.db_dir | Specify the directory to store database and album art cache.
|
| services.firefly-iii.settings.APP_URL | The APP_URL used by firefly-iii internally
|
| services.tuned.settings.sections | attribute set of section of an INI file (attrs of INI atom (null, bool, int, float or string))
|
| services.pds.settings.PDS_REPORT_SERVICE_URL | URL of mod service
|
| services.bluesky-pds.settings.PDS_BSKY_APP_VIEW_URL | URL of bsky frontend
|
| services.lldap.settings.ldap_port | The port on which to have the LDAP server.
|
| services.stash.settings.generated | Path to generated files
|
| services.traefik.static.settings | Static configuration for Traefik, written in Nix.
This will be serialized to JSON (which is considered valid YAML) at build, and passed to Traefik as --configfile.
|
| services.gitea.settings.server.DISABLE_SSH | Disable external SSH feature.
|
| services.pretix.settings.database.host | Database host or socket path.
|
| services.warpgate.settings.http.listen | Listen endpoint of HTTP listener.
|
| networking.ifstate.settings | Content of IfState's configuration file
|
| services.biboumi.settings.ca_file | Specifies which file should be used as the list of trusted CA
when negotiating a TLS session.
|
| services.dnscrypt-proxy.settings | Attrset that is converted and passed as TOML config file
|
| services.fediwall.settings.hideBoosts | Hide boosts
|
| services.bluesky-pds.settings.LOG_ENABLED | Enable logging
|
| services.snips-sh.settings | The configuration of snips-sh is done through environment variables,
therefore you must use upper snake case (e.g. SNIPS_HTTP_INTERNAL)
|
| services.libeufin.bank.settings | Configuration options for the libeufin bank system config file
|
| services.sourcehut.settings.mail.pgp-key-id | OpenPGP key identifier.
|
| services.forgejo.settings.server.DOMAIN | Domain name of your server.
|
| services.headscale.settings.log.level | headscale log level.
|
| services.tlsrpt.reportd.settings.dbname | Path to the sqlite database.
|
| services.kanidm.server.settings.db_path | Path to Kanidm database.
|
| services.ente.api.settings.apps.public-albums | If you're running a self hosted instance and wish to serve public links,
set this to the URL where your albums web app is running.
|
| services.postfix-tlspol.settings | The postfix-tlspol configuration file as a Nix attribute set
|
| services.chhoto-url.settings.site_url | The URL under which Chhoto URL is externally reachable.
|
| services.forgejo.settings.server.HTTP_PORT | Listen port
|
| services.tlsrpt.collectd.settings | Flags from tlsrpt-collectd(1) as key-value pairs.
|
| services.lemmy.settings.captcha.enabled | Enable Captcha.
|
| services.opengfw.settings.ruleset.geoip | Path to geoip.dat.
|
| services.mx-puppet-discord.settings | config.yaml configuration as a Nix attribute set
|
| services.open-web-calendar.settings | Configuration for the server
|
| services.scrutiny.settings.web.listen.port | Port for web application to listen on.
|
| services.tor.settings.TestingTorNetwork | See torrc manual.
|
| services.tor.settings.LogMessageDomains | See torrc manual.
|
| services.tor.settings.RefuseUnknownExits | See torrc manual.
|
| services.rosenpass.settings.peers | List of peers to exchange keys with.
|
| services.sftpgo.settings.ftpd.bindings | Configure listen addresses and ports for ftpd.
|
| services.stalwart-mail.settings | Configuration options for the Stalwart email server
|
| boot.initrd.systemd.tmpfiles.settings | Similar to systemd.tmpfiles.settings but the rules are
only applied by systemd-tmpfiles before initrd-switch-root.target
|
| services.openssh.settings.StrictModes | Whether sshd should check file modes and ownership of directories
|
| services.prowlarr.settings | Attribute set of arbitrary config options
|
| services.whisparr.settings | Attribute set of arbitrary config options
|
| services.evremap.settings.remap.*.input | The key sequence that should be remapped
|
| services.fediwall.settings.loadPublic | Load public posts
|
| services.fediwall.settings.playVideos | Autoplay videos in posts
|
| services.fediwall.settings.loadTrends | Load trending posts
|
| services.caddy.settings | Structured configuration for Caddy to generate a Caddy JSON configuration file
|
| services.kanidm.server.settings.tls_key | TLS key in pem format.
|
| services.sympa.domains.<name>.settings | The robot.conf configuration file as key value set
|
| services.matrix-synapse.settings | The primary synapse configuration
|
| services.forgejo.settings.server.HTTP_ADDR | Listen address
|
| services.taler.settings.taler.CURRENCY | The currency which taler services will operate with
|
| services.waagent.settings.OS.EnableRDMA | If enabled, the agent attempts to install and then load an RDMA kernel driver
that matches the version of the firmware on the underlying hardware.
|
| services.cryptpad.settings.adminKeys | List of public signing keys of users that can access the admin panel
|
| services.tinc.networks.<name>.settings | Configuration of the Tinc daemon for this network
|
| services.acme-dns.settings.database.engine | Database engine to use.
|
| services.scrutiny.settings.web.listen.host | Interface address for web application to bind to.
|
| services.cross-seed.settings.torrentDir | Directory containing torrent files, or if you're using a torrent
client integration and injection - your torrent client's .torrent
file store/cache.
|
| services.zram-generator.settings | Configuration for zram-generator,
see https://github.com/systemd/zram-generator for documentation.
|
| services.gnome.gnome-settings-daemon.enable | Whether to enable GNOME Settings Daemon.
|
| security.agnos.settings.accounts.*.email | Email associated with this account.
|
| services.stash.settings.nobrowser | If we should not auto-open a browser window on startup
|
| services.blackfire-agent.settings | See https://blackfire.io/docs/up-and-running/configuration/agent
|
| services.influxdb2.settings | configuration options for influxdb2, see https://docs.influxdata.com/influxdb/v2.0/reference/config-options for details.
|
| services.displayManager.gdm.settings | Options passed to the gdm daemon
|
| services.misskey.settings.redisForJobQueue | ioredis options for the job queue
|
| services.misskey.settings.redisForPubsub.port | The Redis port.
|
| services.misskey.settings.redisForPubsub.host | The Redis host.
|
| services.acme-dns.settings.general.nsadmin | Zone admin email address for SOA.
|
| services.headscale.settings | Overrides to config.yaml as a Nix attribute set
|
| services.hedgedoc.settings.domain | Domain to use for website
|
| services.journald.upload.settings | Configuration for journal-upload
|
| services.suricata.settings.rule-files | Files to load suricata-update managed rules, relative to 'default-rule-path'.
|
| services.crowdsec.settings.console | Console Configuration attributes
|
| services.fediwall.settings.servers | Servers to load posts from
|
| services.quickwit.settings.version | Configuration file version.
|
| services.umurmur.settings.channels | Channel tree definitions.
|
| services.prometheus.exporters.nginxlog.settings | All settings of nginxlog expressed as an Nix attrset
|
| services.lldap.settings.ldap_host | The host address that the LDAP server will be bound to.
|
| services.lldap.settings.http_host | The host address that the HTTP server will be bound to.
|
| services.lldap.settings.http_port | The port on which to have the HTTP server, for user login and administration.
|
| services.suwayomi-server.settings | Configuration to write to server.conf
|
| services.matrix-synapse.settings.redis | Redis configuration for synapse
|
| services.smartdns.settings | A set that will be generated into configuration file, see the SmartDNS README for details of configuration parameters
|
| services.samba.settings.global.security | Samba security type.
|
| services.anuko-time-tracker.settings.email.mode | Mail sending mode
|
| services.pretix.settings.pretix.datadir | Directory for storing user uploads and similar data.
|
| services.imaginary.settings | Command line arguments passed to the imaginary executable, stripped of
the prefix -
|
| hardware.bluetooth.settings | Set configuration for system-wide bluetooth (/etc/bluetooth/main.conf)
|
| services.opensearch.settings | OpenSearch configuration.
|
| services.wgautomesh.settings | Configuration for wgautomesh.
|
| services.sourcehut.settings.mail.smtp-from | Outgoing SMTP FROM.
|
| services.peering-manager.settings | Configuration options to set in configuration.py
|
| services.pretalx.settings.redis.session | Whether to use redis as the session storage.
|
| services.libeufin.nexus.settings | Configuration options for the libeufin nexus config file
|
| services.taler.exchange.settings | Configuration options for the taler exchange config file
|
| services.taler.merchant.settings | Configuration options for the taler merchant config file
|
| services.anuko-time-tracker.settings.forumLink | Forum link from the main menu.
|
| services.tor.settings.BandwidthBurst | See torrc manual.
|
| services.tsidp.settings.debugAllRequests | For development
|
| services.tor.settings.CacheDirectory | See torrc manual.
|
| services.umurmur.settings.bindport | Port to bind to (UDP and TCP).
|
| services.openbao.settings.listener | Configure a listener for responding to requests.
|
| services.canaille.settings.SECRET_KEY | Flask Secret Key
|
| services.misskey.settings.redisForPubsub | ioredis options for pubsub
|
| services.pgbouncer.settings.users | Optional
|
| services.pgbouncer.settings.peers | Optional
|
| services.firefly-iii.settings.DB_HOST | The machine which hosts your database
|
| services.easytier.instances.<name>.settings | Settings to generate easytier-‹name›.toml
|
| services.peertube-runner.settings | Configuration for peertube-runner
|
| services.gitlab.pages.settings.gitlab-server | Public GitLab server URL.
|
| services.legit.settings.dirs.templates | Directories where template files are located.
|
| services.gitea.settings.mailer.PROTOCOL | Which mail server protocol to use.
|
| services.headscale.settings.oidc.scope | Scopes used in the OIDC flow.
|
| services.misskey.settings.db.disableCache | Whether to disable caching queries.
|
| services.warpgate.settings.mysql.enable | Whether to enable MySQL listener.
|
| services.warpgate.settings.mysql.listen | Listen endpoint of MySQL listener.
|
| services.sympa.settingsFile | Set of files to be linked in /var/lib/sympa.
|
| services.pds.settings.PDS_DATA_DIRECTORY | Directory to store state
|
| services.lasuite-meet.settings.DJANGO_DATA_DIR | Path to the data directory
|
| services.pretalx.settings.celery.broker | URI to the celery broker used for the asynchronous job queue.
|
| services.pretix.settings.celery.backend | URI to the celery backend used for the asynchronous job queue.
|
| services.neard.settings.General.ResetOnError | Power cycle the adapter when getting a driver error from the kernel.
|
| services.suricata.settings.vars.address-groups | The address group variables for suricata, if not defined the
default value of suricata (see example) will be used
|
| security.auditd.plugins.<name>.settings | Plugin-specific config file to link to /etc/audit/.conf
|
| services.sourcehut.settings.mail.smtp-port | Outgoing SMTP port.
|
| services.sourcehut.settings.mail.smtp-host | Outgoing SMTP host.
|
| services.sourcehut.settings.mail.smtp-user | Outgoing SMTP user.
|
| services.nvme-rs.settings.email.smtp_port | SMTP server port
|
| services.postfix.settings.master.<name>.name | The name of the service to run
|
| services.hatsu.settings.HATSU_DATABASE_URL | Database URL.
|
| services.public-inbox.settings.coderepo | code repositories
|
| services.litestream.settings | See the documentation.
|
| services.rebuilderd.settings | Configuration for rebuilderd (rebuilderd.conf)
|
| security.loginDefs.settings.TTYGROUP | The terminal permissions: the login tty will be owned by the TTYGROUP group,
and the permissions will be set to TTYPERM
|
| services.journald.remote.settings | Configuration in the journal-remote configuration file
|
| services.zammad.database.settings | The database.yml configuration file as key value set
|
| services.gitea.settings.server.STATIC_ROOT_PATH | Upper level of template and static files path.
|
| services.livekit.settings.redis.address | Host and port used to connect to a redis instance.
|
| services.opengfw.settings.workers.count | Number of workers
|
| services.canaille.settings.SERVER_NAME | The domain name on which canaille will be served.
|
| services.freeciv.settings.quitidle | Quit if no players for given time in seconds.
|
| services.freeciv.settings.Database | Enable database connection with given configuration.
|
| services.umurmur.settings.password | Required password to join server, if specified.
|
| services.postsrsd.settings.domains | List of local domains, that do not require rewriting.
|
| services.mosquitto.listeners.*.settings | Additional settings for this listener.
|
| services.anuko-time-tracker.settings.email.smtpHost | MTA hostname.
|
| services.grafana.settings.database.type | Database type.
|
| services.anuko-time-tracker.settings.email.smtpPort | MTA port.
|
| services.pretalx.settings.database.name | Database name.
|
| services.pretalx.settings.database.user | Database username.
|
| services.cryptpad.settings.logToStdout | Controls whether log output should go to stdout of the systemd service
|
| nix.settings.sandbox | If set, Nix will perform builds in a sandboxed environment that it
will set up automatically for each build
|
| services.kubo.settings.Addresses.Swarm | Where Kubo listens for incoming p2p connections
|
| services.sftpgo.settings.httpd.bindings | Configure listen addresses and ports for httpd.
|
| services.pretix.settings.redis.sessions | Whether to use redis as the session storage.
|
| services.sftpgo.settings.sftpd.bindings | Configure listen addresses and ports for sftpd.
|
| services.suricata.settings.stats.enable | Whether to enable suricata global stats.
|
| services.hedgedoc.settings.useSSL | Enable to use SSL server.
|
| services.draupnir.settings.dataPath | The path Draupnir will store its state/data in.
This option is read-only.
If you want to customize where this data is stored, use a bind mount.
|
| services.tor.settings.ShutdownWaitLength | See torrc manual.
|
| services.sourcehut.settings.mail.error-to | Address receiving application exceptions
|
| services.suricata.settings.vars.port-groups | The port group variables for suricata.
|
| services.grafana.settings.paths.plugins | Directory where grafana will automatically scan and look for plugins
|
| services.gancio.settings.log_level | Gancio log level.
|
| services.hedgedoc.settings.allowOrigin | List of domains to whitelist.
|
| services.tinyproxy.settings.Listen | Specify which address to listen to.
|
| services.maubot.settings.database | The full URI to the database
|
| services.rsyncd.settings.sections | attribute set of section of an INI file (attrs of INI atom (null, bool, int, float or string))
|
| services.openssh.settings.DenyGroups | If specified, login is denied for all users part of the listed
groups
|
| services.rkvm.client.settings.password | Shared secret token to authenticate the client
|
| services.rkvm.server.settings.password | Shared secret token to authenticate the client
|
| services.scanservjs.settings | Config to set in config.local.js's afterConfig.
|
| services.reposilite.settings | Configuration written to the reposilite.cdn file
|
| services.freeciv.settings.Announce | Announce game in LAN using given protocol.
|
| services.sabnzbd.settings.servers.<name>.ssl | Whether the server supports TLS
|
| services.umurmur.settings.bindaddr | IPv4 address to bind to
|
| services.anuko-time-tracker.settings.email.smtpAuth | MTA requires authentication.
|
| services.anuko-time-tracker.settings.email.smtpUser | MTA authentication username.
|
| services.grafana.settings.database.name | The name of the Grafana database.
|
| services.headscale.settings.log.format | headscale log format.
|
| services.scanservjs.settings.host | The IP to listen on.
|
| services.scanservjs.settings.port | The port to listen on.
|
| services.gitea.settings.server.PROTOCOL | Listen protocol. +unix means "over unix", not "in addition to."
|
| services.tuned.settings.globalSection | global section of an INI file (attrs of INI atom (null, bool, int, float or string))
|
| services.openssh.settings.AllowGroups | If specified, login is allowed only for users part of the
listed groups
|
| services.acme-dns.settings.general.records | Predefined DNS records served in addition to the _acme-challenge TXT records.
|
| services.biboumi.settings.db_name | The name of the database to use
|
| services.openssh.settings.UseDns | Specifies whether sshd(8) should look up the remote host name, and to check that the resolved host name for
the remote IP address maps back to the very same IP address
|
| services.meshcentral.settings | Settings for MeshCentral
|
| services.sabnzbd.settings.servers.<name>.host | Hostname of the server
|
| services.sabnzbd.settings.servers.<name>.port | Port of the server
|
| services.tor.settings.FascistFirewall | See torrc manual.
|
| services.sabnzbd.settings.servers.<name>.name | The name of the server
|
| services.epgstation.settings | Options to add to config.yml
|
| services.freeciv.settings.Newusers | Whether to enable new users to login if auth is enabled.
|
| i18n.inputMethod.fcitx5.settings.globalOptions | The global options in config file in ini format.
|
| services.aesmd.settings.whitelistUrl | URL to retrieve authorized Intel SGX enclave signers.
|
| services.suricata.settings.plugins | Plugins -- Experimental -- specify the filename for each plugin shared object.
|
| services.openssh.settings.PermitRootLogin | Whether the root user can login using ssh.
|
| services.grafana.settings.database.user | The database user (not applicable for sqlite3).
|
| services.grafana.settings.smtp.key_file | File path to a key file.
|
| services.sabnzbd.settings.misc.email_to | Receiving address for email alerts
|
| services.pretalx.settings.database.host | Database host or socket path.
|
| services.parsedmarc.settings.smtp.to | The addresses to send outgoing mail to.
|
| services.frigate.settings.database.path | Path to the SQLite database used
|
| services.resolved.settings.Resolve.DNS | List of IP addresses to query as recursive DNS resolvers.
|
| services.cryptpad.settings.httpSafeOrigin | Cryptpad sandbox URL
|
| services.reposilite.settings.port | The TCP port to bind to.
|
| services.postgresql.settings.port | The port on which PostgreSQL listens.
|
| services.inadyn.settings.custom.<name>.ddns-path | DDNS server path
|
| services.headscale.settings.dns.split | Split DNS configuration (map of domains and which DNS server to use for each)
|
| services.sourcehut.settings."sr.ht".site-info | The top-level info page for your site.
|
| services.sourcehut.settings."sr.ht".site-name | The name of your network of sr.ht-based sites.
|
| services.matrix-hookshot.settings | config.yml configuration as a Nix attribute set
|
| services.opengfw.settings.workers.queueSize | Worker queue size.
|
| services.fediwall.settings.hideReplies | Hide replies
|
| services.headscale.settings.derp.urls | List of urls containing DERP maps
|
| services.openssh.settings.AcceptEnv | Specifies what environment variables sent by the client will be copied into the session's
environment
|
| services.mchprs.settings.schemati | Mimic the verification and directory layout used by the
Open Redstone Engineers
Schemati plugin
|
| services.libinput.mouse.accelSpeed | Cursor acceleration (how fast speed increases from minSpeed to maxSpeed)
|
| services.rosenpass.settings.listen | List of local endpoints to listen for connections.
|
| services.umami.settings.DISABLE_UPDATES | Disables the check for new versions of Umami.
|
| services.maubot.settings.server.hostname | The IP to listen on
|
| system.activatable | Whether to add the activation script to the system profile
|
| services.minidlna.settings.inotify | Whether to enable inotify monitoring to automatically discover new files.
|
| services.metricbeat.settings | Configuration for metricbeat
|
| services.routinator.settings | Configuration for Routinator 3000, see https://routinator.docs.nlnetlabs.nl/en/stable/manual-page.html#configuration-file for options.
|
| services.mautrix-discord.settings | config.yaml configuration as a Nix attribute set
|
| services.grafana.settings.database.wal | For sqlite3 only
|
| services.languagetool.settings | Configuration file options for LanguageTool, see
'languagetool-http-server --help'
for supported settings.
|
| services.yggdrasil.settings | Configuration for yggdrasil, as a structured Nix attribute set
|
| services.firefly-iii.settings.APP_KEY_FILE | The path to your appkey
|
| services.amule.settings.eMule.IncomingDir | Directory where aMule moves completed downloads
|
| services.lokinet.settings.network.exit | Whether to act as an exit node
|
| services.epgstation.settings.port | HTTP port for EPGStation to listen on.
|
| services.tor.settings.VirtualAddrNetworkIPv4 | See torrc manual.
|
| services.tor.settings.VirtualAddrNetworkIPv6 | See torrc manual.
|
| services.snips-sh.settings.SNIPS_SSH_INTERNAL | The internal SSH address of the service
|
| services.tor.settings.AccountingMax | See torrc manual.
|
| services.postgrest.settings.db-uri | libpq connection parameters as documented in:
https://www.postgresql.org/docs/current/libpq-connect.html#LIBPQ-PARAMKEYWORDS
The settings.db-uri.password and settings.db-uri.passfile options are blocked
|
| services.opengfw.settings.ruleset | The path to load specific local geoip/geosite db files
|
| security.loginDefs.settings.ENCRYPT_METHOD | This defines the system default encryption algorithm for encrypting passwords.
|
| services.inadyn.settings.provider.<name>.ssl | Whether to use HTTPS for this DDNS provider.
|
| services.routinator.settings.log | A string specifying where to send log messages to
|
| services.sourcehut.settings."hg.sr.ht".origin | URL hg.sr.ht is being served at (protocol://domain)
|
| services.sourcehut.settings."hg.sr.ht".hg_ssh | Path to hg-ssh (if not in $PATH).
|
| services.sourcehut.settings."hg.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."hg.sr.ht".debug-port | Port to bind the debug server to.
|
| services.snapserver.settings.tcp.port | Port to listen on for snapclient connections.
|
| services.tlsrpt.fetcher.settings.storage | Path to the collectd sqlite database.
|
| services.tuned.ppdSettings.main.default | Default PPD profile.
|
| services.sourcehut.settings."sr.ht".site-blurb | Blurb for your site.
|
| services.sourcehut.settings."sr.ht".owner-name | Owner's name.
|
| services.lasuite-meet.settings.LIVEKIT_API_URL | URL to the livekit server
|
| services.suricata.settings.stats | Engine statistics such as packet counters, memory use counters and others can be logged in several ways
|
| services.wastebin.settings.RUST_LOG | Influences logging
|
| services.broadcast-box.settings | Attribute set of environment variables.
https://github.com/Glimesh/broadcast-box#environment-variables
The status API exposes stream keys so DISABLE_STATUS is enabled
by default.
|
| services.headscale.settings.oidc.issuer | URL to OpenID issuer.
|
| services.c2fmzq-server.settings.verbose | The level of logging verbosity: 1:Error 2:Info 3:Debug
|
| services.bluesky-pds.settings.PDS_CRAWLERS | URL of crawlers
|
| services.zipline.settings.CORE_HOSTNAME | The hostname to listen on.
|
| services.pretix.settings.redis.location | URI to the redis server, used to speed up locking, caching and session storage.
|
| services.warpgate.settings.log.send_to | Path of UNIX socket of log forwarder
|
| services.grafana.settings.server.socket | Path where the socket should be created when protocol=socket
|
| services.lubelogger.settings | Additional configuration for LubeLogger, see https://docs.lubelogger.com/Environment%20Variables for supported values.
|
| services.photoprism.settings | See the getting-started guide for available options.
|
| services.inadyn.settings.custom.<name>.ddns-server | DDNS server name.
|
| services.parsedmarc.settings.smtp.ssl | Use an encrypted SSL/TLS connection.
|
| services.parsedmarc.settings.imap.ssl | Use an encrypted SSL/TLS connection.
|
| services.bitmagnet.settings.dht_server | DHT server settings
|
| services.wg-access-server.settings.storage | A storage backend connection string
|
| services.go-autoconfig.settings | Configuration for go-autoconfig
|
| security.agnos.settings.accounts | A list of ACME accounts
|
| services.netbox.settings.ALLOWED_HOSTS | A list of valid fully-qualified domain names (FQDNs) and/or IP
addresses that can be used to reach the NetBox service.
|
| services.postfix.settings.master.<name>.args | Arguments to pass to the command
|
| services.hedgedoc.settings.uploadsPath | Directory for storing uploaded images.
|
| services.cryptpad.settings.httpAddress | Address on which the Node.js server should listen
|
| services.tor.settings.AssumeReachable | See torrc manual.
|
| services.tor.settings.ServerDNSSearchDomains | See torrc manual.
|
| services.tor.settings.WarnPlaintextPorts | See torrc manual.
|
| services.nvme-rs.settings.thresholds | Threshold configuration for NVMe monitoring
|
| services.tor.settings.RelayBandwidthRate | See torrc manual.
|
| services.tor.settings.UnixSocksGroupWritable | See torrc manual.
|
| services.tor.settings.AutomapHostsOnResolve | See torrc manual.
|
| services.tor.settings.DormantOnFirstStartup | See torrc manual.
|
| services.sourcehut.settings.mail.error-from | Address sending application exceptions
|
| services.sourcehut.settings."hub.sr.ht".debug-port | Port to bind the debug server to.
|
| services.sourcehut.settings."man.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."git.sr.ht".debug-port | Port to bind the debug server to.
|
| services.sourcehut.settings."man.sr.ht".debug-port | Port to bind the debug server to.
|
| services.sourcehut.settings."git.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."man.sr.ht".origin | URL man.sr.ht is being served at (protocol://domain)
|
| services.sourcehut.settings."hub.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."git.sr.ht".origin | URL git.sr.ht is being served at (protocol://domain)
|
| services.sourcehut.settings."hub.sr.ht".origin | URL hub.sr.ht is being served at (protocol://domain)
|
| services.acme-dns.settings.general.protocol | Protocols to serve DNS responses on.
|
| services.pretix.settings.pretix.cachedir | Directory for storing temporary files.
|
| services.matrix-conduit.settings | Generates the conduit.toml configuration file
|
| services.cryptpad.settings.maxWorkers | Number of child processes, defaults to number of cores available
|
| services.veilid.settings.logging.api.enabled | Events of type 'api' will be logged.
|
| services.veilid.settings.logging.system.level | The minimum priority of system events to be logged.
|
| services.xonotic.settings.hostname | The name that will appear in the server list. $g_xonoticversion
gets replaced with the current version.
|
| services.waagent.settings.Logs.Verbose | If you set this option, log verbosity is boosted
|
| services.aesmd.settings.defaultQuotingType | Attestation quote type.
|
| services.yggdrasil.settings.Peers | List of outbound peer connection strings
|
| services.evremap.settings.remap.*.output | The key sequence that should be output when the input sequence is entered
|
| services.grafana-to-ntfy.settings.ntfyBAuthPass | The path to the password for the specified ntfy-sh user
|
| services.crowdsec-firewall-bouncer.settings | Settings for the main CrowdSec Firewall Bouncer
|
| services.anuko-time-tracker.settings.email.smtpDebug | Debug mail sending.
|
| services.anuko-time-tracker.settings.email.sender | Default sender for mail.
|
| services.parsedmarc.settings.imap.port | The IMAP server port.
|
| services.parsedmarc.settings.smtp.user | The SMTP server username.
|
| services.parsedmarc.settings.smtp.port | The SMTP server port.
|
| services.omnom.settings.db.connection | Database connection URI.
|
| services.parsedmarc.settings.imap.user | The IMAP server username.
|
| services.filesender.settings | Configuration options used by FileSender
|
| services.homebridge.settings | Configuration options for homebridge
|
| services.snapserver.settings | Snapserver configuration
|
| services.privatebin.settings | Options for privatebin configuration
|
| services.mattermost.settings | Additional configuration options as Nix attribute set in config.json schema.
|
| services.metricbeat.settings.tags | Tags to place on the shipped metrics
|
| services.metricbeat.settings.name | Name of the beat
|
| networking.wireless.iwd.settings | Options passed to iwd
|
| services.vault-agent.instances.<name>.settings | Free-form settings written directly to the config.json file
|
| services.c2fmzq-server.settings.database | Path of the database
|
| services.stash.settings.blobs_path | Path to blobs
|
| services.postsrsd.settings.chroot-dir | Path to chroot into at runtime as an additional layer of protection.
We confine the runtime environment through systemd hardening instead, so this option is read-only.
|
| services.librespeed.frontend.settings | Override default settings of the speedtest web client
|
| services.forgejo.settings.server.SSH_PORT | SSH port displayed in clone URL
|
| services.oncall.settings.db.conn.kwargs.database | Database name.
|
| services.grafana.settings.database.path | Only applicable to sqlite3 database
|
| <imports = [ pkgs.php.services.default ]>.php-fpm.settings | PHP FPM configuration
|
| services.libeufin.nexus.settings.nexus-ebics.BIC | BIC of the bank account that is associated with the EBICS subscriber.
|
| services.lokinet.settings.dns.upstream | Upstream resolver(s) to use as fallback for non-loki addresses
|
| services.biboumi.settings.hostname | The hostname served by the XMPP gateway
|
| services.dsnet.settings.ExternalIP | The external IP address of the server
|
| services.tor.settings.CellStatistics | See torrc manual.
|
| services.snips-sh.settings.SNIPS_HTTP_INTERNAL | The internal HTTP address of the service
|
| services.tor.settings.OptimisticData | See torrc manual.
|
| services.tor.settings.DirReqStatistics | See torrc manual.
|
| services.gitea.settings.mailer.SENDMAIL_PATH | Path to sendmail binary or script.
|
| services.grafana.settings.smtp.startTLS_policy | StartTLS policy when connecting to server.
|
| services.suwayomi-server.settings.server.ip | The ip that Suwayomi will bind to.
|
| services.snapserver.settings.http.port | Port to listen on for snapclient connections.
|
| services.parsedmarc.settings.smtp.from | The From address to use for the
outgoing mail.
|
| services.samba.settings.global."invalid users" | List of users who are denied to login via Samba.
|
| services.opensnitch.settings | opensnitchd configuration
|
| services.nebula.networks.<name>.settings | Nebula configuration
|
| services.x2goserver.settings | x2goserver.conf ini configuration as nix attributes
|
| services.pretalx.settings.celery.backend | URI to the celery backend used for the asynchronous job queue.
|
| services.sourcehut.settings."hg.sr.ht".repos | Path to mercurial repositories on disk
|
| services.hickory-dns.settings.zones.*.file | Path to the .zone file
|
| services.wgautomesh.settings.peers | wgautomesh peer list.
|
| services.sourcehut.settings.mail.pgp-pubkey | OpenPGP public key.
|
| services.shairport-sync.settings | Configuration options for Shairport-Sync
|
| services.libeufin.nexus.settings.nexus-httpd.PORT | The port on which libeufin-bank should listen.
|
| services.librechat.settings | A free-form attribute set that will be written to librechat.yaml
|
| services.rosenpass.settings.peers.*.peer | WireGuard public key corresponding to the remote Rosenpass peer.
|
| services.umami.settings.TRACKER_SCRIPT_NAME | Allows you to assign a custom name to the tracker script different from the default script.js.
|
| services.rsyncd.settings.globalSection | global section of an INI file (attrs of INI atom (null, bool, int, float or string))
|
| services.postfix-tlspol.settings.server.log-level | Log level
|
| services.mympd.settings.http_port | The HTTP port where mympd's web interface will be available
|
| services.bookstack.settings.APP_URL | The root URL that you want to host BookStack on
|
| services.grafana-to-ntfy.settings.ntfyBAuthUser | The ntfy-sh user to use for authenticating with the ntfy-sh instance
|
| services.bluesky-pds.settings.PDS_HOSTNAME | Instance hostname (base domain name)
|
| services.privoxy.settings.listen-address | Pair of address:port the proxy server is listening to.
|
| services.sourcehut.settings."lists.sr.ht".redis | The Redis connection used for the Celery worker.
|
| services.etebase-server.settings.global.debug | Whether to set django's DEBUG flag.
|
| services.parsedmarc.settings.imap.host | The IMAP server hostname or IP address.
|
| services.parsedmarc.settings.smtp.host | The SMTP server hostname or IP address.
|
| services.kavita.settings.IpAddresses | IP Addresses to bind to
|
| services.autotierfs.settings | The contents of the configuration file for autotier
|
| services.tor.settings.ServerDNSAllowBrokenConfig | See torrc manual.
|
| services.tor.settings.ExitPolicyRejectPrivate | See torrc manual.
|
| services.yggdrasil-jumper.settings | Configuration for Yggdrasil Jumper as a Nix attribute set.
|
| services.sourcehut.settings."todo.sr.ht".origin | URL todo.sr.ht is being served at (protocol://domain)
|
| services.sourcehut.settings."meta.sr.ht".debug-port | Port to bind the debug server to.
|
| services.sourcehut.settings."todo.sr.ht".debug-port | Port to bind the debug server to.
|
| services.sourcehut.settings."meta.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."todo.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."meta.sr.ht".origin | URL meta.sr.ht is being served at (protocol://domain)
|
| services.forgejo.settings.server.DISABLE_SSH | Disable external SSH feature.
|
| services.frp.instances.<name>.settings | Frp configuration, for configuration options
see the example of client
or server on github.
|
| services.libeufin.nexus.settings.nexus-ebics.NAME | Legal entity that is associated with the EBICS subscriber.
|
| services.slskd.settings.global.download.slots | Limit of the number of concurrent download slots.
|
| services.sftpgo.settings.smtp.auth_type |
0: Plain
1: Login
2: CRAM-MD5
|
| services.sourcehut.settings."git.sr.ht".repos | Path to git repositories on disk
|
| services.headscale.settings.derp.paths | List of file paths containing DERP maps
|
| services.sourcehut.settings."sr.ht".owner-email | Owner's email.
|
| services.navidrome.settings.Address | Address to run Navidrome on.
|
| services.pid-fan-controller.settings.fans | List of fans to be controlled.
|
| services.watchdogd.settings.timeout | The WDT timeout before reset.
|
| hardware.tuxedo-drivers.settings.fn-lock | Enables or disables the laptop keyboard's Function (Fn) lock at boot
|
| services.dnsmasq.settings | Configuration of dnsmasq
|
| services.traccar.settings | config.xml configuration as a Nix attribute set
|
| services.scrutiny.settings.web.influxdb.org | InfluxDB organisation under which to store data.
|
| services.grocy.settings.calendar.firstDayOfWeek | Which day of the week (0=Sunday, 1=Monday etc.) should be the
first day.
|
| services.dnscrypt-proxy2.settings | Attrset that is converted and passed as TOML config file
|
| services.actual.settings.serverFiles | The server will put an account.sqlite file in this directory, which will contain the (hashed) server password, a list of all the budget files the server knows about, and the active session token (along with anything else the server may want to store in the future).
|
| services.opengfw.settings.ruleset.geosite | Path to geosite.dat.
|
| services.centrifugo.settings | Declarative Centrifugo configuration
|
| services.libeufin.nexus.settings.nexus-ebics.HOST_ID | Name of the EBICS host.
|
| services.typesense.settings.server.api-port | Port on which the Typesense API service listens.
|
| services.warpgate.settings.postgres.key | Path to PostgreSQL listener private key.
|
| services.sourcehut.settings."sr.ht".source-url | The source code for your fork of sr.ht.
|
| services.imaginary.settings.return-size | Return the image size in the HTTP headers.
|
| services.postgrest.settings.server-port | The TCP port to bind the web server.
|
| services.libeufin.nexus.settings.nexus-ebics.IBAN | IBAN of the bank account that is associated with the EBICS subscriber.
|
| services.invidious-router.settings | Configuration for invidious-router
|
| services.pretix.settings.pretix.currency | Default currency for events in its ISO 4217 three-letter code.
|
| services.amule.settings.WebServer.Password | MD5 hash of the password, obtainaible with echo "<password>" | md5sum | cut -d ' ' -f 1
|
| services.lokinet.settings.network.exit-node | Specify a .loki address and an optional ip range to use as an exit broker
|
| services.radicle.ci.broker.settings.triggers | CI triggers.
|
| services.moosefs.cgiserver.settings | GUI server configuration options.
|
| services.tor.settings.RelayBandwidthBurst | See torrc manual.
|
| services.opensearch.settings."http.port" | The port to listen on for HTTP traffic.
|
| services.mautrix-discord.settings.bridge | Bridge configuration
|
| services.sftpgo.settings.ftpd.bindings.*.port | The port for serving FTP requests
|
| services.gateone.settingsDir | Path of configuration files for GateOne.
|
| services.openssh.settings.GatewayPorts | Specifies whether remote hosts are allowed to connect to
ports forwarded for the client
|
| services.scrutiny.collector.settings | Collector settings to be rendered into the collector configuration file
|
| services.garage.settings.data_dir | The directory in which Garage will store the data blocks of objects
|
| services.watchdogd.settings.safe-exit | With safeExit enabled, the daemon will ask the driver to disable the WDT before exiting
|
| services.typesense.settings.server.data-dir | Path to the directory where data will be stored on disk.
|
| services.openldap.settings.children | Child entries of the current entry, with recursively the same structure.
|
| services.openldap.settings.includes | LDIF files to include after the parent's attributes but before its children.
|
| services.headscale.settings.policy.mode | The mode can be "file" or "database" that defines
where the ACL policies are stored and read from.
|
| services.headscale.settings.policy.path | If the mode is set to "file", the path to a
HuJSON file containing ACL policies.
|
| services.grafana.settings.server.protocol | Which protocol to listen.
|
| services.scrutiny.settings.web.influxdb.port | The port of the InfluxDB instance.
|
| services.vmalert.settings."notifier.url" | Prometheus Alertmanager URL
|
| services.yggdrasil.settings.Listen | Listen addresses for incoming connections
|
| services.opencloud.settings | Additional YAML configuration for OpenCloud services
|
| services.bluesky-pds.settings.PDS_BLOB_UPLOAD_LIMIT | Size limit of uploaded blobs in bytes
|
| services.umurmur.settings.max_users | Maximum number of concurrent clients allowed.
|
| security.krb5.settings.includedir | Directories containing files to include in the Kerberos configuration.
|
| nix.settings.substituters | List of binary cache URLs used to obtain pre-built binaries
of Nix packages
|
| services.sitespeed-io.runs.*.settings | Configuration for sitespeed-io, see
https://www.sitespeed.io/documentation/sitespeed.io/configuration/
for available options
|
| services.postgrest.settings.db-config | Enables the in-database configuration.
https://docs.postgrest.org/en/stable/references/configuration.html#in-database-configuration
This is enabled by default upstream, but disabled by default in this module.
|
| services.matrix-hookshot.settings.passFile | A passkey used to encrypt tokens stored inside the bridge
|
| services.dsnet.settings.ExternalIP6 | The external IPv6 address of the server
|
| services.listmonk.database.settings.smtp | List of outgoing SMTP servers
|
| services.suwayomi-server.settings.server.port | The port that Suwayomi will listen to.
|
| services.tor.settings.UseDefaultFallbackDirs | See torrc manual.
|
| services.tor.settings.AccountingStart | See torrc manual.
|
| services.tor.settings.ProtocolWarnings | See torrc manual.
|
| services.tor.settings.EntryStatistics | See torrc manual.
|
| services.lasuite-docs.settings.CELERY_BROKER_URL | URL of the redis backend for celery
|
| services.lasuite-meet.settings.CELERY_BROKER_URL | URL of the redis backend for celery
|
| services.canaille.settings.CANAILLE.ACL | Access Control Lists
|
| services.prometheus.exporters.fritz.settings | Configuration settings for fritz-exporter.
|
| services.grafana.settings.server.domain | The public facing domain name used to access grafana from a browser
|
| services.crab-hole.settings.blocklist.lists | List of blocklists
|
| services.parsedmarc.settings | Configuration parameters to set in
parsedmarc.ini
|
| services.prometheus.exporters.script.settings.scripts | All settings expressed as an Nix attrset
|
| services.suricata.settings.host-mode | If the Suricata box is a router for the sniffed networks, set it to 'router'
|
| services.postfix-tlspol.settings.server.cache-file | Path to the cache file.
|
| services.tlsrpt.collectd.settings.storage | Storage backend definition.
|
| services.scrutiny.settings.web.influxdb.host | IP or hostname of the InfluxDB instance.
|
| services.btrbk.instances.<name>.settings | configuration options for btrbk
|
| services.reaction.settingsFiles | Configuration for reaction, see the wiki.
reaction supports JSON, YAML and JSONnet
|
| services.postgrest.settings | PostgREST configuration as documented in:
https://docs.postgrest.org/en/stable/references/configuration.html#list-of-parameters
db-uri is represented as an attribute set, see settings.db-uri
The settings.jwt-secret option is blocked
|
| services.hercules-ci-agent.settings.apiBaseUrl | API base URL that the agent will connect to
|
| services.pretalx.settings.redis.location | URI to the redis server, used to speed up locking, caching and session storage.
|
| services.umurmur.settings.bindaddr6 | IPv6 address to bind to
|
| services.syncthing.settings.options | The options element contains all other global configuration options
|
| services.xonotic.settings.sv_public | Controls whether the server will be publicly listed.
|
| services.sourcehut.settings."meta.sr.ht::settings".registration | Whether to enable public registration.
|
| services.grocy.settings.calendar.showWeekNumber | Show the number of the weeks in the calendar views.
|
| services.dependency-track.settings | See https://docs.dependencytrack.org/getting-started/configuration/#default-configuration for possible options
|
| services.public-inbox.settings.coderepo.<name>.dir | Path to a git repository
|
| services.openbao.settings.listener.<name>.type | The listener type to enable.
|
| services.sympa.settingsFile.<name>.text | Text of the file.
|
| services.sourcehut.settings."paste.sr.ht".debug-port | Port to bind the debug server to.
|
| services.sourcehut.settings."pages.sr.ht".debug-port | Port to bind the debug server to.
|
| services.sourcehut.settings."pages.sr.ht".origin | URL pages.sr.ht is being served at (protocol://domain)
|
| services.sourcehut.settings."lists.sr.ht".debug-port | Port to bind the debug server to.
|
| services.sourcehut.settings."paste.sr.ht".origin | URL paste.sr.ht is being served at (protocol://domain)
|
| services.sourcehut.settings."paste.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."lists.sr.ht".origin | URL lists.sr.ht is being served at (protocol://domain)
|
| services.sourcehut.settings."pages.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."lists.sr.ht".debug-host | Address to bind the debug server to.
|
| services.moosefs.cgiserver.settings.PORT | Port for CGI server to listen on.
|
| services.crowdsec.settings.console.tokenFile | The Console Token file to use.
|
| services.grafana.settings.smtp.cert_file | File path to a cert file.
|
| services.kubo.settings.Addresses.Gateway | Where the IPFS Gateway can be reached
|
| services.journald.remote.settings.Remote.Seal | Periodically sign the data in the journal using Forward Secure
Sealing.
|
| services.tor.settings.ExitPortStatistics | See torrc manual.
|
| services.tor.settings.AutomapHostsSuffixes | See torrc manual.
|
| services.collabora-online.settings | Configuration for Collabora Online WebSocket Daemon, see
https://sdk.collaboraonline.com/docs/installation/Configuration.html, or
https://github.com/CollaboraOnline/online/blob/master/coolwsd.xml.in for the default
configuration.
|
| services.wordpress.sites.<name>.settings | Structural Wordpress configuration
|
| users.mysql.pam | Settings for pam_mysql
|
| services.sourcehut.settings."hg.sr.ht".api-origin | Origin URL for the API
|
| services.reposilite.settings.sslPort | SSL port to bind to
|
| services.forgejo.settings.server.STATIC_ROOT_PATH | Upper level of template and static files path.
|
| services.firewalld.settings.RFC3964_IPv4 | Whether to filter IPv6 traffic with 6to4 destination addresses that correspond to IPv4 addresses that should not be routed over the public internet.
|
| services.kanidm.server.settings.domain | The domain that Kanidm manages
|
| services.taler.merchant.settings.merchant.DB | Plugin to use for the database.
|
| services.taler.exchange.settings.exchange.DB | Plugin to use for the database.
|
| services.slskd.settings.filters.search.request | Incoming search requests which match this filter are ignored.
|
| services.sourcehut.settings."builds.sr.ht".redis | The Redis connection used for the Celery worker.
|
| services.resolved.settings.Resolve.DNSSEC | Whether to validate DNSSEC for DNS lookups.
|
| services.sftpgo.settings.webdavd.bindings | Configure listen addresses and ports for webdavd.
|
| services.angrr.settings.touch.project-globs | List of glob patterns to include or exclude files when touching GC roots
|
| services.sabnzbd.settings.servers.<name>.enable | Enable this server by default
|
| services.matrix-synapse.settings.redis.enabled | Whether to use redis support
|
| services.suricata.settings.dpdk.eal-params.proc-type | dpdk eal-params.proc-type, see data plane development kit docs.
|
| services.sourcehut.settings."pages.sr.ht".max-site-size | Maximum size of any given site (post-gunzip), in MiB.
|
| services.sourcehut.settings."hg.sr.ht".srhtext | Path to the srht mercurial extension
(defaults to where the hgsrht code is)
|
| services.epgstation.settings.encode | Encoding presets for recorded videos.
|
| hardware.nvidia.datacenter.settings | Additional configuration options for fabricmanager.
|
| services.tor.settings.ServerDNSRandomizeCase | See torrc manual.
|
| services.tor.settings.BridgeRecordUsageByCountry | See torrc manual.
|
| services.sourcehut.settings."git.sr.ht".api-origin | Origin URL for the API
|
| services.sourcehut.settings."hub.sr.ht".api-origin | Origin URL for the API
|
| services.sourcehut.settings."man.sr.ht".api-origin | Origin URL for the API
|
| services.sftpgo.settings.sftpd.bindings.*.port | The port for serving SFTP requests
|
| services.suricata.settings.default-rule-path | Path in which suricata-update managed rules are stored by default.
|
| services.lidarr.settings.update.mechanism | which update mechanism to use
|
| services.sonarr.settings.update.mechanism | which update mechanism to use
|
| services.radarr.settings.update.mechanism | which update mechanism to use
|
| services.kanidm.server.settings.log_level | Log level of the server.
|
| services.hbase-standalone.settings | configurations in hbase-site.xml, see https://github.com/apache/hbase/blob/master/hbase-server/src/test/resources/hbase-site.xml for details.
|
| services.traefik.dynamic.settings | Dynamic configuration for Traefik, written in Nix
|
| services.forgejo.settings.server.PROTOCOL | Listen protocol. +unix means "over unix", not "in addition to."
|
| services.mbpfan.settings.general.low_temp | If temperature is below this, fans will run at minimum speed.
|
| services.mbpfan.settings.general.max_temp | If temperature is above this, fans will run at maximum speed.
|
| services.peroxide.settings.ServerAddress | The address on which to listen for connections.
|
| services.corteza.settings.HTTP_WEBAPP_ENABLED | Whether to enable webapps.
|
| services.firewalld.settings.DefaultZone | Default zone for connections.
|
| services.matrix-synapse.settings.pid_file | The file to store the PID in.
|
| services.knot-resolver.settings.workers | The number of running kresd (Knot Resolver daemon) workers
|
| services.postfix.settings.master.<name>.wakeup | Automatically wake up the service after the specified number of
seconds
|
| services.umami.settings.APP_SECRET_FILE | A file containing a secure random string
|
| services.apache-kafka.settings.listeners | Kafka Listener List
|
| services.homebridge.settings.bridge.name | Name of the homebridge
|
| services.grafana-image-renderer.settings | Configuration attributes for grafana-image-renderer.
|
| programs.rush.global | The global statement defines global settings.
|
| services.samba.settings.global."passwd program" | Path to a program that can be used to set UNIX user passwords.
|
| services.filebrowser.settings.port | The port to listen on.
|
| services.sourcehut.settings."todo.sr.ht".notify-from | Outgoing email for notifications generated by users.
|
| services.resolved.settings.Resolve.DNSOverTLS | Whether to use TLS encryption for DNS queries
|
| services.hatsu.settings.HATSU_PRIMARY_ACCOUNT | The primary account of your instance (eg 'example.com').
|
| services.inadyn.settings.custom.<name>.hostname | Hostname alias(es).
|
| services.inadyn.settings.custom.<name>.username | Username for this DDNS provider.
|
| services.sourcehut.settings."meta.sr.ht::settings".onboarding-redirect | Where to redirect new users upon registration.
|
| services.sftpgo.settings.httpd.bindings.*.port | The port for serving HTTP(S) requests
|
| services.radicle.ci.broker.settings.adapters | CI adapters
|
| services.suricata.settings.stats.stream-events | Add stream events as stats.
|
| services.kanidm.server.settings.tls_chain | TLS chain in pem format.
|
| services.grafana.settings.smtp.from_name | Name to be used as client identity for EHLO in SMTP dialog.
|
| services.sabnzbd.settings.misc.email_rss | Whether to send alerts for jobs added by RSS feeds
|
| services.pretix.settings.database.backend | Database backend to use
|
| services.tor.settings.MaxCircuitDirtiness | See torrc manual.
|
| services.tor.settings.RejectPlaintextPorts | See torrc manual.
|
| services.bitmagnet.settings.http_server | HTTP server settings
|
| services.scrutiny.settings.web.influxdb.token | Authentication token for connecting to InfluxDB.
|
| services.homebridge.settings.bridge.port | The port homebridge listens on
|
| services.opengfw.settings.workers.udpMaxStreams | UDP max streams.
|
| services.litellm.settings.router_settings | LiteLLM Router settings
|
| services.etebase-server.settings.database.name | The database name.
|
| services.cryptpad.settings.httpUnsafeOrigin | This is the URL that users will enter to load your instance
|
| services.gitlab.pages.settings | Configuration options to set in the GitLab Pages config
file
|
| services.bonsaid.settings.*.command | Command to run when this transition is taken
|
| services.sourcehut.settings."hg.sr.ht".oauth-client-id | hg.sr.ht's OAuth client id for meta.sr.ht.
|
| services.firewalld.settings.ReloadPolicy | The policy during reload.
|
| services.grafana.settings.server.cert_key | Path to the certificate key file (if protocol is set to https or h2).
|
| services.tlsrpt.reportd.settings.fetchers | Comma-separated list of fetcher programs that retrieve collectd data.
|
| services.suricata.settings.includes | Files to include in the suricata configuration
|
| services.wg-access-server.settings.dns.enabled | Enable/disable the embedded DNS proxy server
|
| services.sourcehut.settings."todo.sr.ht::mail".sock | Path for the lmtp daemon's unix socket
|
| services.logrotate.settings.<name>.enable | Whether to enable setting individual kill switch.
|
| services.postfix.settings.master.<name>.chroot | Whether the service is chrooted to have only access to the
services.postfix.queueDir and the closure of
store paths specified by the program option.
|
| services.anuko-time-tracker.settings.reportFooter | Defines whether to use a footer on reports.
|
| services.pid-fan-controller.settings.fans.*.minPwm | Minimum PWM value.
|
| services.pid-fan-controller.settings.fans.*.maxPwm | Maximum PWM value.
|
| services.healthchecks.settings | Environment variables which are read by healthchecks (local)_settings.py
|
| services.snapserver.settings.stream.port | Port to listen on for snapclient connections.
|
| services.rosenpass.settings.peers.*.device | Name of the local WireGuard interface to use for this peer.
|
| services.privoxy.settings.enable-edit-actions | Whether the web-based actions file editor may be used.
|
| services.sourcehut.settings."meta.sr.ht".api-origin | Origin URL for the API
|
| services.sourcehut.settings."todo.sr.ht".api-origin | Origin URL for the API
|
| services.filebrowser.settings.root | The directory where FileBrowser stores files.
|
| services.tor.settings.ExtraInfoStatistics | See torrc manual.
|
| services.mollysocket.settings.port | Listening port of the web server
|
| services.tor.settings.CookieAuthFileGroupReadable | See torrc manual.
|
| services.mollysocket.settings.host | Listening address of the web server
|
| services.postsrsd.settings.srs-domain | Dedicated mail domain used for ephemeral SRS envelope addresses
|
| services.anubis.defaultOptions.settings | Freeform configuration via environment variables for Anubis
|
| services.journald.upload.settings.Upload.URL | The URL to upload the journal entries to
|
| services.mautrix-discord.settings.logging | Logging configuration
|
| services.szurubooru.server.settings | Configuration to write to config.yaml
|
| services.sourcehut.settings."meta.sr.ht::aliases" | Aliases for the client IDs of commonly used OAuth clients.
|
| services.opensnitch.settings.LogLevel | Default log level from 0 to 4 (debug, info, important, warning,
error).
|
| services.autosuspend.settings | Configuration for autosuspend, see
https://autosuspend.readthedocs.io/en/latest/configuration_file.html#general-configuration
for supported values.
|
| services.immichframe.settings | Configuration for ImmichFrame
|
| services.mollysocket.settings | Configuration for MollySocket
|
| services.bitmagnet.settings.postgres | PostgreSQL database configuration
|
| services.filebeat.settings | Configuration for filebeat
|
| services.libeufin.nexus.settings.nexus-ebics.HOST_BASE_URL | URL of the EBICS server.
|
| services.keycloak.settings.hostname | The hostname part of the public URL used as base for
all frontend requests
|
| services.routinator.settings.retry | An integer value specifying the number of seconds an RTR client is requested to wait after it failed to receive a data set.
|
| services.mautrix-signal.settings | config.yaml configuration as a Nix attribute set
|
| services.libeufin.nexus.settings.nexus-ebics.USER_ID | User ID of the EBICS subscriber
|
| services.tinyproxy.settings.Filter | Tinyproxy supports filtering of web sites based on URLs or domains
|
| services.sourcehut.settings."man.sr.ht".oauth-client-id | man.sr.ht's OAuth client id for meta.sr.ht.
|
| services.sourcehut.settings."git.sr.ht".oauth-client-id | git.sr.ht's OAuth client id for meta.sr.ht.
|
| services.sourcehut.settings."hub.sr.ht".oauth-client-id | hub.sr.ht's OAuth client id for meta.sr.ht.
|
| services.listmonk.database.settings.smtp.*.port | Port for the SMTP server
|
| services.listmonk.database.settings.smtp.*.host | Hostname for the SMTP server
|
| services.bluesky-pds.settings.PDS_REPORT_SERVICE_DID | DID of mod service
|
| services.xserver.displayManager.gdm.settings | Options passed to the gdm daemon
|
| services.opensnitch.settings.Rules.Path | Path to the directory where firewall rules can be found and will
get stored by the NixOS module.
|
| services.reposilite.settings.basePath | Custom base path for this Reposilite instance
|
| services.veilid.settings.logging.system.enabled | Events of type 'system' will be logged.
|
| services.gitea.settings.session.COOKIE_SECURE | Marks session cookies as "secure" as a hint for browsers to only send
them via HTTPS
|
| services.firewalld.settings.FlushAllOnReload | Whether to flush all runtime rules on a reload.
|
| services.public-inbox.settings.coderepo.<name>.cgitUrl | URL of a cgit instance
|
| services.umami.settings.DATABASE_URL_FILE | A file containing a connection string for the database
|
| services.sourcehut.settings."builds.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."builds.sr.ht".origin | URL builds.sr.ht is being served at (protocol://domain)
|
| services.sourcehut.settings."builds.sr.ht".debug-port | Port to bind the debug server to.
|
| services.knot-resolver.settings.network.listen | List of interfaces to listen to and its configuration.
|
| services.warpgate.settings.log.retention | How long Warpgate keep its logs.
|
| services.mchprs.settings.bungeecord | Enable compatibility with
BungeeCord
|
| services.taler.settings.taler.CURRENCY_ROUND_UNIT | Smallest amount in this currency that can be transferred using the underlying RTGS
|
| services.opengfw.settings.replay.realtime | Whether the packets in the PCAP file should be replayed in "real time" (instead of as fast as possible).
|
| services.routinator.settings.log-level | A string value specifying the maximum log level for which log messages should be emitted
|
| services.taler.merchant.settings.merchant.PORT | Port on which the HTTP server listens.
|
| services.taler.exchange.settings.exchange.PORT | Port on which the HTTP server listens.
|
| services.filesender.settings.admin | UIDs (as per the configured saml_uid_attribute) of FileSender administrators
|
| services.writefreely.settings | Writefreely configuration (config.ini)
|
| services.moosefs.cgiserver.settings.DATA_PATH | Directory for lock files.
|
| services.szurubooru.server.settings.name | Name shown in the website title and on the front page.
|
| services.bookstack.settings | Options for Bookstack configuration
|
| services.szurubooru.server.settings.smtp.port | Port of the SMTP server.
|
| services.bluesky-pds.settings.PDS_REPORT_SERVICE_URL | URL of mod service
|
| services.bitmagnet.settings.postgres.user | User to connect as
|
| services.writefreely.settings.app.theme | The theme to apply.
|
| services.displayManager.lemurs.settings | Configuration for lemurs, provided as a Nix attribute set and automatically
serialized to TOML
|
| services.firewalld.settings.CleanupOnExit | Whether to clean up firewall rules when firewalld stops.
|
| services.chhoto-url.settings.slug_style | The slug style to use for auto-generated URLs.
|
| services.syncthing.settings.folders.<name>.id | The ID of the folder
|
| services.syncthing.settings.devices.<name>.id | The device ID
|
| services.sourcehut.settings."lists.sr.ht".notify-from | Outgoing email for notifications generated by users.
|
| services.suricata.settings.stats.interval | The interval field (in seconds) controls the interval at
which stats are updated in the log.
|
| services.livekit.ingress.settings.redis.address | Address or hostname and port for redis connection
|
| services.postfix-tlspol.settings.dns.address | IP and port to your DNS resolver
|
| services.suricata.settings.default-log-dir | The default logging directory
|
| services.postsrsd.settings.secrets-file | Path to the file containing the secret keys.
Secrets are passed using LoadCredential= on the systemd unit,
so this options is read-only
|
| services.kubo.settings.Addresses.API | Multiaddr or array of multiaddrs describing the address to serve the local HTTP API on
|
| services.birdwatcher.settings | birdwatcher configuration, for configuration options see the example on github
|
| services.meshtasticd.settings | The Meshtastic configuration file
|
| services.umami.settings.COLLECT_API_ENDPOINT | Allows you to send metrics to a location different than the default /api/send.
|
| services.libeufin.bank.settings.libeufin-bank.PORT | The port on which libeufin-bank should listen.
|
| services.szurubooru.server.settings.smtp.user | User to connect to the SMTP server.
|
| services.amule.settings.ExternalConnect.ECPort | TCP port for external connections, like remote control via amule-gui
|
| services.headscale.settings.oidc.pkce.method | PKCE method to use:
- plain: Use plain code verifier
- S256: Use SHA256 hashed code verifier (default, recommended)
|
| services.hickory-dns.settings.directory | The directory in which hickory-dns should look for .zone files,
whenever zones aren't specified by absolute path.
|
| services.wastebin.settings.WASTEBIN_TITLE | Overrides the HTML page title
|
| services.evremap.settings.dual_role | List of dual-role remappings that output different key sequences based on whether the
input key is held or tapped.
|
| services.biboumi.settings.log_level | Indicate what type of log messages to write in the logs.
0 is debug, 1 is info, 2 is warning, 3 is error.
|
| services.bitmagnet.settings.postgres.name | Database name to connect to
|
| services.routinator.settings.log-file | A string value containing the path to a file to which log messages will be appended if the log configuration value is set to file
|
| services.bookstack.settings.APP_KEY_FILE | The path to your appkey
|
| services.sourcehut.settings."builds.sr.ht".allow-free | Whether to enable nonpaying users to submit builds.
|
| services.opensnitch.settings.Stats.MaxStats | Max stats per item to keep in backlog.
|
| services.matrix-synapse.settings.database.name | The database engine name
|
| services.grafana.settings.server.http_port | Listening port.
|
| services.swapspace.settings.swappath | Location where swapspace may create and delete swapfiles
|
| services.minidlna.settings.log_level | Defines the type of messages that should be logged and down to which level of importance.
|
| services.lasuite-docs.settings.DJANGO_SECRET_KEY_FILE | The path to the file containing Django's secret key
|
| services.lasuite-meet.settings.DJANGO_SECRET_KEY_FILE | The path to the file containing Django's secret key
|
| services.sourcehut.settings."hg.sr.ht".webhooks | The Redis connection used for the webhooks worker.
|
| services.sourcehut.settings."lists.sr.ht".allow-new-lists | Whether to enable creation of new lists.
|
| services.sourcehut.settings."todo.sr.ht".oauth-client-id | todo.sr.ht's OAuth client id for meta.sr.ht.
|
| services.moosefs.cgiserver.settings.BIND_HOST | IP address to bind CGI server to.
|
| services.immich.settings.newVersionCheck.enabled | Check for new versions
|
| services.sftpgo.settings.smtp.encryption | Encryption scheme:
0: No encryption
1: TLS
2: STARTTLS
|
| services.veilid.settings.logging.terminal.level | The minimum priority of terminal events to be logged.
|
| security.pam.u2f.settings.authfile | By default pam-u2f module reads the keys from
$XDG_CONFIG_HOME/Yubico/u2f_keys (or
$HOME/.config/Yubico/u2f_keys if XDG variable is
not set)
|
| services.cryptpad.settings.installMethod | Install method is listed in telemetry if you agree to it through the consentToContact
setting in the admin panel.
|
| services.sourcehut.settings."todo.sr.ht::mail".sock-group | The lmtp daemon will make the unix socket group-read/write
for users in this group.
|
| services.lokinet.settings.network.keyfile | The private key to persist address with
|
| services.gotosocial.settings | Contents of the GoToSocial YAML config
|
| services.pgbackrest.settings | An attribute set of options as described in:
https://pgbackrest.org/configuration.html
All globally available options, i.e. all except stanza options, can be used
|
| services.szurubooru.server.settings.debug | Whether to generate server logs.
|
| services.neard.settings.General.DefaultPowered | Automatically turn an adapter on when being discovered.
|
| services.spacecookie.settings.log.level | Log level for the spacecookie service.
|
| services.warpgate.settings.postgres.enable | Whether to enable PostgreSQL listener.
|
| services.warpgate.settings.postgres.listen | Listen endpoint of PostgreSQL listener.
|
| services.geoipupdate.settings | geoipupdate configuration options
|
| services.scrutiny.settings.web.influxdb.bucket | InfluxDB bucket in which to store data.
|
| services.sourcehut.settings."pages.sr.ht".api-origin | Origin URL for the API
|
| services.sourcehut.settings."lists.sr.ht".api-origin | Origin URL for the API
|
| services.sourcehut.settings."paste.sr.ht".api-origin | Origin URL for the API
|
| services.sabnzbd.settings.misc.https_key | Path to the TLS key for the web UI
|
| services.sourcehut.settings."sr.ht".global-domain | Global domain name.
|
| services.moosefs.metalogger.settings | Metalogger configuration options (mfsmetalogger.cfg).
|
| services.tor.settings.ServerTransportPlugin | See torrc manual.
|
| services.tor.settings.MaxClientCircuitsPending | See torrc manual.
|
| services.syncthing.settings.devices.<name>.name | The name of the device.
|
| services.readarr.settings.update.mechanism | which update mechanism to use
|
| services.matrix-conduit.settings.global.port | The port Conduit will be running on
|
| services.scrutiny.collector.settings.host.id | Host ID for identifying/labelling groups of disks
|
| services.canaille.settings.CANAILLE_LDAP | Configuration for the LDAP backend
|
| services.bluesky-pds.settings.PDS_RATE_LIMITS_ENABLED | Enable rate limiting
|
| services.acme-dns.settings.logconfig.loglevel | Level to log on.
|
| services.legit.settings.meta.description | Website description.
|
| services.botamusique.settings | Your configuration.ini as a Nix attribute set
|
| services.zigbee2mqtt.settings | Your configuration.yaml as a Nix attribute set
|
| services.postfix.settings.master.<name>.command | A program name specifying a Postfix service/daemon process
|
| services.sourcehut.settings."git.sr.ht".webhooks | The Redis connection used for the webhooks worker.
|
| services.snapserver.settings.tcp.enabled | Whether to enable the TCP JSON-RPC.
|
| services.nipap.settings.nipapd.foreground | Remain in foreground rather than forking to background.
|
| services.traefik.dynamic.files.<name>.settings | Dynamic configuration for Traefik, written in Nix.
This will be serialized to JSON (which is considered valid YAML) at build, and passed as part of the static file.
|
| services.scrutiny.settings.web.influxdb.scheme | URL scheme to use when connecting to InfluxDB.
|
| services.sourcehut.settings."pages.sr.ht".user-domain | Configures the user domain, if enabled
|
| services.clamav.fangfrisch.settings | fangfrisch configuration
|
| services.blackfire-agent.settings.server-id | Sets the server id used to authenticate with Blackfire
You can find your personal server-id at https://blackfire.io/my/settings/credentials
|
| services.tlsrpt.reportd.settings.log_level | Level of log messages to emit.
|
| services.tlsrpt.fetcher.settings.log_level | Level of log messages to emit.
|
| services.suricata.settings.stats.decoder-events | Add decode events to stats
|
| services.tsidp.settings.useLocalTailscaled | Use local tailscaled instead of tsnet.
|
| services.stash.settings.theme_color | Sets the theme-color property in the UI
|
| services.postfix-tlspol.settings.server.address | Path or address/port where postfix-tlspol binds its socket to.
|
| services.matrix-conduit.settings.global.address | Address to listen on for connections by the reverse proxy/tls terminator.
|
| services.matrix-tuwunel.settings.global.port | The port(s) tuwunel will be running on
|
| services.szurubooru.server.settings.smtp.host | Host of the SMTP server used to send reset password.
|
| services.radicle.ci.broker.settings.adapters.<name>.env | Environment variables to add when running the adapter.
|
| services.postgrest.settings.admin-server-port | Specifies the port for the admin server, which can be used for healthchecks.
https://docs.postgrest.org/en/stable/references/admin_server.html#admin-server
|
| services.scion.scion-dispatcher.settings | scion-dispatcher configuration
|
| services.postsrsd.settings.socketmap | Listener configuration in socket map format native to Postfix configuration.
|
| security.pam.u2f.settings.interactive | Set to prompt a message and wait before testing the presence of a U2F device
|
| services.tor.settings.ServerTransportPlugin.exec | Command of pluggable transport.
|
| services.syncthing.settings.folders | Folders which should be shared by Syncthing
|
| services.firezone.server.web.settings | Environment variables for this component of the Firezone server
|
| services.firezone.server.api.settings | Environment variables for this component of the Firezone server
|
| services.misskey.settings.redisForTimelines.port | The Redis port.
|
| services.misskey.settings.redisForTimelines.host | The Redis host.
|
| services.fediwall.settings.loadFederated | Load federated posts
|
| services.immich-kiosk.settings.immich_url | URL of the immich instance.
|
| services.bluesky-pds.settings.PDS_DATA_DIRECTORY | Directory to store state
|
| services.suricata.settings.vars.address-groups.HOME_NET | HOME_NET variable.
|
| services.watchdogd.settings.filenr.enabled | Whether to enable watchdogd plugin filenr.
|
| services.grafana.settings.database.host | Only applicable to MySQL or Postgres
|
| services.xonotic.settings.maxplayers | Number of player slots on the server, including spectators.
|
| services.matrix-appservice-irc.settings | Configuration for the appservice, see
https://github.com/matrix-org/matrix-appservice-irc/blob/4.0.0/config.sample.yaml
for supported values
|
| services.resolved.settings.Resolve.Domains | List of search domains used to complete unqualified name lookups.
|
| services.opengfw.settings.workers.tcpTimeout | How long a connection is considered dead when no data is being transferred
|
| services.sabnzbd.settings.misc.email_from | 'From:' field for emails (needs to be an address)
|
| services.opensnitch.settings.Stats.MaxEvents | Max events to send to the GUI.
|
| services.pretalx.settings.filesystem.data | Base path for all other storage paths.
|
| services.suricata.settings.logging.outputs.file.type | Type of logfile.
|
| services.go-csp-collector.settings.output-format | Define how the violation reports are formatted for output.
|
| services.reposilite.settings.cachedLogSize | Amount of messages stored in the cache logger.
|
| services.canaille.settings.CANAILLE_LDAP.BIND_PW | The LDAP bind password
|
| services.bitmagnet.settings.postgres.host | Address, hostname or Unix socket path of the database server
|
| services.immich.settings.server.externalDomain | Domain for publicly shared links, including http(s)://.
|
| services.matrix-synapse.settings.database.args.user | Username to connect with psycopg2, set to null
when using sqlite3.
|
| services.syncthing.settings.devices | Peers/devices which Syncthing should communicate with
|
| services.librespeed.settings | LibreSpeed configuration written as Nix expression
|
| services.sharkey.settings.mediaDirectory | Path to the folder where Sharkey stores uploaded media such as images and attachments.
|
| services.prometheus.xmpp-alerts.settings | Configuration for prometheus xmpp-alerts, see
https://github.com/jelmer/prometheus-xmpp-alerts/blob/master/xmpp-alerts.yml.example
for supported values.
|
| services.nvme-rs.settings.email.smtp_server | SMTP server address
|
| services.cryptpad.settings.websocketPort | Port for the websocket that needs to be separate
|
| services.filebrowser.settings.cache-dir | The directory where FileBrowser stores its cache.
|
| services.tor.settings.ControlPortFileGroupReadable | See torrc manual.
|
| services.reposilite.settings.enforceSsl | Whether to redirect all traffic to SSL.
|
| services.suricata.settings.threshold-file | Suricata threshold configuration file.
|
| services.tor.settings.ServerDNSDetectHijacking | See torrc manual.
|
| services.tor.settings.PaddingStatistics | See torrc manual.
|
| services.biboumi.settings.password | The password used to authenticate the XMPP component to your XMPP server
|
| services.wstunnel.clients.<name>.settings | Command line arguments to pass to wstunnel
|
| services.wstunnel.servers.<name>.settings | Command line arguments to pass to wstunnel
|
| services.mbpfan.settings.general.high_temp | If temperature is above this, fan speed will gradually increase.
|
| services.watchdogd.settings.filenr.warning | The high watermark level
|
| services.logrotate.settings.<name>.files | Single or list of files for which rules are defined
|
| services.pretalx.settings.database.backend | Database backend to use
|
| services.litellm.settings.model_list | List of supported models on the server, with model-specific configs.
|
| services.mautrix-telegram.settings | config.yaml configuration as a Nix attribute set
|
| services.canaille.settings.CANAILLE.SMTP | SMTP configuration
|
| services.watchdogd.settings.interval | The kick interval, i.e. how often watchdogd(8) should reset the WDT timer.
|
| services.sourcehut.settings."meta.sr.ht".webhooks | The Redis connection used for the webhooks worker.
|
| services.sourcehut.settings."todo.sr.ht".webhooks | The Redis connection used for the webhooks worker.
|
| services.sourcehut.settings."lists.sr.ht".oauth-client-id | lists.sr.ht's OAuth client id for meta.sr.ht.
|
| services.sourcehut.settings."pages.sr.ht".oauth-client-id | pages.sr.ht's OAuth client id for meta.sr.ht.
|
| services.sourcehut.settings."paste.sr.ht".oauth-client-id | paste.sr.ht's OAuth client id for meta.sr.ht.
|
| services.sabnzbd.settings.misc.email_full | Whether to send alerts for full disks
|
| services.snapserver.settings.http.enabled | Whether to enable the HTTP JSON-RPC.
|
| services.rke2.cisHardening | Enable CIS Hardening for RKE2
|
| services.evremap.settings.dual_role.*.tap | The key sequence that should be output when the input key is tapped
|
| services.postfix.settings.master.<name>.maxproc | The maximum number of processes to spawn for this service
|
| services.postgresql.settings | PostgreSQL configuration
|
| services.neard.settings.General.ConstantPoll | Enable constant polling
|
| services.firefox-syncserver.settings.port | Port to bind to.
|
| services.opensearch.settings."cluster.name" | The name of the cluster.
|
| services.sabnzbd.settings.servers.<name>.timeout | Time, in seconds, to wait for a response before
attempting error recovery.
|
| services.lidarr.settings.log.analyticsEnabled | Send Anonymous Usage Data
|
| services.sonarr.settings.log.analyticsEnabled | Send Anonymous Usage Data
|
| services.suricata.settings.unix-command.enabled | Enable unix-command socket.
|
| services.radarr.settings.log.analyticsEnabled | Send Anonymous Usage Data
|
| services.grafana.settings.smtp.password | Password used for authentication
|
| services.scrutiny.collector.settings.log.level | Log level for Scrutiny collector.
|
| services.anubis.instances.<name>.settings | Freeform configuration via environment variables for Anubis
|
| services.printing.cups-pdf.instances.<name>.settings | Settings for a cups-pdf instance, see the descriptions in the template config file in the cups-pdf package
|
| services.grafana.settings.server.cert_file | Path to the certificate file (if protocol is set to https or h2).
|
| services.watchdogd.settings.filenr.logmark | Whether to log current stats every poll interval.
|
| services.vmalert.settings."datasource.url" | Datasource compatible with Prometheus HTTP API.
|
| services.fediwall.settings.hideSensitive | Hide sensitive (potentially NSFW) posts
|
| services.openssh.settings.X11Forwarding | Whether to allow X11 connections to be forwarded.
|
| services.hedgedoc.settings.protocolUseSSL | Use https:// for all links
|
| services.opensnitch.settings.Server.LogFile | File to write logs to (use /dev/stdout to write logs to standard
output).
|
| services.firewalld.settings.LogDenied | Add logging rules right before reject and drop rules in the INPUT, FORWARD and OUTPUT chains for the default rules and also final reject and drop rules in zones for the configured link-layer packet type.
|
| services.waagent.settings.OS.RootDeviceScsiTimeout | Configures the SCSI timeout in seconds on the OS disk and data drives
|
| services.syncthing.settings.folders.<name>.type | Controls how the folder is handled by Syncthing
|
| services.saunafs.metalogger.settings | Contents of metalogger config file (see sfsmetalogger.cfg(5)).
|
| services.sourcehut.settings.mail.smtp-password | Outgoing SMTP password.
|
| services.libinput.mouse.accelStepScroll | Sets the step between the points of the scroll acceleration function
|
| services.gemstash.settings.base_path | Path to store the gem files and the sqlite database
|
| services.tor.settings.DirAllowPrivateAddresses | See torrc manual.
|
| services.tor.settings.AuthDirSharedRandomness | See torrc manual.
|
| services.syncthing.settings.folders.<name>.label | The label of the folder.
|
| services.tor.settings.EnforceDistinctSubnets | See torrc manual.
|
| services.pretalx.settings.filesystem.logs | Path to the log directory, that pretalx logs message to.
|
| services.misskey.settings.redisForTimelines | ioredis options for timelines
|
| services.waagent.settings.ResourceDisk.SwapSizeMB | Specifies the size of the swap file in MiB (1024×1024 bytes)
|
| services.healthchecks.settings.DB | Database engine to use.
|
| services.oncall.settings.oncall_host | FQDN for the Oncall instance.
|
| services.opensearch.settings."network.host" | Which port this service should listen on.
|
| services.gitlab.pages.settings.artifacts-server | API URL to proxy artifact requests to.
|
| services.typesense.settings.server.api-address | Address to which Typesense API service binds.
|
| services.frigate.settings.cameras.<name>.ffmpeg.inputs | List of inputs for this camera.
|
| services.sourcehut.settings."pages.sr.ht".gemini-certs | An absolute file path (which should be outside the Nix-store)
to Gemini certificates.
|
| services.reposilite.settings.sslEnabled | Whether to listen for encrypted connections on settings.sslPort.
|
| services.wgautomesh.settings.peers.*.pubkey | Wireguard public key of this peer.
|
| services.postgrest.settings.server-host | Where to bind the PostgREST web server.
The admin server will also bind here, but potentially exposes sensitive information
|
| services.spacecookie.settings.log.enable | Whether to enable logging for spacecookie.
|
| services.snapserver.settings.tcp-control.port | Port to listen on for snapclient connections.
|
| services.keycloak.settings | Configuration options corresponding to parameters set in
conf/keycloak.conf
|
| services.sourcehut.settings."builds.sr.ht".api-origin | Origin URL for the API
|
| services.postfix.settings.master.<name>.private | Whether the service's sockets and storage directory is restricted to
be only available via the mail system
|
| services.sftpgo.settings.webdavd.bindings.*.port | The port for serving WebDAV requests
|
| services.postfix.settings.main.relayhost | List of hosts to use for relaying outbound mail.
Putting the hostname in angled brackets, e.g. [relay.example.com], turns off MX and SRV lookups for the hostname.
https://www.postfix.org/postconf.5.html#relayhost
|
| services.etebase-server.settings.database.engine | The database engine to use.
|
| services.grafana-image-renderer.settings.server.addr | Listen address of the service.
|
| services.lemmy.settings.captcha.difficulty | The difficultly of the captcha to solve.
|
| services.libinput.mouse.accelStepMotion | Sets the step between the points of the (pointer) motion acceleration function
|
| services.tor.settings.DormantCanceledByStartup | See torrc manual.
|
| services.tor.settings.DoSConnectionEnabled | See torrc manual.
|
| services.tor.settings.ServerDNSAllowNonRFC953Hostnames | See torrc manual.
|
| services.tor.settings.ExtORPortCookieAuthFileGroupReadable | See torrc manual.
|
| services.spacecookie.settings.log.hide-time | If enabled, spacecookie will not print timestamps
at the beginning of every log line.
|
| services.spacecookie.settings.log.hide-ips | If enabled, spacecookie will hide personal
information of users like IP addresses from
log output.
|
| services.routinator.settings.expire | An integer value specifying the number of seconds an RTR client is requested to use a data set if it cannot get an update before throwing it away and continuing with no data at all.
|
| services.postgrest.settings.server-unix-socket | Unix domain socket where to bind the PostgREST web server.
|
| services.maubot.settings.server.public_url | Public base URL where the server is visible.
|
| services.stash.settings.stash_boxes | Stash-box facilitates automated tagging of scenes and performers based on fingerprints and filenames
|
| services.postsrsd.settings.separator | SRS tag separator used in generated sender addresses
|
| services.hostapd.radios.<name>.settings | Extra configuration options to put at the end of global initialization, before defining BSSs
|
| services.evremap.settings.dual_role.*.hold | The key sequence that should be output when the input key is held
|
| services.anuko-time-tracker.settings.emailRequired | Defines whether an email is required for new registrations.
|
| services.matrix-synapse.settings.turn_uris | The public URIs of the TURN server to give to clients
|
| services.sslh.settings.protocols | List of protocols sslh will probe for and redirect
|
| services.headscale.settings.dns.magic_dns | Whether to use MagicDNS.
|
| services.sympa.settingsFile.<name>.source | Path of the source file.
|
| services.keyd.keyboards.<name>.settings | Configuration, except ids section, that is written to /etc/keyd/.conf
|
| services.evremap.settings.dual_role.*.input | The key that should be remapped
|
| services.reposilite.settings.idleTimeout | Default idle timeout used by Jetty.
|
| services.stash.settings.stash_boxes.*.name | The name of the Stash Box
|
| services.wastebin.settings.WASTEBIN_MAX_BODY_SIZE | Number of bytes to accept for POST requests
|
| services.sslh.settings.transparent | Whether the services behind sslh (Apache, sshd and so on) will see the
external IP and ports as if the external world connected directly to
them.
|
| services.grafana.settings.users.home_page | Path to a custom home page
|
| services.libinput.touchpad.accelSpeed | Cursor acceleration (how fast speed increases from minSpeed to maxSpeed)
|
| services.inadyn.settings.custom.<name>.password | Password for this DDNS provider
|
| services.writefreely.settings.server.port | The port WriteFreely should listen on.
|
| services.grafana.settings.server.cdn_url | Specify a full HTTP URL address to the root of your Grafana CDN assets
|
| services.journald.remote.settings.Remote.SplitMode | With "host", a separate output file is used, based on the
hostname of the other endpoint of a connection
|
| services.snapserver.settings.stream.source | One or multiple URIs to PCM input streams.
|
| documentation.man.mandoc.settings | Configuration for man.conf(5)
|
| services.tor.settings.DoSCircuitCreationEnabled | See torrc manual.
|
| services.rosenpass.settings.verbosity | Verbosity of output produced by the service.
|
| services.sourcehut.settings."builds.sr.ht::worker".name | Listening address and listening port
of the build runner (with HTTP port if not 80).
|
| services.suricata.settings.app-layer.error-policy | The error-policy setting applies to all app-layer parsers
|
| services.sourcehut.settings."lists.sr.ht::worker".reject-url | Reject URL.
|
| services.litellm.settings.general_settings | LiteLLM Server settings
|
| services.litellm.settings.litellm_settings | LiteLLM Module settings
|
| services.pid-fan-controller.settings.fans.*.cutoff | Whether to stop the fan when minPwm is reached.
|
| services.lasuite-docs.settings.DJANGO_ALLOWED_HOSTS | Comma-separated list of hosts that are able to connect to the server
|
| services.lasuite-meet.settings.DJANGO_ALLOWED_HOSTS | Comma-separated list of hosts that are able to connect to the server
|
| services.szurubooru.server.settings.smtp.passFile | File containing the password associated to the given user for the SMTP server.
|
| services.sourcehut.settings."lists.sr.ht".webhooks | The Redis connection used for the webhooks worker.
|
| services.taler.merchant.settings.merchant.SERVE | Whether the HTTP server should listen on a UNIX domain socket ("unix") or on a TCP socket ("tcp").
|
| services.suricata.settings.af-xdp.*.interface | af-xdp capture interface, see upstream docs.
|
| services.opensnitch.settings.Firewall | Which firewall backend to use.
|
| services.wastebin.settings.WASTEBIN_BASE_URL | Base URL for the QR code display
|
| services.grafana.settings.server.http_addr | Listening address.
This setting intentionally varies from upstream's default to be a bit more secure by default.
|
| services.spacecookie.settings.root | The directory spacecookie should serve via gopher
|
| services.botamusique.settings.server.port | Port of the mumble server to connect to.
|
| services.botamusique.settings.server.host | Hostname of the mumble server to connect to.
|
| services.livekit.ingress.settings.rtmp_port | TCP port for RTMP connections
|
| services.livekit.ingress.settings.whip_port | TCP port for WHIP connections
|
| services.consul-template.instances.<name>.settings | Free-form settings written directly to the config.json file
|
| services.syncthing.settings | Extra configuration options for Syncthing
|
| services.scrutiny.settings.web.listen.basepath | If Scrutiny will be behind a path prefixed reverse proxy, you can override this
value to serve Scrutiny on a subpath.
|
| services.suricata.settings.pcap.*.interface | pcap capture interface, see upstream docs.
|
| services.sourcehut.settings.objects.s3-access-key | Access key to the S3-compatible object storage service
|
| services.szurubooru.server.settings.domain | Full URL to the homepage of this szurubooru site (with no trailing slash).
|
| services.suricata.settings.logging.outputs.file.level | Loglevel for logs written to the logfile.
|
| services.guacamole-client.settings | Configuration written to guacamole.properties.
The Guacamole web application uses one main configuration file called
guacamole.properties
|
| services.froide-govplan.settings.ALLOWED_HOSTS | A list of valid fully-qualified domain names (FQDNs) and/or IP
addresses that can be used to reach the Froide-Govplan service.
|
| services.nextcloud.settings.log_type | Logging backend to use.
systemd automatically adds the php-systemd extensions to services.nextcloud.phpExtraExtensions
|
| services.saunafs.metalogger.settings.DATA_PATH | Data storage directory
|
| services.prowlarr.settings.update.mechanism | which update mechanism to use
|
| services.whisparr.settings.update.mechanism | which update mechanism to use
|
| services.crowdsec.settings.simulation | Attributes inside the simulation.yaml file.
|
| services.chhoto-url.settings.slug_length | The length of auto-generated slugs.
|
| services.chhoto-url.settings.public_mode | Whether to enable public mode.
|
| services.pinnwand.settings.paste_size | Maximum size of a paste in bytes.
|
| services.sourcehut.settings."builds.sr.ht".oauth-client-id | builds.sr.ht's OAuth client id for meta.sr.ht.
|
| services.sourcehut.settings."hg.sr.ht".oauth-client-secret | hg.sr.ht's OAuth client secret for meta.sr.ht.
|
| services.watchdogd.settings.loadavg.enabled | Whether to enable watchdogd plugin loadavg.
|
| services.watchdogd.settings.meminfo.enabled | Whether to enable watchdogd plugin meminfo.
|
| services.openssh.settings.KexAlgorithms | Allowed key exchange algorithms
Uses the lower bound recommended in both
https://stribika.github.io/2015/01/04/secure-secure-shell.html
and
https://infosec.mozilla.org/guidelines/openssh#modern-openssh-67
|
| services.nezha-agent.settings.temperature | Enable temperature monitoring.
|
| services.nezha-agent.settings.disable_nat | Disable NAT penetration.
|
| services.your_spotify.settings.PORT | The port of the api server
|
| services.sourcehut.settings."builds.sr.ht".shell | Scripts used to launch on SSH connection.
/usr/bin/master-shell on master,
/usr/bin/runner-shell on runner
|
| services.privoxy.settings.filterfile | List of paths to Privoxy filter files
|
| services.forgejo.settings.session.COOKIE_SECURE | Marks session cookies as "secure" as a hint for browsers to only send
them via HTTPS
|
| services.sourcehut.settings."lists.sr.ht::worker".sock | Path for the lmtp daemon's unix socket
|
| services.vmalert.instances.<name>.settings | vmalert configuration, passed via command line flags
|
| services.bookstack.settings.DB_PASSWORD_FILE | The file containing your mysql/mariadb database password.
|
| services.rosenpass.settings.peers.*.endpoint | Endpoint of the remote Rosenpass peer.
|
| services.suricata.settings.outputs.*.<name>.enabled | Whether to enable .
|
| services.pgbouncer.settings.databases | Detailed information about PostgreSQL database definitions:
https://www.pgbouncer.org/config.html#section-databases
|
| services.headscale.settings.oidc.client_id | OpenID Connect client ID.
|
| services.tlsrpt.collectd.settings.log_level | Level of log messages to emit.
|
| services.moosefs.metalogger.settings.DATA_PATH | Directory for storing metalogger data.
|
| services.watchdogd.settings.filenr.interval | Amount of seconds between every poll.
|
| services.ferretdb.settings.FERRETDB_HANDLER | Backend handler
|
| services.buffyboard.settings.input.pointer | Enable or disable the use of a hardware mouse or other pointing device.
|
| services.parsedmarc.settings.mailbox.watch | Use the IMAP IDLE command to process messages as they arrive.
|
| services.suricata.settings.app-layer.protocols | app-layer protocols, see upstream docs.
|
| services.blackfire-agent.settings.server-token | Sets the server token used to authenticate with Blackfire
You can find your personal server-token at https://blackfire.io/my/settings/credentials
|
| services.libeufin.nexus.settings.nexus-ebics.CURRENCY | Name of the fiat currency.
|
| services.inadyn.settings.provider.<name>.hostname | Hostname alias(es).
|
| services.ferretdb.settings.FERRETDB_SQLITE_URL | SQLite URI (directory) for 'sqlite' handler
|
| services.inadyn.settings.provider.<name>.username | Username for this DDNS provider.
|
| services.mchprs.settings.max_players | Maximum number of simultaneous players
|
| services.tor.relay.onionServices.<name>.settings.RendPostPeriod | See torrc manual.
|
| services.watchdogd.settings.loadavg.warning | The high watermark level
|
| services.watchdogd.settings.meminfo.warning | The high watermark level
|
| services.reposilite.settings.debugEnabled | Whether to enable debug mode.
|
| services.tor.settings.ReachableAddresses | See torrc manual.
|
| services.sabnzbd.settings.misc.html_login | Prompt for login with an html login mask if enabled,
otherwise prompt for basic auth (useful for SSO)
|
| services.sourcehut.settings."git.sr.ht".oauth-client-secret | git.sr.ht's OAuth client secret for meta.sr.ht.
|
| services.sourcehut.settings."hub.sr.ht".oauth-client-secret | hub.sr.ht's OAuth client secret for meta.sr.ht.
|
| services.sourcehut.settings."man.sr.ht".oauth-client-secret | man.sr.ht's OAuth client secret for meta.sr.ht.
|
| services.postfix-tlspol.settings.server.prefetch | Whether to prefetch DNS records when the TTL of a cached record is about to expire.
|
| services.readarr.settings.log.analyticsEnabled | Send Anonymous Usage Data
|
| services.warpgate.settings.recordings.path | Path to store session recordings.
|
| services.watchdogd.settings.loadavg.logmark | Whether to log current stats every poll interval.
|
| services.watchdogd.settings.meminfo.logmark | Whether to log current stats every poll interval.
|
| services.healthchecks.settings.DB_NAME | Database name.
|
| services.filebrowser.settings.address | The address to listen on.
|
| services.firefly-iii.settings.DB_CONNECTION | The type of database you wish to use
|
| services.sabnzbd.settings.misc.https_cert | Path to the TLS certificate for the web UI
|
| services.postfix.settings.main.myhostname | The internet hostname of this mail system
|
| services.botamusique.settings.bot.comment | Comment displayed for the bot.
|
| services.umami.settings.DISABLE_TELEMETRY | Umami collects completely anonymous telemetry data in order help improve the application
|
| services.frigate.settings.cameras.<name>.ffmpeg.inputs.*.path | Stream URL
|
| services.openbao.settings.listener.<name>.address | The TCP address or UNIX socket path to listen on.
|
| services.suricata.settings.vars.address-groups.DNP3_SERVER | DNP3_SERVER variable.
|
| services.suricata.settings.vars.address-groups.DNP3_CLIENT | DNP3_CLIENT variable.
|
| services.buffyboard.settings.theme.default | Selects the default theme on boot
|
| services.grafana.settings.users.login_hint | Text used as placeholder text on login page for login/username input.
|
| services.slskd.settings.retention.files.complete | Lifespan of completely downloaded files in minutes.
|
| services.veilid.settings.logging.terminal.enabled | Events of type 'terminal' will be logged.
|
| services.tor.settings.ReachableORAddresses | See torrc manual.
|
| services.tor.settings.FetchHidServDescriptors | See torrc manual.
|
| services.pid-fan-controller.settings.heatSources | List of heat sources to be monitored.
|
| services.sourcehut.settings."lists.sr.ht".posting-domain | Posting domain.
|
| services.snapserver.settings.http.doc_root | Path to serve from the HTTP servers root.
|
| services.pinnwand.settings.paste_help | Raw HTML help text shown in the header area.
|
| services.routinator.settings.rtr-listen | An array of string values each providing an address and port on which the RTR server should listen in TCP mode
|
| services.opensnitch.settings.Ebpf.ModulesPath | Configure eBPF modules path
|
| services.headscale.settings.database.sqlite.path | Path to the sqlite3 database file.
|
| services.radicle.ci.broker.settings.triggers.*.filters | Trigger filter.
|
| services.radicle.ci.broker.settings.triggers.*.adapter | Adapter name.
|
| services.misskey.settings.meilisearch | Meilisearch connection options.
|
| services.transmission.settings.rpc-port | The RPC port to listen to.
|
| services.wastebin.settings.WASTEBIN_CACHE_SIZE | Number of rendered syntax highlight items to cache
|
| services.sftpgo.settings.ftpd.bindings.*.address | Network listen address
|
| services.suricata.settings.unix-command.filename | Filename for unix-command socket.
|
| services.misskey.settings.meilisearch.ssl | Whether to connect via SSL.
|
| services.matrix-synapse.settings.listeners.*.type | The type of the listener, usually http.
|
| services.your_spotify.settings | Your Spotify Configuration
|
| services.lldap.settings.ldap_user_pass | Password for default admin password
|
| services.minidlna.settings.media_dir | Directories to be scanned for media files
|
| services.sourcehut.settings."sr.ht".network-key | An absolute file path (which should be outside the Nix-store)
to a secret key to encrypt internal messages with
|
| services.lldap.settings.database_url | Database URL.
|
| services.lldap.settings.ldap_user_dn | Admin username
|
| services.stash.settings.plugins_path | Path to scrapers
|
| services.radicle.ci.broker.settings.report_dir | Directory where HTML and JSON report pages are written.
|
| services.libeufin.nexus.settings.nexus-ebics.PARTNER_ID | Partner ID of the EBICS subscriber
|
| services.acme-dns.settings.database.connection | Database connection string.
|
| services.searx.settingsFile | The path of the Searx server settings.yml file
|
| services.anuko-time-tracker.settings.weekendStartDay | This option defines which days are highlighted with weekend color.
6 means Saturday
|
| services.routinator.settings.http-listen | An array of string values each providing an address and port on which the HTTP server should listen
|
| services.gemstash.settings.db_adapter | Which database type to use
|
| services.rkvm.server.settings.certificate | TLS certificate path.
This should be generated with rkvm-certificate-gen.
|
| services.rkvm.client.settings.certificate | TLS ceritficate path.
This should be generated with rkvm-certificate-gen.
|
| services.sourcehut.settings."git.sr.ht".post-update-script | A post-update script which is installed in every git repo
|
| services.sourcehut.settings."git.sr.ht".outgoing-domain | Outgoing domain.
|
| services.sourcehut.settings."todo.sr.ht::mail".posting-domain | Posting domain.
|
| services.misskey.settings.meilisearch.host | The Meilisearch host.
|
| services.misskey.settings.meilisearch.port | The Meilisearch port.
|
| services.authelia.instances.<name>.settings.theme | The theme to display.
|
| services.tor.settings.KeyDirectoryGroupReadable | See torrc manual.
|
| services.umurmur.settings.welcometext | Welcome message for connected clients.
|
| services.tor.settings.ReachableDirAddresses | See torrc manual.
|
| services.moosefs.chunkserver.settings | Chunkserver configuration options (mfschunkserver.cfg).
|
| services.xonotic.settings.net_address | The address Xonotic will listen on.
|
| services.doh-server.settings.upstream | Upstream DNS resolver
|
| services.sourcehut.settings."todo.sr.ht".oauth-client-secret | todo.sr.ht's OAuth client secret for meta.sr.ht.
|
| services.authelia.instances.<name>.settings.log.level | Level of verbosity for logs.
|
| services.parsedmarc.settings.mailbox.delete | Delete messages after processing them, instead of archiving them.
|
| services.pretalx.settings.filesystem.static | Path to the directory that contains static files.
|
| services.headscale.settings.oidc.pkce.enabled | Enable or disable PKCE (Proof Key for Code Exchange) support
|
| services.anuko-time-tracker.settings.multiorgMode | Defines whether users see the Register option in the menu of Time Tracker that allows them
to self-register and create new organizations (top groups).
|
| services.matrix-synapse.settings.listeners.*.port | The port to listen for HTTP(S) requests on.
|
| services.matrix-synapse.settings.listeners.*.mode | File permissions on the UNIX domain socket.
|
| services.mautrix-whatsapp.settings | config.yaml configuration as a Nix attribute set
|
| services.sourcehut.settings."meta.sr.ht".welcome-emails | Whether to enable sending stock sourcehut welcome emails after signup.
|
| services.nextcloud-whiteboard-server.settings | Settings to configure backend server
|
| services.sourcehut.settings."lists.sr.ht::worker".sock-group | The lmtp daemon will make the unix socket group-read/write
for users in this group.
|
| services.geoipupdate.settings.AccountID | Your MaxMind account ID.
|
| services.healthchecks.settings.DEBUG | Enable debug mode.
|
| services.lldap.settings.ldap_base_dn | Base DN for LDAP.
|
| services.headscale.settings.prefixes.v6 | Each prefix consists of either an IPv4 or IPv6 address,
and the associated prefix length, delimited by a slash
|
| services.headscale.settings.prefixes.v4 | Each prefix consists of either an IPv4 or IPv6 address,
and the associated prefix length, delimited by a slash
|
| services.suricata.settings.logging.outputs.file.format | Logformat for logs written to the logfile.
|
| services.suricata.settings.logging.outputs.file.enable | Whether to enable logging to file.
|
| services.suricata.settings.logging.outputs.syslog.type | Type of logs send to syslog.
|
| services.sympa.settingsFile.<name>.enable | Whether this file should be generated
|
| services.grafana-image-renderer.settings.browser.path | Path to the executable of the chromium to use.
|
| services.public-inbox.settings.publicinbox | public inboxes
|
| services.minidlna.settings.wide_links | Set this to yes to allow symlinks that point outside user-defined media_dir.
|
| services.sourcehut.settings.objects.s3-secret-key | An absolute file path (which should be outside the Nix-store)
to the secret key of the S3-compatible object storage service.
|
| services.headscale.settings.database.type | Database engine to use
|
| services.misskey.settings.meilisearch.apiKey | The Meilisearch API key.
|
| services.mchprs.settings.chat_format | How to format chat message interpolating username
and message with curly braces
|
| services.biboumi.settings.identd_port | The TCP port on which to listen for identd queries.
|
| services.anuko-time-tracker.settings.email.smtpPasswordFile | Path to file containing the MTA authentication password.
|
| services.omnom.settings.activitypub.pubkey | ActivityPub public key
|
| services.suricata.settings.vars.address-groups.ENIP_CLIENT | ENIP_CLIENT variable.
|
| services.suricata.settings.vars.address-groups.ENIP_SERVER | ENIP_SERVER variable.
|
| services.syncthing.settings.folders.<name>.path | The path to the folder which should be shared
|
| services.dsnet.settings.ExternalHostname | The hostname that clients should use to connect to this server
|
| services.libinput.mouse.accelPointsScroll | Sets the points of the scroll acceleration function
|
| services.matrix-tuwunel.settings.global.address | Addresses (IPv4 or IPv6) to listen on for connections by the reverse proxy/tls terminator
|
| services.pid-fan-controller.settings.interval | Interval between controller cycles in milliseconds.
|
| services.tor.settings.ControlSocketsGroupWritable | See torrc manual.
|
| services.grafana-image-renderer.settings.service.port | The TCP port to use for the rendering server.
|
| services.firezone.server.domain.settings | Environment variables for this component of the Firezone server
|
| services.open-web-calendar.settings.ALLOWED_HOSTS | The hosts that the Open Web Calendar permits
|
| services.hercules-ci-agent.settings.labels | A key-value map of user data
|
| services.crowdsec-firewall-bouncer.settings.mode | Firewall mode to use.
|
| services.reposilite.settings.hostname | The hostname to bind to
|
| services.grafana.settings.smtp.skip_verify | Verify SSL for SMTP server.
|
| services.suwayomi-server.settings.server.localSourcePath | Path to the local source folder.
|
| services.listmonk.database.settings.smtp.*.enabled | Whether to enable this SMTP server for listmonk.
|
| services.watchdogd.settings.filenr.critical | The critical watermark level
|
| services.zeronsd.servedNetworks.<name>.settings.token | Path to a file containing the API Token for ZeroTier Central.
|
| services.archisteamfarm.bots.<name>.settings | Additional settings that are documented here.
|
| services.sabnzbd.settings.servers.<name>.priority | Priority of this servers
|
| services.sabnzbd.settings.servers.<name>.required | In case of connection failures, wait for the
server to come back online instead of skipping
it.
|
| services.sourcehut.settings."hg.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.peering-manager.settings.ALLOWED_HOSTS | A list of valid fully-qualified domain names (FQDNs) and/or IP
addresses that can be used to reach the peering manager service.
|
| services.libinput.mouse.accelPointsMotion | Sets the points of the (pointer) motion acceleration function
|
| services.easytier.instances.<name>.settings.dhcp | Automatically determine the IPv4 address of this peer based on
existing peers on network.
|
| <imports = [ pkgs.php.services.default ]>.php-fpm.settings.log_level | Error log level.
|
| services.tor.settings.DataDirectoryGroupReadable | See torrc manual.
|
| services.tor.settings.HiddenServiceNonAnonymousMode | See torrc manual.
|
| services.tor.settings.ConstrainedSockets | See torrc manual.
|
| virtualisation.cri-o.settings | Configuration for cri-o, see
https://github.com/cri-o/cri-o/blob/master/docs/crio.conf.5.md.
|
| services.slskd.settings.shares.directories | Paths to shared directories
|
| services.anubis.instances.<name>.settings.TARGET | The reverse proxy target that Anubis is protecting
|
| services.angrr.settings.temporary-root-policies | Policies for temporary GC roots(e.g. result and direnv).
|
| services.wstunnel.clients.<name>.settings.http-headers | Custom headers to send in the upgrade request
|
| services.grafana.settings.database.ssl_mode | For Postgres, use either disable, require or verify-full
|
| programs.openvpn3.netcfg.settings.systemd_resolved | Whether to use systemd-resolved integration
|
| services.sftpgo.settings.sftpd.bindings.*.address | Network listen address
|
| services.sftpgo.settings.httpd.bindings.*.address | Network listen address
|
| services.ocsinventory-agent.settings.tag | Tag for the generated inventory.
|
| services.sourcehut.settings."meta.sr.ht::billing".enabled | Whether to enable the billing system.
|
| services.omnom.settings.smtp.send_timeout | Send timeout duration in seconds.
|
| services.watchdogd.settings.loadavg.interval | Amount of seconds between every poll.
|
| services.watchdogd.settings.meminfo.interval | Amount of seconds between every poll.
|
| services.grafana.settings.server.root_url | This is the full URL used to access Grafana from a web browser
|
| services.sabnzbd.settings.servers.<name>.optional | In case of connection failures, temporarily
disable this server. (See sabnzbd's documentation
for usage guides).
|
| services.frigate.settings.cameras.<name>.ffmpeg.inputs.*.roles | List of roles for this stream
|
| services.maubot.settings.homeservers.<name>.url | Client-server API URL
|
| services.homebridge.settings.platforms | Homebridge Platforms
|
| services.postfix.settings.main.mynetworks | List of trusted remote SMTP clients, that are allowed to relay mail
|
| services.waagent.settings.ResourceDisk.EnableSwap | If enabled, the agent creates a swap file (/swapfile) on the resource disk
and adds it to the system swap space
|
| services.cryptpad.settings.blockDailyCheck | Disable telemetry
|
| services.suricata.settings.vars.address-groups.DC_SERVERS | DC_SERVERS variable.
|
| services.reposilite.settings.database | Database connection string
|
| services.sourcehut.settings."git.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.sourcehut.settings."man.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.sourcehut.settings."hub.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.hickory-dns.settings.listen_port | Port to listen on (applies to all listen addresses).
|
| services.transmission.settings.peer-port | The peer port to listen for incoming connections.
|
| services.anubis.defaultOptions.settings.POLICY_FNAME | The policy file to use
|
| services.pretix.settings.memcached.location | The host:port combination or the path to the UNIX socket of a memcached instance
|
| services.pds.settings.PDS_BLOBSTORE_DISK_LOCATION | Store blobs at this location, set to null to use e.g
|
| services.umurmur.settings.certificate | Path to your SSL certificate
|
| services.umurmur.settings.private_key | Path to your SSL key
|
| services.saunafs.chunkserver.settings | Contents of chunkserver config file (see sfschunkserver.cfg(5)).
|
| services.misskey.settings.meilisearch.scope | The search scope.
|
| services.routinator.settings.refresh | An integer value specifying the number of seconds Routinator should wait between consecutive validation runs in server mode
|
| services.waagent.settings.ResourceDisk.MountPoint | This option specifies the path at which the resource disk is mounted
|
| services.logrotate.settings.<name>.priority | Order of this logrotate block in relation to the others
|
| services.sourcehut.settings."lists.sr.ht".oauth-client-secret | lists.sr.ht's OAuth client secret for meta.sr.ht.
|
| services.sourcehut.settings."paste.sr.ht".oauth-client-secret | paste.sr.ht's OAuth client secret for meta.sr.ht.
|
| services.sourcehut.settings."pages.sr.ht".oauth-client-secret | pages.sr.ht's OAuth client secret for meta.sr.ht.
|
| programs.clash-verge.tunMode | Whether to enable Setcap for TUN Mode
|
| services.tor.settings.ExtendAllowPrivateAddresses | See torrc manual.
|
| services.firefly-iii-data-importer.settings | Options for firefly-iii data importer configuration
|
| services.matrix-synapse.settings.listeners.*.tls | Whether to enable TLS on the listener socket.
This option will be ignored for UNIX domain sockets.
|
| services.hercules-ci-agent.settings.baseDirectory | State directory (secrets, work directory, etc) for agent
|
| services.hercules-ci-agent.settings.secretsJsonPath | Path to a JSON file containing secrets for effects
|
| services.sabnzbd.secretFiles | Path to a list of ini file containing confidential settings such as credentials
|
| services.wastebin.settings.WASTEBIN_ADDRESS_PORT | Address and port to bind to
|
| services.printing.cups-pdf.instances.<name>.settings.Spool | spool directory
|
| services.stash.settings.stash_boxes.*.apikey | Stash Box API key
|
| services.suricata.settings.unix-command | Unix command socket that can be used to pass commands to Suricata
|
| services.nitter.preferences.hideBanner | Hide profile banner.
|
| services.vmalert.instances.<name>.settings.rule | Path to the files with alerting and/or recording rules.
|
| services.misskey.settings.meilisearch.index | Meilisearch index to use.
|
| hardware.nvidia-container-toolkit.mounts | Mounts to be added to every container under the Nvidia CDI profile.
|
| services.suricata.settings.vars.address-groups.AIM_SERVERS | AIM_SERVERS variable.
|
| services.suricata.settings.vars.address-groups.DNS_SERVERS | DNS_SERVERS variable.
|
| services.suricata.settings.vars.address-groups.SQL_SERVERS | SQL_SERVERS variable.
|
| services.radicle.ci.broker.settings.adapters.<name>.command | Adapter command to run.
|
| services.pid-fan-controller.settings.heatSources.*.name | Name of the heat source.
|
| services.szurubooru.server.settings.secretFile | File containing a secret used to salt the users' password hashes and generate filenames for static content.
|
| services.reposilite.settings.keyPath | Path to the .jsk KeyStore or paths to the PKCS#8 certificate and private key, separated by a space (see example)
|
| services.authelia.instances.<name>.settings.log.format | Format the logs are written as.
|
| services.kanidm.server.settings.bindaddress | Address/port combination the webserver binds to.
|
| services.headscale.settings.server_url | The url clients will connect to.
|
| services.tor.settings.HiddenServiceStatistics | See torrc manual.
|
| services.tor.settings.PublishServerDescriptor | See torrc manual.
|
| services.tor.settings.FetchServerDescriptors | See torrc manual.
|
| services.suricata.settings.reference-config-file | Suricata reference configuration file.
|
| services.libeufin.nexus.settings.nexus-ebics.BANK_PUBLIC_KEYS_FILE | Filesystem location where Nexus should store the bank public keys.
|
| services.public-inbox.settings.publicinbox.css | The local path name of a CSS file for the PSGI web interface.
|
| services.opensnitch.settings.Server.Address | Unix socket path (unix:///tmp/osui.sock, the "unix:///" part is
mandatory) or TCP socket (192.168.1.100:50051).
|
| services.pocket-id.settings.ANALYTICS_DISABLED | Whether to disable analytics
|
| services.zeronsd.servedNetworks.<name>.settings.domain | Domain under which ZeroTier records will be available.
|
| services.yggdrasil.settings.PrivateKeyPath | Path to the private key file on the host system
|
| services.suwayomi-server.settings.server.downloadAsCbz | Download chapters as .cbz files.
|
| services.prowlarr.settings.log.analyticsEnabled | Send Anonymous Usage Data
|
| services.whisparr.settings.log.analyticsEnabled | Send Anonymous Usage Data
|
| services.languagetool.settings.cacheSize | Number of sentences cached.
|
| services.maubot.settings.api_features | API feature switches.
|
| services.easytier.instances.<name>.settings.peers | Peers to connect initially
|
| services.canaille.settings.CANAILLE.SMTP.PASSWORD | SMTP Password
|
| services.wgautomesh.settings.peers.*.address | Wireguard address of this peer (a single IP address, multiple
addresses or address ranges are not supported).
|
| services.yggdrasil.settings.AllowedPublicKeys | List of peer public keys to allow incoming peering connections from
|
| services.transmission.settings.watch-dir | Watch a directory for torrent files and add them to transmission.
|
| services.botamusique.settings.bot.username | Name the bot should appear with.
|
| services.bitmagnet.settings.dht_server.port | DHT listen port
|
| services.tlsrpt.collectd.settings.socketmode | Permissions on the UNIX socket.
|
| services.szurubooru.server.settings.data_dir | Path to the static files.
|
| services.postfix.settings.master.<name>.privileged | |
| services.epgstation.settings.socketioPort | Socket.io port for EPGStation to listen on
|
| services.sourcehut.settings.objects.s3-upstream | Configure the S3-compatible object storage service.
|
| services.sourcehut.settings."meta.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.sourcehut.settings."todo.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.canaille.settings.PREFERRED_URL_SCHEME | The url scheme by which canaille will be served.
|
| services.opensnitch.settings.DefaultAction | Default action whether to block or allow application internet
access.
|
| services.swapspace.settings.cooldown | Duration (roughly in seconds) of the moratorium on swap allocation that is instated if disk space runs out, or the cooldown time after a new swapfile is successfully allocated before swapspace will consider deallocating swap space again
|
| services.sourcehut.settings."builds.sr.ht::worker".timeout | Max build duration
|
| services.canaille.settings.CANAILLE_OIDC.JWT.PRIVATE_KEY | JWT private key
|
| services.tor.settings.CacheDirectoryGroupReadable | See torrc manual.
|
| nix.settings.trusted-substituters | List of binary cache URLs that non-root users can use (in
addition to those specified using
nix.settings.substituters) by passing
--option binary-caches to Nix commands.
|
| services.libeufin.nexus.settings.nexus-ebics.BANK_DIALECT | Name of the following combination: EBICS version and ISO20022
recommendations that Nexus would honor in the communication with the
bank
|
| services.fastnetmon-advanced.traffic_db.settings | Additional settings for /etc/fastnetmon/traffic_db.conf
|
| services.schleuder.settings.keyserver | Key server from which to fetch and update keys
|
| services.szurubooru.server.settings.data_url | Full URL to the data endpoint.
|
| services.warpgate.settings.recordings.enable | Whether to enable session recording.
|
| services.matrix-appservice-irc.settings.ircService | IRC bridge configuration
|
| services.hercules-ci-agent.settings.workDirectory | The directory in which temporary subdirectories are created for task state
|
| services.bonsaid.settings.*.event_name | Name of the event which should trigger this transition when received by bonsaid
|
| services.hardware.openrgb.startupProfile | The profile file to load from "/var/lib/OpenRGB" at startup.
|
| services.mackerel-agent.settings.diagnostic | Whether to enable collecting memory usage for the agent itself.
|
| services.suricata.settings.vars.address-groups.SMTP_SERVERS | SMTP_SERVERS variable.
|
| services.suricata.settings.vars.address-groups.HTTP_SERVERS | HTTP_SERVERS variable.
|
| services.kanidm.unix.settings.hsm_pin_path | Path to a HSM pin.
|
| services.nebula-lighthouse-service.settings | Configuration for nebula-lighthouse-service.
|
| services.sourcehut.settings.mail.pgp-privkey | An absolute file path (which should be outside the Nix-store)
to an OpenPGP private key
|
| services.firezone.server.settingsSecret | This is a convenience option which allows you to set secret values for
environment variables by specifying a file which will contain the value
at runtime
|
| services.omnom.settings.activitypub.privkey | ActivityPub private key
|
| services.anubis.defaultOptions.settings.SERVE_ROBOTS_TXT | Whether to serve a default robots.txt that denies access to common AI bots by name and all other
bots by wildcard.
|
| services.postfix.settings.main.smtp_tls_CAfile | File containing CA certificates of root CAs trusted to sign either remote SMTP server certificates or intermediate CA certificates
|
| services.waagent.settings.ResourceDisk.FileSystem | The file system type for the resource disk
|
| services.parsedmarc.settings.imap.password | The IMAP server password
|
| services.parsedmarc.settings.smtp.password | The SMTP server password
|
| services.printing.cups-pdf.instances.<name>.settings.Out | output directory;
${HOME} will be expanded to the user's home directory,
${USER} will be expanded to the user name.
|
| services.szurubooru.server.settings.show_sql | Whether to show SQL in server logs.
|
| services.tlsrpt.collectd.settings.socketname | Path at which the UNIX socket will be created.
|
| services.dendrite.settings.sync_api.search.enabled | Whether to enable Dendrite's full-text search engine.
|
| services.tinc.networks.<name>.hostSettings.<name>.settings | Configuration for this host
|
| services.filebrowser.settings.database | The path to FileBrowser's Bolt database.
|
| services.opensnitch.settings.ProcMonitorMethod | Which process monitoring method to use.
|
| services.anubis.defaultOptions.settings.BIND_NETWORK | The network family that Anubis should bind to
|
| services.filesender.settings.site_url | Site URL
|
| services.easytier.instances.<name>.settings.ipv4 | IPv4 cidr address of this peer in the virtual network
|
| services.saunafs.chunkserver.settings.DATA_PATH | Directory for chunck meta data
|
| services.oncall.settings.db.conn.require_auth | Whether authentication is required to access the web app.
|
| services.maubot.settings.homeservers | Known homeservers
|
| services.healthchecks.settingsFile | Environment variables which are read by healthchecks (local)_settings.py
|
| services.reposilite.settings.ioThreadPool | The IO thread pool handles all tasks that may benefit from non-blocking IO. (min: 2)
Because most tasks are redirected to IO thread pool, it might be a good idea to keep it at least equal to web thread pool.
|
| services.ocsinventory-agent.settings.ca | Path to CA certificates file in PEM format, for server
SSL certificate validation.
|
| services.suricata.settings.stats.decoder-events-prefix | Decoder event prefix in stats
|
| services.watchdogd.settings.loadavg.critical | The critical watermark level
|
| services.watchdogd.settings.meminfo.critical | The critical watermark level
|
| services.evremap.settings.device_name | The name of the device that should be remapped
|
| services.privoxy.settings.actionsfile | List of paths to Privoxy action files
|
| services.libinput.mouse.accelStepFallback | Sets the step between the points of the fallback acceleration function
|
| services.syncthing.settings.folders.<name>.enable | Whether to share this folder
|
| services.prometheus.exporters.ping.settings | Configuration for ping_exporter, see
https://github.com/czerwonk/ping_exporter
for supported values.
|
| services.waagent.settings.AutoUpdate.UpdateToLatestVersion | Whether or not to enable auto-update of the Extension Handler.
|
| services.hercules-ci-agent.settings.binaryCachesPath | Path to a JSON file containing binary cache secret keys
|
| services.reposilite.settings.webThreadPool | Maximum amount of threads used by the core thread pool. (min: 5)
The web thread pool handles the first few steps of incoming HTTP connections, tasks are redirected as soon as possible to the IO thread pool.
|
| services.suricata.settings.af-packet.*.interface | af-packet capture interface, see upstream docs reagrding tuning.
|
| services.suricata.settings.logging.outputs.syslog.format | Logformat for logs send to syslog.
|
| services.suricata.settings.logging.outputs.syslog.enable | Whether to enable logging to syslog.
|
| services.gitlab.pages.settings.internal-gitlab-server | Internal GitLab server used for API requests, useful
if you want to send that traffic over an internal load
balancer
|
| services.sourcehut.settings."builds.sr.ht".oauth-client-secret | builds.sr.ht's OAuth client secret for meta.sr.ht.
|
| services.moosefs.chunkserver.settings.DATA_PATH | Directory for lock files and other runtime data.
|
| services.snapserver.settings.tcp-control.enabled | Whether to enable the TCP JSON-RPC.
|
| services.inadyn.settings.provider.<name>.password | Password for this DDNS provider
|
| services.firewalld.settings.CleanupModulesOnExit | Whether to unload all firewall-related kernel modules when firewalld stops.
|
| services.tor.settings.AuthDirHasIPv6Connectivity | See torrc manual.
|
| services.journald.upload.settings.Upload.ServerKeyFile | SSL key in PEM format
|
| services.taler.exchange.settings.exchange.CURRENCY | The currency which the exchange will operate with
|
| services.snapserver.settings.tcp-streaming.port | Port to listen on for snapclient connections.
|
| services.warpgate.settings.http.certificate | Path to HTTPS listener certificate.
|
| services.listmonk.database.settings.smtp.*.tls_type | Type of TLS authentication with the SMTP server
|
| programs.openvpn3.log-service.settings.log_dbus_details | Add D-Bus details in log file/syslog
|
| services.epgstation.settings.mirakurunPath | URL to connect to Mirakurun.
|
| services.opensearch.settings."discovery.type" | The type of discovery to use.
|
| services.suricata.settings.vars.address-groups.MODBUS_CLIENT | MODBUS_CLIENT variable
|
| services.suricata.settings.vars.address-groups.MODBUS_SERVER | MODBUS_SERVER variable.
|
| services.authelia.instances.<name>.settings | Your Authelia config.yml as a Nix attribute set
|
| services.bitmagnet.settings.postgres.password | Password for database user
|
| services.sourcehut.settings."git.sr.ht::api".internal-ipnet | Set of IP subnets which are permitted to utilize internal API
authentication
|
| services.immichframe.settings.Accounts | Accounts configuration, multiple are permitted
|
| services.mautrix-meta.instances.<name>.settings | config.yaml configuration as a Nix attribute set
|
| services.sourcehut.settings."pages.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.sourcehut.settings."lists.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.sourcehut.settings."paste.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.wastebin.settings.WASTEBIN_HTTP_TIMEOUT | Maximum number of seconds a request can be processed until wastebin responds with 408
|
| services.slskd.settings.global.upload.speed_limit | Total upload speed limit.
|
| virtualisation.podman.defaultNetwork.settings | Settings for podman's default network.
|
| services.wstunnel.servers.<name>.settings.restrict-to.*.port | The port.
|
| services.wstunnel.servers.<name>.settings.restrict-to.*.host | The hostname.
|
| services.suricata.settings.dpdk.interfaces | See upstream docs: docs/capture-hardware/dpdk and docs/configuration/suricata-yaml.html#data-plane-development-kit-dpdk.
|
| services.opengfw.settings.workers.tcpMaxBufferedPagesTotal | TCP max total buffered pages.
|
| services.quickwit.settings.rest.listen_port | The port to listen on for HTTP REST traffic.
|
| services.garage.settings.metadata_dir | The metadata directory, put this on a fast disk (e.g
|
| services.opensnitch.settings.Audit.AudispSocketPath | Configure audit socket path
|
| services.glitchtip.settings.GLITCHTIP_DOMAIN | The URL under which GlitchTip is externally reachable.
|
| services.homebridge.settings.platforms.*.name | Name of the platform
|
| services.tor.settings.PublishHidServDescriptors | See torrc manual.
|
| services.tor.settings.MaxAdvertisedBandwidth | See torrc manual.
|
| services.opensearch.settings."transport.port" | The port to listen on for transport traffic.
|
| services.ocsinventory-agent.settings.debug | Whether to enable debug mode.
|
| services.amule.settings.ExternalConnect.ECPassword | MD5 hash of the password, obtainaible with echo "<password>" | md5sum | cut -d ' ' -f 1
|
| services.sabnzbd.settings.misc.cache_limit | Size of the RAM cache, in bytes (prefixes supported)
|
| services.anubis.instances.<name>.settings.POLICY_FNAME | The policy file to use
|
| services.printing.cups-pdf.instances.<name>.settings.AnonDirName | path for anonymously created PDF files
|
| services.opengfw.settings.workers.tcpMaxBufferedPagesPerConn | TCP max total bufferd pages per connection.
|
| services.headscale.settings.database.postgres.user | Database user.
|
| services.headscale.settings.database.postgres.name | Database name.
|
| services.epgstation.settings.encodeProcessNum | The maximum number of processes that EPGStation would allow to run
at the same time for encoding or streaming videos.
|
| services.matrix-synapse.settings.presence.enabled | Whether to enable presence tracking
|
| services.waagent.settings.ResourceDisk.MountOptions | This option specifies disk mount options to be passed to the mount -o command
|
| services.suricata.settings.logging.default-log-level | The default log level: can be overridden in an output section
|
| services.mautrix-discord.settings.homeserver | fullDataDiration
|
| services.vault-agent.instances.<name>.settings.pid_file | Path to use for the pid file.
|
| virtualisation.xen.store.settings.pidFile | Path to the Xen Store Daemon PID file.
|
| services.matrix-appservice-irc.settings.database | Configuration for the database
|
| services.tinyproxy.settings.Anonymous | If an Anonymous keyword is present, then anonymous proxying is enabled
|
| services.hddfancontrol.settings | Parameter-sets for each instance of hddfancontrol.
|
| services.fastnetmon-advanced.settings | Extra configuration options to declaratively load into FastNetMon Advanced
|
| services.etebase-server.settings.global.media_root | The media directory.
|
| security.googleOsLogin.enable | Whether to enable Google OS Login
|
| services.draupnir.settings.homeserverUrl | Base URL of the Matrix homeserver that provides the Client-Server API.
|
| services.minidlna.settings.enable_tivo | Support for streaming .jpg and .mp3 files to a TiVo supporting HMO.
|
| services.headscale.settings.database.postgres.host | Database host address.
|
| services.headscale.settings.database.postgres.port | Database host port.
|
| services.tor.settings.FetchUselessDescriptors | See torrc manual.
|
| services.scrutiny.collector.settings.api.endpoint | Scrutiny app API endpoint for sending metrics to.
|
| services.swapspace.settings.freetarget | Percentage of free space swapspace should aim for when adding swapspace
|
| virtualisation.xen.store.settings | The OCaml-based Xen Store Daemon configuration
|
| services.wgautomesh.settings.interface | Wireguard interface to manage (it is NOT created by wgautomesh, you
should use another NixOS option to create it such as
networking.wireguard.interfaces.wg0 = {...};).
|
| services.wgautomesh.settings.peers.*.endpoint | Bootstrap endpoint for connecting to this Wireguard peer if no
other address is known or none are working.
|
| services.suricata.settings.logging.outputs.file.filename | Filename of the logfile.
|
| services.mautrix-discord.settings.appservice | Appservice configuration
|
| services.suricata.settings.vars.address-groups.EXTERNAL_NET | EXTERNAL_NET variable.
|
| services.grafana.settings.security.admin_user | Default admin username.
|
| services.sourcehut.settings."meta.sr.ht::api".internal-ipnet | Set of IP subnets which are permitted to utilize internal API
authentication
|
| services.anuko-time-tracker.settings.defaultCurrency | Defines a default currency symbol for new groups
|
| services.logrotate.settings.<name>.frequency | How often to rotate the logs
|
| services.anubis.instances.<name>.settings.BIND | The address that Anubis listens to
|
| services.waagent.settings.ResourceDisk.Format | If set to true, waagent formats and mounts the resource disk that the platform provides,
unless the file system type in `ResourceDisk
|
| services.tor.settings.ExitPolicyRejectLocalInterfaces | See torrc manual.
|
| services.tor.settings.ConnDirectionStatistics | See torrc manual.
|
| services.slskd.settings.soulseek.description | The user description for the Soulseek network.
|
| services.slskd.settings.soulseek.listen_port | The port on which to listen for incoming connections.
|
| services.warpgate.settings.mysql.certificate | Path to MySQL listener certificate.
|
| services.globalprotect.settings | GlobalProtect-openconnect configuration
|
| services.reposilite.settings.keyPassword | Plaintext password used to unlock the Java KeyStore set in services.reposilite.settings.keyPath
|
| services.dependency-track.settings."alpine.oidc.client.id" | Defines the client ID to be used for OpenID Connect
|
| services.geoipupdate.settings.EditionIDs | List of database edition IDs
|
| services.keycloak.settings.http-relative-path | The path relative to / for serving
resources.
In versions of Keycloak using Wildfly (<17),
this defaulted to /auth
|
| services.syncthing.settings.options.relaysEnabled | When true, relays will be connected to and potentially used for device to device connections.
|
| services.stash.settings.scrapers_path | Path to scrapers
|
| services.stash.settings.blobs_storage | Where to store blobs
|
| services.matrix-synapse.settings.listeners | List of ports that Synapse should listen on, their purpose and their configuration
|
| services.pid-fan-controller.settings.heatSources.*.pidParams.P | K_p of PID controller.
|
| services.pid-fan-controller.settings.heatSources.*.pidParams.D | K_d of PID controller.
|
| services.pid-fan-controller.settings.heatSources.*.pidParams.I | K_i of PID controller.
|
| virtualisation.xen.store.settings.quota.maxSize | Size limit for transactions.
|
| services.sourcehut.settings."builds.sr.ht::worker".bind-address | HTTP bind address for serving local build information/monitoring.
|
| services.stash.settings.stash.*.excludevideo | Whether to exclude video files from being scanned into Stash
|
| services.stash.settings.stash.*.excludeimage | Whether to exclude image files from being scanned into Stash
|
| services.kerberos_server.settings | Settings for the kerberos server of choice
|
| services.tor.settings.GuardfractionFile | See torrc manual.
|
| services.suricata.settings.logging.default-log-format | The default output format
|
| services.grafana.settings.smtp.from_address | Address used when sending out emails.
|
| services.crowdsec.settings.lapi.credentialsFile | The LAPI credential file to use.
|
| services.crowdsec.settings.capi.credentialsFile | The CAPI credential file to use.
|
| services.sftpgo.settings.webdavd.bindings.*.address | Network listen address
|
| services.libinput.touchpad.accelStepScroll | Sets the step between the points of the scroll acceleration function
|
| services.anubis.instances.<name>.settings.SERVE_ROBOTS_TXT | Whether to serve a default robots.txt that denies access to common AI bots by name and all other
bots by wildcard.
|
| services.rosenpass.settings.public_key | Path to a file containing the public key of the local Rosenpass peer
|
| services.rosenpass.settings.secret_key | Path to a file containing the secret key of the local Rosenpass peer
|
| services.geoipupdate.settings.LicenseKey | A file containing the MaxMind license key
|
| services.hickory-dns.settings.zones.*.zone_type | One of:
- "Primary" (the master, authority for the zone).
- "Secondary" (the slave, replicated from the primary).
- "External" (a cached zone that queries other nameservers)
|
| services.suricata.settings.logging.outputs.console.enable | Whether to enable logging to console.
|
| services.vault-agent.instances.<name>.settings.template | Template section of vault-agent
|
| services.ocsinventory-agent.settings | Configuration for /etc/ocsinventory-agent/ocsinventory-agent.cfg
|
| services.sourcehut.settings."builds.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.sourcehut.settings."meta.sr.ht::billing".stripe-public-key | Public key for Stripe
|
| services.suwayomi-server.settings.server.systemTrayEnabled | Whether to enable a system tray icon, if possible.
|
| virtualisation.xen.store.settings.quota.maxPath | Path limit for the quota system.
|
| services.tlsrpt.reportd.settings.http_script | Call to an HTTPS client, that accepts the URL on the commandline and the request body from stdin.
|
| services.anubis.instances.<name>.settings.BIND_NETWORK | The network family that Anubis should bind to
|
| services.taler.exchange.settings.exchange.MASTER_PUBLIC_KEY | Used by the exchange to verify information signed by the offline system.
|
| services.suricata.settings.outputs | Configure the type of alert (and other) logging you would like
|
| services.matrix-synapse.settings.database.args.database | Name of the database when using the psycopg2 backend,
path to the database location when using sqlite3.
|
| services.nezha-agent.settings.report_delay | The interval between system status reportings
|
| services.sabnzbd.settings.misc.enable_https | Whether to enable HTTPS for the web UI
|
| services.sabnzbd.settings.misc.email_server | SMTP server for email alerts (server:host)
|
| services.grafana.provision.alerting.rules.settings | Grafana rules configuration in Nix
|
| systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.mode | The file access mode to use when creating this file or directory.
|
| services.sourcehut.settings."sr.ht".service-key | An absolute file path (which should be outside the Nix-store)
to a key used for encrypting session cookies
|
| services.matrix-synapse.settings.listeners.*.path | Unix domain socket path to bind this listener to.
|
| services.suwayomi-server.settings.server.basicAuthUsername | The username value that you have to provide when authenticating.
|
| services.stash.settings.preview_audio | Include audio stream in previews
|
| services.suricata.settings.vars.address-groups.TELNET_SERVERS | TELNET_SERVERS variable.
|
| services.libinput.touchpad.accelStepMotion | Sets the step between the points of the (pointer) motion acceleration function
|
| system.build.separateActivationScript | A separate activation script package that's not part of the system profile
|
| services.maubot.settings.server.ui_base_path | The base path for the UI.
|
| services.sourcehut.settings."pages.sr.ht::api".internal-ipnet | Set of IP subnets which are permitted to utilize internal API
authentication
|
| services.netbird.server.dashboard.settings | An attribute set that will be used to substitute variables when building the dashboard
|
| services.angrr.settings.temporary-root-policies.<name>.ignore-prefixes | List of path prefixes to ignore
|
| services.spacecookie.settings.hostname | The hostname the service is reachable via
|
| services.firewalld.settings.NftablesCounters | Whether to add a counter to every nftables rule.
|
| services.gitea-actions-runner.instances.<name>.settings | Configuration for act_runner daemon
|
| services.matrix-continuwuity.settings | Generates the continuwuity.toml configuration file
|
| services.grafana.settings.database.password | The database user's password (not applicable for sqlite3)
|
| services.nvme-rs.settings.email.smtp_username | SMTP username
|
| services.grafana.settings.database.cache_mode | For sqlite3 only.
Shared cache setting used for connecting to the database.
|
| services.nextcloud-spreed-signaling.settings.mcu.type | The type of MCU to use
|
| services.wastebin.settings.WASTEBIN_DATABASE_PATH | Path to the sqlite3 database file
|
| services.suwayomi-server.settings.server.basicAuthEnabled | Whether to enable basic access authentication for Suwayomi-Server
|
| services.moosefs.cgiserver.settings.GUISERV_LISTEN_PORT | Port for GUI server to listen on.
|
| services.draupnir.settings.rawHomeserverUrl | Public base URL of the Matrix homeserver that provides the Client-Server API when using the Draupnir's
Report forwarding feature.
When using Pantalaimon, do not set this to the Pantalaimon URL!
|
| services.tor.settings.ClientRejectInternalAddresses | See torrc manual.
|
| services.slskd.settings.retention.files.incomplete | Lifespan of incomplete downloading files in minutes.
|
| services.nextcloud-spreed-signaling.settings | Declarative configuration
|
| services.crab-hole.settings.blocklist.allow_list | List of allowlists
|
| documentation.man.mandoc.settings.output.style | Path to the file used for an external style-sheet
|
| networking.networkmanager.settings | Configuration added to the generated NetworkManager.conf, note that you can overwrite settings with this
|
| services.waagent.settings.Provisioning.Agent | Which provisioning agent to use.
|
| services.invoiceplane.sites.<name>.settings | Structural InvoicePlane configuration
|
| services.crowdsec-firewall-bouncer.settings.api_url | URL of the local API.
|
| services.libinput.mouse.accelPointsFallback | Sets the points of the fallback acceleration function
|
| services.adguardhome.settings | AdGuard Home configuration
|
| services.suricata.settings.pcap-file.checksum-checks | Possible values are:
- yes: checksum validation is forced
- no: checksum validation is disabled
- auto: Suricata uses a statistical approach to detect when
checksum off-loading is used. (default)
Warning: 'checksum-validation' must be set to yes to have checksum tested.
|
| services.grafana-image-renderer.settings.rendering.args | List of CLI flags passed to chromium.
|
| services.healthchecks.settings.SECRET_KEY_FILE | Path to a file containing the secret key.
|
| services.bitmagnet.settings.http_server.port | HTTP server listen port
|
| services.tor.settings.DoSRefuseSingleHopClientRendezvous | See torrc manual.
|
| documentation.man.mandoc.settings.output.toc | Whether to enable printing a table of contents near the beginning of the HTML output
of mandoc(1) if an input file contains at least two
non-standard sections
.
|
| services.dependency-track.settings."alpine.ldap.enabled" | Defines if LDAP will be used for user authentication
|
| services.ferretdb.settings.FERRETDB_TELEMETRY | Enable or disable basic telemetry
|
| services.transmission.settings.utp-enabled | Whether to enable Micro Transport Protocol (µTP).
|
| services.stash.settings.calculate_md5 | Whether to calculate MD5 checksums for scene video files
|
| services.grafana.settings.server.socket_mode | Mode where the socket should be set when protocol=socket
|
| services.moosefs.cgiserver.settings.GUISERV_LISTEN_HOST | IP address to bind GUI server to (* means any).
|
| services.pretix.settings.pretix.registration | Whether to allow registration of new admin users.
|
| services.syncthing.settings.options.localAnnouncePort | The port on which to listen and send IPv4 broadcast announcements to.
|
| services.reposilite.settings.defaultFrontend | Whether to enable the default included frontend with a dashboard.
|
| services.dependency-track.settings."alpine.database.url" | Specifies the JDBC URL to use when connecting to the database.
|
| services.pretalx.settings.files.upload_limit | Maximum file upload size in MiB.
|
| services.printing.cups-pdf.instances.<name>.settings.GhostScript | location of GhostScript binary
|
| services.listmonk.database.settings.smtp.*.max_conns | Maximum number of simultaneous connections, defaults to 1
|
| services.routinator.settings.repository-dir | The path where the collected RPKI data is stored.
|
| services.dependency-track.settings."alpine.oidc.enabled" | Defines if OpenID Connect will be used for user authentication
|
| services.sourcehut.settings."hg.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.dendrite.settings.media_api.base_path | Storage path for uploaded media.
|
| virtualisation.xen.store.settings.quota.maxWatch | Maximum number of watches by the Xenstore Watchdog.
|
| services.wstunnel.servers.<name>.settings.restrict-to | Restrictions on the connections that the server will accept
|
| services.transmission.settings.umask | Sets transmission's file mode creation mask
|
| services.tor.settings.ClientDNSRejectInternalAddresses | See torrc manual.
|
| services.tor.settings.DisableDebuggerAttachment | See torrc manual.
|
| services.tor.settings.DormantTimeoutDisabledByIdleStreams | See torrc manual.
|
| services.libeufin.bank.settings.libeufin-bank.CURRENCY | The currency under which the libeufin-bank should operate
|
| services.suricata.settings.logging.default-output-filter | A regex to filter output
|
| services.pid-fan-controller.settings.fans.*.heatPressureSrcs | Heat pressure sources affected by the fan.
|
| services.stash.settings.stash_boxes.*.endpoint | URL to the Stash Box graphql api
|
| services.grafana.settings.server.socket_gid | GID where the socket should be set when protocol=socket
|
| services.libeufin.nexus.settings.nexus-ebics.CLIENT_PRIVATE_KEYS_FILE | Filesystem location where Nexus should store the subscriber private keys.
|
| services.rosenpass.settings.peers.*.public_key | Path to a file containing the public key of the remote Rosenpass peer.
|
| services.sourcehut.settings."meta.sr.ht::billing".stripe-secret-key | An absolute file path (which should be outside the Nix-store)
to a secret key for Stripe
|
| services.suricata.settings.logging.outputs.syslog.facility | Facility to log to.
|
| services.grafana.provision.alerting.rules.settings.groups | List of rule groups to import or update.
|
| services.suwayomi-server.settings.server.extensionRepos | URL of repositories from which the extensions can be installed.
|
| services.syncthing.settings.folders.<name>.devices | The devices this folder should be shared with
|
| services.ocsinventory-agent.settings.local | If specified, the OCS Inventory Agent will run in offline mode
and the resulting inventory file will be stored in the specified path.
|
| services.sourcehut.settings."hub.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.sourcehut.settings."git.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.sourcehut.settings."man.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.dependency-track.settings."alpine.oidc.issuer" | Defines the issuer URL to be used for OpenID Connect
|
| services.zeronsd.servedNetworks.<name>.settings.wildcard | Whether to serve a wildcard record for ZeroTier Nodes.
|
| services.pgbackrest.stanzas.<name>.settings | An attribute set of options as described in:
https://pgbackrest.org/configuration.html
All options can be used
|
| services.nextcloud-spreed-signaling.settings.nats.url | URL of one or more NATS backends to use
|
| virtualisation.xen.store.settings.quota.enable | Whether to enable the quota system.
|
| services.firewalld.settings.NftablesTableOwner | If enabled, the generated nftables rule set will be owned exclusively by firewalld
|
| services.sourcehut.settings."sr.ht".environment | Values other than "production" adds a banner to each page.
|
| services.angrr.settings.temporary-root-policies.<name>.enable | Whether to enable this angrr policy.
|
| services.listmonk.database.settings.messengers | List of messengers, see: https://github.com/knadh/listmonk/blob/master/models/settings.go#L64-L74 for options.
|
| services.journald.remote.settings.Remote.ServerKeyFile | A path to a SSL secret key file in PEM format
|
| services.maubot.settings.database_opts | Additional arguments for asyncpg.create_pool() or sqlite3.connect()
|
| virtualisation.xen.store.settings.perms.enable | Whether to enable the node permission system.
|
| services.sourcehut.settings."builds.sr.ht::worker".buildlogs | Path to write build logs.
|
| services.authelia.instances.<name>.settings.server.address | The address to listen on.
|
| services.slskd.settings.directories.downloads | Directory where downloaded files are stored.
|
| services.angrr.settings.temporary-root-policies.<name>.ignore-prefixes-in-home | Path prefixes to ignore under home directory
|
| services.bonsaid.settings.*.transitions | List of transitions out of this state
|
| services.transmission.settings.message-level | Set verbosity of transmission messages.
|
| services.anuko-time-tracker.settings.defaultLanguage | Defines Anuko Time Tracker default language
|
| services.matrix-appservice-irc.settings.database.engine | Which database engine to use
|
| services.nitter.preferences.squareAvatars | Square profile pictures.
|
| services.grafana-image-renderer.settings.rendering.width | Width of the PNG used to display the alerting graph.
|
| services.suwayomi-server.settings.server.basicAuthPasswordFile | The password file containing the value that you have to provide when authenticating.
|
| services.transmission.settings.download-dir | Directory where to download torrents.
|
| virtualisation.xen.store.settings.quota.maxEntity | Entity limit for transactions.
|
| services.hercules-ci-agent.settings.clusterJoinTokenPath | Location of the cluster-join-token.key file
|
| services.sourcehut.settings."meta.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.sourcehut.settings."todo.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.tlsrpt.reportd.settings.contact_info | Contact information embedded into the reports.
|
| services.canaille.settings.CANAILLE_SQL.DATABASE_URI | The SQL server URI
|
| services.angrr.settings.temporary-root-policies.<name>.period | Retention period for the GC roots matched by this policy.
|
| services.angrr.settings.temporary-root-policies.<name>.path-regex | Regex pattern to match the GC root path.
|
| services.easytier.instances.<name>.settings.hostname | Hostname shown in peer list and web console.
|
| services.libinput.touchpad.accelPointsScroll | Sets the points of the scroll acceleration function
|
| services.slskd.settings.global.download.speed_limit | Total upload download limit
|
| services.radicle.ci.adapters.native.instances.<name>.settings.log | File where radicle-native-ci should write the run log.
|
| systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.age | Delete a file when it reaches a certain age
|
| services.etebase-server.settings.global.static_root | The directory for static files.
|
| services.listmonk.database.settings."bounce.mailboxes" | List of bounce mailboxes
|
| services.matrix-appservice-irc.settings.ircService.servers | IRC servers to connect to
|
| services.grafana-image-renderer.settings.service.logging.level | The log-level of the grafana-image-renderer.service-unit.
|
| services.vmalert.instances.<name>.settings."notifier.url" | Prometheus Alertmanager URL
|
| services.transmission.settings.rpc-bind-address | Where to listen for RPC connections
|
| services.mchprs.settings.auto_redpiler | Use redpiler automatically
|
| services.warpgate.settings.database_url | Database connection string
|
| services.nextcloud-spreed-signaling.settings.https.key | Path to the private key used for the HTTPS listener
|
| services.sabnzbd.settings.misc.email_endjob | Whether to send emails on job completion
|
| services.authelia.instances.<name>.settingsFiles | Here you can provide authelia with configuration files or directories
|
| services.ocsinventory-agent.settings.server | The URI of the OCS Inventory server where to send the inventory file
|
| services.syncthing.settings.options.urAccepted | Whether the user has accepted to submit anonymous usage data
|
| services.radicle.ci.adapters.native.instances.<name>.settings | Configuration of radicle-native-ci
|
| services.dendrite.settings.sync_api.search.language | The language most likely to be used on the server - used when indexing, to
ensure the returned results match expectations
|
| services.bluesky-pds.settings.PDS_BLOBSTORE_DISK_LOCATION | Store blobs at this location, set to null to use e.g
|
| services.libinput.touchpad.accelPointsMotion | Sets the points of the (pointer) motion acceleration function
|
| services.pid-fan-controller.settings.heatSources.*.pidParams.setPoint | Set point of the controller in °C.
|
| services.suricata.settings.dpdk | Data Plane Development Kit is a framework for fast packet processing in data plane applications running on a wide variety of CPU architectures
|
| services.nitter.preferences.stickyProfile | Make profile sidebar stick to top.
|
| services.angrr.settings.temporary-root-policies.<name>.filter | External filter program to further filter GC roots matched by this policy.
|
| services.reposilite.settings.bypassExternalCache | Add cache bypass headers to responses from /api/* to avoid issues with proxies such as Cloudflare.
|
| services.snapserver.settings.tcp-streaming.enabled | Whether to enable streaming via TCP.
|
| virtualisation.xen.store.settings.enableMerge | Whether to enable transaction merge support.
|
| services.nextcloud.settings.mail_domain | The return address that you want to appear on emails sent by the Nextcloud server, for example nc-admin@example.com, substituting your own domain, of course.
|
| services.grafana.settings.server.enable_gzip | Set this option to true to enable HTTP compression, this can improve transfer speed and bandwidth utilization
|
| services.healthchecks.settings.ALLOWED_HOSTS | The host/domain names that this site can serve.
|
| services.homebridge.settings.accessories | Homebridge Accessories
|
| services.evdevremapkeys.settings | config.yaml for evdevremapkeys
|
| boot.initrd.systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.mode | The file access mode to use when creating this file or directory.
|
| services.logind.settings.Login.KillUserProcesses | Specifies whether the processes of a user should be killed
when the user logs out
|
| services.firewalld.settings.FirewallBackend | The firewall backend implementation
|
| services.transmission.settings.watch-dir-enabled | Whether to enable the
services.transmission.settings.watch-dir.
|
| services.mobilizon.settings.":mobilizon"."Mobilizon.Web.Endpoint".url.host | Your instance's hostname for generating URLs throughout the app
|
| services.grafana.provision.alerting.rules.settings.groups.*.name | Name of the rule group
|
| services.epgstation.settings.clientSocketioPort | Socket.io port that the web client is going to connect to
|
| services.grafana.settings.users.hidden_users | This is a comma-separated list of usernames
|
| services.opensnitch.settings.InterceptUnknown | Whether to intercept spare connections.
|
| services.tor.settings.BridgeAuthoritativeDir | See torrc manual.
|
| services.zeronsd.servedNetworks.<name>.settings.log_level | Log Level.
|
| services.sslh.settings.verbose-connections | Where to log connections information
|
| services.prometheus.exporters.process.settings.process_names | All settings expressed as an Nix attrset
|
| services.grafana.settings.security.admin_email | The email of the default Grafana Admin, created on startup.
|
| systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.user | The user of the file
|
| services.nextcloud.settings.loglevel | Log level value between 0 (DEBUG) and 4 (FATAL).
-
0 (debug): Log all activity.
-
1 (info): Log activity such as user logins and file activities, plus warnings, errors, and fatal errors.
-
2 (warn): Log successful operations, as well as warnings of potential problems, errors and fatal errors.
-
3 (error): Log failed operations and fatal errors.
-
4 (fatal): Log only fatal errors that cause the server to stop.
|
| services.homebridge.settings.description | Description of the homebridge instance.
|
| services.transmission.settings.peer-port-random-on-start | Randomize the peer port.
|
| services.umurmur.settings.channel_links | Channel tree definitions.
|
| services.anubis.defaultOptions.settings.DIFFICULTY | The difficulty required for clients to solve the challenge
|
| services.mchprs.settings.view_distance | Maximal distance (in chunks) between players and loaded chunks
|
| environment.systemPackages | The set of packages that appear in
/run/current-system/sw
|
| services.omnom.settings.server.secure_cookie | Whether to limit cookies to a secure channel.
|
| services.headscale.settings.dns.nameservers.global | List of nameservers to pass to Tailscale clients.
|
| users.mysql.nss | Settings for libnss-mysql
|
| services.sourcehut.settings."pages.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.sourcehut.settings."paste.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.sourcehut.settings."lists.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.grafana.provision.alerting.rules.settings.apiVersion | Config file version.
|
| services.transmission.settings.peer-port-random-low | The minimal peer port to listen to for incoming connections
when services.transmission.settings.peer-port-random-on-start is enabled.
|
| services.maubot.settings.plugin_databases | Plugin database settings
|
| services.etebase-server.settings.global.secret_file | The path to a file containing the secret
used as django's SECRET_KEY.
|
| services.grafana.settings.database.log_queries | Set to true to log the sql calls and execution times
|
| services.grafana-image-renderer.settings.rendering.height | Height of the PNG used to display the alerting graph.
|
| services.anuko-time-tracker.settings.exportDecimalDuration | Defines whether time duration values are decimal in CSV and XML data
exports (1.25 vs 1:15).
|
| services.slskd.settings.retention.transfers.upload.errored | Lifespan of errored upload tasks.
|
| services.sourcehut.settings.webhooks.private-key | An absolute file path (which should be outside the Nix-store)
to a base64-encoded Ed25519 key for signing webhook payloads
|
| virtualisation.docker.daemon.settings | Configuration for docker daemon
|
| services.dendrite.settings.global.server_name | The domain name of the server, with optional explicit port
|
| services.radicle.ci.adapters.native.instances.<name>.settings.state | Directory where per-run directories are stored.
|
| services.sabnzbd.settings.servers.<name>.displayname | Human-friendly description of the server
|
| services.matrix-tuwunel.settings.global.server_name | The server_name is the name of this server
|
| services.matrix-conduit.settings.global.server_name | The server_name is the name of this server
|
| services.prometheus.exporters.fritz.settings.devices | Fritz!-devices to monitor using the exporter.
|
| services.matrix-appservice-irc.settings.ircService.mediaProxy.bindPort | Port that the media proxy binds to.
|
| services.printing.cups-pdf.instances.<name>.settings.Anonuser | User for anonymous PDF creation
|
| services.immichframe.settings.Accounts.*.ApiKeyFile | File containing an API key to talk to the Immich server
|
| services.grafana.provision.alerting.rules.settings.deleteRules | List of alert rule UIDs that should be deleted.
|
| services.netbird.server.management.settings | Configuration of the netbird management server
|
| services.system76-scheduler.settings.cfsProfiles.enable | Tweak CFS latency parameters when going on/off battery
|
| services.tor.relay.onionServices.<name>.settings.HiddenServiceSingleHopMode | See torrc manual.
|
| services.nextcloud-spreed-signaling.settings.grpc.listen | IP and port to listen on for GRPC requests
|
| services.syncthing.settings.options.limitBandwidthInLan | Whether to apply bandwidth limits to devices in the same broadcast domain as the local device.
|
| services.sabnzbd.settings.servers.<name>.connections | Number of parallel connections permitted by
the server.
|
| services.pretix.settings.pretix.instance_name | The name of this installation.
|
| services.veilid.settings.core.capabilities.disable | A list of capabilities to disable (for example, DHTV to say you cannot store DHT information).
|
| services.grafana.provision.dashboards.settings | Grafana dashboard configuration in Nix
|
| services.pinnwand.settings.database_uri | Database URI compatible with SQLAlchemy
|
| services.matrix-synapse.settings.report_stats | Whether or not to report anonymized homeserver usage statistics.
|
| services.dependency-track.settings."alpine.database.driver" | Specifies the JDBC driver class to use.
|
| services.grafana.settings.paths.provisioning | Folder that contains provisioning config files that grafana will apply on startup and while running
|
| services.transmission.settings.peer-port-random-high | The maximum peer port to listen to for incoming connections
when services.transmission.settings.peer-port-random-on-start is enabled.
|
| services.anubis.defaultOptions.settings.WEBMASTER_EMAIL | If set, shows a contact email address when rendering error pages
|
| services.nextcloud-spreed-signaling.settings.app.debug | Set to "true" to install pprof debug handlers
|
| services.firewalld.settings.StrictForwardPorts | If enabled, the generated destination NAT (DNAT) rules will NOT accept traffic that was DNAT'd by other entities, e.g. docker
|
| services.tor.relay.onionServices.<name>.settings.HiddenServiceMaxStreams | See torrc manual.
|
| services.ferretdb.settings.FERRETDB_POSTGRESQL_URL | PostgreSQL URL for 'pg' handler
|
| systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.type | The type of operation to perform on the file
|
| services.veilid.settings.core.table_store.directory | The filesystem directory to store your table store within.
|
| services.veilid.settings.core.block_store.directory | The filesystem directory to store blocks for the block store.
|
| services.taler.exchange.settings.exchange.CURRENCY_ROUND_UNIT | Smallest amount in this currency that can be transferred using the underlying RTGS
|
| services.anubis.defaultOptions.settings.METRICS_BIND_NETWORK | The network family that the metrics server should bind to
|
| systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.group | The group of the file
|
| services.your_spotify.settings.MONGO_ENDPOINT | The endpoint of the Mongo database.
|
| services.omnom.settings.app.disable_signup | Whether to enable restricting user creation.
|
| services.matrix-appservice-irc.settings.homeserver | Homeserver configuration
|
| services.lidarr.settings.update.automatically | Automatically download and install updates.
|
| services.radarr.settings.update.automatically | Automatically download and install updates.
|
| services.sonarr.settings.update.automatically | Automatically download and install updates.
|
| services.libinput.touchpad.accelStepFallback | Sets the step between the points of the fallback acceleration function
|
| services.grafana.settings.smtp.ehlo_identity | Name to be used as client identity for EHLO in SMTP dialog.
|
| services.postfix.settings.main.relay_domains | List of domains delivered via the relay transport.
https://www.postfix.org/postconf.5.html#relay_domains
|
| services.sabnzbd.settings.servers.<name>.ssl_verify | Level of TLS verification
|
| services.simplesamlphp.<name>.settings | Configuration options used by SimpleSAMLphp
|
| services.headscale.settings.tls_key_path | Path to key for already created certificate.
|
| services.swapspace.settings.max_swapsize | Greatest allowed size for individual swapfiles
|
| services.swapspace.settings.min_swapsize | Smallest allowed size for individual swapfiles
|
| services.pid-fan-controller.settings.fans.*.wildcardPath | Wildcard path of the hwmon pwm file
|
| services.syncthing.settings.devices.<name>.autoAcceptFolders | Automatically create or share folders that this device advertises at the default path
|
| services.tor.settings.ServerTransportPlugin.transports | List of pluggable transports.
|
| services.wgautomesh.settings.gossip_port | wgautomesh gossip port, this MUST be the same number on all nodes in
the wgautomesh network.
|
| services.dendrite.settings.global.private_key | The path to the signing private key file, used to sign
requests and events.
nix-shell -p dendrite --command "generate-keys --private-key matrix_key.pem"
|
| services.tuned.settings.dynamic_tuning | Whether to enable dynamic tuning.
|
| services.reposilite.settings.databaseThreadPool | Maximum amount of concurrent connections to the database. (one per thread)
Embedded databases (sqlite, h2) do not support truly concurrent connections, so the value will always be 1 if they are used.
|
| services.matrix-synapse.settings.log_config | The file that holds the logging configuration.
|
| services.immichframe.settings.Accounts.*.ApiKey | API key to talk to the Immich server
|
| services.engelsystem.settings | Options to be added to config.php, as a nix attribute set
|
| services.dendrite.settings.sync_api.search.index_path | The path the search index will be created in.
|
| services.grafana.provision.alerting.rules.settings.deleteRules.*.uid | Unique identifier for the rule
|
| services.firewalld.settings.IndividualCalls | Whether to use individual -restore calls to apply changes to the firewall
|
| hardware.tuxedo-drivers.settings.charging-priority | These options manage the trade-off between battery charging and CPU performance when the USB-C power supply cannot provide sufficient power for both simultaneously:
charge_battery prioritizes battery charging (driver default)
performance prioritizes maximum CPU performance
|
| security.agnos.settings.accounts.*.certificates | Certificates for agnos to issue or renew.
|
| environment.variables | A set of environment variables used in the global environment
|
| services.sourcehut.settings."builds.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.buffyboard.settings.input.touchscreen | Enable or disable the use of the touchscreen.
|
| services.warpgate.settings.postgres.certificate | Path to PostgreSQL listener certificate.
|
| services.kanidm.server.settings.online_backup.path | Path to the output directory for backups.
|
| services.umurmur.settings.max_bandwidth | Maximum bandwidth (in bits per second) that clients may send
speech at.
|
| services.olivetin.settings.ListenAddressSingleHTTPFrontend | The address to listen on for the internal "microproxy" frontend.
|
| services.grafana.provision.alerting.muteTimings.settings | Grafana mute timings configuration in Nix
|
| services.nextcloud-spreed-signaling.settings.http.listen | IP and port to listen on for HTTP requests, in the format of ip:port
|
| services.libeufin.bank.settings.libeufin-bankdb-postgres.CONFIG | The database connection string for the libeufin-bank database.
|
| boot.initrd.systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.age | Delete a file when it reaches a certain age
|
| services.homebridge.settings.accessories.*.name | Name of the accessory
|
| services.matrix-synapse.settings.server_name | The domain name of the server, with optional explicit port
|
| services.dependency-track.settings."alpine.oidc.teams.claim" | Defines the name of the claim that contains group memberships or role assignments in the provider's userinfo endpoint
|
| services.matrix-synapse.settings.listeners.*.resources | List of HTTP resources to serve on this listener.
|
| services.slskd.settings.directories.incomplete | Directory where incomplete downloading files are stored.
|
| services.hostapd.radios.<name>.networks.<name>.settings | Extra configuration options to put at the end of this BSS's defintion in the
hostapd.conf for the associated interface
|
| services.prometheus.exporters.fritz.settings.devices.*.name | Name to use for the device.
|
| services.grafana.provision.alerting.rules.settings.deleteRules.*.orgId | Organization ID, default = 1
|
| security.apparmor.enable | Whether to enable the AppArmor Mandatory Access Control system
|
| services.authelia.instances.<name>.settings.log.file_path | File path where the logs will be written
|
| services.stash.settings.parallel_tasks | Number of parallel tasks to start during scan/generate
|
| services.mackerel-agent.settings.host_status.on_stop | Host status after agent shutdown.
|
| documentation.man.mandoc.settings.output.width | The ASCII and UTF-8 output width, default is 78
|
| services.suricata.settings.app-layer.protocols.<name>.enabled | The option "enabled" takes 3 values - "yes", "no", "detection-only".
"yes" enables both detection and the parser, "no" disables both, and
"detection-only" enables protocol detection only (parser disabled).
|
| services.headscale.settings.oidc.extra_params | Custom query parameters to send with the Authorize Endpoint request.
|
| services.matrix-appservice-irc.settings.homeserver.url | The URL to the home server for client-server API calls
|
| services.syncthing.settings.folders.<name>.versioning.type | The type of versioning
|
| services.headscale.settings.dns.base_domain | Defines the base domain to create the hostnames for MagicDNS
|
| services.homebridge.settings.platforms.*.platform | Platform type
|
| services.anubis.instances.<name>.settings.DIFFICULTY | The difficulty required for clients to solve the challenge
|
| services.tuned.settings.sleep_interval | Interval in which the TuneD daemon is waken up and checks for events (in seconds).
|
| services.your_spotify.settings.SPOTIFY_PUBLIC | The public client ID of your Spotify application
|
| security.unprivilegedUsernsClone | When disabled, unprivileged users will not be able to create new namespaces
|
| virtualisation.xen.store.settings.quota.maxWatchEvents | Maximum number of outstanding watch events per watch.
|
| services.grafana.settings.security.secret_key | Secret key used for signing
|
| services.grafana.provision.alerting.policies.settings | Grafana notification policies configuration in Nix
|
| services.warpgate.settings.ssh.external_port | The SSH listener is reachable via this port externally.
|
| boot.initrd.systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.user | The user of the file
|
| services.tuned.settings.reapply_sysctl | Whether to enable the reapplying of global sysctls after TuneD sysctls are applied.
|
| services.dependency-track.settings."alpine.oidc.username.claim" | Defines the name of the claim that contains the username in the provider's userinfo endpoint
|
| services.nextcloud-spreed-signaling.settings.grpc.targets | For target type static: List of GRPC targets to connect to for clustering mode.
|
| services.borgmatic.settings.repositories.*.path | Path to the repository
|
| services.minidlna.settings.friendly_name | Name that the server presents to clients.
|
| services.matrix-appservice-irc.settings.ircService.mediaProxy.publicUrl | URL under which the media proxy is publicly acccessible.
|
| services.postsrsd.settings.unprivileged-user | Unprivileged user to drop privileges to.
Our systemd unit never runs postsrsd as a privileged process, so this option is read-only.
|
| services.epgstation.settings.concurrentEncodeNum | The maximum number of encoding jobs that EPGStation would run at the
same time.
|
| services.grafana.settings.users.password_hint | Text used as placeholder text on login page for password input.
|
| documentation.man.mandoc.settings.output.man | A template for linked manuals (usually via the Xr macro) in HTML
output
|
| services.consul-template.instances.<name>.settings.pid_file | Path to use for the pid file.
|
| services.dependency-track.settings."alpine.oidc.teams.default" | Defines one or more team names that auto-provisioned OIDC users shall be added to
|
| services.nextcloud-spreed-signaling.settings.turn.servers | A list of TURN servers to use
|
| services.sharkey.settings.fulltextSearch.provider | Which provider to use for full text search
|
| services.warpgate.settings.sso_providers | Configure OIDC single sign-on providers.
|
| services.grafana.settings.users.default_theme | Sets the default UI theme. system matches the user's system theme.
|
| services.nextcloud.settings.enabledPreviewProviders | The preview providers that should be explicitly enabled.
|
| services.grafana.provision.alerting.muteTimings.settings.muteTimes | List of mute time intervals to import or update.
|
| services.grafana.provision.alerting.rules.settings.groups.*.folder | Name of the folder the rule group will be stored in
|
| services.filesender.settings.admin_email | Email address of FileSender administrator(s)
|
| services.vmalert.instances.<name>.settings."datasource.url" | Datasource compatible with Prometheus HTTP API.
|
| services.draupnir.settings.managementRoom | The room ID or alias where moderators can use the bot's functionality
|
| services.prometheus.exporters.script.settings.scripts.*.name | Name of the script.
|
| services.sourcehut.settings."hg.sr.ht".changegroup-script | A changegroup script which is installed in every mercurial repo
|
| services.grafana.settings.database.ca_cert_path | The path to the CA certificate to use.
|
| services.readarr.settings.update.automatically | Automatically download and install updates.
|
| services.syncthing.settings.options.localAnnounceEnabled | Whether to send announcements to the local LAN, also use such announcements to find other devices.
|
| services.angrr.settings.temporary-root-policies.<name>.filter.program | Path to the external filter program.
|
| services.warpgate.settings.http.external_port | The HTTP listener is reachable via this port externally.
|
| services.anubis.instances.<name>.settings.WEBMASTER_EMAIL | If set, shows a contact email address when rendering error pages
|
| virtualisation.xen.store.settings.quota.maxRequests | Maximum number of requests per transaction.
|
| services.grafana.settings.server.read_timeout | Sets the maximum time using a duration format (5s/5m/5ms)
before timing out read of an incoming request and closing idle connections.
0 means there is no timeout for reading the request.
|
| services.anubis.instances.<name>.settings.METRICS_BIND_NETWORK | The network family that the metrics server should bind to
|
| services.nextcloud-spreed-signaling.settings.turn.apikeyFile | The path to the file containing the value for turn.apikey
|
| services.nextcloud-spreed-signaling.settings.turn.secretFile | The path to the file containing the value for turn.secret
|
| services.armagetronad.servers.<name>.settings | Armagetron Advanced server rules configuration
|
| boot.initrd.systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.type | The type of operation to perform on the file
|
| services.taler.exchange.settings.exchangedb-postgres.CONFIG | Database connection URI.
|
| services.taler.merchant.settings.merchantdb-postgres.CONFIG | Database connection URI.
|
| services.sabnzbd.settings.misc.bandwidth_max | Maximum bandwidth in bytes(!)/sec (supports prefixes)
|
| boot.initrd.systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.group | The group of the file
|
| services.journald.upload.settings.Upload.NetworkTimeoutSec | When network connectivity to the server is lost, this option
configures the time to wait for the connectivity to get restored
|
| services.matrix-appservice-discord.settings | config.yaml configuration as a Nix attribute set
|
| services.borgmatic.settings.repositories.*.label | Label to the repository
|
| services.tor.settings.CookieAuthentication | See torrc manual.
|
| virtualisation.xen.store.settings.xenstored.log.file | Path to the Xen Store log file.
|
| services.mobilizon.settings.":mobilizon".":instance".name | The fallback instance name if not configured into the admin UI
|
| services.consul-template.instances.<name>.settings.template | Template section of consul-template
|
| services.suricata.settings.logging.stacktrace-on-signal | Requires libunwind to be available when Suricata is configured and built
|
| services.grafana.provision.dashboards.settings.apiVersion | Config file version.
|
| services.libinput.touchpad.accelPointsFallback | Sets the points of the fallback acceleration function
|
| services.postfix.settings.master.<name>.wakeupUnusedComponent | If set to false the component will only be woken
up if it is used
|
| services.dependency-track.settings."alpine.data.directory" | Defines the path to the data directory
|
| services.immichframe.settings.Accounts.*.ImmichServerUrl | The URL of your Immich server.
|
| services.firewalld.settings.NftablesFlowtable | This may improve forwarded traffic throughput by enabling nftables flowtable
|
| services.matrix-continuwuity.settings.global.port | The port(s) continuwuity will be running on
|
| services.your_spotify.settings.CLIENT_ENDPOINT | The endpoint of your web application
|
| services.grafana.provision.datasources.settings | Grafana datasource configuration in Nix
|
| services.postfix.settings.main.mydestination | List of domain names intended for local delivery using /etc/passwd and /etc/aliases.
Do not include virtual domains in this list.
https://www.postfix.org/postconf.5.html#mydestination
|
| services.veilid.settings.client_api.ipc_enabled | veilid-server will respond to Python and other JSON client requests.
|
| services.mackerel-agent.settings.host_status.on_start | Host status after agent startup.
|
| services.grafana.provision.alerting.contactPoints.settings | Grafana contact points configuration in Nix
|
| services.warpgate.settings.external_host | Configure the domain name of this Warpgate instance
|
| services.slskd.settings.retention.transfers.download.errored | Lifespan of errored download tasks.
|
| services.sabnzbd.settings.servers.<name>.expire_date | If Notifications are enabled and an expiry date is
set, warn 5 days before expiry
|
| services.nvme-rs.settings.thresholds.wear_warning | Wear warning threshold (%)
|
| services.warpgate.settings.mysql.external_port | The MySQL listener is reachable via this port externally.
|
| services.waagent.settings.Provisioning.Enable | Whether to enable provisioning functionality in the agent
|
| documentation.man.mandoc.settings.manpath | Override the default search path for man(1),
apropos(1), and makewhatis(8)
|
| services.syncthing.settings.folders.<name>.versioning | How to keep changed/deleted files with Syncthing
|
| services.navidrome.settings.EnableInsightsCollector | Enable anonymous usage data collection, see https://www.navidrome.org/docs/getting-started/insights/ for details.
|
| services.grafana.settings.users.allow_sign_up | Set to false to prohibit users from being able to sign up / create user accounts
|
| services.livekit.settings.rtc.port_range_end | End of UDP port range for WebRTC
|
| virtualisation.xen.store.settings.xenstored.log.level | Logging level for the Xen Store.
|
| services.nvme-rs.settings.thresholds.temp_warning | Temperature warning threshold (°C)
|
| services.libeufin.nexus.settings.libeufin-nexusdb-postgres.CONFIG | The database connection string for the libeufin-nexus database.
|
| services.warpgate.settings.sso_providers.*.name | Internal identifier of SSO provider.
|
| services.grafana.provision.alerting.muteTimings.settings.apiVersion | Config file version.
|
| services.grafana.provision.alerting.templates.settings | Grafana templates configuration in Nix
|
| services.tor.relay.onionServices.<name>.settings.HiddenServiceExportCircuitID | See torrc manual.
|
| services.matrix-synapse.settings.listeners.*.resources.*.names | List of resources to host on this listener.
|
| services.prometheus.exporters.script.settings | Free-form configuration for script_exporter, expressed as a Nix attrset and rendered to YAML.
Migration note:
The previous format using script = "sleep 5" is no longer supported
|
| services.headscale.settings.dns.extra_records | Extra DNS records to expose to clients.
|
| services.prometheus.exporters.fritz.settings.log_level | Log level to use for the exporter.
|
| services.your_spotify.settings.API_ENDPOINT | The endpoint of your server
This api has to be reachable from the device you use the website from not from the server
|
| services.grafana.provision.datasources.settings.prune | When true, provisioned datasources from this file will be deleted
automatically when removed from
services.grafana.provision.datasources.settings.datasources.
|
| services.slskd.settings.retention.transfers.upload.cancelled | Lifespan of cancelled upload tasks.
|
| services.slskd.settings.retention.transfers.upload.succeeded | Lifespan of succeeded upload tasks.
|
| services.dependency-track.settings."alpine.database.username" | Specifies the username to use when authenticating to the database.
|
| services.grafana-image-renderer.settings.rendering.mode | Rendering mode of grafana-image-renderer:
default: Creates on browser-instance
per rendering request.
reusable: One browser instance
will be started and reused for each rendering request.
clustered: allows to precisely
configure how many browser-instances are supposed to be used
|
| services.hercules-ci-agent.settings.staticSecretsDirectory | This is the default directory to look for statically configured secrets like cluster-join-token.key
|
| services.listmonk.database.settings."privacy.exportable" | List of fields which can be exported through an automatic export request
|
| services.easytier.instances.<name>.settings.listeners | Listener addresses to accept connections from other peers
|
| services.mpd.settings.bind_to_address | The address for the daemon to listen on
|
| services.factorio.mods-dat | Mods settings can be changed by specifying a dat file, in the mod
settings file
format.
|
| services.grafana.provision.alerting.muteTimings.settings.muteTimes.*.name | Name of the mute time interval, must be unique
|
| services.anubis.defaultOptions.settings.OG_PASSTHROUGH | Whether to enable Open Graph tag passthrough
|
| services.headscale.settings.tls_cert_path | Path to already created certificate.
|
| services.prometheus.exporters.nginxlog.settings.consul | Consul integration options
|
| documentation.man.mandoc.settings.output.indent | Number of blank characters at the left margin for normal text,
default of 5 for mdoc(7) and 7 for
man(7)
|
| documentation.man.mandoc.settings.output.includes | A string of relative path used as a template for the output path of
linked header files (usually via the In macro) in HTML output
|
| services.prowlarr.settings.update.automatically | Automatically download and install updates.
|
| services.whisparr.settings.update.automatically | Automatically download and install updates.
|
| services.pid-fan-controller.settings.heatSources.*.wildcardPath | Path of the heat source's hwmon temp_input file
|
| services.nextcloud-spreed-signaling.settings.https.listen | IP and port to listen on for HTTPS requests, in the format of ip:port
|
| services.grafana.provision.alerting.policies.settings.apiVersion | Config file version.
|
| services.system76-scheduler.assignments | Process profile assignments.
|
| services.prometheus.alertmanager-ntfy.settings.http.addr | The address to listen on.
|
| services.synapse-auto-compressor.settings.levels | Sizes of each new level in the compression algorithm, as a comma-separated list
|
| services.tor.relay.onionServices.<name>.settings.HiddenServiceAllowUnknownPorts | See torrc manual.
|
| services.headscale.settings.oidc.allowed_users | Users allowed to authenticate even if not in allowedDomains.
|
| services.nextcloud-spreed-signaling.settings.backend.timeout | Timeout in seconds for requests to the backend
|
| services.hddfancontrol.settings.<drive-bay-name>.extraArgs | Extra commandline arguments for hddfancontrol
|
| services.opensearch.settings."plugins.security.disabled" | Whether to enable the security plugin,
plugins.security.ssl.transport.keystore_filepath or
plugins.security.ssl.transport.server.pemcert_filepath and
plugins.security.ssl.transport.client.pemcert_filepath
must be set for this plugin to be enabled.
|
| services.nextcloud.settings.mail_smtpport | This depends on mail_smtpmode
|
| services.crowdsec-firewall-bouncer.settings.api_key | API key to authenticate with a local crowdsec API
|
| services.lldap.settings.ldap_user_email | Admin email.
|
| services.dependency-track.settings."alpine.database.mode" | Defines the database mode of operation
|
| services.tor.relay.onionServices.<name>.settings.HiddenServiceDirGroupReadable | See torrc manual.
|
| services.system76-scheduler.settings.cfsProfiles.default.latency | sched_latency_ns.
|
| services.chhoto-url.settings.hash_algorithm | The hash algorithm to use for passwords and API keys
|
| services.public-inbox.settings.publicinbox.nntpserver | NNTP URLs to this public-inbox instance
|
| services.public-inbox.settings.publicinbox.pop3server | POP3 URLs to this public-inbox instance
|
| services.public-inbox.settings.publicinbox.imapserver | IMAP URLs to this public-inbox instance
|
| services.sabnzbd.settings.misc.bandwidth_perc | Percentage of bandwidth_max that sabnzbd is allowed to use.
0 means no limit.
|
| services.angrr.settings.temporary-root-policies.<name>.priority | Priority of this policy
|
| services.tor.settings.AuthoritativeDirectory | See torrc manual.
|
| services.nextcloud.settings.mail_smtpname | This depends on mail_smtpauth
|
| services.matrix-appservice-irc.settings.ircService.mediaProxy.signingKeyPath | Path to the signing key file for authenticated media.
|
| services.sourcehut.settings."lists.sr.ht::worker".reject-mimetypes | Comma-delimited list of Content-Types to reject
|
| services.system76-scheduler.settings.cfsProfiles.default.preempt | Preemption mode.
|
| virtualisation.xen.store.settings.ringScanInterval | Perodic scanning for all the rings as a safenet for lazy clients
|
| services.prometheus.alertmanager-ntfy.settings | Configuration of alertmanager-ntfy
|
| services.sabnzbd.settings.ntfosd.ntfosd_enable | Whether to enable NotifyOSD alerts
|
| services.system76-scheduler.settings.cfsProfiles.default.nr-latency | sched_nr_latency.
|
| documentation.man.mandoc.settings.output.paper | This option is for generating PostScript and PDF output
|
| services.headscale.settings.dns.extra_records.*.type | DNS record type.
|
| services.headscale.settings.dns.extra_records.*.name | DNS record name.
|
| services.nextcloud-spreed-signaling.settings.etcd.endpoints | List of static etcd endpoints to connect to.
|
| services.lasuite-docs.collaborationServer.settings.PORT | Port used by collaboration server to listen to
|
| virtualisation.containerd.settings | Verbatim lines to add to containerd.toml
|
| services.prometheus.exporters.script.settings.scripts.*.script | Shell script to execute when metrics are requested.
|
| services.grafana.provision.alerting.rules.settings.groups.*.interval | Interval that the rule group should be evaluated at
|
| services.nextcloud.settings.mail_smtpauth | This depends on mail_smtpmode
|
| services.warpgate.settings.sso_providers.*.label | SSO provider name displayed on login page.
|
| services.matrix-appservice-irc.settings.ircService.mediaProxy.ttlSeconds | Lifetime in seconds, that generated URLs stay valid
|
| services.suricata.settings.dpdk.interfaces.*.interface | See upstream docs: docs/capture-hardware/dpdk and docs/configuration/suricata-yaml.html#data-plane-development-kit-dpdk.
|
| services.grafana.provision.alerting.muteTimings.settings.deleteMuteTimes | List of mute time intervals that should be deleted.
|
| services.lasuite-docs.collaborationServer.settings | Configuration options of collaboration server
|
| services.postfix-tlspol.settings.server.socket-permissions | Permissions to the UNIX socket, if configured.
Due to hardening on the systemd unit the socket can never be created world readable/writable.
|
| services.radicle.ci.adapters.native.instances.<name>.settings.base_url | Base URL for build logs (mandatory for access from CI broker page).
|
| services.tuned.settings.update_interval | Update interval for dynamic tuning (in seconds).
|
| services.lldap.settings.jwt_secret_file | Path to a file containing the JWT secret.
|
| services.nipap.settings.auth.default_backend | Name of auth backend to use by default.
|
| virtualisation.xen.store.settings.persistent | Whether to activate the filed base backend.
|
| services.suricata.settings.exception-policy | Define a common behavior for all exception policies
|
| services.autosuspend.settings.suspend_cmd | The command to execute in case the host shall be suspended
|
| documentation.man.mandoc.settings.output.fragment | Whether to omit the declaration and the , , and
elements and only emit the subtree below the element in HTML
output of mandoc(1)
|
| services.headscale.settings.prefixes.allocation | Strategy used for allocation of IPs to nodes, available options:
- sequential (default): assigns the next free IP from the previous given IP.
- random: assigns the next free IP from a pseudo-random IP generator (crypto/rand).
|
| virtualisation.docker.daemon.settings.live-restore | Allow dockerd to be restarted without affecting running container
|
| services.tor.settings.V3AuthoritativeDirectory | See torrc manual.
|
| systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.argument | An argument whose meaning depends on the type of operation
|
| services.quickwit.settings.listen_address | Listen address of Quickwit.
|
| services.matrix-appservice-irc.settings.homeserver.domain | The 'domain' part for user IDs on this home server
|
| services.public-inbox.settings.publicinbox.wwwlisting | Controls which lists (if any) are listed for when the root
public-inbox URL is accessed over HTTP.
|
| programs.starship.presets | Presets files to be merged with settings in order.
|
| services.grafana.provision.datasources.settings.apiVersion | Config file version.
|
| services.grafana.provision.alerting.contactPoints.settings.apiVersion | Config file version.
|
| services.crowdsec.settings.console.configuration | Attributes inside the console.yaml file.
|
| services.warpgate.settings.http.cookie_max_age | How long until logged in cookie expires.
|
| services.openssh.settings.AuthorizedPrincipalsFile | Specifies a file that lists principal names that are accepted for certificate authentication
|
| virtualisation.docker.rootless.daemon.settings | Configuration for docker daemon
|
| services.grafana.provision.alerting.policies.settings.policies | List of contact points to import or update.
|
| services.automysqlbackup.settings | automysqlbackup configuration
|
| services.pgbouncer.settings.pgbouncer.listen_port | Which port to listen on
|
| services.grafana.settings.database.max_open_conn | The maximum number of open connections to the database.
|
| services.matrix-continuwuity.settings.global.address | Addresses (IPv4 or IPv6) to listen on for connections by the reverse proxy/tls terminator
|
| services.authelia.instances.<name>.settings.log.keep_stdout | Whether to also log to stdout when a file_path is defined.
|
| services.autosuspend.settings.wakeup_cmd | The command to execute for scheduling a wake up of the system
|
| services.tlsrpt.reportd.settings.sender_address | Sender address used for reports.
|
| services.anubis.instances.<name>.settings.OG_PASSTHROUGH | Whether to enable Open Graph tag passthrough
|
| services.kea.dhcp-ddns.configFile | Kea DHCP-DDNS configuration as a path, see https://kea.readthedocs.io/en/kea-3.0.2/arm/ddns.html
|
| services.biboumi.settings.xmpp_server_ip | The IP address to connect to the XMPP server on
|
| services.hddfancontrol.settings.<drive-bay-name>.disks | Drive(s) to get temperature from
Can also use command substitution to automatically grab all matching drives; such as all scsi (sas) drives
|
| services.anubis.instances.<name>.settings.METRICS_BIND | The address Anubis' metrics server listens to
|
| services.grafana.settings.security.cookie_secure | Set to true if you host Grafana behind HTTPS.
|
| services.grafana.settings.database.max_idle_conn | The maximum number of connections in the idle connection pool.
|
| services.grafana.provision.alerting.templates.settings.apiVersion | Config file version.
|
| services.grafana.provision.alerting.muteTimings.settings.deleteMuteTimes.*.orgId | Organization ID, default = 1.
|
| virtualisation.xen.store.settings.xenstored.accessLog.file | Path to the Xen Store access log file.
|
| services.veilid.settings.core.network.dht.min_peer_count | Minimum number of nodes to keep in the peer table.
|
| services.prometheus.exporters.script.settings.scripts.*.timeout | Optional timeout for the script in seconds.
|
| services.kerberos_server.settings.module | Modules to obtain Kerberos configuration from.
|
| services.kerberos_server.settings.realms | The realm(s) to serve keys for.
|
| services.headscale.settings.dns.extra_records.*.value | DNS record value (IP address).
|
| security.agnos.settings.accounts.*.certificates.*.domains | Domains the certificate represents
|
| services.parsedmarc.settings.elasticsearch.ssl | Whether to use an encrypted SSL/TLS connection.
|
| services.pgbouncer.settings.pgbouncer.pool_mode | Specifies when a server connection can be reused by other clients.
session
Server is released back to pool after client disconnects
|
| services.grafana.provision.dashboards.settings.providers | List of dashboards to insert/update.
|
| services.kanidm.server.settings.online_backup.schedule | The schedule for backups in cron format.
|
| security.auditd.settings.space_left | If the free space in the filesystem containing log_file drops below this value, the audit daemon takes the action specified by
space_left_action
|
| services.minidlna.settings.root_container | Use a different container as the root of the directory tree presented to clients.
|
| services.nvme-rs.settings.thresholds.wear_critical | Wear critical threshold (%)
|
| services.chhoto-url.settings.redirect_method | The redirect method to use.
|
| services.system76-scheduler.settings.processScheduler.enable | Tweak scheduling of individual processes in real time.
|
| services.nextcloud-spreed-signaling.settings.backend.allowall | Allow any hostname as backend endpoint
|
| services.parsedmarc.settings.elasticsearch.user | Username to use when connecting to Elasticsearch, if
required.
|
| services.prometheus.exporters.fritz.settings.devices.*.username | Username to authenticate with the target device.
|
| services.prometheus.exporters.fritz.settings.devices.*.hostname | Hostname under which the target device is reachable.
|
| services.opentelemetry-collector.settings | Specify the configuration for Opentelemetry Collector in Nix
|
| services.nvme-rs.settings.thresholds.temp_critical | Temperature critical threshold (°C)
|
| services.nvme-rs.settings.thresholds.spare_warning | Available spare warning threshold (%)
|
| services.suricata.settings.classification-file | Suricata classification configuration file.
|
| services.gitea.settings.service.DISABLE_REGISTRATION | By default any user can create an account on this gitea instance
|
| nix.checkAllErrors | If enabled, checks the nix.conf parsing for any kind of error
|
| services.slskd.settings.retention.transfers.download.cancelled | Lifespan of cancelled download tasks.
|
| services.slskd.settings.retention.transfers.download.succeeded | Lifespan of succeeded download tasks.
|
| services.journald.upload.settings.Upload.ServerCertificateFile | SSL CA certificate in PEM format
|
| services.grafana.provision.alerting.muteTimings.settings.deleteMuteTimes.*.name | Name of the mute time interval, must be unique
|
| boot.initrd.systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.argument | An argument whose meaning depends on the type of operation
|
| services.grafana.settings.database.query_retries | This setting applies to sqlite3 only and controls the number of times the system retries a query when the database is locked.
|
| services.veilid.settings.core.network.routing_table.node_id | Base64-encoded public key for the node, used as the node's ID.
|
| services.angrr.settings.temporary-root-policies.<name>.filter.arguments | Extra command-line arguments pass to the external filter program.
|
| services.wgautomesh.settings.lan_discovery | Enable discovery of peers on the same LAN using UDP broadcast.
|
| services.headscale.settings.dns.search_domains | Search domains to inject to Tailscale clients.
|
| services.transmission.settings.script-torrent-done-enabled | Whether to run
services.transmission.settings.script-torrent-done-filename
at torrent completion.
|
| services.matrix-synapse.settings.enable_metrics | Enable collection and rendering of performance metrics
|
| services.grafana.settings.server.enforce_domain | Redirect to correct domain if the host header does not match the domain
|
| services.transmission.settings.incomplete-dir | When enabled with
services.transmission.home
services.transmission.settings.incomplete-dir-enabled,
new torrents will download the files to this directory
|
| services.tor.relay.onionServices.<name>.settings.HiddenServiceMaxStreamsCloseCircuit | See torrc manual.
|
| services.kanidm.server.settings.online_backup.versions | Number of backups to keep
|
| services.grafana.provision.alerting.policies.settings.resetPolicies | List of orgIds that should be reset to the default policy.
|
| services.journald.upload.settings.Upload.TrustedCertificateFile | SSL CA certificate
|
| virtualisation.xen.store.settings.perms.enableWatch | Whether to enable the watch permission system
|
| services.matrix-synapse.settings.listeners.*.x_forwarded | Use the X-Forwarded-For (XFF) header as the client IP and not the
actual client IP.
|
| services.grafana.provision.dashboards.settings.providers.*.type | Dashboard provider type.
|
| services.grafana.provision.dashboards.settings.providers.*.name | A unique provider name.
|
| services.mobilizon.settings.":mobilizon".":instance".hostname | Your instance's hostname
|
| services.kerberos_server.settings.include | Files to include in the Kerberos configuration.
|
| services.maubot.settings.crypto_database | Separate database URL for the crypto database
|
| services.transmission.settings.incomplete-dir-enabled | |
| services.authelia.instances.<name>.settings.telemetry.metrics.enabled | Enable Metrics.
|
| services.parsedmarc.settings.elasticsearch.hosts | A list of Elasticsearch hosts to push parsed reports
to.
|
| services.warpgate.settings.postgres.external_port | The PostgreSQL listener is reachable via this port externally.
|
| services.mpd.settings.music_directory | The directory or URI where MPD reads music from
|
| security.agnos.settings.dns_listen_addr | Address for agnos to listen on
|
| services.kea.ctrl-agent.configFile | Kea Control Agent configuration as a path, see https://kea.readthedocs.io/en/kea-3.0.2/arm/agent.html
|
| virtualisation.containers.storage.settings | storage.conf configuration
|
| services.mediagoblin.settings.mediagoblin.plugins | Plugins to enable
|
| services.umurmur.settings.default_channel | The channel in which users will appear in when connecting.
|
| services.listmonk.database.settings."app.notify_emails" | Administrator emails for system notifications
|
| services.mchprs.settings.block_in_hitbox | Allow placing blocks inside of players
(hitbox logic is simplified)
|
| services.grafana.settings.server.router_logging | Set to true for Grafana to log all HTTP requests (not just errors)
|
| services.syncthing.settings.options.maxFolderConcurrency | This option controls how many folders may concurrently be in I/O-intensive operations such as syncing or scanning
|
| services.matrix-synapse.settings.public_baseurl | The public-facing base URL for the client API (not including _matrix/...)
|
| services.transmission.settings.script-torrent-done-filename | Executable to be run at torrent completion.
|
| services.prometheus.alertmanager-ntfy.settings.ntfy.baseurl | The base URL of the ntfy.sh instance.
|
| services.openldap.configDir | Use this config directory instead of generating one from the
settings option
|
| services.journald.remote.settings.Remote.ServerCertificateFile | A path to a SSL certificate file in PEM format
|
| services.kerberos_server.settings.realms.<name>.acl | The privileges granted to a user.
|
| services.taler.merchant.settings.merchant.LEGAL_PRESERVATION | How long to keep data in the database for tax audits after the transaction has completed.
|
| services.tor.settings.UseMicrodescriptors | See torrc manual.
|
| services.transmission.settings.trash-original-torrent-files | Whether to delete torrents added from the
services.transmission.settings.watch-dir.
|
| services.hddfancontrol.settings.<drive-bay-name>.pwmPaths | PWM filepath(s) to control fan speed (under /sys), followed by initial and fan-stop PWM values
Can also use command substitution to ensure the correct hwmonX is selected on every boot
|
| virtualisation.xen.store.settings.quota.transaction | Maximum number of transactions.
|
| services.grafana.provision.alerting.contactPoints.settings.contactPoints | List of contact points to import or update.
|
| services.matrix-conduit.settings.global.database_path | Path to the conduit database, the directory where conduit will save its data
|
| services.omnom.settings.app.results_per_page | Number of results per page.
|
| services.mobilizon.settings.":mobilizon"."Mobilizon.Web.Endpoint".http.port | The port to run the server
|
| services.geoipupdate.settings.DatabaseDirectory | The directory to store the database files in
|
| services.firefox-syncserver.settings.tokenserver.enabled | Whether to enable the token service as well.
|
| services.veilid.settings.client_api.ipc_directory | IPC directory where file sockets are stored.
|
| services.mobilizon.settings.":mobilizon"."Mobilizon.Web.Endpoint".http.ip | The IP address to listen on
|
| services.reposilite.settings.compressionStrategy | Compression algorithm used by this instance of Reposilite.
none reduces usage of CPU & memory, but requires transfering more data.
|
| services.nextcloud.settings.mail_smtphost | This depends on mail_smtpmode
|
| services.easytier.instances.<name>.settings.network_name | EasyTier network name.
|
| services.warpgate.settings.sso_providers.*.provider | SSO provider configurations.
|
| services.syncthing.settings.folders.<name>.copyOwnershipFromParent | On Unix systems, tries to copy file/folder ownership from the parent directory (the directory it’s located in)
|
| services.homebridge.settings.accessories.*.accessory | Accessory type
|
| services.authelia.instances.<name>.settings.telemetry.metrics.address | The address to listen on for metrics
|
| services.archisteamfarm.settings | The ASF.json file, all the options are documented here
|
| services.auto-epp.settings.Settings.epp_state_for_AC | energy_performance_preference when on plugged in
See available epp states by running:
cat /sys/devices/system/cpu/cpu0/cpufreq/energy_performance_available_preferences
|
| services.wordpress.sites.<name>.extraConfig | Any additional text to be appended to the wp-config.php
configuration file
|
| services.stash.settings.preview_segments | Number of segments in a preview file
|
| services.stash.settings.sound_on_preview | Enable sound on mouseover previews
|
| services.grafana.provision.alerting.templates.settings.templates | List of templates to import or update.
|
| services.pixelfed.secretFile | A secret file to be sourced for the .env settings
|
| services.warpgate.settings.http.session_max_age | How long until a logged in session expires.
|
| services.bonsaid.settings.*.delay_duration | Nanoseconds to wait after the previous state change before performing this transition
|
| services.system76-scheduler.settings.cfsProfiles.default.bandwidth-size | sched_cfs_bandwidth_slice_us.
|
| services.auto-epp.settings.Settings.epp_state_for_BAT | energy_performance_preference when on battery
See available epp states by running:
cat /sys/devices/system/cpu/cpu0/cpufreq/energy_performance_available_preferences
|
| services.nextcloud.settings.mail_smtpdebug | Enable SMTP class debugging.
loglevel will likely need to be adjusted too.
See docs.
|
| services.kanidm.server.settings.ldapbindaddress | Address and port the LDAP server is bound to
|
| services.mollysocket.settings.allowed_uuids | UUIDs of Signal accounts that may use this server
|
| services.keycloak.settings.hostname-backchannel-dynamic | Enables dynamic resolving of backchannel URLs,
including hostname, scheme, port and context path
|
| services.grafana.provision.alerting.contactPoints.settings.contactPoints.*.name | Name of the contact point
|
| virtualisation.xen.store.settings.quota.maxOutstanding | Maximum outstanding requests, i.e. in-flight requests / domain.
|
| services.pgbouncer.settings.pgbouncer.listen_addr | Specifies a list (comma-separated) of addresses where to listen for TCP connections
|
| services.matrix-appservice-irc.settings.database.connectionString | The database connection string
|
| services.prometheus.exporters.fritz.settings.devices.*.host_info | Enable extended host info for this device. Warning: This will heavily increase scrape time.
|
| services.firezone.server.settingsSecret.TOKENS_SALT | A file containing a unique base64 encoded secret for the
TOKENS_SALT
|
| services.tlsrpt.reportd.settings.sendmail_script | Path to a sendmail-compatible executable for delivery reports.
|
| services.slskd.settings.flags.force_share_scan | Force a rescan of shares on every startup.
|
| services.firewalld.settings.IPv6_rpfilter | Performs reverse path filtering (RPF) on IPv6 packets as per RFC 3704
|
| services.borgmatic.settings.repositories | A required list of local or remote repositories with paths and
optional labels (which can be used with the --repository flag to
select a repository)
|
| services.livekit.settings.rtc.use_external_ip | When set to true, attempts to discover the host's public IP via STUN
|
| services.parsedmarc.settings.general.save_forensic | Save forensic report data to Elasticsearch and/or Splunk.
|
| services.warpgate.settings.config_provider | Source of truth of users
|
| services.glitchtip.settings.ENABLE_USER_REGISTRATION | When true, any user will be able to register
|
| services.synapse-auto-compressor.settings.chunk_size | The number of state groups to work on at once
|
| services.hddfancontrol.settings.<drive-bay-name>.logVerbosity | Verbosity of the log level
|
| services.system76-scheduler.settings.cfsProfiles.responsive.latency | sched_latency_ns.
|
| services.openssh.settings.PasswordAuthentication | Specifies whether password authentication is allowed.
|
| services.hercules-ci-agent.settings.concurrentTasks | Number of tasks to perform simultaneously
|
| services.system76-scheduler.settings.cfsProfiles.responsive.preempt | Preemption mode.
|
| services.radicale.config | Radicale configuration, this will set the service
configuration file
|
| services.chhoto-url.settings.disable_frontend | Whether to disable the frontend.
|
| services.prometheus.alertmanagerIrcRelay.settings | Configuration for Alertmanager IRC Relay as a Nix attribute set
|
| services.system76-scheduler.settings.cfsProfiles.responsive.nr-latency | sched_nr_latency.
|
| services.journald.remote.settings.Remote.TrustedCertificateFile | A path to a SSL CA certificate file in PEM format, or all
|
| services.matrix-synapse.settings.listeners.*.resources.*.compress | Whether synapse should compress HTTP responses to clients that support it
|
| services.dovecot2.pluginSettings | Plugin settings for dovecot in general, e.g. sieve, sieve_default, etc
|
| services.filebeat.settings.output.elasticsearch.hosts | The list of Elasticsearch nodes to connect to
|
| virtualisation.xen.store.settings.conflict.burstLimit | Limits applied to domains whose writes cause other domains' transaction
commits to fail
|
| services.sabnzbd.settings.misc.inet_exposure | Restrictions for access from non-local IP addresses
|
| services.grafana.provision.alerting.templates.settings.templates.*.name | Name of the template, must be unique
|
| services.veilid.settings.core.network.routing_table.bootstrap | Host name of existing well-known Veilid bootstrap servers for the network to connect to.
|
| services.grafana.provision.alerting.contactPoints.settings.deleteContactPoints | List of receivers that should be deleted.
|
| services.prometheus.exporters.nginxlog.settings.namespaces | Namespaces to collect the metrics for
|
| services.nezha-agent.settings.skip_procs_count | Do not monitor the number of processes.
|
| services.ergochat.configFile | Path to configuration file
|
| services.nextcloud-spreed-signaling.settings.sessions.hashkeyFile | The path to the file containing the value for sessions.hashkey
|
| services.matrix-synapse.settings.max_upload_size | The largest allowed upload size in bytes
|
| services.firezone.server.settingsSecret.TOKENS_KEY_BASE | A file containing a unique base64 encoded secret for the
TOKENS_KEY_BASE
|
| services.firezone.server.settingsSecret.SECRET_KEY_BASE | A file containing a unique base64 encoded secret for the
SECRET_KEY_BASE
|
| services.livekit.settings.rtc.port_range_start | Start of UDP port range for WebRTC
|
| services.chhoto-url.settings.try_longer_slugs | Whether to try a longer UID upon collision.
|
| services.discourse.siteSettings | Discourse site settings
|
| security.pam.rssh.settings.auth_key_file | Path to file with trusted public keys in OpenSSH's authorized_keys format
|
| services.syncthing.settings.folders.<name>.ignorePatterns | Syncthing can be configured to ignore certain files in a folder using ignore patterns
|
| services.matrix-continuwuity.settings.global.server_name | The server_name is the name of this server
|
| services.kerberos_server.settings.realms.<name>.acl.*.target | The principals that 'access' applies to.
|
| services.nextcloud-spreed-signaling.settings.https.certificate | Path to the certificate used for the HTTPS listener
|
| services.mediagoblin.settings.mediagoblin.sql_engine | Database to use.
|
| services.grafana.provision.alerting.contactPoints.settings.deleteContactPoints.*.uid | Unique identifier for the receiver
|
| services.grafana.provision.dashboards.settings.providers.*.options.path | Path grafana will watch for dashboards
|
| services.easytier.instances.<name>.settings.instance_name | Identify different instances on same host
|
| services.mobilizon.settings.":mobilizon"."Mobilizon.Storage.Repo".database | Name of the database
|
| programs.captive-browser.enable | Whether to enable captive browser, a dedicated Chrome instance to log into captive portals without messing with DNS settings.
|
| services.grafana.provision.alerting.contactPoints.settings.deleteContactPoints.*.orgId | Organization ID, default = 1.
|
| services.hickory-dns.configFile | Path to an existing toml file to configure hickory-dns with
|
| services.maubot.settings.plugin_databases.sqlite | The directory where SQLite plugin databases should be stored.
|
| services.grafana.provision.alerting.templates.settings.deleteTemplates | List of alert rule UIDs that should be deleted.
|
| services.system76-scheduler.settings.processScheduler.useExecsnoop | Use execsnoop (otherwise poll the precess list periodically).
|
| services.simplesamlphp.<name>.settings.baseurlpath | URL where SimpleSAMLphp can be reached.
|
| services.mobilizon.settings.":mobilizon".":instance".email_from | The email for the From: header in emails
|
| services.nextcloud.settings.trusted_proxies | Trusted proxies, to provide if the nextcloud installation is being
proxied to secure against e.g. spoofing.
|
| services.nextcloud.settings.trusted_domains | Trusted domains, from which the nextcloud installation will be
accessible
|
| services.nextcloud-spreed-signaling.settings.sessions.blockkeyFile | The path to the file containing the value for sessions.blockkey
|
| services.mobilizon.settings.":mobilizon"."Mobilizon.Storage.Repo".username | User used to connect to the database
|
| services.nextcloud-spreed-signaling.settings.stats.allowed_ips | List of IP addresses that are allowed to access the debug, stats and metrics endpoints
|
| services.headscale.settings.oidc.allowed_domains | Allowed principal domains. if an authenticated user's domain
is not in this list authentication request will be rejected.
|
| services.postfix.settings.main.mynetworks_style | The method used for generating the default value for mynetworks, if that option is unset.
https://www.postfix.org/postconf.5.html#mynetworks_style
|
| services.matrix-conduit.settings.global.trusted_servers | Servers trusted with signing server keys.
|
| services.snapserver.settings.tcp.bind_to_address | Address to listen on for snapclient connections.
|
| services.grafana.settings.users.allow_org_create | Set to false to prohibit users from creating new organizations.
|
| services.nextcloud.settings.mail_smtpmode | Which mode to use for sending mail
|
| services.warpgate.settings.http.sni_certificates | Certificates for additional domains.
|
| services.maubot.settings.server.plugin_base_path | The base path for plugin endpoints
|
| services.mbpfan.settings.general.polling_interval | The polling interval.
|
| services.public-inbox.settings.publicinboxmda.spamcheck | If set to spamc, public-inbox-watch(1) will filter spam
using SpamAssassin.
|
| services.swapspace.settings.lower_freelimit | Lower free-space threshold: if the percentage of free space drops below this number, additional swapspace is allocated
|
| services.system76-scheduler.settings.processScheduler.pipewireBoost.enable | Boost Pipewire client priorities.
|
| services.adguardhome.settings.schema_version | Schema version for the configuration
|
| services.grafana.settings.database.client_key_path | The path to the client key
|
| services.glitchtip.settings.ENABLE_ORGANIZATION_CREATION | When false, only superusers will be able to create new organizations after the first
|
| services.grafana.provision.alerting.templates.settings.deleteTemplates.*.orgId | Organization ID, default = 1.
|
| services.grafana.settings.users.auto_assign_org | Set to true to automatically add new users to the main organization (id 1)
|
| services.veilid.settings.core.protected_store.directory | The filesystem directory to store your protected store in.
|
| services.grafana.provision.datasources.settings.datasources | List of datasources to insert/update.
|
| services.tuned.settings.recommend_command | Whether to enable recommend functionality.
|
| services.quickwit.settings.grpc_listen_port | The port to listen on for gRPC traffic.
|
| services.grafana.settings.server.static_root_path | Root path for static assets.
|
| services.snapserver.settings.http.bind_to_address | Address to listen on for snapclient connections.
|
| services.swapspace.settings.upper_freelimit | Upper free-space threshold: if the percentage of free space exceeds this number, swapspace will attempt to free up swapspace
|
| services.parsedmarc.settings.general.save_aggregate | Save aggregate report data to Elasticsearch and/or Splunk.
|
| services.biboumi.settings.policy_directory | A directory that should contain the policy files,
used to customize Botan’s behaviour
when negotiating the TLS connections with the IRC servers.
|
| services.grafana.settings.security.admin_password | Default admin password
|
| services.minidlna.settings.enable_subtitles | Enable subtitle support on unknown clients.
|
| services.grafana.provision.alerting.templates.settings.deleteTemplates.*.name | Name of the template, must be unique
|
| services.nvme-rs.settings.thresholds.error_threshold | Error count warning threshold
|
| virtualisation.xen.store.settings.conflict.maxHistorySeconds | Limits applied to domains whose writes cause other domains' transaction
commits to fail
|
| services.grafana.provision.datasources.settings.datasources.*.url | Url of the datasource.
|
| services.grafana.settings.users.default_language | This setting configures the default UI language, which must be a supported IETF language tag, such as en-US.
|
| services.system76-scheduler.settings.processScheduler.refreshInterval | Process list poll interval, in seconds
|
| services.warpgate.settings.http.sni_certificates.*.key | Path to private key.
|
| services.parsedmarc.settings.elasticsearch.password | The password to use when connecting to Elasticsearch,
if required
|
| services.grafana.settings.users.viewers_can_edit | Viewers can access and use Explore and perform temporary edits on panels in dashboards they have access to
|
| services.minidlna.settings.notify_interval | The interval between announces (in seconds)
|
| services.kerberos_server.settings.includedir | Directories containing files to include in the Kerberos configuration.
|
| services.parsedmarc.settings.elasticsearch.cert_path | The path to a TLS certificate bundle used to verify
the server's certificate.
|
| services.searx.limiterSettings | Limiter settings for SearXNG.
|
| services.firezone.server.settingsSecret.RELEASE_COOKIE | A file containing a unique secret identifier for the Erlang
cluster
|
| services.nextcloud.settings.mail_smtpsecure | This depends on mail_smtpmode
|
| services.headscale.settings.database.postgres.password_file | A file containing the password corresponding to
database.user.
|
| services.grafana.settings.database.isolation_level | Only the MySQL driver supports isolation levels in Grafana
|
| services.grafana.provision.datasources.settings.datasources.*.name | Name of the datasource
|
| services.grafana.provision.datasources.settings.datasources.*.type | Datasource type
|
| services.matrix-appservice-irc.settings.ircService.passwordEncryptionKeyPath | Location of the key with which IRC passwords are encrypted
for storage
|
| services.maubot.configMutable | Whether maubot should write updated config into extraConfigFile. This will make your Nix module settings have no effect besides the initial config, as extraConfigFile takes precedence over NixOS settings!
|
| services.system76-scheduler.settings.cfsProfiles.responsive.bandwidth-size | sched_cfs_bandwidth_slice_us.
|
| virtualisation.containers.containersConf.settings | containers.conf configuration
|
| services.matrix-synapse.settings.media_store_path | Directory where uploaded images and attachments are stored.
|
| services.matrix-synapse.settings.max_image_pixels | Maximum number of pixels that will be thumbnailed
|
| services.matrix-synapse.settings.signing_key_path | Path to the signing key to sign messages with.
|
| services.headscale.settings.derp.update_frequency | Frequency to update DERP maps.
|
| services.tor.relay.onionServices.<name>.settings.HiddenServiceNumIntroductionPoints | See torrc manual.
|
| services.grafana.provision.alerting.templates.settings.templates.*.template | Alerting with a custom text template
|
| services.snapserver.settings.stream.bind_to_address | Address to listen on for snapclient connections.
|
| services.tor.settings.VersioningAuthoritativeDirectory | See torrc manual.
|
| services.undervolt.useTimer | Whether to set a timer that applies the undervolt settings every 30s
|
| services.firezone.server.settingsSecret.LIVE_VIEW_SIGNING_SALT | A file containing a unique base64 encoded secret for the
LIVE_VIEW_SIGNING_SALT
|
| services.swapspace.settings.cache_elasticity | Percentage of cache space considered to be "free"
|
| services.system76-scheduler.settings.cfsProfiles.default.wakeup-granularity | sched_wakeup_granularity_ns.
|
| services.grafana.provision.datasources.settings.datasources.*.uid | Custom UID which can be used to reference this datasource in other parts of the configuration, if not specified will be generated automatically.
|
| services.matrix-synapse.settings.listeners.*.bind_addresses | IP addresses to bind the listener to.
|
| services.grafana.provision.datasources.settings.datasources.*.jsonData | Extra data for datasource plugins.
|
| services.btrbk.instances.<name>.settings.stream_compress | Compress the btrfs send stream before transferring it from/to remote locations using a
compression command.
|
| console.useXkbConfig | If set, configure the virtual console keymap from the xserver
keyboard settings.
|
| services.maubot.settings.plugin_databases.postgres | The connection URL for plugin database
|
| services.grafana.provision.datasources.settings.deleteDatasources | List of datasources that should be deleted from the database.
|
| services.firezone.server.settingsSecret.COOKIE_SIGNING_SALT | A file containing a unique base64 encoded secret for the
COOKIE_SIGNING_SALT
|
| programs.chromium.initialPrefs | Initial preferences are used to configure the browser for the first run
|
| services.matrix-conduit.settings.global.allow_federation | Whether this server federates with other servers.
|
| services.matrix-tuwunel.settings.global.allow_federation | Whether this server federates with other servers.
|
| services.livekit.ingress.settings.rtc_config.port_range_end | End of UDP port range for WebRTC
|
| services.healthchecks.settings.REGISTRATION_OPEN | A boolean that controls whether site visitors can create new accounts
|
| services.postgresql.settings.log_line_prefix | A printf-style string that is output at the beginning of each log line
|
| services.headscale.settings.noise.private_key_path | Path to noise private key file, generated automatically if it does not exist.
|
| services.nextcloud-spreed-signaling.settings.backend.backendtype | Type of backend configuration
|
| services.dependency-track.settings."alpine.oidc.user.provisioning" | Specifies if mapped OpenID Connect accounts are automatically created upon successful
authentication
|
| services.easytier.instances.<name>.settings.network_secret | EasyTier network credential used for verification and
encryption
|
| services.kerberos_server.settings.realms.<name>.acl.*.principal | Which principal the rule applies to
|
| services.hickory-dns.settings.listen_addrs_ipv4 | List of ipv4 addresses on which to listen for DNS queries.
|
| services.hickory-dns.settings.listen_addrs_ipv6 | List of ipv6 addresses on which to listen for DNS queries.
|
| services.matrix-tuwunel.settings.global.trusted_servers | Servers listed here will be used to gather public keys of other servers
(notary trusted key servers)
|
| services.grafana.settings.database.client_cert_path | The path to the client cert
|
| services.kerberos_server.settings.realms.<name>.acl.*.access | The changes the principal is allowed to make.
The "all" permission does not imply the "get-keys" permission
|
| services.grafana.settings.security.allow_embedding | When false, the HTTP header X-Frame-Options: deny will be set in Grafana HTTP responses
which will instruct browsers to not allow rendering Grafana in a <frame>, <iframe>, <embed> or <object>
|
| services.matrix-conduit.settings.global.max_request_size | Max request size in bytes
|
| services.matrix-tuwunel.settings.global.max_request_size | Max request size in bytes
|
| services.snapserver.settings.tcp-control.bind_to_address | Address to listen on for snapclient connections.
|
| services.grafana.provision.datasources.settings.datasources.*.access | Access mode. proxy or direct (Server or Browser in the UI)
|
| services.grafana.provision.datasources.settings.deleteDatasources.*.orgId | Organization ID of the datasource to delete.
|
| services.grafana.provision.datasources.settings.deleteDatasources.*.name | Name of the datasource to delete.
|
| services.tlsrpt.reportd.settings.organization_name | Name of the organization sending out the reports.
|
| services.omnom.settings.smtp.connection_timeout | Connection timeout duration in seconds.
|
| services.headscale.settings.derp.server.private_key_path | Path to derp private key file, generated automatically if it does not exist.
|
| security.apparmor.killUnconfinedConfinables | Whether to enable killing of processes which have an AppArmor profile enabled
(in security.apparmor.policies)
but are not confined (because AppArmor can only confine new processes)
|
| services.nextcloud.settings.mail_smtptimeout | This depends on mail_smtpmode
|
| services.nipap.settings.auth.auth_cache_timeout | Seconds to store cached auth entries for.
|
| services.sftpgo.settings.httpd.bindings.*.enable_web_admin | Enable the built-in web admin for this interface binding.
|
| services.matrix-conduit.settings.global.database_backend | The database backend for the service
|
| services.nvme-rs.settings.email.smtp_password_file | File containing SMTP password
|
| services.omnom.settings.smtp.tls_allow_insecure | Whether to enable Whether to allow insecure TLS..
|
| services.matrix-tuwunel.settings.global.allow_encryption | Whether new encrypted rooms can be created
|
| services.matrix-conduit.settings.global.allow_encryption | Whether new encrypted rooms can be created
|
| services.openssh.settings.KbdInteractiveAuthentication | Specifies whether keyboard-interactive authentication is allowed.
|
| services.searx.faviconsSettings | Favicons settings for SearXNG.
|
| services.grafana.settings.database.server_cert_name | The common name field of the certificate used by the mysql or postgres server
|
| security.auditd.settings.admin_space_left | This is a numeric value in mebibytes (MiB) that tells the audit daemon when to perform a configurable action because the system is running
low on disk space
|
| services.biboumi.settings.realname_from_jid | Whether the realname and username of each biboumi
user will be extracted from their JID
|
| services.filesender.settings.log_facilities | Defines where FileSender logging is sent
|
| services.headscale.settings.database.sqlite.write_ahead_log | Enable WAL mode for SQLite
|
| services.matrix-continuwuity.settings.global.database_path | Path to the continuwuity database, the directory where continuwuity will save its data
|
| services.maubot.settings.plugin_directories | Plugin directory paths
|
| services.snipe-it.nginx | With this option, you can customize the nginx virtualHost settings.
|
| services.prometheus.alertmanager-ntfy.settings.ntfy.notification.tags | Tags to add to ntfy.sh messages
|
| services.grafana.settings.security.cookie_samesite | Sets the SameSite cookie attribute and prevents the browser from sending this cookie along with cross-site requests
|
| services.maubot.settings.plugin_directories.load | The directories from which plugins should be loaded
|
| services.grafana.provision.datasources.settings.datasources.*.editable | Allow users to edit datasources from the UI.
|
| services.swapspace.settings.buffer_elasticity | Percentage of buffer space considered to be "free"
|
| services.public-inbox.settings.publicinboxwatch.watchspam | If set, mail in this maildir will be trained as spam and
deleted from all watched inboxes
|
| services.mediagoblin.settings.mediagoblin.email_debug_mode | Disable email debug mode to start sending outgoing mails
|
| services.prometheus.alertmanager-ntfy.settings.ntfy.notification.tags.*.tag | The tag to add
|
| services.prometheus.exporters.fritz.settings.devices.*.password_file | Path to a file which contains the password to authenticate with the target device
|
| programs.ryzen-monitor-ng.enable | Whether to enable ryzen_monitor_ng, a userspace application for setting and getting Ryzen SMU (System Management Unit) parameters via the ryzen_smu kernel driver
|
| services.nezha-agent.settings.disable_send_query | Disable sending TCP/ICMP/HTTP requests.
|
| services.postfix.settings.main.message_size_limit | Maximum size of an email message in bytes.
https://www.postfix.org/postconf.5.html#message_size_limit
|
| services.mpd.settings.playlist_directory | The directory where MPD stores playlists
|
| services.public-inbox.settings.publicinboxwatch.spamcheck | If set to spamc, public-inbox-watch(1) will filter spam
using SpamAssassin.
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.enable | Boost foreground process priorities.
(And de-boost background ones)
|
| services.maubot.settings.plugin_directories.upload | The directory where uploaded new plugins should be stored.
|
| services.snapserver.settings.tcp-streaming.bind_to_address | Address to listen on for snapclient connections.
|
| services.matrix-tuwunel.settings.global.unix_socket_perms | The default permissions (in octal) to create the UNIX socket with.
|
| services.maubot.settings.plugin_directories.trash | The directory where old plugin versions and conflicting plugins should be moved
|
| services.matrix-tuwunel.settings.global.unix_socket_path | Listen on a UNIX socket at the specified path
|
| services.etebase-server.settings.allowed_hosts.allowed_host1 | The main host that is allowed access.
|
| services.system76-scheduler.settings.cfsProfiles.responsive.wakeup-granularity | sched_wakeup_granularity_ns.
|
| services.grafana.settings.security.x_xss_protection | Set to true to enable the X-XSS-Protection header,
which tells browsers to stop pages from loading when they detect reflected cross-site scripting (XSS) attacks.
Note: this is the default in Grafana, it's turned off here
since it's recommended to not use this header anymore.
|
| services.nextcloud.settings.mail_from_address | FROM address that overrides the built-in sharing-noreply and lostpassword-noreply FROM addresses
|
| services.dendrite.settings.mscs.database.connection_string | Database for exerimental MSC's.
|
| services.warpgate.settings.ssh.inactivity_timeout | How long can user be inactive until Warpgate terminates the connection.
|
| services.mobilizon.settings.":mobilizon"."Mobilizon.Storage.Repo".socket_dir | Path to the postgres socket directory
|
| services.xray.enable | Whether to run xray server
|
| services.sftpgo.settings.httpd.bindings.*.enable_web_client | Enable the built-in web client for this interface binding.
|
| services.nvme-rs.settings.check_interval_secs | Check interval in seconds
|
| services.nextcloud.settings.skeletondirectory | The directory where the skeleton files are located
|
| services.warpgate.settings.ssh.keepalive_interval | If nothing is received from the client for this amount of time, server will send a keepalive message.
|
| services.monica.nginx | With this option, you can customize the nginx virtualHost settings.
|
| security.agnos.settings.accounts.*.private_key_path | Path of the PEM-encoded private key for this account
|
| services.livekit.ingress.settings.rtc_config.use_external_ip | When set to true, attempts to discover the host's public IP via STUN
|
| virtualisation.xen.store.settings.conflict.rateLimitIsAggregate | If the conflict.rateLimitIsAggregate option is true, then after each
tick one point of conflict-credit is given to just one domain: the
one at the front of the queue
|
| services.listmonk.database.settings."privacy.domain_blocklist" | E-mail addresses with these domains are disallowed from subscribing.
|
| services.zitadel.extraSettingsPaths | A list of paths to extra settings files
|
| services.stash.settings.gallery_cover_regex | Regex used to identify images as gallery covers
|
| services.stash.settings.preview_exclude_end | Duration of start of video to exclude when generating previews
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.background.nice | Niceness.
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.foreground.nice | Niceness.
|
| services.libeufin.bank.settings.libeufin-bank.SUGGESTED_WITHDRAWAL_EXCHANGE | Exchange that is suggested to wallets when withdrawing
|
| services.nextcloud.settings.mail_sendmailmode | For smtp, the sendmail binary is started with the parameter -bs: Use the SMTP protocol on standard input and output
|
| services.grafana.provision.datasources.settings.datasources.*.secureJsonData | Datasource specific secure configuration
|
| services.grafana.settings.database.conn_max_lifetime | Sets the maximum amount of time a connection may be reused
|
| services.grafana.settings.users.auto_assign_org_id | Set this value to automatically add new users to the provided org
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.background.prio | CPU scheduler priority.
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.foreground.prio | CPU scheduler priority.
|
| services.livekit.ingress.settings.rtc_config.port_range_start | Start of UDP port range for WebRTC
|
| services.minio.configDir | The config directory, for the access keys and other settings.
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.background.ioPrio | IO scheduler priority.
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.foreground.ioPrio | IO scheduler priority.
|
| services.firezone.server.settingsSecret.COOKIE_ENCRYPTION_SALT | A file containing a unique base64 encoded secret for the
COOKIE_ENCRYPTION_SALT
|
| services.buffyboard.configFile | Path to an INI format configuration file to provide Buffyboard
|
| services.mollysocket.settings.allowed_endpoints | List of UnifiedPush servers
|
| services.headscale.settings.oidc.strip_email_domain | Whether the domain part of the email address should be removed when generating namespaces.
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.background.class | CPU scheduler class.
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.foreground.class | CPU scheduler class.
|
| services.nextcloud.settings.overwriteprotocol | Force Nextcloud to always use HTTP or HTTPS i.e. for link generation
|
| services.prometheus.alertmanager-ntfy.settings.ntfy.notification.topic | Note: when using ntfy.sh and other public instances
it is recommended to set this option to an empty string and set the actual topic via
services.prometheus.alertmanager-ntfy.extraConfigFiles since
the topic in ntfy.sh is essentially a password
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.foreground.ioClass | IO scheduler class.
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.background.ioClass | IO scheduler class.
|
| services.stash.settings.sequential_scanning | Modifies behaviour of the scanning functionality to generate support files (previews/sprites/phash) at the same time as fingerprinting/screenshotting
|
| services.crab-hole.settings.blocklist.include_subdomains | Whether to enable Include subdomains.
|
| services.cgit.<name>.repos | cgit repository settings, see cgitrc(5)
|
| services.headscale.settings.oidc.client_secret_path | Path to OpenID Connect client secret file
|
| services.prometheus.alertmanager-ntfy.settings.ntfy.notification.priority | The ntfy.sh message priority (see https://docs.ntfy.sh/publish/#message-priority for more information)
|
| services.mobilizon.settings.":mobilizon".":instance".email_reply_to | The email for the Reply-To: header in emails
|
| services.matrix-synapse.settings.turn_shared_secret | The shared secret used to compute passwords for the TURN server
|
| services.matrix-conduit.settings.global.allow_registration | Whether new users can register on this server.
|
| services.nextcloud-spreed-signaling.settings.clients.internalsecretFile | The path to the file containing the value for clients.internalsecret
|
| services.dnscrypt-proxy2.configFile | Path to TOML config file
|
| services.prometheus.alertmanager-ntfy.settings.ntfy.notification.templates.title | The ntfy.sh message title template.
|
| services.warpgate.settings.http.sni_certificates.*.certificate | Path to certificate.
|
| services.borgmatic.settings.source_directories | List of source directories and files to backup
|
| services.doh-server.settings.ecs_use_precise_ip | If ECS is added to the request, let the full IP address or cap it to 24 or 128 mask
|
| services.movim.secretFile | The secret file to be sourced for the .env settings.
|
| services.dendrite.settings.sync_api.database.connection_string | Database for the Sync API.
|
| services.acme-dns.settings.api.disable_registration | Whether to disable the HTTP registration endpoint.
|
| services.grafana.settings.analytics.reporting_enabled | When enabled Grafana will send anonymous usage statistics to stats.grafana.org
|
| services.postfix.settings.main.recipient_delimiter | Set of characters used as the delimiters for address extensions
|
| services.prometheus.alertmanager-ntfy.settings.ntfy.notification.tags.*.condition | The condition under which this tag should be added
|
| services.cross-seed.useGenConfigDefaults | Whether to use the option defaults from the configuration generated by
cross-seed gen-config
|
| services.matrix-continuwuity.settings.global.allow_federation | Whether this server federates with other servers.
|
| services.pgbouncer.settings.pgbouncer.default_pool_size | How many server connections to allow per user/database pair
|
| services.lldap.settings.ldap_user_pass_file | Path to a file containing the default admin password
|
| services.dependency-track.settings."alpine.oidc.team.synchronization" | This option will ensure that team memberships for OpenID Connect users are dynamic and
synchronized with membership of OpenID Connect groups or assigned roles
|
| services.matrix-continuwuity.settings.global.trusted_servers | Servers listed here will be used to gather public keys of other servers
(notary trusted key servers)
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.background.matchers | Process matchers.
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.foreground.matchers | Process matchers.
|
| services.matrix-continuwuity.settings.global.max_request_size | Max request size in bytes
|
| services.dendrite.settings.media_api.database.connection_string | Database for the Media API.
|
| services.dendrite.settings.relay_api.database.connection_string | Database for the Relay Server.
|
| services.maubot.settings.plugin_databases.postgres_opts | Overrides for the default database_opts when using a non-default postgres connection URL.
|
| services.matrix-synapse.settings.enable_registration | Enable registration for new users.
|
| services.matrix-synapse.settings.dynamic_thumbnails | Whether to generate new thumbnails on the fly to precisely match
the resolution requested by the client
|
| services.grafana.settings.analytics.check_for_updates | When set to false, disables checking for new versions of Grafana from Grafana's GitHub repository
|
| services.matrix-synapse.settings.trusted_key_servers | The trusted servers to download signing keys from.
|
| services.matrix-tuwunel.settings.global.allow_registration | Whether new users can register on this server
|
| services.headscale.settings.derp.auto_update_enabled | Whether to automatically update DERP maps on a set frequency.
|
| services.lasuite-docs.collaborationServer.settings.COLLABORATION_SERVER_ORIGIN | Origins allowed to connect to the collaboration server
|
| services.matrix-continuwuity.settings.global.allow_encryption | Whether new encrypted rooms can be created
|
| services.cgit.<name>.gitHttpBackend.enable | Whether to bypass cgit and use git-http-backend for HTTP clones
|
| services.lasuite-docs.collaborationServer.settings.COLLABORATION_BACKEND_BASE_URL | URL to the backend server base
|
| services.invidious.extraSettingsFile | A file including Invidious settings
|
| services.chhoto-url.settings.cache_control_header | The Cache-Control header to send.
|
| services.peertube.settings.video_transcription.enabled | Enable automatic transcription of videos.
|
| networking.networkmanager.ensureProfiles.secrets.entries.*.matchUuid | UUID of the connection profile
UUIDs are assigned once on connection creation and should never change as long as the connection still applies to the same network.
|
| services.quorum.genesis | Blockchain genesis settings.
|
| services.cloud-init.config | raw cloud-init configuration
|
| security.agnos.settings.accounts.*.certificates.*.key_output_file | Output path for the certificate private key
|
| services.grafana.settings.plugins.preinstall_disabled | When set to true, disables the Background Plugin Installer, which runs before Grafana starts
|
| services.matrix-synapse.settings.url_preview_enabled | Is the preview URL API enabled? If enabled, you must specify an
explicit url_preview_ip_range_blacklist of IPs that the spider is
denied from accessing.
|
| services.dependency-track.database.type | h2 database is not recommended for a production setup.
postgresql this settings it recommended for production setups.
manual the module doesn't handle database settings.
|
| services.jellyfin.forceEncodingConfig | Whether to overwrite Jellyfin's encoding.xml configuration file on each service start
|
| programs.captive-browser.browser | The shell (/bin/sh) command executed once the proxy starts
|
| services.grafana.settings.users.verify_email_enabled | Require email validation before sign up completes.
|
| services.pgbouncer.settings.pgbouncer.max_client_conn | Maximum number of client connections allowed
|
| services.grafana.settings.database.transaction_retries | This setting applies to sqlite3 only and controls the number of times the system retries a transaction when the database is locked.
|
| services.dendrite.settings.key_server.database.connection_string | Database for the Key Server (for end-to-end encryption).
|
| services.gatus.configFile | Path to the Gatus configuration file
|
| services.grafana.settings.server.serve_from_sub_path | Serve Grafana from subpath specified in the root_url setting
|
| services.matrix-synapse.settings.macaroon_secret_key | Secret key for authentication tokens
|
| services.grafana.settings.users.auto_assign_org_role | The role new users will be assigned for the main organization (if the auto_assign_org setting is set to true).
|
| services.kmscon.useXkbConfig | Whether to configure keymap from xserver keyboard settings.
|
| services.matrix-continuwuity.settings.global.unix_socket_perms | The default permissions (in octal) to create the UNIX socket with.
|
| services.nextcloud.settings.mail_template_class | Replaces the default mail template layout
|
| services.dendrite.settings.room_server.database.connection_string | Database for the Room Server.
|
| services.szurubooru.server.settings.delete_source_files | Whether to delete thumbnails and source files on post delete.
|
| services.authelia.instances.<name>.settings.default_2fa_method | Default 2FA method for new users and fallback for preferred but disabled methods.
|
| services.stash.settings.notifications_enabled | If we should send notifications to the desktop
|
| services.stash.settings.preview_exclude_start | Duration of end of video to exclude when generating previews
|
| services.synapse-auto-compressor.settings.chunks_to_compress | chunks_to_compress chunks of size chunk_size will be compressed
|
| services.buffyboard.settings.quirks.fbdev_force_refresh | If true and using the framebuffer backend, this triggers a display refresh after every draw operation
|
| services.fediwall.nginx | Allows customizing the nginx virtualHost settings
|
| services.scrutiny.settings.web.influxdb.tls.insecure_skip_verify | Whether to enable skipping TLS verification when connecting to InfluxDB.
|
| services.jitsi-meet.config | Client-side web application settings that override the defaults in config.js
|
| services.movim.h2o.tls.recommendations | By default, H2O, without prejudice, will use as many TLS versions &
cipher suites as it & the TLS library (OpenSSL) can support
|
| services.matrix-synapse.settings.tls_private_key_path | PEM encoded private key for TLS
|
| services.pipewire.wireplumber.extraScripts | Additional scripts for WirePlumber to be used by configuration files
|
| services.nezha-agent.settings.skip_connection_count | Do not monitor the number of connections.
|
| services.chhoto-url.settings.allow_capital_letters | Whether to allow capital letters in slugs.
|
| services.matrix-continuwuity.settings.global.unix_socket_path | Listen on a UNIX socket at the specified path
|
| services.agorakit.nginx | With this option, you can customize the nginx virtualHost settings.
|
| services.librenms.nginx | With this option, you can customize the nginx virtualHost settings.
|
| services.nezha-agent.settings.use_ipv6_country_code | Use ipv6 countrycode to report location.
|
| services.prometheus.alertmanager-ntfy.settings.ntfy.notification.templates.description | The ntfy.sh message description template.
|
| services.litellm.settings.environment_variables | Environment variables to pass to the Lite
|
| services.grafana.settings.security.csrf_trusted_origins | List of additional allowed URLs to pass by the CSRF check
|
| services.rmfakecloud.extraSettings | Extra settings in the form of a set of key-value pairs
|
| services.xonotic.settings.sv_termsofservice_url | URL for the Terms of Service for playing on your server.
|
| services.artalk.allowModify | allow Artalk store the settings to config file persistently
|
| services.h2o.hosts | The hosts config to be merged with the settings
|
| services.nsd.zones | Define your zones here
|
| services.warpgate.settings.ssh.host_key_verification | Specify host key verification action when connecting to a SSH target with unknown/differing host key.
|
| services.postfix.settings.main.smtpd_tls_chain_files | List of paths to the server private keys and certificates.
The order of items matters and a private key must always be followed by the corresponding certificate.
https://www.postfix.org/postconf.5.html#smtpd_tls_chain_files
|
| services.peertube.settings.video_transcription.engine_path | Custom engine path for local transcription.
|
| services.doh-server.settings.log_guessed_client_ip | Enable log IP from HTTPS-reverse proxy header: X-Forwarded-For or X-Real-IP
Note: http uri/useragent log cannot be controlled by this config
|
| services.matrix-synapse.settings.tls_certificate_path | PEM encoded X509 certificate for TLS
|
| services.nextcloud-spreed-signaling.settings.backend.connectionsperhost | Maximum number of concurrent backend connections per host
|
| services.h2o.hosts.<name>.tls.recommendations | By default, H2O, without prejudice, will use as many TLS versions &
cipher suites as it & the TLS library (OpenSSL) can support
|
| services.tuned.ppdSettings | Settings for TuneD's power-profiles-daemon compatibility service.
|
| services.cgit.<name>.gitHttpBackend.checkExportOkFiles | Whether git-http-backend should only export repositories that contain a git-daemon-export-ok file
|
| services.nextcloud.settings.default_phone_region | An ISO 3166-1
country code which replaces automatic phone-number detection
without a country code
|
| services.jupyter.user | Name of the user used to run the jupyter service
|
| services.stash.settings.write_image_thumbnails | Write image thumbnails to disk when generating on the fly
|
| services.slskd.settings.remote_file_management | Whether to enable modification of share contents through the web ui.
|
| services.dolibarr.h2o.tls.recommendations | By default, H2O, without prejudice, will use as many TLS versions &
cipher suites as it & the TLS library (OpenSSL) can support
|
| services.matrix-continuwuity.settings.global.allow_registration | Whether new users can register on this server
|
| services.bluemap.maps | Settings for files in maps/
|
| services.doh-server.configFile | The config file for the doh-server
|
| services.deepin.dde-daemon.enable | Whether to enable daemon for handling the deepin session settings.
|
| services.mobilizon.settings.":mobilizon"."Mobilizon.Web.Endpoint".has_reverse_proxy | Whether you use a reverse proxy
|
| services.opendkim.keyPath | The path that opendkim should put its generated private keys into
|
| services.maubot.settings.server.override_resource_path | Override path from where to load UI resources.
|
| services.anuko-time-tracker.nginx | With this option, you can customize the Nginx virtualHost settings.
|
| services.pgbouncer.settings.pgbouncer.max_db_connections | Do not allow more than this many server connections per database (regardless of user)
|
| services.mediagoblin.settings.mediagoblin.allow_registration | Whether to enable user self registration
|
| services.biboumi.settings.persistent_by_default | Whether all rooms will be persistent by default:
the value of the “persistent” option in the global configuration of each
user will be “true”, but the value of each individual room will still
default to false
|
| services.sabnzbd.configFile | Path to config file (deprecated, use settings instead and set this value to null)
|
| services.dendrite.settings.federation_api.database.connection_string | Database for the Federation API.
|
| services.crab-hole.configFile | The config file of crab-hole
|
| services.matrix-synapse.settings.trusted_key_servers.*.server_name | Hostname of the trusted server.
|
| services.veilid.settings.core.network.detect_address_changes | Should veilid-core detect and notify on network address changes?
|
| services.h2o.defaultTLSRecommendations | By default, H2O, without prejudice, will use as many TLS versions &
cipher suites as it & the TLS library (OpenSSL) can support
|
| fonts.fontconfig.localConf | System-wide customization file contents, has higher priority than
defaultFonts settings.
|
| services.newt.blueprint | Blueprint for declarative settings, see Newt Blueprint docs for more information.
|
| services.biboumi.settings.realname_customization | Whether the users will be able to use
the ad-hoc commands that lets them configure
their realname and username.
|
| services.bookstack.nginx | With this option, you can customize the nginx virtualHost settings.
|
| services.coturn.realm | The default realm to be used for the users when no explicit
origin/realm relationship was found in the database, or if the TURN
server is not using any database (just the commands-line settings
and the userdb file)
|
| services.xandikos.nginx.enable | Configure the nginx reverse proxy settings.
|
| services.timekpr.adminUsers | All listed users will become part of the timekpr group so they can manage timekpr settings without requiring sudo.
|
| services.grav.systemSettings | Settings written to user/config/system.yaml.
|
| services.sourcehut.settings."hg.sr.ht".clone_bundle_threshold | .hg/store size (in MB) past which the nightly job generates clone bundles.
|
| services.dendrite.settings.app_service_api.database.connection_string | Database for the Appservice API.
|
| services.longview.apiKey | Longview API key
|
| services.dendrite.settings.user_api.device_database.connection_string | Database for the User API, devices.
|
| services.dendrite.settings.client_api.registration_disabled | Whether to disable user registration to the server
without the shared secret.
|
| services.graphite.web.extraConfig | Graphite webapp settings
|
| services.geoclue2.appConfig | Specify extra settings per application.
|
| services.nextcloud.settings.mail_smtpstreamoptions | This depends on mail_smtpmode
|
| services.nezha-agent.settings.disable_command_execute | Disable executing the command from dashboard.
|
| services.akkoma.config | Configuration for Akkoma
|
| services.longview.apiKeyFile | A file containing the Longview API key
|
| services.headscale.settings.tls_letsencrypt_listen | When HTTP-01 challenge is chosen, letsencrypt must set up a
verification endpoint, and it will be listening on:
:http = port 80.
|
| services.grafana.settings.analytics.feedback_links_enabled | Set to false to remove all feedback links from the UI.
|
| services.postfix.settings.main.smtp_tls_security_level | The client TLS security level.
Use dane with a local DNSSEC validating DNS resolver enabled.
https://www.postfix.org/postconf.5.html#smtp_tls_security_level
|
| boot.isNspawnContainer | Whether the machine is running in an nspawn container
|
| services.factorio.saveName | The name of the savegame that will be used by the server
|
| services.mailman.webSettings | Overrides for the default mailman-web Django settings.
|
| services.bonsaid.configFile | Path to a .json file specifying the state transitions
|
| services.dendrite.settings.user_api.account_database.connection_string | Database for the User API, accounts.
|
| services.cyrus-imap.cyrusSettings | Cyrus configuration settings
|
| services.cyrus-imap.imapdSettings | IMAP configuration settings
|
| services.mediagoblin.settings.mediagoblin.email_sender_address | Email address which notices are sent from.
|
| services.neo4j.extraServerConfig | Extra configuration for Neo4j Community server
|
| services.hardware.lcd.server.usbGroup | The group to use for settings permissions
|
| services.trilium-server.nginx.enable | Configure the nginx reverse proxy settings.
|
| services.grafana.settings.security.x_content_type_options | Set to false to disable the X-Content-Type-Options response header
|
| services.matrix-synapse.log | Default configuration for the loggers used by matrix-synapse and its workers
|
| services.davis.database.urlFile | A file containing the database connection url
|
| services.cpupower-gui.enable | Enables dbus/systemd service needed by cpupower-gui
|
| services.journald.rateLimitBurst | Configures the rate limiting burst limit (number of messages per
interval) that is applied to all messages generated on the system
|
| services.stash.settings.preview_segment_duration | Preview segment duration, in seconds
|
| services.bluemap.coreSettings | Settings for the core.conf file, see upstream docs.
|
| hardware.cpu.amd.ryzen-smu.enable | Whether to enable ryzen_smu, a linux kernel driver that exposes access to the SMU (System Management Unit) for certain AMD Ryzen Processors
|
| services.kanidm.unix.settings.kanidm.pam_allowed_login_groups | Kanidm groups that are allowed to login using PAM.
|
| services.pgbouncer.settings.pgbouncer.max_user_connections | Do not allow more than this many server connections per user (regardless of database)
|
| services.grafana.settings.security.csrf_additional_headers | List of allowed headers to be set by the user
|
| services.postfix.settings.main.smtpd_tls_security_level | The server TLS security level
|
| services.chhoto-url.settings.custom_landing_directory | The path of a directory which contains a custom landing page.
|
| services.hardware.bolt.enable | Whether to enable Bolt, a userspace daemon to enable
security levels for Thunderbolt 3 on GNU/Linux
|
| services.matrix-conduit.settings.global.allow_check_for_updates | Whether to allow Conduit to automatically contact
https://conduit.rs hourly to check for important Conduit news
|
| services.chhoto-url.settings.public_mode_expiry_delay | The maximum expiry delay in seconds to force in public mode.
|
| services.sitespeed-io.runs | A list of run configurations
|
| services.bitlbee.extraSettings | Will be inserted in the Settings section of the config file.
|
| services.cloudlog.extraConfig | Any additional text to be appended to the config.php
configuration file
|
| services.grafana.settings.security.content_security_policy | Set to true to add the Content-Security-Policy header to your requests
|
| services.radicale.rights | Configuration for Radicale's rights file
|
| services.nomad.extraSettingsPaths | Additional settings paths used to configure nomad
|
| hardware.nvidia.nvidiaSettings | Whether to enable nvidia-settings, NVIDIA's GUI configuration tool
.
|
| services.filesender.settings.storage_filesystem_path | When using storage type filesystem this is the absolute path to the file system where uploaded files are stored until they expire
|
| services.minetest-server.config | Settings to add to the minetest config file
|
| services.syncthing.configDir | The path where the settings and keys will exist.
|
| services.doh-server.settings.ecs_allow_non_global_ip | By default, non global IP addresses are never forwarded to upstream servers
|
| services.kanidm.serverSettings | Settings for Kanidm, see
the documentation
and example configuration
for possible values.
|
| services.matrix-synapse.settings.app_service_config_files | A list of application service config file to use
|
| i18n.inputMethod.fcitx5.plasma6Support | Use qt6 versions of fcitx5 packages
|
| services.headscale.settings.tls_letsencrypt_hostname | Domain name to request a TLS certificate for.
|
| services.tuned.settings.default_instance_priority | Default instance (unit) priority.
|
| security.agnos.settings.accounts.*.certificates.*.fullchain_output_file | Output path for the full chain including the acquired certificate
|
| services.mattermost.environmentFile | Environment file (see systemd.exec(5)
"EnvironmentFile=" section for the syntax) which sets config options
for mattermost (see the Mattermost documentation)
|
| services.postgresql.settings.shared_preload_libraries | List of libraries to be preloaded.
|
| services.nextcloud.settings.mail_send_plaintext_only | Email will be sent by default with an HTML and a plain text body
|
| services.portunus.seedSettings | Seed settings for users and groups
|
| services.bluemap.webappSettings | Settings for the webapp.conf file, see upstream docs.
|
| services.logstash.extraSettings | Extra Logstash settings in YAML format.
|
| services.mediawiki.extraConfig | Any additional text to be appended to MediaWiki's
LocalSettings.php configuration file
|
| services.warpgate.settings.http.trust_x_forwarded_headers | Trust X-Forwarded-* headers
|
| services.snipe-it.config | Snipe-IT configuration options to set in the
.env file
|
| users.users.<name>.linger | Whether to enable or disable lingering for this user
|
| programs.opengamepadui.powerstation.enable | Whether to enable Run PowerStation service for TDP control and performance settings.
.
|
| services.apcupsd.configText | Contents of the runtime configuration file, apcupsd.conf
|
| services.matrix-synapse.settings.url_preview_url_blacklist | Optional list of URL matches that the URL preview spider is
denied from accessing.
|
| services.buffyboard.settings.quirks.ignore_unused_terminals | If true, buffyboard won't automatically update the layout of a new terminal and
draw the keyboard, if the terminal is not opened by any process
|
| services.grafana.settings.analytics.check_for_plugin_updates | When set to false, disables checking for new versions of installed plugins from https://grafana.com
|
| services.olivetin.extraConfigFiles | Config files to merge into the settings defined in services.olivetin.settings
|
| services.mailman.enablePostfix | Enable Postfix integration
|
| services.btrbk.extraPackages | Extra packages for btrbk, like compression utilities for stream_compress.
Note: This option will get deprecated in future releases
|
| services.github-runners.<name>.user | User under which to run the service
|
| services.pfix-srsd.configurePostfix | Whether to configure the required settings to use pfix-srsd in the local Postfix instance.
|
| services.veilid.settings.core.protected_store.allow_insecure_fallback | If we can't use system-provided secure storage, should we proceed anyway?
|
| environment.wvdial.pppDefaults | Default ppp settings for wvdial.
|
| services.openldap.mutableConfig | Whether to allow writable on-line configuration
|
| services.grafana.settings.security.strict_transport_security | Set to true if you want to enable HTTP Strict-Transport-Security (HSTS) response header
|
| services.foundationdb.tls | FoundationDB Transport Security Layer (TLS) settings.
|
| services.tinc.networks.<name>.extraConfig | Extra lines to add to the tinc service configuration file
|
| services.yarr.environmentFile | Environment file for specifying additional settings such as secrets
|
| services.gitlab-runner.configFile | Configuration file for gitlab-runner.
configFile takes precedence over services.
checkInterval and concurrent will be ignored too
|
| services.libvirtd.autoSnapshot.vms | If specified only the list of VMs will be snapshotted else all existing one
|
| services.jitsi-meet.interfaceConfig | Client-side web-app interface settings that override the defaults in interface_config.js
|
| services.schleuder.listDefaults | Default settings for lists (list-defaults.yml)
|
| services.filebeat.inputs | Inputs specify how Filebeat locates and processes input data
|
| services.stash.settings.video_file_naming_algorithm | Hash algorithm to use for generated file naming
|
| services.flexget.systemScheduler | When true, execute the runs via the flexget-runner.timer
|
| services.multipath.overrides | This section defines values for attributes that should override the
device-specific settings for all devices.
|
| services.matrix-synapse.settings.registration_shared_secret | If set, allows registration by anyone who also has the shared
secret, even if registration is otherwise disabled
|
| services.monica.config | monica configuration options to set in the
.env file
|
| users.extraUsers.<name>.linger | Whether to enable or disable lingering for this user
|
| services.oink.domains | List of attribute sets containing configuration for each domain
|
| services.librespeed.secrets | Attribute set of filesystem paths
|
| services.lldap.settings.force_ldap_user_pass_reset | Force reset of the admin password
|
| services.wgautomesh.settings.upnp_forward_external_port | Public port number to try to redirect to this machine's Wireguard
daemon using UPnP IGD.
|
| services.matrix-continuwuity.settings.global.allow_announcements_check | If enabled, continuwuity will send a simple GET request periodically to
https://continuwuity.org/.well-known/continuwuity/announcements for any new announcements made.
|
| services.prometheus.remoteWrite.*.sigv4 | Configures AWS Signature Version 4 settings.
|
| services.yggdrasil.configFile | A file which contains JSON or HJSON configuration for yggdrasil
|
| services.factorio.extraSettingsFile | File, which is dynamically applied to server-settings.json before
startup
|
| services.postgresql.systemCallFilter | Configures the syscall filter for postgresql.service
|
| services.pgbouncer.settings.pgbouncer.ignore_startup_parameters | By default, PgBouncer allows only parameters it can keep track of in startup packets:
client_encoding, datestyle, timezone and standard_conforming_strings
|
| services.grafana.settings.database.locking_attempt_timeout_sec | For mysql, if the migrationLocking feature toggle is set,
specify the time (in seconds) to wait before failing to lock the database for the migrations.
|
| hardware.openrazer.batteryNotifier | Settings for device battery notifications.
|
| services.mattermost.preferNixConfig | If both mutableConfig and this option are set, the Nix configuration
will take precedence over any settings configured in the server
console.
|
| services.prosody.muc.*.tombstoneExpiry | This settings controls how long a tombstone is considered
valid
|
| i18n.extraLocaleSettings | A set of additional system-wide locale settings other than LANG
which can be configured with i18n.defaultLocale
|
| services.grafana.settings.security.data_source_proxy_whitelist | Define a whitelist of allowed IP addresses or domains, with ports,
to be used in data source URLs with the Grafana data source proxy
|
| services.asterisk.useTheseDefaultConfFiles | Sets these config files to the default content
|
| services.komodo-periphery.extraSettings | Extra settings to add to the generated TOML config.
|
| services.packagekit.vendorSettings | Additional settings passed straight through to Vendor.conf
|
| services.bluemap.webserverSettings | Settings for the webserver.conf file, usually not required.
See upstream docs.
|
| services.postsrsd.configurePostfix | Whether to configure the required settings to use postsrsd in the local Postfix instance.
|
| services.clamav.clamonacc.enable | Whether to enable ClamAV on-access scanner
|
| services.stash.settings.create_image_clip_from_videos | Create Image Clips from Video extensions when Videos are disabled in Library
|
| services.akkoma.initDb.enable | Whether to automatically initialise the database on startup
|
| services.cryptpad.configureNginx | Configure Nginx as a reverse proxy for Cryptpad
|
| services.agorakit.config | Agorakit configuration options to set in the
.env file
|
| services.pufferpanel.environment | Environment variables to set for the service
|
| services.rathole.credentialsFile | Path to a TOML file to be merged with the settings
|
| services.bookstack.config | BookStack configuration options to set in the
.env file
|
| virtualisation.appvm.enable | This enables AppVMs and related virtualisation settings.
|
| services.netbird.useRoutingFeatures | Enables settings required for NetBird's routing features: Network Resources, Network Routes & Exit Nodes
|
| services.nginx.recommendedTlsSettings | Enable recommended TLS settings.
|
| services.postfix-tlspol.configurePostfix | Whether to configure the required settings to use postfix-tlspol in the local Postfix instance.
|
| services.foundationdb.locality | FoundationDB locality settings.
|
| services.easytier.instances.<name>.configFile | Path to easytier config file
|
| services.veilid.settings.core.protected_store.always_use_insecure_storage | Should we bypass any attempt to use system-provided secure storage?
|
| services.printing.cups-pdf.instances.<name>.confFileText | This will contain the contents of cups-pdf.conf for this instance, derived from settings
|
| services.librenms.environmentFile | File containing env-vars to be substituted into the final config
|
| services.filebeat.modules | Filebeat modules provide a quick way to get started
processing common log formats
|
| services.metricbeat.modules | Metricbeat modules are responsible for reading metrics from the various sources
|
| services.sanoid.datasets.<name>.recursive | Whether to recursively snapshot dataset children
|
| services.grafana.settings.security.disable_initial_admin_creation | Disable creation of admin user on first start of Grafana.
|
| services.apache-kafka.configFiles.serverProperties | Kafka server.properties configuration file path
|
| services.dendrite.settings.global.trusted_third_party_id_servers | Lists of domains that the server will trust as identity
servers to verify third party identifiers such as phone
numbers and email addresses
|
| services.karakeep.extraEnvironment | Environment variables to pass to Karakaeep
|
| services.nginx.recommendedGzipSettings | Enable recommended gzip settings
|
| services.privoxy.inspectHttps | Whether to configure Privoxy to inspect HTTPS requests, meaning all
encrypted traffic will be filtered as well
|
| services.matrix-synapse.settings.url_preview_ip_range_blacklist | List of IP address CIDR ranges that the URL preview spider is denied
from accessing.
|
| services.matrix-synapse.settings.url_preview_ip_range_whitelist | List of IP address CIDR ranges that the URL preview spider is allowed
to access even if they are specified in url_preview_ip_range_blacklist.
|
| virtualisation.lxc.bridgeConfig | This is the config file for override lxc-net bridge default settings.
|
| services.biboumi.credentialsFile | Path to a configuration file to be merged with the settings
|
| services.headscale.settings.tls_letsencrypt_challenge_type | Type of ACME challenge to use, currently supported types:
HTTP-01 or TLS-ALPN-01.
|
| services.sunshine.applications | Configuration for applications to be exposed to Moonlight
|
| services.listmonk.database.mutableSettings | Database settings will be reset to the value set in this module if this is not enabled
|
| services.displayManager.dms-greeter.configFiles | List of DankMaterialShell configuration files to copy into the greeter
data directory at /var/lib/dms-greeter
|
| services.discourse.backendSettings | Additional settings to put in the
discourse.conf file
|
| services.nginx.recommendedZstdSettings | Enable recommended zstd settings
|
| services.nginx.recommendedUwsgiSettings | Whether to enable recommended uwsgi settings if a vhost does not specify the option manually.
|
| services.nginx.recommendedProxySettings | Whether to enable recommended proxy settings if a vhost does not specify the option manually.
|
| services.xserver.displayManager.sx.enable | Whether to enable the "sx" pseudo-display manager, which allows users
to start manually via the "sx" command from a vt shell
|
| services.easytier.instances.<name>.extraSettings | Extra settings to add to easytier-‹name›.toml.
|
| services.nextcloud.configureRedis | Whether to configure Nextcloud to use the recommended Redis settings for small instances.
The Nextcloud system check recommends to configure either Redis or Memcache for file lock caching.
The notify_push app requires Redis to be configured
|
| services.stash.settings.show_one_time_moved_notification | Whether a small notification to inform the user that Stash will no longer show a terminal window, and instead will be available in the tray
|
| services.opencloud.environment | Extra environment variables to set for the service
|
| services.mattermost.mutableConfig | Whether the Mattermost config.json is writeable by Mattermost
|
| services.prometheus.remoteRead.*.tls_config | Configures the remote read request's TLS settings.
|
| services.crossfire-server.configFiles | Text to append to the corresponding configuration files
|
| services.opencloud.environmentFile | An environment file as defined in systemd.exec(5)
|
| services.nginx.recommendedBrotliSettings | Enable recommended brotli settings
|
| services.maubot.settings.plugin_databases.postgres_max_conns_per_plugin | Maximum number of connections per plugin instance.
|
| services.prometheus.remoteWrite.*.tls_config | Configures the remote write request's TLS settings.
|
| services.firezone.server.provision.accounts | All accounts to provision
|
| services.weblate.configurePostgresql | Whether to enable and configure a local PostgreSQL server by creating a user and database for weblate
|
| services.yggdrasil.openMulticastPort | Whether to open the UDP port used for multicast peer discovery
|
| services.dovecot2.imapsieve.mailbox.*.name | This setting configures the name of a mailbox for which administrator scripts are configured
|
| services.easytier.instances.<name>.configServer | Configure the instance from config server
|
| virtualisation.graphics | Whether to run QEMU with a graphics window, or in nographic mode
|
| services.grafana.settings.users.user_invite_max_lifetime_duration | The duration in time a user invitation remains valid before expiring
|
| services.dnscrypt-proxy2.upstreamDefaults | Whether to base the config declared in services.dnscrypt-proxy2.settings on the upstream example config (https://github.com/DNSCrypt/dnscrypt-proxy/blob/master/dnscrypt-proxy/example-dnscrypt-proxy.toml)
Disable this if you want to declare your dnscrypt config from scratch.
|
| services.nginx.experimentalZstdSettings | Enable alpha quality zstd module with recommended settings
|
| services.grafana.settings.security.strict_transport_security_preload | Set to true to enable HSTS preloading option
|
| services.librenms.distributedPoller.enable | Configure this LibreNMS instance as a distributed poller
|
| services.dysnomia.extraContainerProperties | An attribute set providing additional container settings in addition to the default properties
|
| services.headscale.settings.ephemeral_node_inactivity_timeout | Time before an inactive ephemeral node is deleted.
|
| services.tailscale.useRoutingFeatures | Enables settings required for Tailscale's routing features like subnet routers and exit nodes
|
| services.crowdsec-firewall-bouncer.createRulesets | Whether to have the module create the appropriate firewall configuration
based on the bouncer settings
|
| services.frp.instances.<name>.environmentFiles | List of paths files that follows systemd environmentfile structure
|
| services.mastodon.configureNginx | Configure nginx as a reverse proxy for mastodon
|
| services.prometheus.scrapeConfigs.*.tls_config | Configures the scrape request's TLS settings.
|
| networking.wireless.userControlled.enable | Allow normal users to control wpa_supplicant through wpa_gui or wpa_cli
|
| services.stash.settings.dangerous_allow_public_without_auth | Learn more at https://docs.stashapp.cc/networking/authentication-required-when-accessing-stash-from-the-internet/
|
| services.archisteamfarm.ipcSettings | Settings to write to IPC.config
|
| networking.wireless.userControlled | Allow users of the wpa_supplicant group to control wpa_supplicant
through wpa_gui or wpa_cli
|
| services.bitwarden-directory-connector-cli.ldap | Options to configure the LDAP connection
|
| services.bitwarden-directory-connector-cli.sync | Options to configure what gets synced
|
| services.centrifugo.environmentFiles | Files to load environment variables from
|
| virtualisation.rosetta.enable | Whether to enable Rosetta support
|
| virtualisation.libvirtd.onBoot | Specifies the action to be done to / on the guests when the host boots
|
| services.nghttpx.backends.*.params.affinity | If "ip" is given, client IP based session affinity is
enabled
|
| services.nginx.recommendedOptimisation | Enable recommended optimisation settings.
|
| services.grafana.settings.security.content_security_policy_report_only | Set to true to add the Content-Security-Policy-Report-Only header to your requests
|
| services.grafana.settings.security.disable_brute_force_login_protection | Set to true to disable brute force login protection.
|
| services.grafana.settings.security.strict_transport_security_subdomains | Set to true to enable HSTS includeSubDomains option
|
| virtualisation.containerd.configFile | Path to containerd config file
|
| services.davis.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.davis.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.movim.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.slskd.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.slskd.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.movim.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.snipe-it.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.snipe-it.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.transmission.credentialsFile | Path to a JSON file to be merged with the settings
|
| services.akkoma.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.gancio.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.fluidd.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.fluidd.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.gancio.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.akkoma.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.matomo.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.matomo.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.monica.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.monica.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| networking.networkmanager.enable | Whether to use NetworkManager to obtain an IP address and other
configuration for all network interfaces that are not manually
configured
|
| services.fluent-bit.configurationFile | Fluent Bit configuration
|
| services.prometheus.alertmanager-ntfy.extraConfigFiles | Config files to merge into the settings defined in services.prometheus.alertmanager-ntfy.settings
|
| services.xserver.desktopManager.surf-display.screensaverSettings | Screensaver settings, see man 1 xset for possible options.
|
| services.radicle.httpd.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.radicle.httpd.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.prometheus.exporters.ecoflow.scrapingInterval | Scrapping interval in seconds
|
| services.dolibarr.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.agorakit.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.librenms.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.kanboard.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.fediwall.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.librenms.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.kanboard.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.fediwall.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.agorakit.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.dolibarr.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.mainsail.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.pixelfed.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.pixelfed.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.mainsail.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| qt.platformTheme | Selects the platform theme to use for Qt applications
|
| services.zabbixWeb.nginx.virtualHost.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.zabbixWeb.nginx.virtualHost.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.anuko-time-tracker.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.anuko-time-tracker.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.bookstack.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.bookstack.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.jirafeau.nginxConfig.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.jirafeau.nginxConfig.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.grafana.settings.security.strict_transport_security_max_age_seconds | Sets how long a browser should cache HSTS in seconds
|
| services.nginx.virtualHosts.<name>.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.nginx.virtualHosts.<name>.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.fedimintd.<name>.nginx.config.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.fedimintd.<name>.nginx.config.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| virtualisation.oci-containers.containers.<name>.podman | Podman-specific settings in OCI containers
|
| services.limesurvey.nginx.virtualHost.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.limesurvey.nginx.virtualHost.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| virtualisation.lxd.recommendedSysctlSettings | Enables various settings to avoid common pitfalls when
running containers requiring many file operations
|
| services.misskey.reverseProxy.webserver.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.misskey.reverseProxy.webserver.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.transmission.performanceNetParameters | Whether to enable tweaking of kernel parameters
to open many more connections at the same time
|
| networking.networkmanager.ensureProfiles.secrets.entries.*.matchType | NetworkManager connection type
The NetworkManager configuration settings reference roughly corresponds to connection types
|
| services.stash.settings.security_tripwire_accessed_from_public_internet | Learn more at https://docs.stashapp.cc/networking/authentication-required-when-accessing-stash-from-the-internet/
|
| services.changedetection-io.environmentFile | Securely pass environment variables to changedetection-io
|
| services.prometheus.scrapeConfigs.*.http_sd_configs.*.tls_config | Configures the scrape request's TLS settings.
|
| virtualisation.oci-containers.containers.<name>.capabilities | Capabilities to configure for the container
|
| services.hostapd.radios.<name>.networks.<name>.authentication.mode | Selects the authentication mode for this AP.
- "none": Don't configure any authentication
|
| services.prometheus.scrapeConfigs.*.consul_sd_configs.*.tls_config | Configures the Consul request's TLS settings.
|