| services.authelia.instances.<name>.settingsFiles | Here you can provide authelia with configuration files or directories
|
| services.authelia.instances.<name>.name | Name is used as a suffix for the service name, user, and group
|
| services.authelia.instances | Multi-domain protection currently requires multiple instances of Authelia
|
| services.authelia.instances.<name>.environmentVariables | Additional environment variables to provide to authelia
|
| services.authelia.instances.<name>.settings | Your Authelia config.yml as a Nix attribute set
|
| services.authelia.instances.<name>.settings.theme | The theme to display.
|
| services.authelia.instances.<name>.settings.log.level | Level of verbosity for logs.
|
| services.authelia.instances.<name>.settings.log.format | Format the logs are written as.
|
| services.authelia.instances.<name>.settings.server.address | The address to listen on.
|
| services.authelia.instances.<name>.settings.log.file_path | File path where the logs will be written
|
| services.mobilizon.settings.":mobilizon".":instance".name | The fallback instance name if not configured into the admin UI
|
| services.authelia.instances.<name>.settings.log.keep_stdout | Whether to also log to stdout when a file_path is defined.
|
| services.authelia.instances.<name>.settings.telemetry.metrics.enabled | Enable Metrics.
|
| services.authelia.instances.<name>.settings.telemetry.metrics.address | The address to listen on for metrics
|
| services.printing.cups-pdf.instances.<name>.settings | Settings for a cups-pdf instance, see the descriptions in the template config file in the cups-pdf package
|
| services.anubis.instances.<name>.settings.BIND | The address that Anubis listens to
|
| services.grafana-to-ntfy.settings.ntfyBAuthUser | The ntfy-sh user to use for authenticating with the ntfy-sh instance
|
| services.frp.instances.<name>.settings | Frp configuration, for configuration options
see the example of client
or server on github.
|
| services.btrbk.instances.<name>.settings | configuration options for btrbk
|
| services.cryptpad.settings | Cryptpad configuration settings
|
| services.easytier.instances.<name>.settings | Settings to generate easytier-‹name›.toml
|
| services.anubis.instances.<name>.policy.settings | Additional policy settings merged into the policy file
|
| services.vault-agent.instances.<name>.settings | Free-form settings written directly to the config.json file
|
| services.mobilizon.settings.":mobilizon".":instance".hostname | Your instance's hostname
|
| services.sharkey.settings.url | The full URL that the Sharkey instance will be publically accessible on
|
| services.anubis.instances.<name>.settings | Freeform configuration via environment variables for Anubis
|
| services.pretalx.settings.site.url | The base URI below which your pretalx instance will be reachable.
|
| services.vmalert.instances.<name>.settings | vmalert configuration, passed via command line flags
|
| services.hatsu.settings.HATSU_DOMAIN | The domain name of your instance (eg 'hatsu.local').
|
| services.pds.settings.PDS_HOSTNAME | Instance hostname (base domain name)
|
| services.lemmy.settings.hostname | The domain name of your instance (eg 'lemmy.ml').
|
| services.mobilizon.settings.":mobilizon".":instance".email_from | The email for the From: header in emails
|
| nix.settings.trusted-users | A list of names of users that have additional rights when
connecting to the Nix daemon, such as the ability to specify
additional binary caches, or to import unsigned NARs
|
| services.anubis.instances.<name>.settings.METRICS_BIND | The address Anubis' metrics server listens to
|
| services.easytier.instances.<name>.settings.dhcp | Automatically determine the IPv4 address of this peer based on
existing peers on network.
|
| services.anubis.instances.<name>.settings.TARGET | The reverse proxy target that Anubis is protecting
|
| services.mautrix-meta.instances.<name>.settings | config.yaml configuration as a Nix attribute set
|
| services.easytier.instances.<name>.settings.instance_name | Identify different instances on same host
|
| services.easytier.instances.<name>.configServer | Configure the instance from config server
|
| services.consul-template.instances.<name>.settings | Free-form settings written directly to the config.json file
|
| services.easytier.instances.<name>.settings.peers | Peers to connect initially
|
| services.vmalert.instances.<name>.settings.rule | Path to the files with alerting and/or recording rules.
|
| services.actual.settings.dataDir | Directory under which Actual runs and saves its data
|
| services.kanidm.server.settings.origin | The origin of your Kanidm instance
|
| services.easytier.instances.<name>.settings.ipv4 | IPv4 cidr address of this peer in the virtual network
|
| services.gitea-actions-runner.instances.<name>.settings | Configuration for act_runner daemon
|
| services.printing.cups-pdf.instances.<name>.settings.Spool | spool directory
|
| services.vault-agent.instances.<name>.settings.pid_file | Path to use for the pid file.
|
| services.anubis.instances.<name>.settings.POLICY_FNAME | The policy file to use
|
| services.authelia.instances.<name>.settings.default_2fa_method | Default 2FA method for new users and fallback for preferred but disabled methods.
|
| services.printing.cups-pdf.instances.<name>.settings.Out | output directory;
${HOME} will be expanded to the user's home directory,
${USER} will be expanded to the user name.
|
| services.vault-agent.instances.<name>.settings.template | Template section of vault-agent
|
| services.anubis.instances.<name>.settings.SERVE_ROBOTS_TXT | Whether to serve a default robots.txt that denies access to common AI bots by name and all other
bots by wildcard.
|
| services.anubis.instances.<name>.settings.BIND_NETWORK | The network family that Anubis should bind to
|
| services.printing.cups-pdf.instances.<name>.settings.AnonDirName | path for anonymously created PDF files
|
| services.livekit.settings.redis.address | Host and port used to connect to a redis instance.
|
| services.bluesky-pds.settings.PDS_HOSTNAME | Instance hostname (base domain name)
|
| services.ente.api.settings.apps.public-albums | If you're running a self hosted instance and wish to serve public links,
set this to the URL where your albums web app is running.
|
| services.grafana-to-ntfy.settings.ntfyBAuthPass | The path to the password for the specified ntfy-sh user
|
| services.easytier.instances.<name>.configFile | Path to easytier config file
|
| services.easytier.instances.<name>.settings.hostname | Hostname shown in peer list and web console.
|
| services.vmalert.instances.<name>.settings."notifier.url" | Prometheus Alertmanager URL
|
| services.printing.cups-pdf.instances.<name>.settings.GhostScript | location of GhostScript binary
|
| services.hatsu.settings.HATSU_PRIMARY_ACCOUNT | The primary account of your instance (eg 'example.com').
|
| services.traccar.settings | config.xml configuration as a Nix attribute set
|
| services.cryptpad.settings.httpUnsafeOrigin | This is the URL that users will enter to load your instance
|
| services.public-inbox.settings.coderepo.<name>.cgitUrl | URL of a cgit instance
|
| services.reposilite.settings.basePath | Custom base path for this Reposilite instance
|
| services.anubis.instances.<name>.settings.DIFFICULTY | The difficulty required for clients to solve the challenge
|
| services.pretix.settings.pretix.instance_name | The name of this installation.
|
| services.scrutiny.settings.web.influxdb.port | The port of the InfluxDB instance.
|
| services.printing.cups-pdf.instances.<name>.settings.Anonuser | User for anonymous PDF creation
|
| services.mobilizon.settings.":mobilizon".":instance".email_reply_to | The email for the Reply-To: header in emails
|
| services.consul-template.instances.<name>.settings.pid_file | Path to use for the pid file.
|
| services.vmalert.instances.<name>.settings."datasource.url" | Datasource compatible with Prometheus HTTP API.
|
| services.printing.cups-pdf.instances.<name>.confFileText | This will contain the contents of cups-pdf.conf for this instance, derived from settings
|
| services.radicle.ci.adapters.native.instances.<name>.settings | Configuration of radicle-native-ci
|
| services.scrutiny.settings.web.influxdb.host | IP or hostname of the InfluxDB instance.
|
| services.immich-kiosk.settings.immich_url | URL of the immich instance.
|
| services.anubis.instances.<name>.settings.WEBMASTER_EMAIL | If set, shows a contact email address when rendering error pages
|
| services.anubis.instances.<name>.settings.METRICS_BIND_NETWORK | The network family that the metrics server should bind to
|
| services.consul-template.instances.<name>.settings.template | Template section of consul-template
|
| services.oncall.settings.oncall_host | FQDN for the Oncall instance.
|
| services.radicle.ci.adapters.native.instances.<name>.settings.log | File where radicle-native-ci should write the run log.
|
| services.kanidm.server.settings.domain | The domain that Kanidm manages
|
| services.grafana-image-renderer.settings.rendering.mode | Rendering mode of grafana-image-renderer:
default: Creates on browser-instance
per rendering request.
reusable: One browser instance
will be started and reused for each rendering request.
clustered: allows to precisely
configure how many browser-instances are supposed to be used
|
| services.easytier.instances.<name>.settings.listeners | Listener addresses to accept connections from other peers
|
| services.radicle.ci.adapters.native.instances.<name>.settings.state | Directory where per-run directories are stored.
|
| services.matrix-conduit.settings.global.port | The port Conduit will be running on
|
| services.matrix-tuwunel.settings.global.port | The port(s) tuwunel will be running on
|
| services.anubis.instances.<name>.settings.OG_PASSTHROUGH | Whether to enable Open Graph tag passthrough
|
| services.hedgedoc.settings.allowGravatar | Whether to enable Libravatar as
profile picture source on your instance
|
| services.hddfancontrol.settings | Parameter-sets for each instance of hddfancontrol.
|
| services.h2o.hosts | The hosts config to be merged with the settings
|
| services.easytier.instances.<name>.settings.network_name | EasyTier network name.
|
| services.pretix.settings.memcached.location | The host:port combination or the path to the UNIX socket of a memcached instance
|
| services.radicle.ci.adapters.native.instances.<name>.settings.base_url | Base URL for build logs (mandatory for access from CI broker page).
|
| services.homebridge.settings.description | Description of the homebridge instance.
|
| services.authelia.instances.<name>.user | The name of the user for this authelia instance.
|
| services.btrbk.instances.<name>.settings.stream_compress | Compress the btrfs send stream before transferring it from/to remote locations using a
compression command.
|
| services.easytier.instances.<name>.settings.network_secret | EasyTier network credential used for verification and
encryption
|
| services.authelia.instances.<name>.group | The name of the group for this authelia instance.
|
| services.warpgate.settings.external_host | Configure the domain name of this Warpgate instance
|
| programs.captive-browser.enable | Whether to enable captive browser, a dedicated Chrome instance to log into captive portals without messing with DNS settings.
|
| services.librenms.distributedPoller.enable | Configure this LibreNMS instance as a distributed poller
|
| services.authelia.instances.<name>.enable | Whether to enable Authelia instance.
|
| services.matrix-continuwuity.settings.global.port | The port(s) continuwuity will be running on
|
| services.public-inbox.settings.publicinbox.nntpserver | NNTP URLs to this public-inbox instance
|
| services.public-inbox.settings.publicinbox.pop3server | POP3 URLs to this public-inbox instance
|
| services.public-inbox.settings.publicinbox.imapserver | IMAP URLs to this public-inbox instance
|
| services.biboumi.settings.xmpp_server_ip | The IP address to connect to the XMPP server on
|
| services.mobilizon.settings.":mobilizon"."Mobilizon.Web.Endpoint".url.host | Your instance's hostname for generating URLs throughout the app
|
| services.pfix-srsd.configurePostfix | Whether to configure the required settings to use pfix-srsd in the local Postfix instance.
|
| services.reposilite.settings.compressionStrategy | Compression algorithm used by this instance of Reposilite.
none reduces usage of CPU & memory, but requires transfering more data.
|
| services.easytier.instances.<name>.extraSettings | Extra settings to add to easytier-‹name›.toml.
|
| services.gitea.settings.service.DISABLE_REGISTRATION | By default any user can create an account on this gitea instance
|
| services.prometheus.alertmanager-ntfy.settings.ntfy.baseurl | The base URL of the ntfy.sh instance.
|
| services.postsrsd.configurePostfix | Whether to configure the required settings to use postsrsd in the local Postfix instance.
|
| services.tuned.settings.default_instance_priority | Default instance (unit) priority.
|
| services.frp.instances.<name>.environmentFiles | List of paths files that follows systemd environmentfile structure
|
| services.maubot.settings.server.plugin_base_path | The base path for plugin endpoints
|
| services.cryptpad.configureNginx | Configure Nginx as a reverse proxy for Cryptpad
|
| services.postfix-tlspol.configurePostfix | Whether to configure the required settings to use postfix-tlspol in the local Postfix instance.
|
| services.healthchecks.settings.REGISTRATION_OPEN | A boolean that controls whether site visitors can create new accounts
|
| services.matrix-conduit.settings.global.database_backend | The database backend for the service
|
| services.matrix-synapse.log | Default configuration for the loggers used by matrix-synapse and its workers
|
| services.authelia.instances.<name>.package | The authelia package to use.
|
| services.authelia.instances.<name>.secrets | It is recommended you keep your secrets separate from the configuration
|
| programs.captive-browser.browser | The shell (/bin/sh) command executed once the proxy starts
|
| services.mastodon.configureNginx | Configure nginx as a reverse proxy for mastodon
|
| services.authelia.instances.<name>.secrets.manual | Configuring authelia's secret files via the secrets attribute set
is intended to be convenient and help catch cases where values are required
to run at all
|
| services.authelia.instances.<name>.secrets.jwtSecretFile | Path to your JWT secret used during identity verificaton.
|
| services.authelia.instances.<name>.secrets.oidcHmacSecretFile | Path to your HMAC secret used to sign OIDC JWTs.
|
| services.trickster.instance-id | Instance ID for when running multiple processes (default null).
|
| services.trilium-server.instanceName | Instance name used to distinguish between different instances
|
| services.uwsgi.instance | uWSGI configuration
|
| services.authelia.instances.<name>.secrets.sessionSecretFile | Path to your session secret
|
| services.lifecycled.instanceId | The instance ID to listen for events for.
|
| services.authelia.instances.<name>.secrets.oidcIssuerPrivateKeyFile | Path to your private key file used to encrypt OIDC JWTs.
|
| services.akkoma.config.":pleroma".":instance".name | Instance name.
|
| services.kanidm.provision.instanceUrl | The instance url to which the provisioning tool should connect.
|
| services.akkoma.config.":pleroma".":instance".email | Instance administrator email.
|
| services.authelia.instances.<name>.secrets.storageEncryptionKeyFile | Path to your storage encryption key.
|
| services.transmission.performanceNetParameters | Whether to enable tweaking of kernel parameters
to open many more connections at the same time
|
| services.btrbk.instances | Set of btrbk instances
|
| services.errbot.instances | Errbot instance configs
|
| services.printing.cups-pdf.instances | Permits to raise one or more cups-pdf instances
|
| services.gitea-actions-runner.instances.<name>.name | The name identifying the runner instance towards the Gitea/Forgejo instance.
|
| services.btrbk.instances.<name>.onCalendar | How often this btrbk instance is started
|
| services.printing.cups-pdf.instances.<name>.installPrinter | Whether to enable a CUPS printer queue for this instance
|
| services.vault-agent.instances | Attribute set of vault-agent instances
|
| services.errbot.instances.<name>.dataDir | Data directory for errbot instance.
|
| services.vault-agent.instances.<name>.user | User under which this instance runs.
|
| services.v4l2-relayd.instances.<name>.name | The name of the instance.
|
| services.ytdl-sub.instances.<name>.enable | Whether to enable ytdl-sub instance.
|
| services.vault-agent.instances.<name>.group | Group under which this instance runs.
|
| services.anubis.instances.<name>.enable | Whether to enable this instance of Anubis.
|
| services.akkoma.config.":pleroma".":instance".description | Instance description.
|
| services.prometheus.exporters.varnish.instance | varnishstat -n value.
|
| services.lact.settings | Settings for LACT
|
| services.vault-agent.instances.<name>.enable | Whether to enable this vault-agent instance.
|
| services.v4l2-relayd.instances.<name>.enable | Whether to enable this v4l2-relayd instance.
|
| services.mjolnir.settings | Additional settings (see mjolnir default config for available settings)
|
| services.nitter.settings | Add settings here to override NixOS module generated settings
|
| services.icingaweb2.modules.monitoring.transports.<name>.instance | Assign a icinga instance to this transport
|
| services.easytier.instances.<name>.enable | Enable the instance.
|
| services.consul-template.instances | Attribute set of consul-template instances
|
| services.frp.instances | Frp instances.
|
| services.consul-template.instances.<name>.user | User under which this instance runs.
|
| boot.uki.settings | The configuration settings for ukify
|
| services.gitea-actions-runner.instances.<name>.url | Base URL of your Gitea/Forgejo instance.
|
| nix.package | This option specifies the Nix package instance to use throughout the system.
|
| services.amule.settings | Free form attribute set for aMule settings
|
| services.consul-template.instances.<name>.group | Group under which this instance runs.
|
| services.maubot.settings.plugin_databases.postgres_max_conns_per_plugin | Maximum number of connections per plugin instance.
|
| services.printing.cups-pdf.instances.<name>.enable | Whether to enable this cups-pdf instance.
|
| services.davfs2.settings | Extra settings appended to the configuration of davfs2
|
| services.odoo.settings | Odoo configuration settings
|
| services.gitea-actions-runner.instances.<name>.token | Plain token to register at the configured Gitea/Forgejo instance.
|
| services.consul-template.instances.<name>.enable | Whether to enable this consul-template instance.
|
| services.ncdns.settings | ncdns settings
|
| services.ytdl-sub.instances | Configuration for ytdl-sub instances.
|
| services.v4l2-relayd.instances.<name>.extraPackages | Extra packages to add to GST_PLUGIN_PATH for the instance.
|
| services.sslh.settings | sslh configuration
|
| services.gitea-actions-runner.instances.<name>.enable | Whether to enable Gitea Actions Runner instance.
|
| services.newt.settings | Settings for Newt module, see Newt CLI docs for more information.
|
| services.xray.settings | The configuration object
|
| services.picom.settings | Picom settings
|
| services.marytts.settings | Settings for MaryTTS
|
| services.fcgiwrap.instances.<name>.process.group | Group as which this instance of fcgiwrap will be run.
|
| services.akkoma.config.":pleroma".":instance".upload_dir | Directory where Akkoma will put uploaded files.
|
| services.ntpd-rs.settings | Settings to write to ntp.toml
See https://docs.ntpd-rs.pendulum-project.org/man/ntp.toml.5
for more information about available options.
|
| services.auto-epp.settings | Settings for the auto-epp application
|
| services.fcgiwrap.instances.<name>.process.user | User as which this instance of fcgiwrap will be run
|
| services.rimgo.settings | Settings for rimgo, see the official documentation for supported options.
|
| services.gitea-actions-runner.instances.<name>.tokenFile | Path to an environment file, containing the TOKEN environment
variable, that holds a token to register at the configured
Gitea/Forgejo instance.
|
| services.searx.settings | Searx settings
|
| services.stubby.settings | Content of the Stubby configuration file
|
| services.redlib.settings | See GitHub for available settings.
|
| services.acme-dns.settings | Free-form settings written directly to the acme-dns.cfg file
|
| services.aria2.settings | Generates the aria2.conf file
|
| services.hickory-dns.settings | Settings for hickory-dns
|
| services.movim.settings | .env settings for Movim
|
| services.lldap.settings | Free-form settings written directly to the lldap_config.toml file
|
| services.peertube-runner.instancesToRegister.<name>.url | URL of the PeerTube instance.
|
| services.screego.settings | Screego settings passed as Nix attribute set, they will be merged with
the defaults
|
| services.hercules-ci-agent.settings | These settings are written to the agent.toml file
|
| services.wakapi.settings | Settings for Wakapi
|
| services.logrotate.settings | logrotate freeform settings: each attribute here will define its own section,
ordered by services.logrotate.settings.<name>.priority,
which can either define files to rotate with their settings
or settings common to all further files settings
|
| services.g3proxy.settings | Settings of g3proxy.
|
| services.mailman.settings | Settings for mailman.cfg
|
| services.gokapi.settings | Configuration settings for the generated config json file
|
| services.v4l2-relayd.instances | v4l2-relayd instances to be created.
|
| services.privoxy.settings | This option is mapped to the main Privoxy configuration file
|
| services.h2o.settings | Configuration for H2O (see https://h2o.examp1e.net/configure.html)
|
| services.vmalert.instances | Define multiple instances of vmalert.
|
| services.rauc.slots.<name>.*.settings | Settings for this slot.
|
| services.akkoma.config.":pleroma".":instance".static_dir | Directory of static files
|
| services.pgadmin.settings | Settings for pgadmin4.
Documentation
|
| services.draupnir.settings | Free-form settings written to Draupnir's configuration file
|
| services.sanoid.settings | Free-form settings written directly to the config file
|
| services.tor.settings | See torrc manual
for documentation.
|
| services.fluent-bit.settings | See configurationFile.
configurationFile takes precedence over settings.
|
| services.umurmur.settings | Settings of uMurmur
|
| services.maubot.settings | YAML settings for maubot
|
| services.misskey.settings.db | Database settings.
|
| services.opengfw.settings.io | IO settings.
|
| services.frp.instances.<name>.enable | Whether to enable frp.
|
| services.sssd.settings | Contents of sssd.conf.
|
| services.n8n.settings | Configuration for n8n, see https://docs.n8n.io/hosting/environment-variables/configuration-methods/
for supported values.
|
| services.openbao.settings | Settings of OpenBao
|
| services.opengfw.settings | Settings passed to OpenGFW. Example config
|
| services.kresd.instances | The number of instances to start
|
| services.private-gpt.settings | settings-local.yaml for private-gpt
|
| services.knot.settings | Extra configuration as nix values.
|
| services.pretix.settings | pretix configuration as a Nix attribute set
|
| services.tlp.settings | Options passed to TLP
|
| services.anubis.instances | An attribute set of Anubis instances
|
| services.radicle.ci.adapters.native.instances.<name>.enable | Whether to enable this radicle-native-ci instance.
|
| services.eintopf.settings | Settings to configure web service
|
| services.evremap.settings | Settings for evremap
|
| services.nexus.home | Home directory of the Nexus3 instance.
|
| services.public-inbox.settings | Settings for the public-inbox config file.
|
| services.grafana.settings | Grafana settings
|
| services.easytier.instances | EasyTier instances.
|
| services.bee.settings | Ethereum Swarm Bee configuration
|
| services.apache-kafka.settings | Kafka broker configuration
server.properties
|
| services.lemmy.settings | Lemmy configuration
|
| services.aesmd.settings | AESM configuration
|
| services.stash.settings | Stash configuration
|
| services.frp.instances.<name>.role | The frp consists of client and server
|
| services.ntfy-sh.settings | Configuration for ntfy.sh, supported values are here.
|
| services.turn-rs.settings | Turn-rs server config file
|
| services.suricata.settings | Suricata settings
|
| services.clamsmtp.instances | Instances of clamsmtp to run.
|
| services.fcgiwrap.instances | Configuration for fcgiwrap instances.
|
| services.ifm.settings | Configuration of the IFM service
|
| services.haven.settings | See https://github.com/bitvora/haven for documentation.
|
| services.peertube-runner.instancesToRegister.<name>.runnerName | Runner name declared to the PeerTube instance.
|
| services.zwave-js.settings | Configuration settings for the generated config file
|
| services.pgbackrest.stanzas.<name>.instances | An attribute set of database instances as described in:
https://pgbackrest.org/configuration.html#section-stanza
Each instance defaults to set pg-host to the attribute's name
|
| services.frp.settings | Frp configuration, for configuration options
see the example of client
or server on github.
|
| services.forgejo.settings | Free-form settings written directly to the app.ini configfile file
|
| services.envoy.settings | Specify the configuration for Envoy in Nix.
|
| services.qui.settings.port | The port qui listens on.
|
| services.thinkfan.settings | Thinkfan settings
|
| services.rsync.jobs.<name>.settings | Settings that should be passed to rsync via long options
|
| services.hydra.logo | Path to a file containing the logo of your Hydra instance.
|
| services.wiki-js.settings | Settings to configure wiki-js
|
| services.pantalaimon-headless.instances | Declarative instance config
|
| services.isso.settings | Configuration for isso
|
| services.goss.settings | The global options in config file in yaml format
|
| services.kubo.settings | Attrset of daemon configuration
|
| services.nats.settings | Declarative NATS configuration
|
| services.pdns-recursor.settings | PowerDNS Recursor settings
|
| services.ytdl-sub.instances.<name>.config | Configuration for ytdl-sub
|
| services.dolibarr.settings | Dolibarr settings, see https://github.com/Dolibarr/dolibarr/blob/develop/htdocs/conf/conf.php.example for details.
|
| services.mediamtx.settings | Settings for MediaMTX
|
| services.komga.settings | Komga configuration
|
| services.angrr.settings | Global configuration for angrr in TOML format.
|
| services.dunst.settings | Dunst configuration, see dunst(5)
|
| services.qui.settings.host | The host address qui listens on.
|
| services.zrepl.settings | Configuration for zrepl
|
| services.actual.settings | Server settings, refer to the documentation for available options
|
| services.actkbd.enable | Whether to enable the actkbd key mapping daemon
|
| services.pretalx.settings | pretalx configuration as a Nix attribute set
|
| services.lokinet.settings | Configuration for Lokinet
|
| services.pdfding.backup.enable | Automatic backup of important data to a AWS S3 (or compatible) instance
|
| services.mailpit.instances | Configure mailpit instances
|
| services.canaille.settings | Settings for Canaille
|
| services.nfs.settings | General configuration for NFS daemons and tools
|
| services.errbot.instances.<name>.logLevel | Errbot log level
|
| services.howdy.settings | Howdy configuration file
|
| services.gonic.settings | Configuration for Gonic, see https://github.com/sentriz/gonic#configuration-options for supported values.
|
| services.clatd.settings | Configuration of clatd
|
| services.plikd.settings | Configuration for plikd, see https://github.com/root-gg/plik/blob/master/server/plikd.cfg
for supported values.
|
| services.omnom.settings | Configuration options for the /etc/omnom/config.yml file.
|
| services.slskd.settings | Application configuration for slskd
|
| services.nipap.settings | Configuration options to set in /etc/nipap/nipap.conf.
|
| services.inadyn.settings.custom | Settings for custom DNS providers.
|
| services.cross-seed.settingsFile | Path to a JSON file containing settings that will be merged with the
settings option
|
| services.openssh.settings.Macs | Allowed MACs
Defaults to recommended settings from both
https://stribika.github.io/2015/01/04/secure-secure-shell.html
and
https://infosec.mozilla.org/guidelines/openssh#modern-openssh-67
|
| services.tor.settings.ORPort | See torrc manual.
|
| services.logind.settings.Login | Settings option for systemd-logind
|
| services.mailpit.instances.<name>.smtp | SMTP bind interface and port.
|
| services.nylon.<name>.name | The name of this nylon instance.
|
| services.pds.settings | Environment variables to set for the service
|
| services.grocy.hostName | FQDN for the grocy instance.
|
| services.uhub.<name>.plugins.*.settings | Settings specific to this plugin.
|
| services.cgit.<name>.settings | cgit configuration, see cgitrc(5)
|
| services.karma.settings | Karma dashboard configuration as nix attributes
|
| services.hatsu.settings | Configuration for Hatsu, see
|
| services.gitea.settings | Gitea configuration
|
| services.tuned.settings | Configuration for TuneD
|
| services.uhub.<name>.settings | Configuration of uhub
|
| services.xmrig.settings | XMRig configuration
|
| services.nvme-rs.settings | Configuration for nvme-rs in TOML format
|
| services.pds.settings.PDS_PORT | Port to listen on
|
| services.cockpit.settings | Settings for cockpit that will be saved in /etc/cockpit/cockpit.conf
|
| services.easytier.instances.<name>.environmentFiles | Environment files for this instance
|
| services.kanboard.settings | Customize the default settings, refer to https://github.com/kanboard/kanboard/blob/main/config.default.php
for details on supported values.
|
| services.dendrite.settings | Configuration for dendrite, see:
https://github.com/matrix-org/dendrite/blob/main/dendrite-sample.yaml
for available options with which to populate settings.
|
| services.pixelfed.settings | .env settings for Pixelfed
|
| services.umami.settings.BASE_PATH | Allows you to host Umami under a subdirectory
|
| services.aria2.settings.dir | Directory to store downloaded files.
|
| services.tor.settings.DirPort | See torrc manual.
|
| services.tor.settings.DNSPort | See torrc manual.
|
| services.tor.settings.PidFile | See torrc manual.
|
| services.wiki-js.settings.db.db | Name of the database to use.
|
| services.gatus.settings | Configuration for Gatus
|
| services.ulogd.settings | Configuration for ulogd
|
| services.pgscv.settings | Configuration for pgSCV, in YAML format
|
| services.tempo.settings | Specify the configuration for Tempo in Nix
|
| services.mpd.settings.port | This setting is the TCP port that is desired for the daemon to get assigned
to.
|
| security.agnos.settings | Settings
|
| services.harmonia.settings | Settings to merge with the default configuration
|
| services.crab-hole.settings | Crab-holes config
|
| services.inadyn.settings | See inadyn.conf (5)
|
| services.mbpfan.settings | INI configuration for Mbpfan.
|
| services.errbot.instances.<name>.admins | List of identifiers of errbot admins.
|
| services.anubis.instances.<name>.user | The user under which Anubis is run
|
| services.legit.settings | The primary legit configuration
|
| services.umami.settings | Additional configuration (environment variables) for Umami, see
https://umami.is/docs/environment-variables for supported values.
|
| services.tor.settings.IPv6Exit | See torrc manual.
|
| services.tor.settings.ExtORPort | See torrc manual.
|
| services.tor.settings.GeoIPFile | See torrc manual.
|
| services.wiki-js.settings.port | TCP port the process should listen to.
|
| services.rauc.settings | Rauc configuration that will be converted to INI
|
| services.cloud-init.settings | Structured cloud-init configuration.
|
| services.kismet.settings | Options for Kismet
|
| services.vector.settings | Specify the configuration for Vector in Nix.
|
| services.wiki-js.settings.bindIP | IPs the service should listen to.
|
| services.ntopng.redis.createInstance | Local Redis instance name
|
| services.oink.settings.apiKey | API key to use when modifying DNS records.
|
| services.sabnzbd.settings.ntfosd | NotifyOSD settings
|
| services.rimgo.settings.PORT | The port to use.
|
| services.umami.settings.PORT | The port to listen on.
|
| services.neo4j.readOnly | Only allow read operations from this Neo4j instance.
|
| services.alice-lg.settings | alice-lg configuration, for configuration options see the example on github
|
| services.mautrix-meta.instances | Configuration of multiple mautrix-meta instances.
services.mautrix-meta.instances.facebook and services.mautrix-meta.instances.instagram
come preconfigured with network.mode, appservice.id, bot username, display name and avatar.
|
| services.atticd.settings | Structured configurations of atticd
|
| services.garage.settings | Garage configuration, see https://garagehq.deuxfleurs.fr/documentation/reference-manual/configuration/ for reference.
|
| services.tor.settings.NATDPort | See torrc manual.
|
| services.anubis.instances.<name>.policy | Anubis policy configuration
|
| services.sunshine.settings | Settings to be rendered into the configuration file
|
| services.opengfw.settings.replay | PCAP replay settings.
|
| services.kea.dhcp4.settings | Kea DHCP4 configuration as an attribute set, see https://kea.readthedocs.io/en/kea-3.0.2/arm/dhcp4-srv.html.
|
| services.kea.dhcp6.settings | Kea DHCP6 configuration as an attribute set, see https://kea.readthedocs.io/en/kea-3.0.2/arm/dhcp6-srv.html.
|
| services.stash.settings.port | The port that Stash should listen on.
|
| services.kanidm.server.settings | Settings for Kanidm, see
the documentation
and example configuration
for possible values.
|
| services.dex.settings | The available options can be found in
the example configuration
|
| services.hebbot.settings | Configuration for Hebbot, see, for examples:
|
| services.kavita.settings | Kavita configuration options, as configured in appsettings.json.
|
| services.acme-dns.settings.api.ip | IP to bind the HTTP API on.
|
| services.gancio.settings | Configuration for Gancio, see https://gancio.org/install/config for supported values.
|
| services.dgraph.settings | Contents of the dgraph config
|
| services.rsyncd.settings | Configuration for rsyncd
|
| services.paperless.settings | Extra paperless config options
|
| services.godns.settings | Configuration for GoDNS
|
| services.sympa.settings | The sympa.conf configuration file as key value set
|
| services.anubis.instances.<name>.group | The group under which Anubis is run
|
| services.part-db.settings | Options for part-db configuration
|
| services.acme-dns.settings.api.tls | TLS backend to use.
|
| services.tsidp.settings.port | Port to listen on (default: 443).
|
| services.tor.settings.DirCache | See torrc manual.
|
| services.tor.settings.GeoIPv6File | See torrc manual.
|
| services.stash.settings.host | The ip address that Stash should bind to.
|
| services.ytdl-sub.instances.<name>.readWritePaths | List of paths that ytdl-sub can write to.
|
| services.xray.settingsFile | The absolute path to the configuration file
|
| services.evcc.settings | evcc configuration as a Nix attribute set
|
| services.anubis.instances.<name>.extraFlags | A list of extra flags to be passed to Anubis.
|
| services.paisa.settings.dbFile | Filename of the Paisa database.
|
| services.nvme-rs.settings.email | Email notification configuration
|
| systemd.oomd.settings.OOM | Settings option for systemd-oomd
|
| services.mailpit.instances.<name>.max | Maximum number of emails to keep
|
| services.blocky.settings | Blocky configuration
|
| services.erigon.settings | Configuration for Erigon
Refer to https://github.com/ledgerwatch/erigon#usage for details on supported values.
|
| services.greetd.settings | greetd configuration (documentation)
as a Nix attribute set.
|
| services.gobgpd.settings | GoBGP configuration
|
| services.soft-serve.settings | The contents of the configuration file for soft-serve
|
| services.qdrant.settings | Configuration for Qdrant
Refer to https://github.com/qdrant/qdrant/blob/master/config/config.yaml for details on supported values.
|
| services.gerrit.settings | Gerrit configuration
|
| services.zeyple.settings | Zeyple configuration. refer to
https://github.com/infertux/zeyple/blob/master/zeyple/zeyple.conf.example
for details on supported values.
|
| services.v4l2-relayd.instances.<name>.cardLabel | The name the camera will show up as.
|
| services.neard.settings | Neard INI-style configuration file as a Nix attribute set
|
| programs.nncp.settings | NNCP configuration, see
http://www.nncpgo.org/Configuration.html
|
| services.lemmy.settings.port | Port where lemmy should listen for incoming requests.
|
| services.wiki-js.settings.db.host | Hostname or socket-path to connect to.
|
| services.errbot.instances.<name>.backend | Errbot backend name.
|
| services.phpfpm.settings | PHP-FPM global directives
|
| services.renovate.settings | Renovate's global configuration
|
| services.mympd.settings.ssl | Whether to enable listening on the SSL port
|
| services.qui.settings | qui configuration options
|
| services.tor.settings.HidServAuth | See torrc manual.
|
| services.mopidy.settings | The configuration that Mopidy should use
|
| services.strfry.settings | Configuration options to set for the Strfry service
|
| services.mchprs.settings | Configuration for MCHPRS via Config.toml
|
| services.zenohd.settings | Config options for zenoh.json5 configuration file
|
| services.errbot.instances.<name>.plugins | List of errbot plugin derivations.
|
| services.pds.settings.PDS_DID_PLC_URL | URL of DID PLC directory
|
| services.omnom.settings.db.type | Database type.
|
| services.movim.enable | Whether to enable a Movim instance.
|
| services.nostr-rs-relay.settings | See https://git.sr.ht/~gheartsfield/nostr-rs-relay/#configuration for documentation.
|
| services.stash.settings.cache | Path to cache
|
| services.mailpit.instances.<name>.listen | HTTP bind interface and port for UI.
|
| services.postfix.settings.main | The main.cf configuration file as key value set
|
| services.ananicy.settings | See https://github.com/Nefelim4ag/Ananicy/blob/master/ananicy.d/ananicy.conf
|
| services.radicle.settings | See https://app.radicle.xyz/nodes/seed.radicle.garden/rad:z3gqcJUoA1n9HaHKufZs5FCSGazv5/tree/radicle/src/node/config.rs#L275
|
| services.clight.settings | Additional configuration to extend clight.conf
|
| services.netbox.settings | Configuration options to set in configuration.py
|
| services.sftpgo.settings | The primary sftpgo configuration
|
| services.porn-vault.settings | Configuration for Porn-Vault
|
| services.pghero.settings | PgHero configuration
|
| services.kea.dhcp-ddns.settings | Kea DHCP-DDNS configuration as an attribute set, see https://kea.readthedocs.io/en/kea-3.0.2/arm/ddns.html.
|
| services.zwave-js-ui.settings | Extra environment variables passed to the zwave-js-ui process
|
| services.samba.settings | Configuration file for the Samba suite in ini format
|
| services.listmonk.settings | Static settings set in the config.toml, see https://github.com/knadh/listmonk/blob/master/config.toml.sample for details
|
| services.ente.api.settings.db.port | The database port
|
| services.ente.api.settings.db.host | The database host
|
| services.ente.api.settings.db.user | The database user
|
| services.ente.api.settings.db.name | The database name
|
| services.paisa.settings.dataDir | Path to paisa data directory.
|
| services.tor.settings.ExitRelay | See torrc manual.
|
| services.tor.settings.SOCKSPort | See torrc manual.
|
| services.tor.settings.TransPort | See torrc manual.
|
| services.tor.settings.PerConnBWRate | See torrc manual.
|
| services.pocket-id.settings | Environment variables to be passed
|
| services.aesmd.settings.proxy | HTTP network proxy.
|
| services.aria2.settings.conf-path | Configuration file path.
|
| services.schleuder.settings | Settings for schleuder.yml
|
| services.gitea-actions-runner.instances | Gitea Actions Runner instances.
|
| services.chhoto-url.settings | Configuration of Chhoto URL
|
| services.doh-server.settings | Configuration of doh-server in toml
|
| services.pihole-ftl.settings | Configuration options for pihole.toml
|
| services.opengfw.settings.workers | Worker settings.
|
| services.freeciv.settings | Parameters of freeciv-server.
|
| services.actual.settings.port | The port to listen on
|
| services.kavita.settings.Port | Port to bind to.
|
| services.openssh.settings | Configuration for sshd_config(5).
|
| services.reaction.settings | Configuration for reaction
|
| services.dsnet.settings.IP | The IPv4 address that the server will use on the network
|
| services.taler.settings | Global configuration options for the taler config file
|
| services.uhub.<name>.enable | Whether to enable hub instance.
|
| services.errbot.instances.<name>.extraConfig | String to be appended to the config verbatim
|
| services.acme-dns.settings.api.port | Listen port for the HTTP API.
|
| services.nfs.idmapd.settings | libnfsidmap configuration
|
| services.jitsi-meet.hostName | FQDN of the Jitsi Meet instance.
|
| services.invidious.settings | The settings Invidious should use
|
| services.nominatim.settings | Nominatim configuration settings
|
| services.vault-agent.instances.<name>.package | The vault package to use.
|
| services.slskd.settings.web.port | The HTTP listen port.
|
| services.nvme-rs.settings.email.to | Recipient email address
|
| services.slskd.settings.rooms | Chat rooms to join on startup.
|
| services.tor.settings.AuthDirPinKeys | See torrc manual.
|
| services.dwm-status.settings | Config options for dwm-status, see https://github.com/Gerschtli/dwm-status#configuration
for available options.
|
| services.mealie.settings | Configuration of the Mealie service
|
| services.veilid.settings | Build veilid-server.conf with nix expression
|
| services.go2rtc.settings | go2rtc configuration as a Nix attribute set
|
| services.sftpgo.settings.smtp | SMTP configuration section.
|
| services.litellm.settings | Configuration for LiteLLM
|
| services.dsnet.settings.IP6 | The IPv6 address that the server will use on the network
Leave this empty to let dsnet choose an address.
|
| services.hydra.hydraURL | The base URL for the Hydra webserver instance
|
| services.logrotate.settings.<name>.global | Whether this setting is a global option or not: set to have these
settings apply to all files settings with a higher priority.
|
| services.v4l2-relayd.instances.<name>.input.width | The width to read from input-stream.
|
| services.mysql.replication.serverId | Id of the MySQL server instance
|
| services.llama-swap.settings | llama-swap configuration
|
| services.mympd.settings | Manages the configuration files declaratively
|
| services.artalk.settings.port | Artalk server listen port
|
| services.artalk.settings.host | Artalk server listen host
|
| services.biboumi.settings | See biboumi 9.0
for documentation.
|
| services.tsidp.settings.hostName | The hostname to use for the tsnet node.
|
| services.tor.settings.DirPolicy | See torrc manual.
|
| services.rkvm.server.settings | Structured server daemon configuration
|
| services.rkvm.client.settings | Structured client daemon configuration
|
| services.waagent.settings | The waagent.conf configuration, see https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/agent-linux for documentation.
|
| services.zipline.settings | Configuration of Zipline
|
| services.jboss.serverDir | Location of the server instance files
|
| services.molly-brown.settings | molly-brown configuration
|
| services.nezha-agent.settings.gpu | Enable GPU monitoring.
|
| services.ytdl-sub.instances.<name>.schedule | How often to run ytdl-sub
|
| services.gatus.settings.web.port | The TCP port to serve the Gatus service at.
|
| services.wiki-js.settings.logLevel | Define how much detail is supposed to be logged at runtime.
|
| services.glance.settings | Configuration written to a yaml file that is read by glance
|
| services.artalk.settings | The artalk configuration
|
| services.chhoto-url.settings.port | The port to listen on.
|
| services.zfs.zed.settings | ZFS Event Daemon /etc/zfs/zed.d/zed.rc content
See
zed(8)
for details on ZED and the scripts in /etc/zfs/zed.d to find the possible variables
|
| services.go-csp-collector.settings | Settings for go-csp-collector
|
| services.cross-seed.settings.port | Port the cross-seed daemon listens on.
|
| services.kea.ctrl-agent.settings | Kea Control Agent configuration as an attribute set, see https://kea.readthedocs.io/en/kea-3.0.2/arm/agent.html.
|
| services.homed.settings.Home | Options for systemd-homed
|
| programs.rust-motd.settings | Settings on what to generate
|
| services.vmalert.instances.<name>.rules | A list of the given alerting or recording rules against configured "datasource.url" compatible with
Prometheus HTTP API for vmalert to execute
|
| services.knot.settingsFile | As alternative to settings, you can provide whole configuration
directly in the almost-YAML format of Knot DNS
|
| services.tor.settings.HidServAuth.*.auth | Authentication cookie.
|
| services.nezha-agent.settings.tls | Enable SSL/TLS encryption.
|
| services.tor.settings.PerConnBWBurst | See torrc manual.
|
| services.omnom.settings.smtp.host | SMTP server hostname.
|
| services.postfix.settings.master | The master.cf configuration file as an attribute set of service
defitions
|
| services.errbot.instances.<name>.identity | Errbot identity configuration
|
| services.automx2.settings | Bootstrap json to populate database
|
| services.omnom.settings.smtp.tls | Whether to enable Whether TLS encryption should be used..
|
| services.uptime-kuma.settings | Additional configuration for Uptime Kuma, see
https://github.com/louislam/uptime-kuma/wiki/Environment-Variables
for supported values.
|
| services.movim.domain | Fully-qualified domain name (FQDN) for the Movim instance.
|
| services.nzbget.settings | NZBGet configuration, passed via command line using switch -o
|
| services.phpfpm.pools.<name>.settings | PHP-FPM pool directives
|
| services.autobrr.settings | Autobrr configuration options
|
| services.klipper.settings | Configuration for Klipper
|
| services.readeck.settings | Additional configuration for Readeck, see
https://readeck.org/en/docs/configuration
for supported values.
|
| services.redmine.settings | Redmine configuration (configuration.yml)
|
| services.mchprs.settings.port | Port for the server
|
| services.misskey.settings | Configuration for Misskey, see
example.yml
for all supported options.
|
| services.mchprs.settings.motd | Message of the day
|
| services.zitadel.settings | Contents of the runtime configuration file
|
| services.vikunja.settings | Vikunja configuration
|
| services.grafana-to-ntfy.settings.bauthPass | The path to the password you will use in the Grafana webhook settings.
|
| services.openssh.settings.Ciphers | Allowed ciphers
Defaults to recommended settings from both
https://stribika.github.io/2015/01/04/secure-secure-shell.html
and
https://infosec.mozilla.org/guidelines/openssh#modern-openssh-67
|
| services.clamsmtp.instances.*.listen | Address to wait for incoming SMTP connections on
|
| services.movim.h2o.settings | Attrset to be transformed into YAML for host config
|
| services.displayManager.ly.settings | Extra settings merged in and overwriting defaults in config.ini.
|
| services.omnom.settings.smtp.port | SMTP server port address.
|
| services.mautrix-meta.instances.<name>.dataDir | Path to the directory with database, registration, and other data for the bridge service
|
| services.clamsmtp.instances.*.timeout | Time-out for network connections.
|
| services.paisa.settings | Paisa configuration
|
| services.gitea.settings.log.LEVEL | General log level.
|
| services.doh-server.settings.path | HTTP path for resolve application
|
| services.tor.settings.ExitPolicy | See torrc manual.
|
| services.nvme-rs.settings.email.from | Sender email address
|
| services.pocket-id.settings.APP_URL | The URL where you will access the app.
|
| services.glpiAgent.settings | GLPI Agent configuration options
|
| services.corteza.settings | Configuration for Corteza, will be passed as environment variables
|
| services.orthanc.settings | Configuration written to a json file that is read by orthanc
|
| services.zeronet.settings | zeronet.conf configuration
|
| services.sing-box.settings | The sing-box configuration, see https://sing-box.sagernet.org/configuration/ for documentation
|
| services.nezha-agent.settings | Generate to config.json as a Nix attribute set
|
| services.mpd.settings.db_file | The path to MPD's database.
|
| services.tsidp.settings.localPort | Listen on localhost:.
|
| services.go-httpbin.settings | Configuration of go-httpbin
|
| services.vmalert.instances.<name>.enable | Wether to enable VictoriaMetrics's vmalert.
vmalert evaluates alerting and recording rules against a data source, sends notifications via Alertmanager.
|
| services.gns3-server.settings | The global options in config file in ini format
|
| services.udisks2.settings | Options passed to udisksd
|
| services.clamsmtp.instances.*.header | A header to add to scanned messages
|
| services.easytier.instances.<name>.extraArgs | Extra args append to the easytier command-line.
|
| services.oink.settings.ttl | The TTL ("Time to Live") value to set for your DNS records
|
| services.gancio.settings.db.host | Connection string for the PostgreSQL database
|
| services.omnom.settings.app.debug | Whether to enable debug mode.
|
| services.openbao.settings.ui | Whether to enable the OpenBao web UI.
|
| services.spacecookie.settings | Settings for spacecookie
|
| services.v4l2-relayd.instances.<name>.input.height | The height to read from input-stream.
|
| services.goeland.settings | Configuration of goeland
|
| services.corerad.settings | Configuration for CoreRAD, see https://github.com/mdlayher/corerad/blob/main/internal/config/reference.toml
for supported values
|
| services.merecat.settings | Merecat configuration
|
| services.sharkey.settings | Configuration options for Sharkey
|
| services.sabnzbd.settings | The sabnzbd configuration (see also
sabnzbd's wiki
for extra documentation)
|
| services.packagekit.settings | Additional settings passed straight through to PackageKit.conf
|
| services.kubo.settings.Mounts.MFS | Where to mount the MFS namespace to
|
| services.grocy.phpfpm.settings | Options for grocy's PHPFPM pool.
|
| services.tor.settings.Address | See torrc manual.
|
| services.tor.settings.ClientUseIPv6 | See torrc manual.
|
| services.tor.settings.HSLayer3Nodes | See torrc manual.
|
| services.tor.settings.Sandbox | See torrc manual.
|
| services.tor.settings.HSLayer2Nodes | See torrc manual.
|
| services.tor.settings.ClientUseIPv4 | See torrc manual.
|
| services.tsidp.settings.logLevel | Set logging level: debug, info, warn, error.
|
| services.legit.settings.meta.title | Website title.
|
| services.misskey.settings.db.db | The database name.
|
| services.ente.api.settings | Museum yaml configuration
|
| services.v4l2-relayd.instances.<name>.input.format | The video-format to read from input-stream.
|
| services.clamsmtp.instances.*.action | Action to take when a virus is detected
|
| services.pds.settings.PDS_BSKY_APP_VIEW_DID | DID of bsky frontend
|
| services.freeciv.settings.read | Startup script.
|
| services.sftpgo.settings.smtp.from | From address.
|
| services.sslh.settings.timeout | Timeout in seconds.
|
| services.xonotic.settings | Generates the server.cfg file
|
| services.tuned.settings.daemon | Whether to enable the use of a daemon for TuneD.
|
| services.stash.settings.stash.*.path | location of your media files
|
| services.peertube.settings | Configuration for peertube.
|
| services.quickwit.settings | Quickwit configuration.
|
| services.warpgate.settings | Warpgate configuration.
|
| services.hound.settings | The full configuration of the Hound daemon
|
| services.memos.settings | The environment variables to configure Memos.
At time of writing, there is no clear documentation about possible values
|
| services.tor.settings.HidServAuth.*.onion | Onion address.
|
| services.tor.settings.DirPortFrontPage | See torrc manual.
|
| services.opengfw.settingsFile | Path to file containing OpenGFW settings.
|
| services.mautrix-meta.instances.<name>.enable | Whether to enable Mautrix-Meta, a Matrix <-> Facebook and Matrix <-> Instagram hybrid puppeting/relaybot bridge.
|
| services.dashy.settings | Settings serialized into user-data/conf.yml before build
|
| services.displayManager.sddm.settings | Extra settings merged in and overwriting defaults in sddm.conf.
|
| services.haste-server.settings | Configuration for haste-server
|
| services.zabbixProxy.settings | Zabbix Proxy configuration
|
| services.zabbixAgent.settings | Zabbix Agent configuration
|
| services.clamsmtp.instances.*.xClient | Send the XCLIENT command to the receiving server, for forwarding
client addresses and connection information if the receiving
server supports this feature.
|
| services.pds.settings.PDS_BSKY_APP_VIEW_URL | URL of bsky frontend
|
| services.sftpgo.settings.smtp.user | SMTP username.
|
| services.zitadel.settings.Port | The port that ZITADEL listens on.
|
| services.homebox.settings | The homebox configuration as environment variables
|
| services.bonsaid.settings | State transition definitions
|
| services.unbound.settings | Declarative Unbound configuration
See the unbound.conf(5) manpage for a list of
available options.
|
| services.osquery.settings | Configuration to be written to the osqueryd JSON configuration file
|
| services.glance.settings.pages | List of pages to be present on the dashboard
|
| services.pds.settings.LOG_ENABLED | Enable logging
|
| services.go-httpbin.settings.PORT | The port to listen on.
|
| services.go-httpbin.settings.HOST | The host to listen on.
|
| services.opendkim.settings | Additional opendkim configuration
|
| services.inadyn.settings.provider | Settings for DDNS providers built-in to inadyn
|
| services.oncall.settings | Extra configuration options to append or override
|
| services.lasuite-meet.livekit.settings | Settings to pass to the livekit server
|
| services.scrutiny.settings | Scrutiny settings to be rendered into the configuration file
|
| services.gitea.settings.log.ROOT_PATH | Root path for log files.
|
| services.clamsmtp.instances.*.outAddress | Address of the SMTP server to send email to once it has been
scanned.
|
| services.kimai.sites.<name>.settings | Structural Kimai's local.yaml configuration
|
| services.sharkey.settings.id | The ID generation method for Sharkey to use
|
| services.vmalert.settings | vmalert configuration, passed via command line flags
|
| services.freeciv.settings.auth | Whether to enable server authentication.
|
| services.kubo.settings.Mounts.IPNS | Where to mount the IPNS namespace to
|
| services.dwm-status.settings.order | List of enabled features in order.
|
| services.freeciv.settings.port | Listen for clients on given port
|
| services.kubo.settings.Mounts.IPFS | Where to mount the IPFS namespace to
|
| services.openssh.settings.UsePAM | Whether to enable PAM authentication.
|
| services.tor.settings.TransProxyType | See torrc manual.
|
| services.sftpgo.settings.smtp.port | Port of the SMTP Server.
|
| services.misskey.settings.port | The port your Misskey server should listen on.
|
| services.tor.settings.SocksPolicy | See torrc manual.
|
| services.tor.settings.BridgeRelay | See torrc manual.
|
| services.tor.settings.LongLivedPorts | See torrc manual.
|
| services.sharkey.settings.port | The port that Sharkey will listen on.
|
| services.xonotic.settings.port | The port Xonotic will listen on.
|
| services.grafana-to-ntfy.settings.bauthUser | The user that you will authenticate with in the Grafana webhook settings
|
| services.mysql.settings | MySQL configuration
|
| services.influxdb.settings | Extra configuration options for influxdb
|
| services.crowdsec.settings | Set of various configuration attributes
|
| services.openldap.settings | Configuration for OpenLDAP, in OLC format
|
| services.minidlna.settings | Configuration for minidlna.conf(5).
|
| services.h2o.hosts.<name>.settings | Attrset to be transformed into YAML for host config
|
| services.aria2.settings.enable-rpc | Enable JSON-RPC/XML-RPC server.
|
| services.lxd-image-server.settings | Configuration for lxd-image-server
|
| services.maubot.settings.server | Listener config
|
| services.pdns-recursor.yaml-settings | PowerDNS Recursor settings
|
| services.sonic-server.settings | Sonic Server configuration options
|
| services.misskey.settings.id | The ID generation method to use
|
| services.patroni.settings | The primary patroni configuration
|
| services.livekit.settings | LiveKit configuration file expressed in nix
|
| services.kanidm.unix.settings | Configure Kanidm unix daemon
|
| services.doh-server.settings.tries | Number of tries if upstream DNS fails
|
| services.anubis.instances.<name>.botPolicy | Anubis policy configuration in Nix syntax
|
| services.ente.api.settings.apps.cast | Set this to the URL where your cast page is running
|
| services.hedgedoc.settings | HedgeDoc configuration, see
https://docs.hedgedoc.org/configuration/
for documentation.
|
| services.tor.settings.HTTPTunnelPort | See torrc manual.
|
| services.olivetin.settings | Configuration of OliveTin
|
| services.tor.settings.CookieAuthFile | See torrc manual.
|
| services.tor.settings.AuthDirListBadExits | See torrc manual.
|
| services.routedns.settings | Configuration for RouteDNS, see https://github.com/folbricht/routedns/blob/master/doc/configuration.md
for more information.
|
| services.homer.settings | Settings serialized into config.yml before build
|
| services.stash.settings.stash | Add directories containing your adult videos and images
|
| services.lidarr.settings | Attribute set of arbitrary config options
|
| services.cross-seed.settings | Configuration options for cross-seed
|
| services.sonarr.settings | Attribute set of arbitrary config options
|
| services.radarr.settings | Attribute set of arbitrary config options
|
| services.oink.settings.secretApiKey | Secret API key to use when modifying DNS records.
|
| services.traccar.settingsFile | File used as configuration for traccar
|
| services.fcgiwrap.instances.<name>.socket.user | User to be set as owner of the UNIX socket.
|
| services.fcgiwrap.instances.<name>.socket.type | Socket type: 'unix', 'tcp' or 'tcp6'.
|
| services.v4l2-relayd.instances.<name>.output.format | The video-format to write to output-stream.
|
| services.misskey.settings.db.port | The PostgreSQL port.
|
| services.misskey.settings.db.host | The PostgreSQL host.
|
| services.wg-access-server.settings | See https://www.freie-netze.org/wg-access-server/2-configuration/ for possible options
|
| services.legit.settings.repo.scanPath | Directory where legit will scan for repositories.
|
| services.livekit.settings.port | Main TCP port for RoomService and RTC endpoint.
|
| services.evremap.settings.remap | List of remappings.
|
| services.rimgo.settings.ADDRESS | The address to listen on.
|
| services.step-ca.settings | Settings that go into ca.json
|
| services.sogo.timezone | Timezone of your SOGo instance
|
| services.ergochat.settings | Ergo IRC daemon configuration file.
https://raw.githubusercontent.com/ergochat/ergo/master/default.yaml
|
| services.spotifyd.settings | Configuration for Spotifyd
|
| services.netatalk.settings | Configuration for Netatalk
|
| services.bonsaid.settings.*.type | Type of transition
|
| services.crowdsec.settings.general | Settings for the main CrowdSec configuration file
|
| services.amule.settings.eMule.Port | TCP port for eD2k connections
|
| services.tor.settings.ControlPort | See torrc manual.
|
| services.tor.settings.FetchDirInfoEarly | See torrc manual.
|
| services.tor.settings.ContactInfo | See torrc manual.
|
| services.polaris.settings | Contents for the TOML Polaris config, applied each start
|
| services.wiki-js.settings.db.type | Database driver to use for persistence
|
| services.biboumi.settings.port | The TCP port to use to connect to the local XMPP component.
|
| services.tsidp.settings.enableSts | Enable OAuth token exchange using RFC 8693.
|
| services.pretix.settings.mail.host | Hostname of the SMTP server use for mail delivery.
|
| services.pretix.settings.mail.port | Port of the SMTP server to use for mail delivery.
|
| services.legit.settings.server.host | Host address.
|
| services.legit.settings.server.name | Server name.
|
| services.legit.settings.server.port | Legit port.
|
| services.legit.settings.repo.ignore | Repositories to ignore.
|
| services.grocy.settings.culture | Display language of the frontend.
|
| services.rkvm.server.settings.key | TLS key path.
This should be generated with rkvm-certificate-gen.
|
| services.peroxide.settings | Configuration for peroxide
|
| services.fediwall.settings | Fediwall configuration
|
| services.ferretdb.settings | Additional configuration for FerretDB, see
https://docs.ferretdb.io/configuration/flags/
for supported values.
|
| services.mpd.settings | Configuration for MPD
|
| services.amule.settings.eMule.TempDir | Directory where aMule stores incomplete downloads (.part/.part.met files).
|
| services.inadyn.settings.allow-ipv6 | Whether to get IPv6 addresses from interfaces.
|
| services.misskey.settings.db.user | The user used for database authentication.
|
| services.opengfw.settings.io.sndBuf | Netlink send buffer size.
|
| services.misskey.settings.db.pass | The password used for database authentication.
|
| services.opengfw.settings.io.rcvBuf | Netlink receive buffer size.
|
| services.fcgiwrap.instances.<name>.socket.mode | Mode to be set on the UNIX socket
|
| services.peertube-runner.instancesToRegister.<name>.runnerDescription | Runner description declared to the PeerTube instance.
|
| services.pretix.settings.mail.from | E-Mail address used in the FROM header of outgoing mails.
|
| services.hockeypuck.settings | Configuration file for hockeypuck, here you can override
certain settings (loglevel and
openpgp.db.dsn) by just setting those values
|
| services.freeciv.settings.debug | Set debug log level.
|
| services.legit.settings.repo.readme | Readme files to look for.
|
| services.karma.settings.listen.port | HTTP port to listen on.
|
| services.nipap.settings.nipapd.port | Port to bind nipapd to.
|
| services.tor.settings.V3AuthUseLegacyKey | See torrc manual.
|
| services.resolved.settings.Resolve | Settings option for systemd-resolved
|
| services.gitlab-runner.settings | Global gitlab-runner configuration
|
| services.libeufin.settings | Global configuration options for the libeufin bank system config file.
|
| services.temporal.settings | Temporal configuration
|
| services.sshwifty.settings | Configuration for Sshwifty
|
| services.tsidp.settings.debugTsnet | For development
|
| services.zabbixServer.settings | Zabbix Server configuration
|
| services.wiki-js.settings.offline | Disable latest file updates and enable
sideloading.
|
| services.chhoto-url.settings.db_url | The path of the sqlite database.
|
| services.apache-kafka.settings."log.dirs" | Log file directories.
|
| services.auto-cpufreq.settings | Configuration for auto-cpufreq
|
| services.bluesky-pds.settings | Environment variables to set for the service
|
| services.rathole.settings | Rathole configuration, for options reference
see the example on GitHub
|
| services.frigate.settings | Frigate configuration as a nix attribute set
|
| services.fcgiwrap.instances.<name>.socket.group | Group to be set as owner of the UNIX socket.
|
| services.bluesky-pds.settings.PDS_PORT | Port to listen on
|
| services.nezha-agent.settings.server | Address to the dashboard.
|
| services.zipline.settings.CORE_PORT | The port to listen on.
|
| services.anubis.instances.<name>.policy.extraBots | Additional bot rules appended to the policy
|
| services.komga.settings.server.port | The port that Komga will listen on.
|
| services.legit.settings.dirs.static | Directories where static files are located.
|
| services.omnom.settings.smtp.sender | Omnom sender e-mail.
|
| services.clamsmtp.instances.*.keepAlives | Number of seconds to wait between each NOOP sent to the sending
server. 0 to disable
|
| services.mediagoblin.settings | Settings which are written into mediagoblin.ini.
|
| services.castopod.settings | Environment variables used for Castopod
|
| services.radicale.settings | Configuration for Radicale
|
| services.doh-server.settings.listen | HTTP listen address and port
|
| services.tor.settings.DisableAllSwap | See torrc manual.
|
| services.tor.settings.Nickname | See torrc manual.
|
| services.clamsmtp.instances.*.virusAction | Command to run when a virus is found
|
| services.clamav.daemon.settings | ClamAV configuration
|
| services.prosody-filer.settings | Configuration for Prosody Filer
|
| services.grafana.settings.smtp.host | Host to connect to.
|
| services.hickory-dns.settings.zones | List of zones to serve.
|
| services.oncall.settings.db.conn.str | Database connection scheme
|
| services.gokapi.settingsFile | Path to config file to parse and append to settings
|
| services.misskey.settings.redis | ioredis options
|
| services.lokinet.settings.dns.bind | Address to bind to for handling DNS requests.
|
| services.buffyboard.settings | Settings to include in /etc/buffyboard.conf
|
| services.inadyn.settings.custom.<name>.include | File to include additional settings for this provider from.
|
| programs.schroot.settings | Schroot configuration settings
|
| services.fediwall.settings.tags | Tags to follow
|
| services.hedgedoc.settings.port | Port to listen on.
|
| services.hedgedoc.settings.host | Address to listen on.
|
| services.lasuite-meet.settings.DB_NAME | Name of the database
|
| services.lasuite-docs.settings.DB_NAME | Name of the database
|
| services.lasuite-docs.settings.DB_USER | User of the database
|
| services.lasuite-meet.settings.DB_HOST | Host of the database
|
| services.lasuite-meet.settings.DB_USER | User of the database
|
| services.lasuite-docs.settings.DB_HOST | Host of the database
|
| services.pangolin.settings | Additional attributes to be merged with the configuration options and written to Pangolin's config.yml file.
|
| services.pinnwand.settings | Your pinnwand.toml as a Nix attribute set
|
| services.postsrsd.settings | Configuration options for the postsrsd.conf file
|
| services.cross-seed.settings.linkDirs | List of directories where cross-seed will create links
|
| services.immich-kiosk.settings | Configuration for immich-kiosk
|
| services.actual.settings.userFiles | The server will put all the budget files in this directory as binary blobs.
|
| services.syncthing.openDefaultPorts | Whether to open the default ports in the firewall: TCP/UDP 22000 for transfers
and UDP 21027 for discovery
|
| services.firefox-syncserver.settings | Settings for the sync server
|
| services.amule.settings.WebServer.Port | Web server port
|
| services.grafana.settings.smtp.user | User used for authentication.
|
| services.tor.settings.ClientAutoIPv6ORPort | See torrc manual.
|
| services.misskey.settings.db.extra | Extra connection options.
|
| services.frigate.settings.mqtt.host | MQTT server hostname
|
| services.kanidm.client.settings.uri | Address of the Kanidm server.
|
| services.sftpgo.settings.smtp.host | Location of SMTP email server
|
| services.sslh.settings.numeric | Whether to disable reverse DNS lookups, thus keeping IP
address literals in the log.
|
| services.pdns-recursor.old-settings | Older PowerDNS Recursor settings
|
| services.freeciv.settings.exit-on-end | Whether to enable exit instead of restarting when a game ends.
|
| services.sympa.domains | Email domains handled by this instance
|
| services.crowdsec.settings.capi | CAPI Configuration attributes
|
| services.crowdsec.settings.lapi | LAPI Configuration attributes
|
| services.froide-govplan.settings | Configuration options to set in extra_settings.py.
|
| programs.yazi.settings | Configuration included in $YAZI_CONFIG_HOME.
|
| services.pds.settings.PDS_CRAWLERS | URL of crawlers
|
| services.webdav-server-rs.settings | Attrset that is converted and passed as config file
|
| services.filebrowser.settings | Settings for FileBrowser
|
| services.opengfw.settings.io.rst | Set to true if you want to send RST for blocked TCP connections, needs local = false.
|
| services.dsnet.settings | The settings to use for dsnet
|
| services.tor.relay.onionServices.<name>.settings | Settings of the onion service
|
| services.go2rtc.settings.ffmpeg.bin | The ffmpeg package to use for transcoding.
|
| xdg.portal.wlr.settings | Configuration for xdg-desktop-portal-wlr
|
| services.borgmatic.settings | See https://torsion.org/borgmatic/docs/reference/configuration/
|
| services.forgejo.settings.log.LEVEL | General log level.
|
| services.tor.settings.ClientOnionAuthDir | See torrc manual.
|
| services.quickwit.settings.rest | Rest server configuration for Quickwit
|
| services.pretix.settings.tools.pdftk | Path to the pdftk executable.
|
| services.nipap.settings.nipapd.debug | Enable debug logging.
|
| services.aria2.settings.listen-port | Set UDP listening port range used by DHT(IPv4, IPv6) and UDP tracker.
|
| services.microbin.settings | Additional configuration for MicroBin, see
https://microbin.eu/docs/installation-and-configuration/configuration/
for supported values
|
| services.wastebin.settings | Additional configuration for wastebin, see
https://github.com/matze/wastebin#usage for supported values
|
| services.readarr.settings | Attribute set of arbitrary config options
|
| services.firefly-iii.settings.DB_PORT | The port your database is listening at. sqlite does not require
this value to be filled.
|
| services.lidarr.settings.server.port | Port Number
|
| services.maubot.settings.server.port | The port to listen on
|
| services.radarr.settings.server.port | Port Number
|
| services.sonarr.settings.server.port | Port Number
|
| services.lasuite-docs.settings.DATA_DIR | Path to the data directory
|
| services.v4l2-relayd.instances.<name>.input.pipeline | The gstreamer-pipeline to use for the input-stream.
|
| services.zitadel.settings.TLS.KeyPath | Path to the TLS certificate private key.
|
| services.sourcehut.settings | The configuration for the sourcehut network.
|
| services.bitmagnet.settings | Bitmagnet configuration (https://bitmagnet.io/setup/configuration.html).
|
| services.tinyproxy.settings | Configuration for tinyproxy.
|
| services.c2fmzq-server.settings | Configuration for c2FmZQ-server passed as CLI arguments
|
| services.teleport.settings | Contents of the teleport.yaml config file
|
| services.gemstash.settings.bind | Host and port combination for the server to listen on.
|
| services.suricata.settings.vars | Variables to be used within the suricata rules.
|
| services.oink.settings.interval | Seconds to wait before sending another request.
|
| services.suricata.settings.pcap | Cross platform libpcap capture support.
|
| services.lasuite-docs.settings | Configuration options of docs
|
| services.graylog.isMaster | Whether this is the master instance of your Graylog cluster
|
| services.cross-seed.settings.outputDir | Directory where cross-seed will place torrent files it finds.
|
| services.immich.settings | Configuration for Immich
|
| services.nitter.server.title | Title of the instance.
|
| services.dokuwiki.sites.<name>.settings | Structural DokuWiki configuration
|
| services.transmission.settings | Settings whose options overwrite fields in
.config/transmission-daemon/settings.json
(each time the service starts)
|
| services.glance.settings.server.port | Glance port to listen on
|
| services.dnsmasq.settings.server | The DNS servers which dnsmasq should query.
|
| services.grafana-to-ntfy.settings.ntfyUrl | The URL to the ntfy-sh topic.
|
| services.glance.settings.server.host | Glance bind address
|
| services.gancio.settings.baseurl | The full URL under which the server is reachable.
|
| services.legit.settings.repo.mainBranch | Main branch to look for.
|
| services.tor.settings.DisableOOSCheck | See torrc manual.
|
| services.moosefs.master.settings | Master configuration options (mfsmaster.cfg).
|
| services.zitadel.settings.TLS.CertPath | Path to the TLS certificate.
|
| services.sabnzbd.settings.misc.port | Port for the Web UI to listen on for incoming connections.
|
| services.pretix.settings.pretix.url | The installation’s full URL, without a trailing slash.
|
| services.sabnzbd.settings.misc.host | Address for the Web UI to listen on for incoming connections.
|
| services.misskey.settings.redis.host | The Redis host.
|
| services.omnom.settings.storage.type | Storage type.
|
| services.misskey.settings.redis.port | The Redis port.
|
| services.firefly-iii.settings.APP_ENV | The app environment
|
| services.dnsproxy.settings | Contents of the config.yaml config file
|
| services.stalwart.settings | Configuration options for the Stalwart server
|
| programs.bat.settings | Parameters to be written to the system-wide bat configuration file.
|
| services.gitea.settings.server.ROOT_URL | Full public URL of gitea server.
|
| services.aria2.settings.save-session | Save error/unfinished downloads to FILE on exit.
|
| power.ups.upsmon.settings | Additional settings to add to upsmon.conf.
|
| services.mosquitto.bridges.<name>.settings | Additional settings for this bridge.
|
| services.meilisearch.settings | Configuration settings for Meilisearch
|
| services.doh-server.settings.timeout | Upstream timeout
|
| services.doh-server.settings.verbose | Enable logging
|
| services.umami.settings.HOSTNAME | The address to listen on.
|
| services.sourcehut.settings."meta.sr.ht::settings".user-invites | How many invites each user is issued upon registration
(only applicable if open registration is disabled).
|
| services.transfer-sh.settings | Additional configuration for transfer-sh, see
https://github.com/dutchcoders/transfer.sh#usage-1
for supported values
|
| services.influxdb2.settings | configuration options for influxdb2, see https://docs.influxdata.com/influxdb/v2.0/reference/config-options for details.
|
| services.misskey.settings.socket | The UNIX socket your Misskey server should listen on.
|
| services.paisa.settings.journalFile | Filename of the main journal / ledger file.
|
| services.pocket-id.settings.TRUST_PROXY | Whether the app is behind a reverse proxy.
|
| programs.atop.settings | Parameters to be written to /etc/atoprc.
|
| services.aesmd.settings.proxyType | Type of proxy to use
|
| services.misskey.settings.url | The final user-facing URL
|
| services.scion.scion-router.settings | scion-router configuration
|
| services.scion.scion-daemon.settings | scion-daemon configuration
|
| services.go2rtc.settings.api.listen | API listen address, conforming to a Go address string.
|
| services.listmonk.database.settings | Dynamic settings in the PostgreSQL database, set by a SQL script, see https://github.com/knadh/listmonk/blob/master/schema.sql#L177-L230 for details.
|
| services.glitchtip.settings | Configuration of GlitchTip
|
| services.supergfxd.settings | The content of /etc/supergfxd.conf
|
| services.rosenpass.settings | Configuration for Rosenpass, see https://rosenpass.eu/ for further information.
|
| services.mackerel-agent.settings | Options for mackerel-agent.conf
|
| services.tor.settings.ExtORPortCookieAuthFile | See torrc manual.
|
| services.tor.settings.AuthDirTestEd25519LinkKeys | See torrc manual.
|
| services.manticore.settings | Configuration for Manticoresearch
|
| services.mosquitto.settings | Global configuration options for the mosquitto broker.
|
| services.anubis.defaultOptions.policy.settings | Additional policy settings merged into the policy file
|
| services.livekit.redis.port | Port to bind local redis instance to.
|
| services.livekit.redis.host | Address to bind local redis instance to.
|
| services.librenms.settings | Attrset of the LibreNMS configuration
|
| services.gemstash.settings | Configuration for Gemstash
|
| services.lasuite-meet.settings | Configuration options of meet
|
| services.bluesky-pds.settings.PDS_DID_PLC_URL | URL of DID PLC directory
|
| services.openldap.settings.attrs | Attributes of the parent entry.
|
| services.stash.settings.database | Path to the SQLite database
|
| services.consul-template.instances.<name>.package | The consul-template package to use.
|
| services.freeciv.settings.Guests | Whether to enable guests to login if auth is enabled.
|
| services.saunafs.master.settings | Contents of config file (sfsmaster.cfg(5)).
|
| services.homepage-dashboard.settings | Homepage settings
|
| services.forgejo.settings.log.ROOT_PATH | Root path for log files.
|
| services.immich-public-proxy.settings | Configuration for IPP
|
| services.swapspace.settings | Config file for swapspace
|
| services.navidrome.settings | Configuration for Navidrome, see https://www.navidrome.org/docs/usage/configuration-options/ for supported values.
|
| services.nextcloud.settings | Extra options which should be appended to Nextcloud's config.php file.
|
| services.pgbouncer.settings | Configuration for PgBouncer, see https://www.pgbouncer.org/config.html
for supported values.
|
| services.webdav.settings | Attrset that is converted and passed as config file
|
| services.amule.settings.eMule.UDPPort | UDP port for eD2k traffic (searches, source exchange) and all Kad network communication
|
| services.etebase-server.settings | Configuration for etebase-server
|
| services.redis.servers.<name>.settings | Redis configuration
|
| services.matrix-tuwunel.settings | Generates the tuwunel.toml configuration file
|
| services.minidlna.settings.port | Port number for HTTP traffic (descriptions, SOAP, media transfer).
|
| services.pocket-id.settings.PUBLIC_APP_URL | The URL where you will access the app.
|
| services.gancio.settings.db.storage | Location for the SQLite database.
|
| services.gancio.settings.db.dialect | The database dialect to use
|
| services.opengfw.settings.io.queueSize | IO queue size.
|
| services.tor.settings.FetchDirInfoExtraEarly | See torrc manual.
|
| services.tor.settings.ControlSocket | See torrc manual.
|
| services.kanidm.client.settings | Configure Kanidm clients, needed for the PAM daemon
|
| services.clamav.updater.settings | freshclam configuration
|
| services.lasuite-docs.settings.REDIS_URL | URL of the redis backend
|
| services.lasuite-meet.settings.REDIS_URL | URL of the redis backend
|
| services.radicle.ci.adapters.native.instances | radicle-native-ci adapter instances.
|
| services.opengfw.settings.io.local | Set to false if you want to run OpenGFW on FORWARD chain. (e.g. on a router)
|
| networking.jool.siit | Definitions of SIIT instances of Jool
|
| services.aria2.settings.rpc-listen-port | Specify a port number for JSON-RPC/XML-RPC server to listen to
|
| services.jirafeau.hostName | URL of instance
|
| services.firewalld.settings | FirewallD config file
|
| services.moonraker.settings | Configuration for Moonraker
|
| services.mobilizon.settings | Mobilizon Elixir documentation, see
https://docs.joinmobilizon.org/administration/configure/reference/
for supported values.
|
| services.typesense.settings | Typesense configuration
|
| services.peertube-runner.instancesToRegister | PeerTube instances to register this runner with.
|
| services.pomerium.settings | The contents of Pomerium's config.yaml, in Nix expressions
|
| services.lasuite-docs.domain | Domain name of the docs instance.
|
| services.lasuite-meet.domain | Domain name of the meet instance.
|
| services.peertube-runner.instancesToRegister.<name>.registrationTokenFile | Path to a file containing a registration token for the PeerTube instance
|
| services.firefly-iii.settings | Options for firefly-iii configuration
|
| services.canaille.settings.CANAILLE_OIDC | OpenID Connect settings
|
| services.workout-tracker.settings | Extra config options.
|
| services.sunshine.settings.port | Base port -- others used are offset from this one, see https://docs.lizardbyte.dev/projects/sunshine/en/latest/about/advanced_usage.html#port for details.
|
| services.pds.settings.PDS_BLOB_UPLOAD_LIMIT | Size limit of uploaded blobs in bytes
|
| services.grocy.settings.currency | ISO 4217 code for the currency to display.
|
| services.nvme-rs.settings.email.use_tls | Use TLS for SMTP connection
|
| services.stash.settings.no_proxy | A list of domains for which the proxy must not be used
|
| services.vmalert.settings.rule | Path to the files with alerting and/or recording rules.
Consider using the services.vmalert.rules option as a convenient alternative for declaring rules
directly in the nix language.
|
| services.tlsrpt.fetcher.settings | Flags from tlsrpt-fetcher(1) as key-value pairs.
|
| services.tlsrpt.reportd.settings | Flags from tlsrpt-reportd(1) as key-value pairs.
|
| services.rkvm.server.settings.listen | An internet socket address to listen on, either IPv4 or IPv6.
|
| services.sharkey.settings.socket | If specified, creates a UNIX socket at the given path that Sharkey listens on.
|
| services.openssh.settings.PrintMotd | Whether to enable printing /etc/motd when a user logs in interactively.
|
| services.mautrix-meta.instances.<name>.serviceUnit | The systemd unit (a service or a target) for other services to depend on if they
need to be started after matrix-synapse
|
| services.gitlab.pages.settings.pages-root | The directory where pages are stored.
|
| services.fediwall.settings.hideBots | Hide posts from bot accounts
|
| services.gitea.settings.server.DOMAIN | Domain name of your server.
|
| services.cryptpad.settings.httpPort | Port on which the Node.js server should listen
|
| services.zeronsd.servedNetworks.<name>.settings | Settings for zeronsd
|
| services.dsnet.settings.Network | The IPv4 network that the server will use to allocate IPs on the network
|
| services.inadyn.settings.custom.<name>.ssl | Whether to use HTTPS for this DDNS provider.
|
| services.gitea.settings.server.HTTP_PORT | Listen port
|
| services.cryptpad.settings.logLevel | Controls log level
|
| services.rspamd-trainer.settings | IMAP authentication configuration for rspamd-trainer
|
| services.lldap.settings.http_url | The public URL of the server, for password reset links.
|
| services.warpgate.settings.http.key | Path to HTTPS listener private key.
|
| services.rkvm.client.settings.server | An RKVM server's internet socket address, either IPv4 or IPv6.
|
| services.kanidm.server.settings.role | The role of this server
|
| services.nomad.settings | Configuration for Nomad
|
| services.keycloak.settings.http-host | On which address Keycloak should accept new connections.
|
| services.nipap.settings.nipapd.listen | IP address to bind nipapd to.
|
| services.knot-resolver.settings | Nix-based (RFC 42) configuration for Knot Resolver
|
| services.mailpit.instances.<name>.database | Specify the local database filename to store persistent data
|
| services.clamsmtp.instances.*.tempDirectory | Temporary directory that needs to be accessible to both clamd
and clamsmtpd.
|
| services.freeciv.settings.saves | Save games to given directory,
a sub-directory named after the starting date of the service
will me inserted to preserve older saves.
|
| services.mediagoblin.paste.settings | Settings which are written into paste.ini.
|
| services.kanboard.domain | FQDN for the Kanboard instance.
|
| services.pixelfed.domain | FQDN for the Pixelfed instance.
|
| services.gitea.settings.server.HTTP_ADDR | Listen address
|
| services.create_ap.settings | Configuration for create_ap
|
| services.watchdogd.settings | Configuration to put in watchdogd.conf
|
| services.v4l2-relayd.instances.<name>.input.framerate | The framerate to read from input-stream.
|
| services.tor.settings.MainloopStats | See torrc manual.
|
| services.tor.settings.NewCircuitPeriod | See torrc manual.
|
| services.tor.settings.OfflineMasterKey | See torrc manual.
|
| services.fcgiwrap.instances.<name>.socket.address | Socket address
|
| services.paperless.exporter.settings | Settings to pass to the document exporter as CLI arguments.
|
| services.dsnet.settings.Network6 | The IPv6 network that the server will use to allocate IPs on the
network
|
| services.warpgate.settings.ssh.keys | Path to store SSH host & client keys.
|
| services.sharkey.settings.address | The address that Sharkey binds to.
|
| services.sabnzbd.settings.servers | Usenet provider specification
|
| services.readarr.settings.server.port | Port Number
|
| services.maubot.settings.logging | Python logging configuration
|
| services.keycloak.settings.http-port | On which port Keycloak should listen for new HTTP connections.
|
| services.immich-kiosk.settings.kiosk.port | Port on which immich-kiosk will listen.
|
| services.suricata.settings.run-as.user | Run Suricata with a specific user-id.
|
| networking.jool.nat64 | Definitions of NAT64 instances of Jool
|
| services.btrbk.instances.<name>.snapshotOnly | Whether to run in snapshot only mode
|
| services.actual.settings.hostname | The address to listen on
|
| services.cross-seed.settings.dataDirs | Paths to be searched for matching data
|
| services.taler.runtimeDir | Runtime directory shared between the taler services
|
| services.hedgedoc.settings.urlPath | URL path for the website
|
| services.dnscrypt-proxy.settings | Attrset that is converted and passed as TOML config file
|
| services.firezone.server.settings | Environment variables for the Firezone server
|
| services.hatsu.settings.HATSU_LISTEN_PORT | Port where hatsu should listen for incoming requests.
|
| services.hatsu.settings.HATSU_LISTEN_HOST | Host where hatsu should listen for incoming requests.
|
| services.radicle.ci.broker.settings.db | Database file path.
|
| services.postfix-tlspol.settings | The postfix-tlspol configuration file as a Nix attribute set
|
| services.snips-sh.settings | The configuration of snips-sh is done through environment variables,
therefore you must use upper snake case (e.g. SNIPS_HTTP_INTERNAL)
|
| services.dolibarr.h2o.settings | Attrset to be transformed into YAML for host config
|
| services.radicle.ci.broker.settings | Configuration of radicle-ci-broker
|
| services.kea.dhcp6.configFile | Kea DHCP6 configuration as a path, see https://kea.readthedocs.io/en/kea-3.0.2/arm/dhcp6-srv.html
|
| services.kea.dhcp4.configFile | Kea DHCP4 configuration as a path, see https://kea.readthedocs.io/en/kea-3.0.2/arm/dhcp4-srv.html
|
| services.tor.settings.ClientPreferIPv6ORPort | See torrc manual.
|
| services.scrutiny.settings.log.level | Log level for Scrutiny.
|
| services.umurmur.settings.ca_path | Path to your SSL CA certificate.
|
| services.mx-puppet-discord.settings | config.yaml configuration as a Nix attribute set
|
| services.open-web-calendar.settings | Configuration for the server
|
| services.pixelfed.enable | Whether to enable a Pixelfed instance.
|
| services.stalwart-mail.settings | Configuration options for the Stalwart email server
|
| services.suricata.settings.af-xdp | Linux high speed af-xdp capture support, see
docs/capture-hardware/af-xdp.
|
| services.biboumi.settings.admin | The bare JID of the gateway administrator
|
| services.prowlarr.settings | Attribute set of arbitrary config options
|
| services.whisparr.settings | Attribute set of arbitrary config options
|
| services.gancio.settings.log_path | Directory Gancio logs into
|
| services.fediwall.settings.showMedia | Show media in posts
|
| services.navidrome.settings.Port | Port to run Navidrome on.
|
| services.tinyproxy.settings.Port | Specify which port to listen to.
|
| services.pinnwand.settings.footer | The footer in raw HTML.
|
| services.ntfy-sh.settings.base-url | Public facing base URL of the service
This setting is required for any of the following features:
- attachments (to return a download URL)
- e-mail sending (for the topic URL in the email footer)
- iOS push notifications for self-hosted servers
(to calculate the Firebase poll_request topic)
- Matrix Push Gateway (to validate that the pushkey is correct)
|
| services.hedgedoc.settings.path | Path to UNIX domain socket to listen on
If specified, host and port will be ignored.
|
| services.sympa.domains.<name>.settings | The robot.conf configuration file as key value set
|
| services.matrix-synapse.settings | The primary synapse configuration
|
| services.caddy.settings | Structured configuration for Caddy to generate a Caddy JSON configuration file
|
| services.hickory-dns.settings.zones.*.zone | Zone name, like "example.com", "localhost", or "0.0.127.in-addr.arpa".
|
| services.tinc.networks.<name>.settings | Configuration of the Tinc daemon for this network
|
| services.fcgiwrap.instances.<name>.process.prefork | Number of processes to prefork.
|
| services.zram-generator.settings | Configuration for zram-generator,
see https://github.com/systemd/zram-generator for documentation.
|
| services.frigate.settings.cameras | Attribute set of cameras configurations.
https://docs.frigate.video/configuration/cameras
|
| services.xonotic.settings.sv_motd | Text displayed when players join the server.
|
| services.blackfire-agent.settings | See https://blackfire.io/docs/up-and-running/configuration/agent
|
| services.mongodb.replSetName | If this instance is part of a replica set, set its name here
|
| services.apache-kafka.settings."broker.id" | Broker ID. -1 or null to auto-allocate in zookeeper mode.
|
| services.scion.scion-control.settings | scion-control configuration
|
| services.gancio.settings.hostname | The domain name under which the server is reachable.
|
| services.kanboard.phpfpm.settings | Options for kanboard's PHPFPM pool.
|
| services.inadyn.settings.forced-update | Duration (in seconds) after which an update is forced.
|
| services.tor.settings.KeyDirectory | See torrc manual.
|
| services.tor.settings.ClientPreferIPv6DirPort | See torrc manual.
|
| services.tor.settings.ReducedExitPolicy | See torrc manual.
|
| services.headscale.settings | Overrides to config.yaml as a Nix attribute set
|
| hardware.cpu.x86.msr.settings | Parameters for the msr kernel module.
|
| services.angrr.settings.owned-only | Only monitors owned symbolic link target of GC roots.
- "auto": behaves like true for normal users, false for root.
- "true": only monitor GC roots owned by the current user.
- "false": monitor all GC roots.
|
| services.suricata.settings.app-layer | app-layer configuration, see upstream docs.
|
| services.zwave-js.settings.storage.cacheDir | Cache directory
|
| services.inadyn.settings.provider.<name>.include | File to include additional settings for this provider from.
|
| services.mchprs.settings.address | Address for the server
|
| services.go2rtc.settings.streams | Stream source configuration
|
| services.slskd.settings.web.url_base | The base path in the url for web requests.
|
| services.suwayomi-server.settings | Configuration to write to server.conf
|
| services.warpgate.settings.mysql.key | Path to MySQL listener private key.
|
| services.openssh.settings.LogLevel | Gives the verbosity level that is used when logging messages from sshd(8)
|
| services.smartdns.settings | A set that will be generated into configuration file, see the SmartDNS README for details of configuration parameters
|
| services.ocis.package | Which package to use for the ownCloud Infinite Scale instance.
|
| services.part-db.settings.DATABASE_URL | The postgresql database server to connect to
|
| services.imaginary.settings | Command line arguments passed to the imaginary executable, stripped of
the prefix -
|
| services.opensearch.settings | OpenSearch configuration.
|
| services.wgautomesh.settings | Configuration for wgautomesh.
|
| services.evremap.settings.phys | The physical device name to listen on
|
| services.peering-manager.settings | Configuration options to set in configuration.py
|
| services.maubot.settings.admins | List of administrator users
|
| services.peroxide.settings.UserPortImap | The port on which to listen for IMAP connections.
|
| services.peroxide.settings.UserPortSmtp | The port on which to listen for SMTP connections.
|
| services.acme-dns.settings.general.nsname | Zone name server.
|
| services.tor.settings.ControlPortWriteToFile | See torrc manual.
|
| services.tor.settings.ServerDNSResolvConfFile | See torrc manual.
|
| services.tor.settings.DisableNetwork | See torrc manual.
|
| services.tsidp.settings.enableFunnel | Use Tailscale Funnel to make tsidp available on the public internet so it works with SaaS products.
|
| services.openssh.settings.DenyUsers | If specified, login is denied for all listed users
|
| services.livekit.ingress.settings | LiveKit Ingress configuration
|
| services.peertube-runner.settings | Configuration for peertube-runner
|
| services.umami.settings.DATABASE_URL | Connection string for the database
|
| services.hedgedoc.settings.db | Specify the configuration for sequelize
|
| services.bookstack.settings.DB_PORT | The port your database is listening at.
|
| services.omnom.settings.server.address | Server address.
|
| services.openssh.settings.AllowUsers | If specified, login is allowed only for the listed users
|
| services.sympa.settingsFile | Set of files to be linked in /var/lib/sympa.
|
| programs.yazi.settings.vfs | Configuration included in vfs.toml
|
| services.keycloak.settings.https-port | On which port Keycloak should listen for new HTTPS connections.
|
| services.gemstash.settings.db_url | The database to connect to when using postgres, mysql, or mysql2.
|
| services.suricata.settings.run-as.group | Run Suricata with a specific group-id.
|
| services.nezha-agent.settings.uuid | Must be set to a unique identifier, preferably a UUID according to
RFC 4122
|
| services.pds.settings.PDS_REPORT_SERVICE_DID | DID of mod service
|
| services.bluesky-pds.settings.PDS_BSKY_APP_VIEW_DID | DID of bsky frontend
|
| services.go-csp-collector.settings.port | The port to listen on.
|
| services.litestream.settings | See the documentation.
|
| services.rebuilderd.settings | Configuration for rebuilderd (rebuilderd.conf)
|
| services.maddy.config | Server configuration, see
https://maddy.email for
more information
|
| services.dnscrypt-proxy2.settings | Attrset that is converted and passed as TOML config file
|
| services.clamsmtp.instances.*.quarantine | Whether to quarantine files that contain viruses by leaving them
in the temporary directory.
|
| services.mosquitto.listeners.*.settings | Additional settings for this listener.
|
| services.weblate.localDomain | The domain name serving your Weblate instance.
|
| services.acme-dns.settings.general.domain | Domain name to serve the requests off of.
|
| services.oncall.settings.db.conn.kwargs.host | Database host.
|
| services.misskey.settings.chmodSocket | The file access mode of the UNIX socket.
|
| services.pretix.settings.pretix.logdir | Directory for storing log files.
|
| services.oncall.settings.db.conn.kwargs.user | Database user.
|
| services.suricata.settings.af-packet | Linux high speed capture support.
|
| services.dsnet.settings.Networks | The CIDR networks that should route through this server
|
| services.froide-govplan.hostName | FQDN for the froide-govplan instance.
|
| nix.settings.max-jobs | This option defines the maximum number of jobs that Nix will try to
build in parallel
|
| services.frigate.settings.ffmpeg.path | Package providing the ffmpeg and ffprobe executables below the bin/ directory.
|
| services.bookstack.settings.DB_HOST | The IP or hostname which hosts your database.
|
| services.anuko-time-tracker.settings.helpLink | Help link from the main menu.
|
| services.gancio.settings.db.database | Name of the PostgreSQL database
|
| services.karma.settings.listen.address | Hostname or IP to listen on.
|
| services.tor.settings.DownloadExtraInfo | See torrc manual.
|
| services.tor.settings.DataDirectory | See torrc manual.
|
| services.tor.settings.BandwidthRate | See torrc manual.
|
| services.postfix.settings.master.<name>.type | The type of the service
|
| hardware.nfc-nci.settings | Configuration to be written to the libncf-nci configuration files
|
| services.minidlna.settings.db_dir | Specify the directory to store database and album art cache.
|
| services.pds.settings.PDS_REPORT_SERVICE_URL | URL of mod service
|
| services.bluesky-pds.settings.PDS_BSKY_APP_VIEW_URL | URL of bsky frontend
|
| services.scanservjs.settings | Config to set in config.local.js's afterConfig.
|
| services.lldap.settings.ldap_port | The port on which to have the LDAP server.
|
| services.reposilite.settings | Configuration written to the reposilite.cdn file
|
| services.stash.settings.generated | Path to generated files
|
| services.tuned.settings.sections | attribute set of section of an INI file (attrs of INI atom (null, bool, int, float or string))
|
| services.gitlab.pages.settings.listen-http | The address(es) to listen on for HTTP requests.
|
| services.gancio.settings.server.socket | The unix socket for the gancio server to listen on.
|
| services.fediwall.settings.hideBoosts | Hide boosts
|
| services.bluesky-pds.settings.LOG_ENABLED | Enable logging
|
| services.traefik.static.settings | Static configuration for Traefik, written in Nix.
This will be serialized to JSON (which is considered valid YAML) at build, and passed to Traefik as --configfile.
|
| services.zitadel.settings.TLS.Key | The TLS certificate private key, as a base64-encoded string
|
| services.firefly-iii.settings.APP_URL | The APP_URL used by firefly-iii internally
|
| services.biboumi.settings.ca_file | Specifies which file should be used as the list of trusted CA
when negotiating a TLS session.
|
| services.chhoto-url.settings.site_url | The URL under which Chhoto URL is externally reachable.
|
| services.nextcloud.occ | The nextcloud-occ program preconfigured to target this Nextcloud instance.
|
| services.meshcentral.settings | Settings for MeshCentral
|
| services.uptime.usesRemoteMongo | Whether the configuration file specifies a remote mongo instance
|
| services.tlsrpt.collectd.settings | Flags from tlsrpt-collectd(1) as key-value pairs.
|
| services.libeufin.bank.settings | Configuration options for the libeufin bank system config file
|
| services.gitea-actions-runner.instances.<name>.labels | Labels used to map jobs to their runtime environment
|
| services.epgstation.settings | Options to add to config.yml
|
| services.tor.settings.TestingTorNetwork | See torrc manual.
|
| services.tor.settings.LogMessageDomains | See torrc manual.
|
| services.tor.settings.RefuseUnknownExits | See torrc manual.
|
| services.rosenpass.settings.peers | List of peers to exchange keys with.
|
| security.krb5.settings | Structured contents of the krb5.conf file
|
| services.smokeping.owner | Real name of the owner of the instance
|
| nix.settings.extra-sandbox-paths | Directories from the host filesystem to be included
in the sandbox.
|
| services.nextcloud.hostName | FQDN for the nextcloud instance.
|
| services.rutorrent.hostName | FQDN for the ruTorrent instance.
|
| services.kubo.settings.Mounts.FuseAllowOther | Allow all users to access the FUSE mount points
|
| services.openssh.settings.StrictModes | Whether sshd should check file modes and ownership of directories
|
| services.fediwall.settings.loadPublic | Load public posts
|
| services.fediwall.settings.playVideos | Autoplay videos in posts
|
| services.fediwall.settings.loadTrends | Load trending posts
|
| services.zitadel.settings.TLS.Cert | The TLS certificate, as a base64-encoded string
|
| services.matrix-hookshot.settings | config.yml configuration as a Nix attribute set
|
| services.waagent.settings.HttpProxy.Host | If you set http proxy, waagent will use is proxy to access the Internet.
|
| services.waagent.settings.HttpProxy.Port | If you set http proxy, waagent will use this proxy to access the Internet.
|
| boot.initrd.unl0kr.settings | Configuration for unl0kr
|
| services.forgejo.settings.server.ROOT_URL | Full public URL of Forgejo server.
|
| services.nipap.settings.nipapd.db_name | Name of database to use on PostgreSQL server.
|
| services.slskd.settings.shares.filters | Regular expressions of files to exclude from sharing.
|
| services.evremap.settings.remap.*.input | The key sequence that should be remapped
|
| services.cryptpad.settings.adminKeys | List of public signing keys of users that can access the admin panel
|
| programs.gamemode.settings | System-wide configuration for GameMode (/etc/gamemode.ini)
|
| services.languagetool.settings | Configuration file options for LanguageTool, see
'languagetool-http-server --help'
for supported settings.
|
| services.gnome.gnome-settings-daemon.enable | Whether to enable GNOME Settings Daemon.
|
| services.metricbeat.settings | Configuration for metricbeat
|
| services.routinator.settings | Configuration for Routinator 3000, see https://routinator.docs.nlnetlabs.nl/en/stable/manual-page.html#configuration-file for options.
|
| services.warpgate.settings.ssh.enable | Whether to enable SSH listener.
|
| services.warpgate.settings.ssh.listen | Listen endpoint of SSH listener.
|
| services.stash.settings.nobrowser | If we should not auto-open a browser window on startup
|
| services.mautrix-discord.settings | config.yaml configuration as a Nix attribute set
|
| services.yggdrasil.settings | Configuration for yggdrasil, as a structured Nix attribute set
|
| services.cross-seed.settings.torrentDir | Directory containing torrent files, or if you're using a torrent
client integration and injection - your torrent client's .torrent
file store/cache.
|
| services.acme-dns.settings.general.listen | IP+port combination to bind and serve the DNS server on.
|
| services.displayManager.gdm.settings | Options passed to the gdm daemon
|
| services.misskey.settings.redisForJobQueue | ioredis options for the job queue
|
| services.pretix.settings.celery.broker | URI to the celery broker used for the asynchronous job queue.
|
| services.grafana.settings.smtp.enabled | Whether to enable SMTP.
|
| services.saunafs.master.settings.DATA_PATH | Data storage directory.
|
| services.broadcast-box.settings | Attribute set of environment variables.
https://github.com/Glimesh/broadcast-box#environment-variables
The status API exposes stream keys so DISABLE_STATUS is enabled
by default.
|
| programs.yazi.settings.yazi | Configuration included in yazi.toml
|
| services.gitea.settings.mailer.ENABLED | Whether to use an email service to send notifications.
|
| services.crowdsec.settings.console | Console Configuration attributes
|
| services.fediwall.settings.servers | Servers to load posts from
|
| services.prowlarr.settings.server.port | Port Number
|
| services.pretix.settings.database.user | Database username.
|
| services.quickwit.settings.version | Configuration file version.
|
| services.pretix.settings.database.name | Database name.
|
| services.umurmur.settings.channels | Channel tree definitions.
|
| services.whisparr.settings.server.port | Port Number
|
| services.hedgedoc.settings.domain | Domain to use for website
|
| services.journald.upload.settings | Configuration for journal-upload
|
| services.suricata.settings.rule-files | Files to load suricata-update managed rules, relative to 'default-rule-path'.
|
| services.alerta.databaseName | Name of the database instance to connect to
|
| services.vlagent.remoteWrite.url | Endpoint for the victorialogs instance
|
| services.lldap.settings.ldap_host | The host address that the LDAP server will be bound to.
|
| services.lldap.settings.http_host | The host address that the HTTP server will be bound to.
|
| services.lubelogger.settings | Additional configuration for LubeLogger, see https://docs.lubelogger.com/Environment%20Variables for supported values.
|
| services.lldap.settings.http_port | The port on which to have the HTTP server, for user login and administration.
|
| services.photoprism.settings | See the getting-started guide for available options.
|
| services.stash.settings.ui.frontPageContent | Search filters to display on the front page.
|
| security.please.settings | Please configuration
|
| services.matrix-synapse.settings.redis | Redis configuration for synapse
|
| hardware.amdgpu.amdvlk.settings | Runtime settings for AMDVLK to be configured /etc/amd/amdVulkanSettings.cfg
|
| services.go-autoconfig.settings | Configuration for go-autoconfig
|
| services.gitlab.pages.settings.pages-domain | The domain to serve static pages on.
|
| services.moosefs.master.settings.DATA_PATH | Directory for storing master metadata.
|
| services.frigate.settings.mqtt.enabled | Whether to enable MQTT support.
|
| services.gitea.settings.server.SSH_PORT | SSH port displayed in clone URL
|
| services.matrix-conduit.settings | Generates the conduit.toml configuration file
|
| services.anuko-time-tracker.settings.forumLink | Forum link from the main menu.
|
| services.tor.settings.BandwidthBurst | See torrc manual.
|
| services.tsidp.settings.debugAllRequests | For development
|
| services.tor.settings.CacheDirectory | See torrc manual.
|
| services.umurmur.settings.bindport | Port to bind to (UDP and TCP).
|
| services.openbao.settings.listener | Configure a listener for responding to requests.
|
| services.pgbackrest.stanzas.<name>.instances.<name>.host | PostgreSQL host for operating remotely.
|
| services.crowdsec-firewall-bouncer.settings | Settings for the main CrowdSec Firewall Bouncer
|
| services.rkvm.server.settings.switch-keys | A key list specifying a host switch combination.
A list of key names is available in https://github.com/htrefil/rkvm/blob/master/switch-keys.md.
|
| services.filesender.settings | Configuration options used by FileSender
|
| services.homebridge.settings | Configuration options for homebridge
|
| services.canaille.settings.SECRET_KEY | Flask Secret Key
|
| services.snapserver.settings | Snapserver configuration
|
| services.misskey.settings.redisForPubsub | ioredis options for pubsub
|
| services.privatebin.settings | Options for privatebin configuration
|
| services.pgbouncer.settings.users | Optional
|
| services.pgbouncer.settings.peers | Optional
|
| services.mattermost.settings | Additional configuration options as Nix attribute set in config.json schema.
|
| services.anubis.instances.<name>.policy.useDefaultBotRules | Whether to include Anubis's default bot detection rules via the
(data)/meta/default-config.yaml import
|
| services.libeufin.nexus.settings | Configuration options for the libeufin nexus config file
|
| services.taler.exchange.settings | Configuration options for the taler exchange config file
|
| services.taler.merchant.settings | Configuration options for the taler merchant config file
|
| services.pds.settings.PDS_DATA_DIRECTORY | Directory to store state
|
| services.misskey.settings.redisForJobQueue.port | The Redis port.
|
| services.misskey.settings.redisForJobQueue.host | The Redis host.
|
| services.lasuite-meet.settings.DJANGO_DATA_DIR | Path to the data directory
|
| services.ente.api.settings.apps.accounts | Set this to the URL where your accounts page is running
|
| services.gitlab.pages.settings.listen-https | The address(es) to listen on for HTTPS requests.
|
| services.amule.settings.WebServer.Enabled | Set to 1 to enable the web server
|
| services.gitlab.pages.settings.listen-proxy | The address(es) to listen on for proxy requests.
|
| services.hatsu.settings.HATSU_DATABASE_URL | Database URL.
|
| services.public-inbox.settings.coderepo | code repositories
|
| services.radicle.ci.adapters.native.instances.<name>.name | Adapter name that is used in the radicle-ci-broker configuration
|
| services.nipap.settings.nipapd.db_host | PostgreSQL host to connect to
|
| services.postfix.settings.master.<name>.name | The name of the service to run
|
| services.firefly-iii.settings.DB_HOST | The machine which hosts your database
|
| services.plantuml-server.home | Home directory of the PlantUML server instance.
|
| services.gitea.settings.server.DISABLE_SSH | Disable external SSH feature.
|
| services.canaille.settings.SERVER_NAME | The domain name on which canaille will be served.
|
| services.freeciv.settings.quitidle | Quit if no players for given time in seconds.
|
| services.freeciv.settings.Database | Enable database connection with given configuration.
|
| services.pretix.settings.database.host | Database host or socket path.
|
| services.umurmur.settings.password | Required password to join server, if specified.
|
| services.postsrsd.settings.domains | List of local domains, that do not require rewriting.
|
| services.warpgate.settings.http.listen | Listen endpoint of HTTP listener.
|
| programs.direnv.settings | Direnv configuration
|
| services.journald.remote.settings | Configuration in the journal-remote configuration file
|
| services.zammad.database.settings | The database.yml configuration file as key value set
|
| services.gitea-actions-runner.instances.<name>.hostPackages | List of packages, that are available to actions, when the runner is configured
with a host execution label.
|
| services.cryptpad.settings.logToStdout | Controls whether log output should go to stdout of the systemd service
|
| services.opensnitch.settings | opensnitchd configuration
|
| services.nebula.networks.<name>.settings | Nebula configuration
|
| services.x2goserver.settings | x2goserver.conf ini configuration as nix attributes
|
| services.sourcehut.settings.mail.pgp-key-id | OpenPGP key identifier.
|
| services.forgejo.settings.server.DOMAIN | Domain name of your server.
|
| services.headscale.settings.log.level | headscale log level.
|
| services.tlsrpt.reportd.settings.dbname | Path to the sqlite database.
|
| services.tor.settings.ShutdownWaitLength | See torrc manual.
|
| services.kanidm.server.settings.db_path | Path to Kanidm database.
|
| services.mautrix-meta.instances.<name>.registerToSynapse | Whether to add registration file to services.matrix-synapse.settings.app_service_config_files and
make Synapse wait for registration service.
|
| services.prometheus.exporters.nginxlog.settings | All settings of nginxlog expressed as an Nix attrset
|
| services.shairport-sync.settings | Configuration options for Shairport-Sync
|
| services.forgejo.settings.server.HTTP_PORT | Listen port
|
| services.draupnir.settings.dataPath | The path Draupnir will store its state/data in.
This option is read-only.
If you want to customize where this data is stored, use a bind mount.
|
| services.lemmy.settings.captcha.enabled | Enable Captcha.
|
| services.gancio.settings.log_level | Gancio log level.
|
| services.hedgedoc.settings.allowOrigin | List of domains to whitelist.
|
| services.opengfw.settings.ruleset.geoip | Path to geoip.dat.
|
| services.tinyproxy.settings.Listen | Specify which address to listen to.
|
| services.librechat.settings | A free-form attribute set that will be written to librechat.yaml
|
| services.hedgedoc.settings.useSSL | Enable to use SSL server.
|
| services.freeciv.settings.Announce | Announce game in LAN using given protocol.
|
| services.sabnzbd.settings.servers.<name>.ssl | Whether the server supports TLS
|
| services.umurmur.settings.bindaddr | IPv4 address to bind to
|
| services.sftpgo.settings.ftpd.bindings | Configure listen addresses and ports for ftpd.
|
| services.maubot.settings.database | The full URI to the database
|
| services.rsyncd.settings.sections | attribute set of section of an INI file (attrs of INI atom (null, bool, int, float or string))
|
| nix.settings.cores | This option defines the maximum number of concurrent tasks during
one build
|
| services.scanservjs.settings.host | The IP to listen on.
|
| services.scanservjs.settings.port | The port to listen on.
|
| services.openssh.settings.DenyGroups | If specified, login is denied for all users part of the listed
groups
|
| services.autotierfs.settings | The contents of the configuration file for autotier
|
| services.kanidm.server.settings.tls_key | TLS key in pem format.
|
| services.yggdrasil-jumper.settings | Configuration for Yggdrasil Jumper as a Nix attribute set.
|
| services.redis.servers.<name>.slaveOf | IP and port to which this redis instance acts as a slave.
|
| services.tuned.settings.globalSection | global section of an INI file (attrs of INI atom (null, bool, int, float or string))
|
| services.openssh.settings.AllowGroups | If specified, login is allowed only for users part of the
listed groups
|
| services.biboumi.settings.db_name | The name of the database to use
|
| services.forgejo.settings.server.HTTP_ADDR | Listen address
|
| services.taler.settings.taler.CURRENCY | The currency which taler services will operate with
|
| services.acme-dns.settings.database.engine | Database engine to use.
|
| services.sabnzbd.settings.servers.<name>.host | Hostname of the server
|
| services.sabnzbd.settings.servers.<name>.port | Port of the server
|
| services.tor.settings.FascistFirewall | See torrc manual.
|
| services.sabnzbd.settings.servers.<name>.name | The name of the server
|
| services.waagent.settings.OS.EnableRDMA | If enabled, the agent attempts to install and then load an RDMA kernel driver
that matches the version of the firmware on the underlying hardware.
|
| services.freeciv.settings.Newusers | Whether to enable new users to login if auth is enabled.
|
| services.aesmd.settings.whitelistUrl | URL to retrieve authorized Intel SGX enclave signers.
|
| services.suricata.settings.plugins | Plugins -- Experimental -- specify the filename for each plugin shared object.
|
| services.openssh.settings.PermitRootLogin | Whether the root user can login using ssh.
|
| services.slskd.settings.global.upload.slots | Limit of the number of concurrent upload slots.
|
| services.veilid.settings.logging.api.level | The minimum priority of api events to be logged.
|
| services.dnsmasq.settings | Configuration of dnsmasq
|
| services.cryptpad.settings.httpSafeOrigin | Cryptpad sandbox URL
|
| services.misskey.settings.redisForPubsub.port | The Redis port.
|
| services.misskey.settings.redisForPubsub.host | The Redis host.
|
| services.reposilite.settings.port | The TCP port to bind to.
|
| services.postgresql.settings.port | The port on which PostgreSQL listens.
|
| security.pam.u2f.settings.debug | Debug output to stderr.
|
| services.centrifugo.settings | Declarative Centrifugo configuration
|
| services.openssh.settings.UseDns | Specifies whether sshd(8) should look up the remote host name, and to check that the resolved host name for
the remote IP address maps back to the very same IP address
|
| services.sourcehut.settings."sr.ht".site-info | The top-level info page for your site.
|
| services.sourcehut.settings."sr.ht".site-name | The name of your network of sr.ht-based sites.
|
| services.invidious-router.settings | Configuration for invidious-router
|
| services.acme-dns.settings.general.nsadmin | Zone admin email address for SOA.
|
| services.inadyn.settings.custom.<name>.ddns-path | DDNS server path
|
| services.fediwall.settings.hideReplies | Hide replies
|
| services.clamsmtp.instances.*.maxConnections | Maximum number of connections to accept at once.
|
| services.rosenpass.settings.listen | List of local endpoints to listen for connections.
|
| services.umami.settings.DISABLE_UPDATES | Disables the check for new versions of Umami.
|
| services.mchprs.settings.schemati | Mimic the verification and directory layout used by the
Open Redstone Engineers
Schemati plugin
|
| services.minidlna.settings.inotify | Whether to enable inotify monitoring to automatically discover new files.
|
| programs.foot.settings | Configuration for foot terminal emulator
|
| programs.htop.settings | Extra global default configuration for htop
which is read on first startup only
|
| services.epgstation.settings.port | HTTP port for EPGStation to listen on.
|
| services.tor.settings.VirtualAddrNetworkIPv4 | See torrc manual.
|
| services.tor.settings.VirtualAddrNetworkIPv6 | See torrc manual.
|
| services.samba.settings.global.security | Samba security type.
|
| services.snips-sh.settings.SNIPS_SSH_INTERNAL | The internal SSH address of the service
|
| services.tor.settings.AccountingMax | See torrc manual.
|
| services.openssh.settings.AcceptEnv | Specifies what environment variables sent by the client will be copied into the session's
environment
|
| services.gateone.settingsDir | Path of configuration files for GateOne.
|
| services.openvpn.servers.<name>.up | Shell commands executed when the instance is starting.
|
| security.auditd.settings | auditd configuration file contents
|
| services.anuko-time-tracker.settings.email.mode | Mail sending mode
|
| services.inadyn.settings.provider.<name>.ssl | Whether to use HTTPS for this DDNS provider.
|
| services.routinator.settings.log | A string specifying where to send log messages to
|
| services.pretix.settings.pretix.datadir | Directory for storing user uploads and similar data.
|
| services.bitmagnet.settings.dht_server | DHT server settings
|
| services.sourcehut.settings."sr.ht".site-blurb | Blurb for your site.
|
| services.sourcehut.settings.mail.smtp-from | Outgoing SMTP FROM.
|
| services.sourcehut.settings."sr.ht".owner-name | Owner's name.
|
| services.lasuite-meet.settings.LIVEKIT_API_URL | URL to the livekit server
|
| services.suricata.settings.vars.address-groups | The address group variables for suricata, if not defined the
default value of suricata (see example) will be used
|
| services.postgrest.settings.db-uri | libpq connection parameters as documented in:
https://www.postgresql.org/docs/current/libpq-connect.html#LIBPQ-PARAMKEYWORDS
The settings.db-uri.password and settings.db-uri.passfile options are blocked
|
| services.opengfw.settings.ruleset | The path to load specific local geoip/geosite db files
|
| services.dawarich.localDomain | The domain serving your Dawarich instance.
|
| services.castopod.localDomain | The domain serving your CastoPod instance.
|
| services.mastodon.localDomain | The domain serving your Mastodon instance.
|
| services.peertube.localDomain | The domain serving your PeerTube instance.
|
| programs.yazi.settings.theme | Configuration included in theme.toml
|
| services.firefly-iii.settings.APP_KEY_FILE | The path to your appkey
|
| services.opencloud.settings | Additional YAML configuration for OpenCloud services
|
| services.veilid.settings.core.network.upnp | Should the app try to improve its incoming network connectivity using UPnP?
|
| services.slskd.settings.web.https.disabled | Disable the built-in HTTPS server
|
| services.pretalx.settings.redis.session | Whether to use redis as the session storage.
|
| services.bluesky-pds.settings.PDS_CRAWLERS | URL of crawlers
|
| services.zipline.settings.CORE_HOSTNAME | The hostname to listen on.
|
| services.sitespeed-io.runs.*.settings | Configuration for sitespeed-io, see
https://www.sitespeed.io/documentation/sitespeed.io/configuration/
for available options
|
| services.c2fmzq-server.settings.verbose | The level of logging verbosity: 1:Error 2:Info 3:Debug
|
| services.suricata.settings.stats | Engine statistics such as packet counters, memory use counters and others can be logged in several ways
|
| services.wastebin.settings.RUST_LOG | Influences logging
|
| services.gitlab.pages.settings.gitlab-server | Public GitLab server URL.
|
| services.legit.settings.dirs.templates | Directories where template files are located.
|
| services.gitea.settings.mailer.PROTOCOL | Which mail server protocol to use.
|
| services.headscale.settings.oidc.scope | Scopes used in the OIDC flow.
|
| services.inadyn.settings.custom.<name>.ddns-server | DDNS server name.
|
| services.misskey.settings.db.disableCache | Whether to disable caching queries.
|
| services.warpgate.settings.mysql.enable | Whether to enable MySQL listener.
|
| services.warpgate.settings.mysql.listen | Listen endpoint of MySQL listener.
|
| services.parsedmarc.settings | Configuration parameters to set in
parsedmarc.ini
|
| services.pretalx.settings.celery.broker | URI to the celery broker used for the asynchronous job queue.
|
| services.pretix.settings.celery.backend | URI to the celery backend used for the asynchronous job queue.
|
| services.neard.settings.General.ResetOnError | Power cycle the adapter when getting a driver error from the kernel.
|
| services.wg-access-server.settings.storage | A storage backend connection string
|
| services.sourcehut.settings.mail.smtp-port | Outgoing SMTP port.
|
| services.sourcehut.settings.mail.smtp-host | Outgoing SMTP host.
|
| services.sourcehut.settings.mail.smtp-user | Outgoing SMTP user.
|
| services.hedgedoc.settings.uploadsPath | Directory for storing uploaded images.
|
| services.cryptpad.settings.httpAddress | Address on which the Node.js server should listen
|
| services.nvme-rs.settings.email.smtp_port | SMTP server port
|
| services.tor.settings.AssumeReachable | See torrc manual.
|
| services.tor.settings.ServerDNSSearchDomains | See torrc manual.
|
| services.tor.settings.WarnPlaintextPorts | See torrc manual.
|
| services.nvme-rs.settings.thresholds | Threshold configuration for NVMe monitoring
|
| services.tor.settings.RelayBandwidthRate | See torrc manual.
|
| services.tor.settings.UnixSocksGroupWritable | See torrc manual.
|
| services.tor.settings.AutomapHostsOnResolve | See torrc manual.
|
| services.tor.settings.DormantOnFirstStartup | See torrc manual.
|
| services.reaction.settingsFiles | Configuration for reaction, see the wiki.
reaction supports JSON, YAML and JSONnet
|
| services.postgrest.settings | PostgREST configuration as documented in:
https://docs.postgrest.org/en/stable/references/configuration.html#list-of-parameters
db-uri is represented as an attribute set, see settings.db-uri
The settings.jwt-secret option is blocked
|
| services.netbox.settings.ALLOWED_HOSTS | A list of valid fully-qualified domain names (FQDNs) and/or IP
addresses that can be used to reach the NetBox service.
|
| services.postfix.settings.master.<name>.args | Arguments to pass to the command
|
| services.gitea.settings.server.STATIC_ROOT_PATH | Upper level of template and static files path.
|
| services.cryptpad.settings.maxWorkers | Number of child processes, defaults to number of cores available
|
| services.opengfw.settings.workers.count | Number of workers
|
| services.cfssl.mutualTlsClientCert | Mutual TLS - client certificate to call remote instance requiring client certs.
|
| services.anuko-time-tracker.settings.email.smtpHost | MTA hostname.
|
| services.grafana.settings.database.type | Database type.
|
| services.dependency-track.settings | See https://docs.dependencytrack.org/getting-started/configuration/#default-configuration for possible options
|
| services.anuko-time-tracker.settings.email.smtpPort | MTA port.
|
| services.aesmd.settings.defaultQuotingType | Attestation quote type.
|
| services.pretalx.settings.database.name | Database name.
|
| services.pretalx.settings.database.user | Database username.
|
| services.librespeed.frontend.settings | Override default settings of the speedtest web client
|
| services.xonotic.settings.hostname | The name that will appear in the server list. $g_xonoticversion
gets replaced with the current version.
|
| services.sympa.settingsFile.<name>.text | Text of the file.
|
| services.kubo.settings.Addresses.Swarm | Where Kubo listens for incoming p2p connections
|
| services.sftpgo.settings.httpd.bindings | Configure listen addresses and ports for httpd.
|
| services.metricbeat.settings.tags | Tags to place on the shipped metrics
|
| services.metricbeat.settings.name | Name of the beat
|
| services.pretix.settings.redis.sessions | Whether to use redis as the session storage.
|
| services.scrutiny.settings.web.listen.port | Port for web application to listen on.
|
| services.sftpgo.settings.sftpd.bindings | Configure listen addresses and ports for sftpd.
|
| services.suricata.settings.stats.enable | Whether to enable suricata global stats.
|
| services.yggdrasil.settings.Peers | List of outbound peer connection strings
|
| services.c2fmzq-server.settings.database | Path of the database
|
| services.stash.settings.blobs_path | Path to blobs
|
| services.evremap.settings.remap.*.output | The key sequence that should be output when the input sequence is entered
|
| services.collabora-online.settings | Configuration for Collabora Online WebSocket Daemon, see
https://sdk.collaboraonline.com/docs/installation/Configuration.html, or
https://github.com/CollaboraOnline/online/blob/master/coolwsd.xml.in for the default
configuration.
|
| services.wordpress.sites.<name>.settings | Structural Wordpress configuration
|
| services.immich-public-proxy.immichUrl | URL of the Immich instance
|
| services.sourcehut.settings.mail.error-to | Address receiving application exceptions
|
| services.suricata.settings.vars.port-groups | The port group variables for suricata.
|
| services.postsrsd.settings.chroot-dir | Path to chroot into at runtime as an additional layer of protection.
We confine the runtime environment through systemd hardening instead, so this option is read-only.
|
| services.grafana.settings.paths.plugins | Directory where grafana will automatically scan and look for plugins
|
| services.anuko-time-tracker.settings.email.smtpAuth | MTA requires authentication.
|
| services.anuko-time-tracker.settings.email.smtpUser | MTA authentication username.
|
| services.grafana.settings.database.name | The name of the Grafana database.
|
| services.headscale.settings.log.format | headscale log format.
|
| services.tor.settings.CellStatistics | See torrc manual.
|
| services.snips-sh.settings.SNIPS_HTTP_INTERNAL | The internal HTTP address of the service
|
| services.tor.settings.OptimisticData | See torrc manual.
|
| services.tor.settings.DirReqStatistics | See torrc manual.
|
| services.biboumi.settings.hostname | The hostname served by the XMPP gateway
|
| services.rkvm.client.settings.password | Shared secret token to authenticate the client
|
| services.rkvm.server.settings.password | Shared secret token to authenticate the client
|
| security.krb5.settings.module | Modules to obtain Kerberos configuration from.
|
| services.gitea.settings.server.PROTOCOL | Listen protocol. +unix means "over unix", not "in addition to."
|
| services.scrutiny.settings.web.listen.host | Interface address for web application to bind to.
|
| services.samba.settings.global."invalid users" | List of users who are denied to login via Samba.
|
| services.wgautomesh.settings.peers | wgautomesh peer list.
|
| services.cfssl.mutualTlsClientKey | Mutual TLS - client key to call remote instance requiring client certs
|
| services.acme-dns.settings.general.records | Predefined DNS records served in addition to the _acme-challenge TXT records.
|
| services.dsnet.settings.ExternalIP | The external IP address of the server
|
| services.rosenpass.settings.peers.*.peer | WireGuard public key corresponding to the remote Rosenpass peer.
|
| services.umami.settings.TRACKER_SCRIPT_NAME | Allows you to assign a custom name to the tracker script different from the default script.js.
|
| services.hickory-dns.settings.zones.*.file | Path to the .zone file
|
| services.grafana.settings.database.user | The database user (not applicable for sqlite3).
|
| services.grafana.settings.smtp.key_file | File path to a key file.
|
| services.hbase-standalone.settings | configurations in hbase-site.xml, see https://github.com/apache/hbase/blob/master/hbase-server/src/test/resources/hbase-site.xml for details.
|
| services.privoxy.settings.listen-address | Pair of address:port the proxy server is listening to.
|
| services.sabnzbd.settings.misc.email_to | Receiving address for email alerts
|
| services.pretalx.settings.database.host | Database host or socket path.
|
| services.parsedmarc.settings.smtp.to | The addresses to send outgoing mail to.
|
| services.frigate.settings.database.path | Path to the SQLite database used
|
| services.rsyncd.settings.globalSection | global section of an INI file (attrs of INI atom (null, bool, int, float or string))
|
| services.sympa.mta.type | Mail transfer agent (MTA) integration
|
| services.mattermost.host | Host or address that this Mattermost instance listens on.
|
| services.mympd.settings.http_port | The HTTP port where mympd's web interface will be available
|
| services.kavita.settings.IpAddresses | IP Addresses to bind to
|
| services.resolved.settings.Resolve.DNS | List of IP addresses to query as recursive DNS resolvers.
|
| services.bookstack.settings.APP_URL | The root URL that you want to host BookStack on
|
| services.grafana-image-renderer.settings | Configuration attributes for grafana-image-renderer.
|
| services.tor.settings.ServerDNSAllowBrokenConfig | See torrc manual.
|
| services.tor.settings.ExitPolicyRejectPrivate | See torrc manual.
|
| services.opengfw.settings.workers.queueSize | Worker queue size.
|
| services.headscale.settings.dns.split | Split DNS configuration (map of domains and which DNS server to use for each)
|
| services.sourcehut.settings."sr.ht".owner-email | Owner's email.
|
| services.navidrome.settings.Address | Address to run Navidrome on.
|
| services.pid-fan-controller.settings.fans | List of fans to be controlled.
|
| services.maubot.settings.server.hostname | The IP to listen on
|
| services.watchdogd.settings.timeout | The WDT timeout before reset.
|
| services.jitsi-meet.jibri.enable | Whether to enable a Jibri instance and configure it to connect to Prosody
|
| programs.lazygit.settings | Lazygit configuration
|
| services.headscale.settings.derp.urls | List of urls containing DERP maps
|
| services.grafana.settings.database.wal | For sqlite3 only
|
| services.jitsi-meet.jicofo.enable | Whether to enable JiCoFo instance and configure it to connect to Prosody
|
| services.sourcehut.settings."hg.sr.ht".origin | URL hg.sr.ht is being served at (protocol://domain)
|
| services.sourcehut.settings."hg.sr.ht".hg_ssh | Path to hg-ssh (if not in $PATH).
|
| services.sourcehut.settings."sr.ht".source-url | The source code for your fork of sr.ht.
|
| services.sourcehut.settings."hg.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."hg.sr.ht".debug-port | Port to bind the debug server to.
|
| services.snapserver.settings.tcp.port | Port to listen on for snapclient connections.
|
| services.imaginary.settings.return-size | Return the image size in the HTTP headers.
|
| services.postgrest.settings.server-port | The TCP port to bind the web server.
|
| services.tlsrpt.fetcher.settings.storage | Path to the collectd sqlite database.
|
| services.clamsmtp.instances.*.transparentProxy | Enable clamsmtp's transparent proxy support.
|
| services.radicle.ci.adapters.native.instances.<name>.package | The radicle-native-ci package to use.
|
| services.amule.settings.eMule.IncomingDir | Directory where aMule moves completed downloads
|
| services.lokinet.settings.network.exit | Whether to act as an exit node
|
| nix.settings | Configuration for Nix, see
https://nixos.org/manual/nix/stable/command-ref/conf-file.html or
nix.conf(5) for available options
|
| services.headscale.settings.oidc.issuer | URL to OpenID issuer.
|
| services.angrr.settings.profile-policies | Profile GC root policies.
|
| services.moosefs.cgiserver.settings | GUI server configuration options.
|
| services.tor.settings.RelayBandwidthBurst | See torrc manual.
|
| services.opensearch.settings."http.port" | The port to listen on for HTTP traffic.
|
| services.actual.settings.serverFiles | The server will put an account.sqlite file in this directory, which will contain the (hashed) server password, a list of all the budget files the server knows about, and the active session token (along with anything else the server may want to store in the future).
|
| services.bonsaid.settings.*.command | Command to run when this transition is taken
|
| services.hologram-agent.enable | Whether to enable the Hologram agent for AWS instance credentials
|
| services.openvpn.servers.<name>.down | Shell commands executed when the instance is shutting down.
|
| services.pantalaimon-headless.instances.<name>.ssl | Whether or not SSL verification should be enabled for outgoing
connections to the homeserver.
|
| services.healthchecks.settings | Environment variables which are read by healthchecks (local)_settings.py
|
| services.mautrix-discord.settings.bridge | Bridge configuration
|
| services.logrotate.settings.<name>.enable | Whether to enable setting individual kill switch.
|
| services.scrutiny.collector.settings | Collector settings to be rendered into the collector configuration file
|
| services.pretix.settings.redis.location | URI to the redis server, used to speed up locking, caching and session storage.
|
| services.warpgate.settings.log.send_to | Path of UNIX socket of log forwarder
|
| services.parsedmarc.settings.smtp.ssl | Use an encrypted SSL/TLS connection.
|
| services.openldap.settings.children | Child entries of the current entry, with recursively the same structure.
|
| services.openldap.settings.includes | LDIF files to include after the parent's attributes but before its children.
|
| services.parsedmarc.settings.imap.ssl | Use an encrypted SSL/TLS connection.
|
| services.grafana.settings.server.socket | Path where the socket should be created when protocol=socket
|
| services.openssh.settings.GatewayPorts | Specifies whether remote hosts are allowed to connect to
ports forwarded for the client
|
| services.watchdogd.settings.safe-exit | With safeExit enabled, the daemon will ask the driver to disable the WDT before exiting
|
| programs.regreet.settings | ReGreet configuration file
|
| services.garage.settings.data_dir | The directory in which Garage will store the data blocks of objects
|
| services.sourcehut.settings.mail.error-from | Address sending application exceptions
|
| services.sourcehut.settings."hub.sr.ht".debug-port | Port to bind the debug server to.
|
| services.sourcehut.settings."man.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."git.sr.ht".debug-port | Port to bind the debug server to.
|
| services.sourcehut.settings."man.sr.ht".debug-port | Port to bind the debug server to.
|
| services.sourcehut.settings."git.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."man.sr.ht".origin | URL man.sr.ht is being served at (protocol://domain)
|
| services.sourcehut.settings."hub.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."git.sr.ht".origin | URL git.sr.ht is being served at (protocol://domain)
|
| services.sourcehut.settings."hub.sr.ht".origin | URL hub.sr.ht is being served at (protocol://domain)
|
| services.autosuspend.settings | Configuration for autosuspend, see
https://autosuspend.readthedocs.io/en/latest/configuration_file.html#general-configuration
for supported values.
|
| services.acme-dns.settings.general.protocol | Protocols to serve DNS responses on.
|
| services.bluesky-pds.settings.PDS_BLOB_UPLOAD_LIMIT | Size limit of uploaded blobs in bytes
|
| services.immichframe.settings | Configuration for ImmichFrame
|
| services.umurmur.settings.max_users | Maximum number of concurrent clients allowed.
|
| services.pretix.settings.pretix.cachedir | Directory for storing temporary files.
|
| services.mollysocket.settings | Configuration for MollySocket
|
| services.vmalert.settings."notifier.url" | Prometheus Alertmanager URL
|
| services.yggdrasil.settings.Listen | Listen addresses for incoming connections
|
| services.filebeat.settings | Configuration for filebeat
|
| services.jitsi-meet.jigasi.enable | Whether to enable jigasi instance and configure it to connect to Prosody
|
| services.mautrix-signal.settings | config.yaml configuration as a Nix attribute set
|
| services.anuko-time-tracker.settings.email.smtpDebug | Debug mail sending.
|
| services.anuko-time-tracker.settings.email.sender | Default sender for mail.
|
| services.tor.settings.UseDefaultFallbackDirs | See torrc manual.
|
| services.parsedmarc.settings.imap.port | The IMAP server port.
|
| services.tor.settings.AccountingStart | See torrc manual.
|
| services.tor.settings.ProtocolWarnings | See torrc manual.
|
| services.parsedmarc.settings.smtp.user | The SMTP server username.
|
| services.parsedmarc.settings.smtp.port | The SMTP server port.
|
| services.tor.settings.EntryStatistics | See torrc manual.
|
| services.omnom.settings.db.connection | Database connection URI.
|
| services.parsedmarc.settings.imap.user | The IMAP server username.
|
| services.lasuite-docs.settings.CELERY_BROKER_URL | URL of the redis backend for celery
|
| services.lasuite-meet.settings.CELERY_BROKER_URL | URL of the redis backend for celery
|
| services.postgrest.settings.db-config | Enables the in-database configuration.
https://docs.postgrest.org/en/stable/references/configuration.html#in-database-configuration
This is enabled by default upstream, but disabled by default in this module.
|
| services.matrix-hookshot.settings.passFile | A passkey used to encrypt tokens stored inside the bridge
|
| services.waagent.settings.Logs.Verbose | If you set this option, log verbosity is boosted
|
| services.dsnet.settings.ExternalIP6 | The external IPv6 address of the server
|
| services.umurmur.settings.bindaddr6 | IPv6 address to bind to
|
| services.syncthing.settings.options | The options element contains all other global configuration options
|
| services.writefreely.settings | Writefreely configuration (config.ini)
|
| services.xonotic.settings.sv_public | Controls whether the server will be publicly listed.
|
| services.sourcehut.settings."meta.sr.ht::settings".registration | Whether to enable public registration.
|
| services.hercules-ci-agent.settings.apiBaseUrl | API base URL that the agent will connect to
|
| services.nitter.server.hostname | Hostname of the instance.
|
| services.grafana.settings.database.path | Only applicable to sqlite3 database
|
| <imports = [ pkgs.php.services.default ]>.php-fpm.settings | PHP FPM configuration
|
| services.bookstack.settings | Options for Bookstack configuration
|
| services.gitea.settings.mailer.SENDMAIL_PATH | Path to sendmail binary or script.
|
| services.grafana.settings.smtp.startTLS_policy | StartTLS policy when connecting to server.
|
| services.public-inbox.settings.coderepo.<name>.dir | Path to a git repository
|
| services.suwayomi-server.settings.server.ip | The ip that Suwayomi will bind to.
|
| services.snapserver.settings.http.port | Port to listen on for snapclient connections.
|
| services.openbao.settings.listener.<name>.type | The listener type to enable.
|
| services.parsedmarc.settings.smtp.from | The From address to use for the
outgoing mail.
|
| services.suricata.settings.host-mode | If the Suricata box is a router for the sniffed networks, set it to 'router'
|
| services.lokinet.settings.dns.upstream | Upstream resolver(s) to use as fallback for non-loki addresses
|
| services.ytdl-sub.instances.<name>.subscriptions | Subscriptions for ytdl-sub
|
| programs.yazi.settings.keymap | Configuration included in keymap.toml
|
| services.pretalx.settings.celery.backend | URI to the celery backend used for the asynchronous job queue.
|
| services.sourcehut.settings.mail.pgp-pubkey | OpenPGP public key.
|
| services.tor.settings.ExitPortStatistics | See torrc manual.
|
| services.tor.settings.AutomapHostsSuffixes | See torrc manual.
|
| systemd.settings.Manager | Options for the global systemd service manager
|
| services.forgejo.settings.server.SSH_PORT | SSH port displayed in clone URL
|
| services.litellm.settings.router_settings | LiteLLM Router settings
|
| services.birdwatcher.settings | birdwatcher configuration, for configuration options see the example on github
|
| services.meshtasticd.settings | The Meshtastic configuration file
|
| services.sourcehut.settings."hg.sr.ht".repos | Path to mercurial repositories on disk
|
| services.postfix-tlspol.settings.server.log-level | Log level
|
| services.reposilite.settings.sslPort | SSL port to bind to
|
| services.sourcehut.settings."lists.sr.ht".redis | The Redis connection used for the Celery worker.
|
| services.etebase-server.settings.global.debug | Whether to set django's DEBUG flag.
|
| services.parsedmarc.settings.imap.host | The IMAP server hostname or IP address.
|
| services.parsedmarc.settings.smtp.host | The SMTP server hostname or IP address.
|
| services.firewalld.settings.RFC3964_IPv4 | Whether to filter IPv6 traffic with 6to4 destination addresses that correspond to IPv4 addresses that should not be routed over the public internet.
|
| services.rethinkdb.dbpath | Location where RethinkDB stores its data, 1 data directory per instance.
|
| services.sourcehut.settings."todo.sr.ht".origin | URL todo.sr.ht is being served at (protocol://domain)
|
| services.sourcehut.settings."meta.sr.ht".debug-port | Port to bind the debug server to.
|
| services.sourcehut.settings."todo.sr.ht".debug-port | Port to bind the debug server to.
|
| services.sourcehut.settings."meta.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."todo.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."meta.sr.ht".origin | URL meta.sr.ht is being served at (protocol://domain)
|
| services.forgejo.settings.server.DISABLE_SSH | Disable external SSH feature.
|
| services.sabnzbd.settings.servers.<name>.enable | Enable this server by default
|
| services.sftpgo.settings.smtp.auth_type |
0: Plain
1: Login
2: CRAM-MD5
|
| services.epgstation.settings.encode | Encoding presets for recorded videos.
|
| services.tor.settings.ServerDNSRandomizeCase | See torrc manual.
|
| services.tor.settings.BridgeRecordUsageByCountry | See torrc manual.
|
| services.gotosocial.settings | Contents of the GoToSocial YAML config
|
| services.pgbackrest.settings | An attribute set of options as described in:
https://pgbackrest.org/configuration.html
All globally available options, i.e. all except stanza options, can be used
|
| services.geoipupdate.settings | geoipupdate configuration options
|
| services.suricata.settings.default-rule-path | Path in which suricata-update managed rules are stored by default.
|
| services.sourcehut.settings."git.sr.ht".repos | Path to git repositories on disk
|
| services.headscale.settings.derp.paths | List of file paths containing DERP maps
|
| services.peroxide.settings.ServerAddress | The address on which to listen for connections.
|
| services.corteza.settings.HTTP_WEBAPP_ENABLED | Whether to enable webapps.
|
| services.firewalld.settings.DefaultZone | Default zone for connections.
|
| services.opengfw.settings.ruleset.geosite | Path to geosite.dat.
|
| services.matrix-synapse.settings.pid_file | The file to store the PID in.
|
| security.pam.u2f.settings | Options to pass to the PAM module
|
| services.grocy.settings.calendar.firstDayOfWeek | Which day of the week (0=Sunday, 1=Monday etc.) should be the
first day.
|
| services.bitmagnet.settings.http_server | HTTP server settings
|
| services.apache-kafka.settings.listeners | Kafka Listener List
|
| services.typesense.settings.server.api-port | Port on which the Typesense API service listens.
|
| services.warpgate.settings.postgres.key | Path to PostgreSQL listener private key.
|
| services.knot-resolver.settings.workers | The number of running kresd (Knot Resolver daemon) workers
|
| services.postfix.settings.master.<name>.wakeup | Automatically wake up the service after the specified number of
seconds
|
| services.filebrowser.settings.port | The port to listen on.
|
| services.botamusique.settings | Your configuration.ini as a Nix attribute set
|
| services.samba.settings.global."passwd program" | Path to a program that can be used to set UNIX user passwords.
|
| services.pretix.settings.pretix.currency | Default currency for events in its ISO 4217 three-letter code.
|
| services.zigbee2mqtt.settings | Your configuration.yaml as a Nix attribute set
|
| services.pantalaimon-headless.instances.<name>.logLevel | Set the log level of the daemon.
|
| services.inadyn.settings.custom.<name>.hostname | Hostname alias(es).
|
| services.inadyn.settings.custom.<name>.username | Username for this DDNS provider.
|
| services.traefik.dynamic.settings | Dynamic configuration for Traefik, written in Nix
|
| nix.settings.system-features | The set of features supported by the machine
|
| services.amule.settings.WebServer.Password | MD5 hash of the password, obtainaible with echo "<password>" | md5sum | cut -d ' ' -f 1
|
| services.sourcehut.settings."meta.sr.ht::settings".onboarding-redirect | Where to redirect new users upon registration.
|
| services.prometheus.exporters.fritz.settings | Configuration settings for fritz-exporter.
|
| services.lokinet.settings.network.exit-node | Specify a .loki address and an optional ip range to use as an exit broker
|
| services.tor.settings.MaxCircuitDirtiness | See torrc manual.
|
| services.tor.settings.RejectPlaintextPorts | See torrc manual.
|
| services.pantalaimon-headless.instances.<name>.dataPath | The directory where pantalaimon should store its state such as the database file.
|
| services.mattermost.siteUrl | URL this Mattermost instance is reachable under, without trailing slash.
|
| services.umami.settings.APP_SECRET_FILE | A file containing a secure random string
|
| services.typesense.settings.server.data-dir | Path to the directory where data will be stored on disk.
|
| services.veilid.settings.logging.api.enabled | Events of type 'api' will be logged.
|
| services.veilid.settings.logging.system.level | The minimum priority of system events to be logged.
|
| services.sftpgo.settings.ftpd.bindings.*.port | The port for serving FTP requests
|
| services.grafana.settings.server.protocol | Which protocol to listen.
|
| services.headscale.settings.policy.mode | The mode can be "file" or "database" that defines
where the ACL policies are stored and read from.
|
| services.headscale.settings.policy.path | If the mode is set to "file", the path to a
HuJSON file containing ACL policies.
|
| services.firewalld.settings.ReloadPolicy | The policy during reload.
|
| services.anuko-time-tracker.settings.reportFooter | Defines whether to use a footer on reports.
|
| services.listmonk.database.settings.smtp | List of outgoing SMTP servers
|
| services.pid-fan-controller.settings.fans.*.minPwm | Minimum PWM value.
|
| services.pid-fan-controller.settings.fans.*.maxPwm | Maximum PWM value.
|
| services.suwayomi-server.settings.server.port | The port that Suwayomi will listen to.
|
| services.matrix-appservice-irc.settings | Configuration for the appservice, see
https://github.com/matrix-org/matrix-appservice-irc/blob/4.0.0/config.sample.yaml
for supported values
|
| services.suricata.settings.includes | Files to include in the suricata configuration
|
| services.libeufin.nexus.settings.nexus-ebics.BIC | BIC of the bank account that is associated with the EBICS subscriber.
|
| services.canaille.settings.CANAILLE.ACL | Access Control Lists
|
| services.rosenpass.settings.peers.*.device | Name of the local WireGuard interface to use for this peer.
|
| services.privoxy.settings.enable-edit-actions | Whether the web-based actions file editor may be used.
|
| services.postfix.settings.master.<name>.chroot | Whether the service is chrooted to have only access to the
services.postfix.queueDir and the closure of
store paths specified by the program option.
|
| services.filebrowser.settings.root | The directory where FileBrowser stores files.
|
| services.postfix-tlspol.settings.server.cache-file | Path to the cache file.
|
| services.tor.settings.ExtraInfoStatistics | See torrc manual.
|
| services.mollysocket.settings.port | Listening port of the web server
|
| services.tor.settings.CookieAuthFileGroupReadable | See torrc manual.
|
| services.tlsrpt.collectd.settings.storage | Storage backend definition.
|
| services.mollysocket.settings.host | Listening address of the web server
|
| security.krb5.settings.include | Files to include in the Kerberos configuration.
|
| services.crab-hole.settings.blocklist.lists | List of blocklists
|
| services.syncplay.salt | Salt to allow room operator passwords generated by this server
instance to still work when the server is restarted
|
| services.librespeed.settings | LibreSpeed configuration written as Nix expression
|
| services.mautrix-discord.settings.logging | Logging configuration
|
| services.szurubooru.server.settings | Configuration to write to config.yaml
|
| services.anubis.defaultOptions.settings | Freeform configuration via environment variables for Anubis
|
| services.bitmagnet.settings.postgres | PostgreSQL database configuration
|
| services.hologram-server.enable | Whether to enable the Hologram server for AWS instance credentials
|
| services.wstunnel.clients.<name>.settings | Command line arguments to pass to wstunnel
|
| services.wstunnel.servers.<name>.settings | Command line arguments to pass to wstunnel
|
| services.pretalx.settings.redis.location | URI to the redis server, used to speed up locking, caching and session storage.
|
| services.opensnitch.settings.LogLevel | Default log level from 0 to 4 (debug, info, important, warning,
error).
|
| services.grafana.settings.server.domain | The public facing domain name used to access grafana from a browser
|
| services.logrotate.settings.<name>.files | Single or list of files for which rules are defined
|
| services.mautrix-telegram.settings | config.yaml configuration as a Nix attribute set
|
| services.grocy.settings.calendar.showWeekNumber | Show the number of the weeks in the calendar views.
|
| services.libeufin.nexus.settings.nexus-httpd.PORT | The port on which libeufin-bank should listen.
|
| services.postsrsd.settings.srs-domain | Dedicated mail domain used for ephemeral SRS envelope addresses
|
| services.bluesky-pds.settings.PDS_REPORT_SERVICE_DID | DID of mod service
|
| services.keycloak.settings.hostname | The hostname part of the public URL used as base for
all frontend requests
|
| services.routinator.settings.retry | An integer value specifying the number of seconds an RTR client is requested to wait after it failed to receive a data set.
|
| services.gitlab.pages.settings | Configuration options to set in the GitLab Pages config
file
|
| services.tinyproxy.settings.Filter | Tinyproxy supports filtering of web sites based on URLs or domains
|
| services.sourcehut.settings."paste.sr.ht".debug-port | Port to bind the debug server to.
|
| services.sourcehut.settings."pages.sr.ht".debug-port | Port to bind the debug server to.
|
| services.sourcehut.settings."pages.sr.ht".origin | URL pages.sr.ht is being served at (protocol://domain)
|
| services.sourcehut.settings."lists.sr.ht".debug-port | Port to bind the debug server to.
|
| services.sourcehut.settings."paste.sr.ht".origin | URL paste.sr.ht is being served at (protocol://domain)
|
| services.sourcehut.settings."paste.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."lists.sr.ht".origin | URL lists.sr.ht is being served at (protocol://domain)
|
| services.sourcehut.settings."pages.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."lists.sr.ht".debug-host | Address to bind the debug server to.
|
| services.moosefs.cgiserver.settings.PORT | Port for CGI server to listen on.
|
| services.crowdsec.settings.console.tokenFile | The Console Token file to use.
|
| services.grafana.settings.smtp.cert_file | File path to a cert file.
|
| services.firewalld.settings.FlushAllOnReload | Whether to flush all runtime rules on a reload.
|
| services.kubo.settings.Addresses.Gateway | Where the IPFS Gateway can be reached
|
| services.postgresql.settings | PostgreSQL configuration
|
| services.couchdb.uriFile | This file contains the full URI that can be used to access this
instance of CouchDB
|
| services.mchprs.settings.bungeecord | Enable compatibility with
BungeeCord
|
| security.loginDefs.settings.UMASK | The file mode creation mask is initialized to this value.
|
| services.sourcehut.settings."hg.sr.ht".api-origin | Origin URL for the API
|
| services.routinator.settings.log-level | A string value specifying the maximum log level for which log messages should be emitted
|
| services.umami.settings.DATABASE_URL_FILE | A file containing a connection string for the database
|
| services.libeufin.nexus.settings.nexus-ebics.NAME | Legal entity that is associated with the EBICS subscriber.
|
| services.forgejo.settings.server.STATIC_ROOT_PATH | Upper level of template and static files path.
|
| services.slskd.settings.global.download.slots | Limit of the number of concurrent download slots.
|
| services.filesender.settings.admin | UIDs (as per the configured saml_uid_attribute) of FileSender administrators
|
| services.prometheus.exporters.script.settings.scripts | All settings expressed as an Nix attrset
|
| services.bluesky-pds.settings.PDS_REPORT_SERVICE_URL | URL of mod service
|
| services.mautrix-meta.instances.<name>.registrationFile | Path to the yaml registration file of the appservice.
|
| services.sourcehut.settings."builds.sr.ht".redis | The Redis connection used for the Celery worker.
|
| services.firewalld.settings.CleanupOnExit | Whether to clean up firewall rules when firewalld stops.
|
| services.chhoto-url.settings.slug_style | The slug style to use for auto-generated URLs.
|
| services.resolved.settings.Resolve.DNSSEC | Whether to validate DNSSEC for DNS lookups.
|
| services.scrutiny.settings.web.influxdb.org | InfluxDB organisation under which to store data.
|
| services.syncthing.settings.folders.<name>.id | The ID of the folder
|
| services.syncthing.settings.devices.<name>.id | The device ID
|
| services.sftpgo.settings.webdavd.bindings | Configure listen addresses and ports for webdavd.
|
| services.akkoma.installWrapper | Whether to install a wrapper around pleroma_ctl to simplify administration of the
Akkoma instance.
|
| services.displayManager.lemurs.settings | Configuration for lemurs, provided as a Nix attribute set and automatically
serialized to TOML
|
| services.libeufin.nexus.settings.nexus-ebics.HOST_ID | Name of the EBICS host.
|
| services.matrix-synapse.settings.redis.enabled | Whether to use redis support
|
| services.roundcube.extraConfig | Extra configuration for roundcube webmail instance
|
| services.sourcehut.settings."pages.sr.ht".max-site-size | Maximum size of any given site (post-gunzip), in MiB.
|
| services.sourcehut.settings."hg.sr.ht".srhtext | Path to the srht mercurial extension
(defaults to where the hgsrht code is)
|
| services.libeufin.nexus.settings.nexus-ebics.IBAN | IBAN of the bank account that is associated with the EBICS subscriber.
|
| services.umami.settings.COLLECT_API_ENDPOINT | Allows you to send metrics to a location different than the default /api/send.
|
| security.loginDefs.settings.UID_MAX | Range of user IDs used for the creation of regular users by useradd or newusers.
|
| security.loginDefs.settings.UID_MIN | Range of user IDs used for the creation of regular users by useradd or newusers.
|
| services.lidarr.settings.update.mechanism | which update mechanism to use
|
| services.radicle.ci.broker.settings.triggers | CI triggers.
|
| services.sonarr.settings.update.mechanism | which update mechanism to use
|
| services.radarr.settings.update.mechanism | which update mechanism to use
|
| services.kanidm.server.settings.log_level | Log level of the server.
|
| services.wastebin.settings.WASTEBIN_TITLE | Overrides the HTML page title
|
| services.keycloak.settings | Configuration options corresponding to parameters set in
conf/keycloak.conf
|
| services.suricata.settings.default-log-dir | The default logging directory
|
| services.postsrsd.settings.secrets-file | Path to the file containing the secret keys.
Secrets are passed using LoadCredential= on the systemd unit,
so this options is read-only
|
| services.sourcehut.settings."git.sr.ht".api-origin | Origin URL for the API
|
| services.sourcehut.settings."hub.sr.ht".api-origin | Origin URL for the API
|
| services.sourcehut.settings."man.sr.ht".api-origin | Origin URL for the API
|
| services.hickory-dns.settings.directory | The directory in which hickory-dns should look for .zone files,
whenever zones aren't specified by absolute path.
|
| services.angrr.settings.touch.project-globs | List of glob patterns to include or exclude files when touching GC roots
|
| services.forgejo.settings.server.PROTOCOL | Listen protocol. +unix means "over unix", not "in addition to."
|
| services.mbpfan.settings.general.low_temp | If temperature is below this, fans will run at minimum speed.
|
| services.mbpfan.settings.general.max_temp | If temperature is above this, fans will run at maximum speed.
|
| services.evremap.settings.dual_role | List of dual-role remappings that output different key sequences based on whether the
input key is held or tapped.
|
| services.biboumi.settings.log_level | Indicate what type of log messages to write in the logs.
0 is debug, 1 is info, 2 is warning, 3 is error.
|
| services.sftpgo.settings.sftpd.bindings.*.port | The port for serving SFTP requests
|
| services.homebridge.settings.bridge.name | Name of the homebridge
|
| services.routinator.settings.log-file | A string value containing the path to a file to which log messages will be appended if the log configuration value is set to file
|
| services.openssh.startWhenNeeded | If set, sshd is socket-activated; that
is, instead of having it permanently running as a daemon,
systemd will start an instance for each incoming connection.
|
| services.sourcehut.settings."todo.sr.ht".notify-from | Outgoing email for notifications generated by users.
|
| services.swapspace.settings.swappath | Location where swapspace may create and delete swapfiles
|
| services.minidlna.settings.log_level | Defines the type of messages that should be logged and down to which level of importance.
|
| services.lasuite-docs.settings.DJANGO_SECRET_KEY_FILE | The path to the file containing Django's secret key
|
| services.lasuite-meet.settings.DJANGO_SECRET_KEY_FILE | The path to the file containing Django's secret key
|
| services.bookstack.settings.APP_KEY_FILE | The path to your appkey
|
| services.hostapd.radios.<name>.settings | Extra configuration options to put at the end of global initialization, before defining BSSs
|
| services.cryptpad.settings.installMethod | Install method is listed in telemetry if you agree to it through the consentToContact
setting in the admin panel.
|
| services.suricata.settings.stats.stream-events | Add stream events as stats.
|
| services.oncall.settings.db.conn.kwargs.database | Database name.
|
| services.kanidm.server.settings.tls_chain | TLS chain in pem format.
|
| nix.settings.require-sigs | If enabled (the default), Nix will only download binaries from binary caches if
they are cryptographically signed with any of the keys listed in
nix.settings.trusted-public-keys
|
| programs.gnupg.agent.settings | Configuration for /etc/gnupg/gpg-agent.conf
|
| services.resolved.settings.Resolve.DNSOverTLS | Whether to use TLS encryption for DNS queries
|
| security.pam.sshAgentAuth.enable | Whether to enable authenticating using a signature performed by the ssh-agent
|
| services.keyd.keyboards.<name>.settings | Configuration, except ids section, that is written to /etc/keyd/.conf
|
| services.sympa.settingsFile.<name>.source | Path of the source file.
|
| services.pingvin-share.hostname | The domain name of your instance
|
| services.netbird.clients.<name>.user.name | A system user name for this client instance.
|
| services.netbird.tunnels.<name>.user.name | A system user name for this client instance.
|
| services.grafana.settings.smtp.from_name | Name to be used as client identity for EHLO in SMTP dialog.
|
| services.sabnzbd.settings.misc.email_rss | Whether to send alerts for jobs added by RSS feeds
|
| services.pretix.settings.database.backend | Database backend to use
|
| services.sftpgo.settings.httpd.bindings.*.port | The port for serving HTTP(S) requests
|
| services.sourcehut.settings."sr.ht".global-domain | Global domain name.
|
| services.homebridge.settings.bridge.port | The port homebridge listens on
|
| services.opengfw.settings.workers.udpMaxStreams | UDP max streams.
|
| services.moosefs.metalogger.settings | Metalogger configuration options (mfsmetalogger.cfg).
|
| services.tor.settings.ServerTransportPlugin | See torrc manual.
|
| services.tor.settings.MaxClientCircuitsPending | See torrc manual.
|
| services.syncthing.settings.devices.<name>.name | The name of the device.
|
| services.librechat.enableLocalDB | Whether to enable a local mongodb instance.
|
| services.openvpn.servers | Each attribute of this option defines a systemd service that
runs an OpenVPN instance
|
| security.loginDefs.settings.GID_MAX | Range of group IDs used for the creation of regular groups by useradd, groupadd, or newusers.
|
| security.loginDefs.settings.GID_MIN | Range of group IDs used for the creation of regular groups by useradd, groupadd, or newusers.
|
| services.etebase-server.settings.database.name | The database name.
|
| services.bluesky-pds.settings.PDS_RATE_LIMITS_ENABLED | Enable rate limiting
|
| services.canaille.settings.CANAILLE_LDAP | Configuration for the LDAP backend
|
| services.sourcehut.settings."hg.sr.ht".oauth-client-id | hg.sr.ht's OAuth client id for meta.sr.ht.
|
| services.postfix.settings.master.<name>.command | A program name specifying a Postfix service/daemon process
|
| nix.settings.allowed-users | A list of names of users (separated by whitespace) that are
allowed to connect to the Nix daemon
|
| services.grafana.settings.server.cert_key | Path to the certificate key file (if protocol is set to https or h2).
|
| services.tlsrpt.reportd.settings.fetchers | Comma-separated list of fetcher programs that retrieve collectd data.
|
| services.snapserver.settings.stream.port | Port to listen on for snapclient connections.
|
| services.tsidp.settings.useLocalTailscaled | Use local tailscaled instead of tsnet.
|
| services.stash.settings.theme_color | Sets the theme-color property in the UI
|
| services.traefik.dynamic.files.<name>.settings | Dynamic configuration for Traefik, written in Nix.
This will be serialized to JSON (which is considered valid YAML) at build, and passed as part of the static file.
|
| services.syncthing.settings | Extra configuration options for Syncthing
|
| services.clamav.fangfrisch.settings | fangfrisch configuration
|
| services.blackfire-agent.settings.server-id | Sets the server id used to authenticate with Blackfire
You can find your personal server-id at https://blackfire.io/my/settings/credentials
|
| services.guacamole-client.settings | Configuration written to guacamole.properties.
The Guacamole web application uses one main configuration file called
guacamole.properties
|
| services.postgrest.settings.admin-server-port | Specifies the port for the admin server, which can be used for healthchecks.
https://docs.postgrest.org/en/stable/references/admin_server.html#admin-server
|
| services.scion.scion-dispatcher.settings | scion-dispatcher configuration
|
| services.postsrsd.settings.socketmap | Listener configuration in socket map format native to Postfix configuration.
|
| services.sourcehut.settings."todo.sr.ht::mail".sock | Path for the lmtp daemon's unix socket
|
| services.teamspeak3.queryIP | IP on which the server instance will listen for incoming ServerQuery connections
|
| services.teamspeak3.voiceIP | IP on which the server instance will listen for incoming voice connections
|
| services.sourcehut.settings."meta.sr.ht".api-origin | Origin URL for the API
|
| services.sourcehut.settings."todo.sr.ht".api-origin | Origin URL for the API
|
| services.wg-access-server.settings.dns.enabled | Enable/disable the embedded DNS proxy server
|
| services.syncplay.saltFile | Path to the file that contains the server salt
|
| services.sourcehut.settings."meta.sr.ht::aliases" | Aliases for the client IDs of commonly used OAuth clients.
|
| services.fediwall.settings.loadFederated | Load federated posts
|
| services.bluesky-pds.settings.PDS_DATA_DIRECTORY | Directory to store state
|
| services.openvpn.servers.<name>.autoStart | Whether this OpenVPN instance should be started automatically.
|
| services.syncthing.settings.folders | Folders which should be shared by Syncthing
|
| hardware.apple.touchBar.settings | Configuration for tiny-dfr
|
| services.journald.remote.settings.Remote.Seal | Periodically sign the data in the journal using Forward Secure
Sealing.
|
| services.sourcehut.settings."man.sr.ht".oauth-client-id | man.sr.ht's OAuth client id for meta.sr.ht.
|
| services.sourcehut.settings."git.sr.ht".oauth-client-id | git.sr.ht's OAuth client id for meta.sr.ht.
|
| services.sourcehut.settings."hub.sr.ht".oauth-client-id | hub.sr.ht's OAuth client id for meta.sr.ht.
|
| services.listmonk.database.settings.smtp.*.port | Port for the SMTP server
|
| services.listmonk.database.settings.smtp.*.host | Hostname for the SMTP server
|
| services.xonotic.settings.maxplayers | Number of player slots on the server, including spectators.
|
| services.xserver.displayManager.gdm.settings | Options passed to the gdm daemon
|
| services.sourcehut.settings."builds.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."builds.sr.ht".origin | URL builds.sr.ht is being served at (protocol://domain)
|
| services.sourcehut.settings."builds.sr.ht".debug-port | Port to bind the debug server to.
|
| services.go-csp-collector.settings.output-format | Define how the violation reports are formatted for output.
|
| services.knot-resolver.settings.network.listen | List of interfaces to listen to and its configuration.
|
| services.taler.merchant.settings.merchant.DB | Plugin to use for the database.
|
| services.taler.exchange.settings.exchange.DB | Plugin to use for the database.
|
| services.reposilite.settings.cachedLogSize | Amount of messages stored in the cache logger.
|
| services.warpgate.settings.log.retention | How long Warpgate keep its logs.
|
| services.opensnitch.settings.Rules.Path | Path to the directory where firewall rules can be found and will
get stored by the NixOS module.
|
| services.sharkey.settings.mediaDirectory | Path to the folder where Sharkey stores uploaded media such as images and attachments.
|
| services.slskd.settings.filters.search.request | Incoming search requests which match this filter are ignored.
|
| services.prometheus.xmpp-alerts.settings | Configuration for prometheus xmpp-alerts, see
https://github.com/jelmer/prometheus-xmpp-alerts/blob/master/xmpp-alerts.yml.example
for supported values.
|
| services.gitea.settings.session.COOKIE_SECURE | Marks session cookies as "secure" as a hint for browsers to only send
them via HTTPS
|
| services.cryptpad.settings.websocketPort | Port for the websocket that needs to be separate
|
| services.filebrowser.settings.cache-dir | The directory where FileBrowser stores its cache.
|
| services.tor.settings.ControlPortFileGroupReadable | See torrc manual.
|
| services.reposilite.settings.enforceSsl | Whether to redirect all traffic to SSL.
|
| services.moosefs.cgiserver.settings.DATA_PATH | Directory for lock files.
|
| services.suricata.settings.threshold-file | Suricata threshold configuration file.
|
| services.tor.settings.ServerDNSDetectHijacking | See torrc manual.
|
| services.tor.settings.PaddingStatistics | See torrc manual.
|
| services.syncthing.settings.devices | Peers/devices which Syncthing should communicate with
|
| services.taler.settings.taler.CURRENCY_ROUND_UNIT | Smallest amount in this currency that can be transferred using the underlying RTGS
|
| services.opengfw.settings.replay.realtime | Whether the packets in the PCAP file should be replayed in "real time" (instead of as fast as possible).
|
| services.szurubooru.server.settings.name | Name shown in the website title and on the front page.
|
| services.litellm.settings.model_list | List of supported models on the server, with model-specific configs.
|
| programs.starship.settings | Configuration included in starship.toml
|
| services.bitmagnet.settings.postgres.user | User to connect as
|
| services.writefreely.settings.app.theme | The theme to apply.
|
| services.watchdogd.settings.interval | The kick interval, i.e. how often watchdogd(8) should reset the WDT timer.
|
| services.sourcehut.settings."lists.sr.ht".notify-from | Outgoing email for notifications generated by users.
|
| services.firefox-syncserver.settings.port | Port to bind to.
|
| services.opensearch.settings."cluster.name" | The name of the cluster.
|
| services.suricata.settings.dpdk.eal-params.proc-type | dpdk eal-params.proc-type, see data plane development kit docs.
|
| security.loginDefs.settings | Config options for the /etc/login.defs file, that defines
the site-specific configuration for the shadow password suite
|
| services.biboumi.settings.password | The password used to authenticate the XMPP component to your XMPP server
|
| services.suricata.settings.stats.interval | The interval field (in seconds) controls the interval at
which stats are updated in the log.
|
| services.sabnzbd.settings.servers.<name>.timeout | Time, in seconds, to wait for a response before
attempting error recovery.
|
| services.evremap.settings.dual_role.*.tap | The key sequence that should be output when the input key is tapped
|
| services.postfix.settings.master.<name>.maxproc | The maximum number of processes to spawn for this service
|
| services.vmalert.settings."datasource.url" | Datasource compatible with Prometheus HTTP API.
|
| services.fediwall.settings.hideSensitive | Hide sensitive (potentially NSFW) posts
|
| services.openssh.settings.X11Forwarding | Whether to allow X11 connections to be forwarded.
|
| security.pam.rssh.settings | Options to pass to the pam_rssh module
|
| services.syncthing.settings.folders.<name>.type | Controls how the folder is handled by Syncthing
|
| services.saunafs.metalogger.settings | Contents of metalogger config file (see sfsmetalogger.cfg(5)).
|
| services.hedgedoc.settings.protocolUseSSL | Use https:// for all links
|
| services.litellm.settings.general_settings | LiteLLM Server settings
|
| services.litellm.settings.litellm_settings | LiteLLM Module settings
|
| services.bitmagnet.settings.postgres.name | Database name to connect to
|
| services.tor.settings.DirAllowPrivateAddresses | See torrc manual.
|
| services.tor.settings.AuthDirSharedRandomness | See torrc manual.
|
| services.syncthing.settings.folders.<name>.label | The label of the folder.
|
| services.tor.settings.EnforceDistinctSubnets | See torrc manual.
|
| services.postfix-tlspol.settings.dns.address | IP and port to your DNS resolver
|
| services.amule.settings.ExternalConnect.ECPort | TCP port for external connections, like remote control via amule-gui
|
| services.gemstash.settings.base_path | Path to store the gem files and the sqlite database
|
| security.loginDefs.settings.SYS_UID_MAX | Range of user IDs used for the creation of system users by useradd or newusers.
|
| security.loginDefs.settings.SYS_UID_MIN | Range of user IDs used for the creation of system users by useradd or newusers.
|
| services.sourcehut.settings."builds.sr.ht".allow-free | Whether to enable nonpaying users to submit builds.
|
| services.misskey.settings.redisForTimelines | ioredis options for timelines
|
| services.opensnitch.settings.Stats.MaxStats | Max stats per item to keep in backlog.
|
| services.matrix-synapse.settings.database.name | The database engine name
|
| services.firewalld.settings.LogDenied | Add logging rules right before reject and drop rules in the INPUT, FORWARD and OUTPUT chains for the default rules and also final reject and drop rules in zones for the configured link-layer packet type.
|
| services.grafana.settings.server.http_port | Listening port.
|
| services.healthchecks.settings.DB | Database engine to use.
|
| services.opensearch.settings."network.host" | Which port this service should listen on.
|
| services.radicle.ci.broker.settings.adapters | CI adapters
|
| services.peertube.enableWebHttps | Whether clients will access your PeerTube instance with HTTPS
|
| services.sourcehut.settings."hg.sr.ht".webhooks | The Redis connection used for the webhooks worker.
|
| services.sourcehut.settings."lists.sr.ht".allow-new-lists | Whether to enable creation of new lists.
|
| services.sourcehut.settings."todo.sr.ht".oauth-client-id | todo.sr.ht's OAuth client id for meta.sr.ht.
|
| services.moosefs.cgiserver.settings.BIND_HOST | IP address to bind CGI server to.
|
| services.reposilite.settings.sslEnabled | Whether to listen for encrypted connections on settings.sslPort.
|
| services.scrutiny.settings.web.influxdb.token | Authentication token for connecting to InfluxDB.
|
| services.your_spotify.settings | Your Spotify Configuration
|
| services.wgautomesh.settings.peers.*.pubkey | Wireguard public key of this peer.
|
| services.immich.settings.newVersionCheck.enabled | Check for new versions
|
| services.sftpgo.settings.smtp.encryption | Encryption scheme:
0: No encryption
1: TLS
2: STARTTLS
|
| services.redis.servers.<name>.user | User account under which this instance of redis-server runs.
If left as the default value this user will automatically be
created on system activation, otherwise you are responsible for
ensuring the user exists before the redis service starts.
|
| services.szurubooru.server.settings.debug | Whether to generate server logs.
|
| services.neard.settings.General.DefaultPowered | Automatically turn an adapter on when being discovered.
|
| services.spacecookie.settings.log.level | Log level for the spacecookie service.
|
| services.warpgate.settings.postgres.enable | Whether to enable PostgreSQL listener.
|
| services.warpgate.settings.postgres.listen | Listen endpoint of PostgreSQL listener.
|
| services.sourcehut.settings."todo.sr.ht::mail".sock-group | The lmtp daemon will make the unix socket group-read/write
for users in this group.
|
| services.kubo.settings.Addresses.API | Multiaddr or array of multiaddrs describing the address to serve the local HTTP API on
|
| services.netbird.tunnels.<name>.user.group | A system group name for this client instance.
|
| services.netbird.clients.<name>.user.group | A system group name for this client instance.
|
| services.postgrest.settings.server-host | Where to bind the PostgREST web server.
The admin server will also bind here, but potentially exposes sensitive information
|
| services.livekit.keyFile | LiveKit key file holding one or multiple application secrets
|
| services.lokinet.settings.network.keyfile | The private key to persist address with
|
| services.searx.settingsFile | The path of the Searx server settings.yml file
|
| services.tor.settings.DormantCanceledByStartup | See torrc manual.
|
| services.tor.settings.DoSConnectionEnabled | See torrc manual.
|
| services.readarr.settings.update.mechanism | which update mechanism to use
|
| services.tor.settings.ServerDNSAllowNonRFC953Hostnames | See torrc manual.
|
| services.tor.settings.ExtORPortCookieAuthFileGroupReadable | See torrc manual.
|
| services.postfix.settings.master.<name>.private | Whether the service's sockets and storage directory is restricted to
be only available via the mail system
|
| services.sourcehut.settings."pages.sr.ht".api-origin | Origin URL for the API
|
| services.sourcehut.settings."lists.sr.ht".api-origin | Origin URL for the API
|
| services.sourcehut.settings."paste.sr.ht".api-origin | Origin URL for the API
|
| services.nextcloud-whiteboard-server.settings | Settings to configure backend server
|
| services.mautrix-whatsapp.settings | config.yaml configuration as a Nix attribute set
|
| services.postgrest.settings.server-unix-socket | Unix domain socket where to bind the PostgREST web server.
|
| services.acme-dns.settings.logconfig.loglevel | Level to log on.
|
| services.legit.settings.meta.description | Website description.
|
| services.sabnzbd.settings.misc.https_key | Path to the TLS key for the web UI
|
| security.loginDefs.settings.SYS_GID_MAX | Range of group IDs used for the creation of system groups by useradd, groupadd, or newusers
|
| security.loginDefs.settings.SYS_GID_MIN | Range of group IDs used for the creation of system groups by useradd, groupadd, or newusers
|
| services.routinator.settings.expire | An integer value specifying the number of seconds an RTR client is requested to use a data set if it cannot get an update before throwing it away and continuing with no data at all.
|
| services.stash.settings.stash_boxes | Stash-box facilitates automated tagging of scenes and performers based on fingerprints and filenames
|
| services.sympa.settingsFile.<name>.enable | Whether this file should be generated
|
| services.sourcehut.settings."git.sr.ht".webhooks | The Redis connection used for the webhooks worker.
|
| services.snapserver.settings.tcp.enabled | Whether to enable the TCP JSON-RPC.
|
| services.anuko-time-tracker.settings.emailRequired | Defines whether an email is required for new registrations.
|
| services.nipap.settings.nipapd.foreground | Remain in foreground rather than forking to background.
|
| services.matrix-synapse.settings.turn_uris | The public URIs of the TURN server to give to clients
|
| services.postsrsd.settings.separator | SRS tag separator used in generated sender addresses
|
| services.sourcehut.settings."pages.sr.ht".user-domain | Configures the user domain, if enabled
|
| services.evremap.settings.dual_role.*.hold | The key sequence that should be output when the input key is held
|
| services.libeufin.nexus.settings.nexus-ebics.HOST_BASE_URL | URL of the EBICS server.
|
| services.tlsrpt.reportd.settings.log_level | Level of log messages to emit.
|
| services.reposilite.settings.idleTimeout | Default idle timeout used by Jetty.
|
| services.tlsrpt.fetcher.settings.log_level | Level of log messages to emit.
|
| services.suricata.settings.stats.decoder-events | Add decode events to stats
|
| services.stash.settings.stash_boxes.*.name | The name of the Stash Box
|
| services.wastebin.settings.WASTEBIN_MAX_BODY_SIZE | Number of bytes to accept for POST requests
|
| programs.spacefm.settings | The system-wide spacefm configuration
|
| services.evremap.settings.dual_role.*.input | The key that should be remapped
|
| services.postfix-tlspol.settings.server.address | Path or address/port where postfix-tlspol binds its socket to.
|
| services.matrix-conduit.settings.global.address | Address to listen on for connections by the reverse proxy/tls terminator.
|
| services.sslh.settings.transparent | Whether the services behind sslh (Apache, sshd and so on) will see the
external IP and ports as if the external world connected directly to
them.
|
| services.tor.settings.DoSCircuitCreationEnabled | See torrc manual.
|
| services.tor.settings.ServerTransportPlugin.exec | Command of pluggable transport.
|
| services.rosenpass.settings.verbosity | Verbosity of output produced by the service.
|
| services.journald.upload.settings.Upload.URL | The URL to upload the journal entries to
|
| services.inadyn.settings.custom.<name>.password | Password for this DDNS provider
|
| services.pid-fan-controller.settings.fans.*.cutoff | Whether to stop the fan when minPwm is reached.
|
| services.lasuite-docs.settings.DJANGO_ALLOWED_HOSTS | Comma-separated list of hosts that are able to connect to the server
|
| services.lasuite-meet.settings.DJANGO_ALLOWED_HOSTS | Comma-separated list of hosts that are able to connect to the server
|
| services.veilid.settings.logging.system.enabled | Events of type 'system' will be logged.
|
| services.misskey.settings.redisForTimelines.port | The Redis port.
|
| services.misskey.settings.redisForTimelines.host | The Redis host.
|
| services.opensnitch.settings.Firewall | Which firewall backend to use.
|
| services.libeufin.nexus.settings.nexus-ebics.USER_ID | User ID of the EBICS subscriber
|
| services.livekit.redis.createLocally | Whether to set up a local redis instance.
|
| services.sslh.settings.protocols | List of protocols sslh will probe for and redirect
|
| services.suricata.settings.af-xdp.*.interface | af-xdp capture interface, see upstream docs.
|
| services.archisteamfarm.bots.<name>.settings | Additional settings that are documented here.
|
| services.taler.merchant.settings.merchant.PORT | Port on which the HTTP server listens.
|
| services.taler.exchange.settings.exchange.PORT | Port on which the HTTP server listens.
|
| services.watchdogd.settings.filenr.enabled | Whether to enable watchdogd plugin filenr.
|
| services.wastebin.settings.WASTEBIN_BASE_URL | Base URL for the QR code display
|
| services.suricata.settings.pcap.*.interface | pcap capture interface, see upstream docs.
|
| services.resolved.settings.Resolve.Domains | List of search domains used to complete unqualified name lookups.
|
| services.spacecookie.settings.root | The directory spacecookie should serve via gopher
|
| services.sabnzbd.settings.misc.email_from | 'From:' field for emails (needs to be an address)
|
| services.szurubooru.server.settings.smtp.port | Port of the SMTP server.
|
| services.opensnitch.settings.Stats.MaxEvents | Max events to send to the GUI.
|
| services.pretalx.settings.filesystem.data | Base path for all other storage paths.
|
| services.canaille.settings.CANAILLE_LDAP.BIND_PW | The LDAP bind password
|
| services.bitmagnet.settings.postgres.host | Address, hostname or Unix socket path of the database server
|
| services.immich.settings.server.externalDomain | Domain for publicly shared links, including http(s)://.
|
| services.froide-govplan.settings.ALLOWED_HOSTS | A list of valid fully-qualified domain names (FQDNs) and/or IP
addresses that can be used to reach the Froide-Govplan service.
|
| services.opengfw.settings.workers.tcpTimeout | How long a connection is considered dead when no data is being transferred
|
| services.nextcloud.settings.log_type | Logging backend to use.
systemd automatically adds the php-systemd extensions to services.nextcloud.phpExtraExtensions
|
| services.crowdsec.settings.simulation | Attributes inside the simulation.yaml file.
|
| services.chhoto-url.settings.slug_length | The length of auto-generated slugs.
|
| services.chhoto-url.settings.public_mode | Whether to enable public mode.
|
| services.nvme-rs.settings.email.smtp_server | SMTP server address
|
| services.pinnwand.settings.paste_size | Maximum size of a paste in bytes.
|
| services.pantalaimon-headless.instances.<name>.listenPort | The port where the daemon will listen to client connections for
this homeserver
|
| services.livekit.ingress.settings.redis.address | Address or hostname and port for redis connection
|
| services.mbpfan.settings.general.high_temp | If temperature is above this, fan speed will gradually increase.
|
| services.watchdogd.settings.filenr.warning | The high watermark level
|
| services.nezha-agent.settings.temperature | Enable temperature monitoring.
|
| services.nezha-agent.settings.disable_nat | Disable NAT penetration.
|
| services.your_spotify.settings.PORT | The port of the api server
|
| services.grafana.settings.database.host | Only applicable to MySQL or Postgres
|
| services.pretalx.settings.database.backend | Database backend to use
|
| services.openssh.settings.KexAlgorithms | Allowed key exchange algorithms
Uses the lower bound recommended in both
https://stribika.github.io/2015/01/04/secure-secure-shell.html
and
https://infosec.mozilla.org/guidelines/openssh#modern-openssh-67
|
| services.firezone.server.web.settings | Environment variables for this component of the Firezone server
|
| services.firezone.server.api.settings | Environment variables for this component of the Firezone server
|
| services.netbird.clients.<name>.bin.suffix | A system group name for this client instance.
|
| services.netbird.tunnels.<name>.bin.suffix | A system group name for this client instance.
|
| services.sourcehut.settings."meta.sr.ht".webhooks | The Redis connection used for the webhooks worker.
|
| services.sourcehut.settings."todo.sr.ht".webhooks | The Redis connection used for the webhooks worker.
|
| services.sourcehut.settings."lists.sr.ht".oauth-client-id | lists.sr.ht's OAuth client id for meta.sr.ht.
|
| services.sourcehut.settings."pages.sr.ht".oauth-client-id | pages.sr.ht's OAuth client id for meta.sr.ht.
|
| services.sourcehut.settings."paste.sr.ht".oauth-client-id | paste.sr.ht's OAuth client id for meta.sr.ht.
|
| services.bookstack.settings.DB_PASSWORD_FILE | The file containing your mysql/mariadb database password.
|
| services.libeufin.bank.settings.libeufin-bank.PORT | The port on which libeufin-bank should listen.
|
| services.rosenpass.settings.peers.*.endpoint | Endpoint of the remote Rosenpass peer.
|
| services.suricata.settings.outputs.*.<name>.enabled | Whether to enable .
|
| services.szurubooru.server.settings.smtp.user | User to connect to the SMTP server.
|
| services.sabnzbd.settings.misc.email_full | Whether to send alerts for full disks
|
| services.snapserver.settings.http.enabled | Whether to enable the HTTP JSON-RPC.
|
| services.pgbouncer.settings.databases | Detailed information about PostgreSQL database definitions:
https://www.pgbouncer.org/config.html#section-databases
|
| services.ferretdb.settings.FERRETDB_HANDLER | Backend handler
|
| services.privoxy.settings.filterfile | List of paths to Privoxy filter files
|
| services.inadyn.settings.provider.<name>.hostname | Hostname alias(es).
|
| services.ferretdb.settings.FERRETDB_SQLITE_URL | SQLite URI (directory) for 'sqlite' handler
|
| services.lidarr.settings.log.analyticsEnabled | Send Anonymous Usage Data
|
| services.inadyn.settings.provider.<name>.username | Username for this DDNS provider.
|
| services.sonarr.settings.log.analyticsEnabled | Send Anonymous Usage Data
|
| services.suricata.settings.unix-command.enabled | Enable unix-command socket.
|
| services.radarr.settings.log.analyticsEnabled | Send Anonymous Usage Data
|
| services.canaille.settings.CANAILLE.SMTP | SMTP configuration
|
| services.blackfire-agent.settings.server-token | Sets the server token used to authenticate with Blackfire
You can find your personal server-token at https://blackfire.io/my/settings/credentials
|
| services.logrotate.settings.<name>.priority | Order of this logrotate block in relation to the others
|
| services.mautrix-meta.instances.<name>.environmentFile | File containing environment variables to substitute when copying the configuration
out of Nix store to the services.mautrix-meta.dataDir
|
| services.grafana.settings.server.cert_file | Path to the certificate file (if protocol is set to https or h2).
|
| services.mchprs.settings.max_players | Maximum number of simultaneous players
|
| services.watchdogd.settings.filenr.logmark | Whether to log current stats every poll interval.
|
| services.firefly-iii-data-importer.settings | Options for firefly-iii data importer configuration
|
| services.sourcehut.settings.mail.smtp-password | Outgoing SMTP password.
|
| services.reposilite.settings.debugEnabled | Whether to enable debug mode.
|
| services.tor.settings.ReachableAddresses | See torrc manual.
|
| services.headscale.settings.oidc.pkce.method | PKCE method to use:
- plain: Use plain code verifier
- S256: Use SHA256 hashed code verifier (default, recommended)
|
| services.neard.settings.General.ConstantPoll | Enable constant polling
|
| services.opensnitch.settings.Server.LogFile | File to write logs to (use /dev/stdout to write logs to standard
output).
|
| services.pretalx.settings.filesystem.logs | Path to the log directory, that pretalx logs message to.
|
| services.veilid.settings.logging.terminal.level | The minimum priority of terminal events to be logged.
|
| services.waagent.settings.OS.RootDeviceScsiTimeout | Configures the SCSI timeout in seconds on the OS disk and data drives
|
| services.gitlab.pages.settings.artifacts-server | API URL to proxy artifact requests to.
|
| services.typesense.settings.server.api-address | Address to which Typesense API service binds.
|
| services.scrutiny.settings.web.influxdb.bucket | InfluxDB bucket in which to store data.
|
| services.frigate.settings.cameras.<name>.ffmpeg.inputs | List of inputs for this camera.
|
| services.healthchecks.settings.DB_NAME | Database name.
|
| services.filebrowser.settings.address | The address to listen on.
|
| services.grafana.settings.smtp.password | Password used for authentication
|
| services.sourcehut.settings."pages.sr.ht".gemini-certs | An absolute file path (which should be outside the Nix-store)
to Gemini certificates.
|
| services.firefly-iii.settings.DB_CONNECTION | The type of database you wish to use
|
| services.waagent.settings.ResourceDisk.SwapSizeMB | Specifies the size of the swap file in MiB (1024×1024 bytes)
|
| services.redis.servers.<name>.group | Group account under which this instance of redis-server runs.
If left as the default value this group will automatically be
created on system activation, otherwise you are responsible for
ensuring the group exists before the redis service starts.
|
| security.pam.u2f.settings.appid | By default pam-u2f module sets the application
ID to pam://$HOSTNAME
|
| services.spacecookie.settings.log.enable | Whether to enable logging for spacecookie.
|
| services.snapserver.settings.tcp-control.port | Port to listen on for snapclient connections.
|
| services.misskey.redis.createLocally | Create and use a local Redis instance
|
| hardware.cpu.x86.msr.settings.allow-writes | Whether to allow writes to MSRs ("on") or not ("off").
|
| services.wstunnel.clients.<name>.enable | Whether to enable this wstunnel instance.
|
| services.wstunnel.servers.<name>.enable | Whether to enable this wstunnel instance.
|
| services.lldap.settings.ldap_user_pass | Password for default admin password
|
| services.openbao.settings.listener.<name>.address | The TCP address or UNIX socket path to listen on.
|
| services.scrutiny.collector.settings.host.id | Host ID for identifying/labelling groups of disks
|
| services.radicle.ci.adapters.native.instances.<name>.runtimePackages | Packages added to the adapter's PATH.
|
| services.umami.settings.DISABLE_TELEMETRY | Umami collects completely anonymous telemetry data in order help improve the application
|
| services.etebase-server.settings.database.engine | The database engine to use.
|
| services.grafana-image-renderer.settings.server.addr | Listen address of the service.
|
| services.lemmy.settings.captcha.difficulty | The difficultly of the captcha to solve.
|
| services.tor.settings.ReachableORAddresses | See torrc manual.
|
| services.tor.settings.FetchHidServDescriptors | See torrc manual.
|
| services.pid-fan-controller.settings.heatSources | List of heat sources to be monitored.
|
| services.filesender.localDomain | The domain serving your FileSender instance.
|
| services.sourcehut.settings."builds.sr.ht".api-origin | Origin URL for the API
|
| services.scrutiny.settings.web.influxdb.scheme | URL scheme to use when connecting to InfluxDB.
|
| services.pinnwand.settings.paste_help | Raw HTML help text shown in the header area.
|
| services.misskey.settings.meilisearch | Meilisearch connection options.
|
| services.transmission.settings.rpc-port | The RPC port to listen to.
|
| services.sftpgo.settings.webdavd.bindings.*.port | The port for serving WebDAV requests
|
| xdg.terminal-exec.settings | Configuration options for the Default Terminal Execution Specification
|
| services.spacecookie.settings.log.hide-time | If enabled, spacecookie will not print timestamps
at the beginning of every log line.
|
| services.wastebin.settings.WASTEBIN_CACHE_SIZE | Number of rendered syntax highlight items to cache
|
| nix.settings.trusted-public-keys | List of public keys used to sign binary caches
|
| services.angrr.settings.profile-policies.<name>.enable | Whether to enable this angrr policy.
|
| services.maubot.settings.server.public_url | Public base URL where the server is visible.
|
| services.matrix-synapse.settings.listeners.*.type | The type of the listener, usually http.
|
| services.postfix.settings.main.relayhost | List of hosts to use for relaying outbound mail.
Putting the hostname in angled brackets, e.g. [relay.example.com], turns off MX and SRV lookups for the hostname.
https://www.postfix.org/postconf.5.html#relayhost
|
| services.routinator.settings.rtr-listen | An array of string values each providing an address and port on which the RTR server should listen in TCP mode
|
| services.lldap.settings.database_url | Database URL.
|
| services.lldap.settings.ldap_user_dn | Admin username
|
| services.stash.settings.plugins_path | Path to scrapers
|
| services.spacecookie.settings.log.hide-ips | If enabled, spacecookie will hide personal
information of users like IP addresses from
log output.
|
| services.szurubooru.server.settings.smtp.host | Host of the SMTP server used to send reset password.
|
| services.radicle.ci.broker.settings.adapters.<name>.env | Environment variables to add when running the adapter.
|
| services.mautrix-meta.instances.<name>.serviceDependencies | List of Systemd services to require and wait for when starting the application service.
|
| services.headscale.settings.dns.magic_dns | Whether to use MagicDNS.
|
| services.minidlna.settings.media_dir | Directories to be scanned for media files
|
| services.pgmanage.superOnly | This tells pgmanage whether or not to only allow super users to
login
|
| security.pam.u2f.settings.cue | By default pam-u2f module does not inform user
that he needs to use the u2f device, it just waits without a prompt
|
| services.sourcehut.settings."sr.ht".network-key | An absolute file path (which should be outside the Nix-store)
to a secret key to encrypt internal messages with
|
| services.gemstash.settings.db_adapter | Which database type to use
|
| services.suricata.settings.vars.address-groups.HOME_NET | HOME_NET variable.
|
| services.tor.settings.KeyDirectoryGroupReadable | See torrc manual.
|
| services.umurmur.settings.welcometext | Welcome message for connected clients.
|
| services.tor.settings.ReachableDirAddresses | See torrc manual.
|
| services.moosefs.chunkserver.settings | Chunkserver configuration options (mfschunkserver.cfg).
|
| services.xonotic.settings.net_address | The address Xonotic will listen on.
|
| services.writefreely.settings.server.port | The port WriteFreely should listen on.
|
| services.bonsaid.settings.*.event_name | Name of the event which should trigger this transition when received by bonsaid
|
| services.anuko-time-tracker.settings.weekendStartDay | This option defines which days are highlighted with weekend color.
6 means Saturday
|
| services.routinator.settings.http-listen | An array of string values each providing an address and port on which the HTTP server should listen
|
| services.angrr.settings.profile-policies.<name>.keep-since | Retention period for the GC roots in this profile.
|
| services.snapserver.settings.stream.source | One or multiple URIs to PCM input streams.
|
| services.matrix-synapse.settings.listeners.*.port | The port to listen for HTTP(S) requests on.
|
| services.matrix-synapse.settings.listeners.*.mode | File permissions on the UNIX domain socket.
|
| services.sourcehut.settings."lists.sr.ht::worker".reject-url | Reject URL.
|
| services.geoipupdate.settings.AccountID | Your MaxMind account ID.
|
| services.healthchecks.settings.DEBUG | Enable debug mode.
|
| services.lldap.settings.ldap_base_dn | Base DN for LDAP.
|
| services.nebula-lighthouse-service.settings | Configuration for nebula-lighthouse-service.
|
| services.send.redis.passwordFile | The path to the file containing the Redis password
|
| services.anubis.defaultOptions.enable | Whether to enable this instance of Anubis.
|
| services.sourcehut.settings."builds.sr.ht::worker".name | Listening address and listening port
of the build runner (with HTTP port if not 80).
|
| services.anuko-time-tracker.settings.multiorgMode | Defines whether users see the Register option in the menu of Time Tracker that allows them
to self-register and create new organizations (top groups).
|
| services.grafana.settings.users.home_page | Path to a custom home page
|
| services.sourcehut.settings."lists.sr.ht".webhooks | The Redis connection used for the webhooks worker.
|
| services.public-inbox.settings.publicinbox | public inboxes
|
| services.tinc.networks.<name>.hostSettings.<name>.settings | Configuration for this host
|
| services.minidlna.settings.wide_links | Set this to yes to allow symlinks that point outside user-defined media_dir.
|
| services.matrix-synapse.settings.database.args.user | Username to connect with psycopg2, set to null
when using sqlite3.
|
| services.botamusique.settings.server.port | Port of the mumble server to connect to.
|
| services.biboumi.settings.identd_port | The TCP port on which to listen for identd queries.
|
| services.botamusique.settings.server.host | Hostname of the mumble server to connect to.
|
| services.livekit.ingress.settings.rtmp_port | TCP port for RTMP connections
|
| services.livekit.ingress.settings.whip_port | TCP port for WHIP connections
|
| services.grafana.settings.server.http_addr | Listening address.
This setting intentionally varies from upstream's default to be a bit more secure by default.
|
| services.mchprs.settings.chat_format | How to format chat message interpolating username
and message with curly braces
|
| services.suricata.settings.app-layer.error-policy | The error-policy setting applies to all app-layer parsers
|
| services.doh-server.settings.upstream | Upstream DNS resolver
|
| services.sourcehut.settings.objects.s3-access-key | Access key to the S3-compatible object storage service
|
| services.szurubooru.server.settings.domain | Full URL to the homepage of this szurubooru site (with no trailing slash).
|
| services.healthchecks.settingsFile | Environment variables which are read by healthchecks (local)_settings.py
|
| services.grafana.settings.server.cdn_url | Specify a full HTTP URL address to the root of your Grafana CDN assets
|
| services.pid-fan-controller.settings.interval | Interval between controller cycles in milliseconds.
|
| services.saunafs.metalogger.settings.DATA_PATH | Data storage directory
|
| services.tuned.settings.profile_dirs | Directories to search for profiles, separated by , or ;.
|
| services.tor.settings.ControlSocketsGroupWritable | See torrc manual.
|
| services.prowlarr.settings.update.mechanism | which update mechanism to use
|
| services.whisparr.settings.update.mechanism | which update mechanism to use
|
| services.syncthing.settings.folders.<name>.path | The path to the folder which should be shared
|
| services.dsnet.settings.ExternalHostname | The hostname that clients should use to connect to this server
|
| services.crowdsec-firewall-bouncer.settings.mode | Firewall mode to use.
|
| services.pantalaimon-headless.instances.<name>.listenAddress | The address where the daemon will listen to client connections
for this homeserver.
|
| services.reposilite.settings.hostname | The hostname to bind to
|
| services.wstunnel.clients.<name>.autoStart | Whether to enable starting this wstunnel instance automatically.
|
| services.wstunnel.servers.<name>.autoStart | Whether to enable starting this wstunnel instance automatically.
|
| services.sourcehut.settings."builds.sr.ht".oauth-client-id | builds.sr.ht's OAuth client id for meta.sr.ht.
|
| services.sourcehut.settings."hg.sr.ht".oauth-client-secret | hg.sr.ht's OAuth client secret for meta.sr.ht.
|
| services.scrutiny.collector.settings.log.level | Log level for Scrutiny collector.
|
| services.watchdogd.settings.loadavg.enabled | Whether to enable watchdogd plugin loadavg.
|
| services.watchdogd.settings.meminfo.enabled | Whether to enable watchdogd plugin meminfo.
|
| services.open-web-calendar.settings.ALLOWED_HOSTS | The hosts that the Open Web Calendar permits
|
| services.zeronsd.servedNetworks.<name>.settings.token | Path to a file containing the API Token for ZeroTier Central.
|
| services.headscale.settings.oidc.client_id | OpenID Connect client ID.
|
| services.tlsrpt.collectd.settings.log_level | Level of log messages to emit.
|
| services.moosefs.metalogger.settings.DATA_PATH | Directory for storing metalogger data.
|
| services.watchdogd.settings.filenr.interval | Amount of seconds between every poll.
|
| services.sabnzbd.settings.servers.<name>.priority | Priority of this servers
|
| services.sabnzbd.settings.servers.<name>.required | In case of connection failures, wait for the
server to come back online instead of skipping
it.
|
| services.hercules-ci-agent.settings.labels | A key-value map of user data
|
| services.buffyboard.settings.input.pointer | Enable or disable the use of a hardware mouse or other pointing device.
|
| services.parsedmarc.settings.mailbox.watch | Use the IMAP IDLE command to process messages as they arrive.
|
| services.suricata.settings.app-layer.protocols | app-layer protocols, see upstream docs.
|
| services.forgejo.settings.session.COOKIE_SECURE | Marks session cookies as "secure" as a hint for browsers to only send
them via HTTPS
|
| services.peering-manager.settings.ALLOWED_HOSTS | A list of valid fully-qualified domain names (FQDNs) and/or IP
addresses that can be used to reach the peering manager service.
|
| services.tor.settings.DataDirectoryGroupReadable | See torrc manual.
|
| services.tor.settings.HiddenServiceNonAnonymousMode | See torrc manual.
|
| services.tor.settings.ConstrainedSockets | See torrc manual.
|
| services.sourcehut.settings."lists.sr.ht::worker".sock | Path for the lmtp daemon's unix socket
|
| services.angrr.settings.temporary-root-policies | Policies for temporary GC roots(e.g. result and direnv).
|
| services.tor.relay.onionServices.<name>.settings.RendPostPeriod | See torrc manual.
|
| services.watchdogd.settings.loadavg.warning | The high watermark level
|
| services.watchdogd.settings.meminfo.warning | The high watermark level
|
| services.wstunnel.clients.<name>.settings.http-headers | Custom headers to send in the upgrade request
|
| services.ocsinventory-agent.settings.tag | Tag for the generated inventory.
|
| services.sourcehut.settings."builds.sr.ht".shell | Scripts used to launch on SSH connection.
/usr/bin/master-shell on master,
/usr/bin/runner-shell on runner
|
| services.sourcehut.settings."git.sr.ht".oauth-client-secret | git.sr.ht's OAuth client secret for meta.sr.ht.
|
| services.sourcehut.settings."hub.sr.ht".oauth-client-secret | hub.sr.ht's OAuth client secret for meta.sr.ht.
|
| services.sourcehut.settings."man.sr.ht".oauth-client-secret | man.sr.ht's OAuth client secret for meta.sr.ht.
|
| services.maubot.settings.homeservers.<name>.url | Client-server API URL
|
| services.homebridge.settings.platforms | Homebridge Platforms
|
| services.sabnzbd.settings.misc.html_login | Prompt for login with an html login mask if enabled,
otherwise prompt for basic auth (useful for SSO)
|
| services.sabnzbd.settings.servers.<name>.optional | In case of connection failures, temporarily
disable this server. (See sabnzbd's documentation
for usage guides).
|
| services.postfix-tlspol.settings.server.prefetch | Whether to prefetch DNS records when the TTL of a cached record is about to expire.
|
| services.hickory-dns.settings.listen_port | Port to listen on (applies to all listen addresses).
|
| services.transmission.settings.peer-port | The peer port to listen for incoming connections.
|
| services.readarr.settings.log.analyticsEnabled | Send Anonymous Usage Data
|
| services.warpgate.settings.recordings.path | Path to store session recordings.
|
| services.reposilite.settings.database | Database connection string
|
| systemd.tmpfiles.settings | Declare systemd-tmpfiles rules to create, delete, and clean up volatile
and temporary files and directories
|
| services.pds.settings.PDS_BLOBSTORE_DISK_LOCATION | Store blobs at this location, set to null to use e.g
|
| services.umurmur.settings.certificate | Path to your SSL certificate
|
| services.umurmur.settings.private_key | Path to your SSL key
|
| services.saunafs.chunkserver.settings | Contents of chunkserver config file (see sfschunkserver.cfg(5)).
|
| services.watchdogd.settings.loadavg.logmark | Whether to log current stats every poll interval.
|
| services.watchdogd.settings.meminfo.logmark | Whether to log current stats every poll interval.
|
| services.botamusique.settings.bot.comment | Comment displayed for the bot.
|
| services.tor.settings.ExtendAllowPrivateAddresses | See torrc manual.
|
| services.onlyoffice.hostname | FQDN for the OnlyOffice instance.
|
| i18n.inputMethod.fcitx5.settings.addons | The addon configures in conf folder in ini format with global sections
|
| services.hercules-ci-agent.settings.baseDirectory | State directory (secrets, work directory, etc) for agent
|
| services.frigate.settings.cameras.<name>.ffmpeg.inputs.*.path | Stream URL
|
| services.routinator.settings.refresh | An integer value specifying the number of seconds Routinator should wait between consecutive validation runs in server mode
|
| services.sourcehut.settings."lists.sr.ht".posting-domain | Posting domain.
|
| services.wastebin.settings.WASTEBIN_ADDRESS_PORT | Address and port to bind to
|
| services.fastnetmon-advanced.settings | Extra configuration options to declaratively load into FastNetMon Advanced
|
| services.sabnzbd.settings.misc.https_cert | Path to the TLS certificate for the web UI
|
| services.postfix.settings.main.myhostname | The internet hostname of this mail system
|
| services.matrix-synapse.settings.listeners.*.tls | Whether to enable TLS on the listener socket.
This option will be ignored for UNIX domain sockets.
|
| services.cryptpad.settings.blockDailyCheck | Disable telemetry
|
| services.buffyboard.settings.theme.default | Selects the default theme on boot
|
| services.grafana.settings.users.login_hint | Text used as placeholder text on login page for login/username input.
|
| services.snapserver.settings.http.doc_root | Path to serve from the HTTP servers root.
|
| services.stash.settings.stash_boxes.*.apikey | Stash Box API key
|
| services.hercules-ci-agent.settings.secretsJsonPath | Path to a JSON file containing secrets for effects
|
| services.opensnitch.settings.Ebpf.ModulesPath | Configure eBPF modules path
|
| services.suricata.settings.unix-command.filename | Filename for unix-command socket.
|
| services.suricata.settings.logging.outputs.file.type | Type of logfile.
|
| services.pid-fan-controller.settings.heatSources.*.name | Name of the heat source.
|
| services.misskey.settings.meilisearch.ssl | Whether to connect via SSL.
|
| services.pantalaimon-headless.instances.<name>.extraSettings | Extra configuration options
|
| boot.initrd.network.ifstate.settings | Content of IfState's initrd configuration file
|
| services.headscale.settings.server_url | The url clients will connect to.
|
| services.acme-dns.settings.database.connection | Database connection string.
|
| services.tor.settings.HiddenServiceStatistics | See torrc manual.
|
| services.tor.settings.PublishServerDescriptor | See torrc manual.
|
| services.tor.settings.FetchServerDescriptors | See torrc manual.
|
| services.suricata.settings.reference-config-file | Suricata reference configuration file.
|
| services.kanidm.serverSettings.origin | The origin of your Kanidm instance
|
| services.logrotate.settings.<name>.frequency | How often to rotate the logs
|
| services.lemmy.database.createLocally | Whether to enable creation of database on the instance.
|
| services.pocket-id.settings.ANALYTICS_DISABLED | Whether to disable analytics
|
| services.zeronsd.servedNetworks.<name>.settings.domain | Domain under which ZeroTier records will be available.
|
| services.sftpgo.settings.ftpd.bindings.*.address | Network listen address
|
| services.mysql.replication.role | Role of the MySQL server instance.
|
| services.sourcehut.settings."git.sr.ht".outgoing-domain | Outgoing domain.
|
| services.sourcehut.settings."todo.sr.ht::mail".posting-domain | Posting domain.
|
| services.languagetool.settings.cacheSize | Number of sentences cached.
|
| services.maubot.settings.api_features | API feature switches.
|
| services.misskey.settings.meilisearch.host | The Meilisearch host.
|
| services.misskey.settings.meilisearch.port | The Meilisearch port.
|
| services.suricata.settings.unix-command | Unix command socket that can be used to pass commands to Suricata
|
| services.rkvm.server.settings.certificate | TLS certificate path.
This should be generated with rkvm-certificate-gen.
|
| services.szurubooru.server.settings.smtp.passFile | File containing the password associated to the given user for the SMTP server.
|
| services.rkvm.client.settings.certificate | TLS ceritficate path.
This should be generated with rkvm-certificate-gen.
|
| services.journald.remote.settings.Remote.SplitMode | With "host", a separate output file is used, based on the
hostname of the other endpoint of a connection
|
| services.fastnetmon-advanced.traffic_db.settings | Additional settings for /etc/fastnetmon/traffic_db.conf
|
| services.sourcehut.settings."todo.sr.ht".oauth-client-secret | todo.sr.ht's OAuth client secret for meta.sr.ht.
|
| services.transmission.settings.watch-dir | Watch a directory for torrent files and add them to transmission.
|
| services.parsedmarc.settings.mailbox.delete | Delete messages after processing them, instead of archiving them.
|
| services.pretalx.settings.filesystem.static | Path to the directory that contains static files.
|
| services.postfix.settings.master.<name>.privileged | |
| services.sourcehut.settings."git.sr.ht".post-update-script | A post-update script which is installed in every git repo
|
| services.taler.merchant.settings.merchant.SERVE | Whether the HTTP server should listen on a UNIX domain socket ("unix") or on a TCP socket ("tcp").
|
| services.wgautomesh.settings.peers.*.address | Wireguard address of this peer (a single IP address, multiple
addresses or address ranges are not supported).
|
| services.yggdrasil.settings.AllowedPublicKeys | List of peer public keys to allow incoming peering connections from
|
| services.reposilite.settings.keyPath | Path to the .jsk KeyStore or paths to the PKCS#8 certificate and private key, separated by a space (see example)
|
| services.sourcehut.settings."meta.sr.ht".welcome-emails | Whether to enable sending stock sourcehut welcome emails after signup.
|
| services.epgstation.settings.socketioPort | Socket.io port for EPGStation to listen on
|
| services.yggdrasil.settings.PrivateKeyPath | Path to the private key file on the host system
|
| services.globalprotect.settings | GlobalProtect-openconnect configuration
|
| services.canaille.settings.PREFERRED_URL_SCHEME | The url scheme by which canaille will be served.
|
| services.grafana-image-renderer.settings.browser.path | Path to the executable of the chromium to use.
|
| services.sourcehut.settings."lists.sr.ht::worker".sock-group | The lmtp daemon will make the unix socket group-read/write
for users in this group.
|
| services.opensnitch.settings.DefaultAction | Default action whether to block or allow application internet
access.
|
| services.tor.settings.CacheDirectoryGroupReadable | See torrc manual.
|
| services.misskey.settings.meilisearch.apiKey | The Meilisearch API key.
|
| services.scrutiny.settings.web.listen.basepath | If Scrutiny will be behind a path prefixed reverse proxy, you can override this
value to serve Scrutiny on a subpath.
|
| services.anuko-time-tracker.settings.email.smtpPasswordFile | Path to file containing the MTA authentication password.
|
| services.omnom.settings.activitypub.pubkey | ActivityPub public key
|
| services.matrix-appservice-irc.settings.ircService | IRC bridge configuration
|
| services.sourcehut.settings.objects.s3-secret-key | An absolute file path (which should be outside the Nix-store)
to the secret key of the S3-compatible object storage service.
|
| services.headscale.settings.prefixes.v6 | Each prefix consists of either an IPv4 or IPv6 address,
and the associated prefix length, delimited by a slash
|
| services.headscale.settings.prefixes.v4 | Each prefix consists of either an IPv4 or IPv6 address,
and the associated prefix length, delimited by a slash
|
| services.kerberos_server.settings | Settings for the kerberos server of choice
|
| services.swapspace.settings.cooldown | Duration (roughly in seconds) of the moratorium on swap allocation that is instated if disk space runs out, or the cooldown time after a new swapfile is successfully allocated before swapspace will consider deallocating swap space again
|
| services.hercules-ci-agent.settings.workDirectory | The directory in which temporary subdirectories are created for task state
|
| services.schleuder.settings.keyserver | Key server from which to fetch and update keys
|
| services.grafana-image-renderer.settings.service.port | The TCP port to use for the rendering server.
|
| services.mackerel-agent.settings.diagnostic | Whether to enable collecting memory usage for the agent itself.
|
| services.headscale.settings.database.type | Database engine to use
|
| services.grafana.settings.smtp.skip_verify | Verify SSL for SMTP server.
|
| services.libeufin.nexus.settings.nexus-ebics.CURRENCY | Name of the fiat currency.
|
| services.suwayomi-server.settings.server.localSourcePath | Path to the local source folder.
|
| networking.ifstate.settings | Content of IfState's configuration file
|
| services.nextcloud.datadir | Nextcloud's data storage path
|
| services.ocsinventory-agent.settings | Configuration for /etc/ocsinventory-agent/ocsinventory-agent.cfg
|
| services.matrix-tuwunel.settings.global.address | Addresses (IPv4 or IPv6) to listen on for connections by the reverse proxy/tls terminator
|
| services.angrr.settings.profile-policies.<name>.keep-latest-n | Keep the latest N GC roots in this profile.
|
| services.listmonk.database.settings.smtp.*.enabled | Whether to enable this SMTP server for listmonk.
|
| services.filebrowser.settings.database | The path to FileBrowser's Bolt database.
|
| services.opensnitch.settings.ProcMonitorMethod | Which process monitoring method to use.
|
| services.ncps.cache.redis.addresses | A list of host:port for the Redis servers that are part of a cluster
|
| services.watchdogd.settings.filenr.critical | The critical watermark level
|
| services.sourcehut.settings."hg.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.firezone.server.settingsSecret | This is a convenience option which allows you to set secret values for
environment variables by specifying a file which will contain the value
at runtime
|
| services.ocsinventory-agent.settings.ca | Path to CA certificates file in PEM format, for server
SSL certificate validation.
|
| services.filesender.settings.site_url | Site URL
|
| nixpkgs.buildPlatform | Specifies the platform on which NixOS should be built
|
| services.maubot.settings.homeservers | Known homeservers
|
| services.evremap.settings.device_name | The name of the device that should be remapped
|
| services.privoxy.settings.actionsfile | List of paths to Privoxy action files
|
| services.firezone.server.domain.settings | Environment variables for this component of the Firezone server
|
| services.slskd.settings.shares.directories | Paths to shared directories
|
| services.reposilite.settings.ioThreadPool | The IO thread pool handles all tasks that may benefit from non-blocking IO. (min: 2)
Because most tasks are redirected to IO thread pool, it might be a good idea to keep it at least equal to web thread pool.
|
| services.syncthing.settings.folders.<name>.enable | Whether to share this folder
|
| services.sourcehut.settings."meta.sr.ht::billing".enabled | Whether to enable the billing system.
|
| services.omnom.settings.smtp.send_timeout | Send timeout duration in seconds.
|
| services.watchdogd.settings.loadavg.interval | Amount of seconds between every poll.
|
| services.watchdogd.settings.meminfo.interval | Amount of seconds between every poll.
|
| i18n.inputMethod.fcitx5.settings.inputMethod | The input method configure in profile file in ini format.
|
| services.suricata.settings.af-packet.*.interface | af-packet capture interface, see upstream docs reagrding tuning.
|
| services.hercules-ci-agent.settings.binaryCachesPath | Path to a JSON file containing binary cache secret keys
|
| services.firewalld.settings.CleanupModulesOnExit | Whether to unload all firewall-related kernel modules when firewalld stops.
|
| services.matrix-continuwuity.settings | Generates the continuwuity.toml configuration file
|
| services.frigate.settings.cameras.<name>.ffmpeg.inputs.*.roles | List of roles for this stream
|
| services.tor.settings.AuthDirHasIPv6Connectivity | See torrc manual.
|
| services.suricata.settings.vars.address-groups.DNP3_SERVER | DNP3_SERVER variable.
|
| services.suricata.settings.vars.address-groups.DNP3_CLIENT | DNP3_CLIENT variable.
|
| services.grafana.settings.database.ssl_mode | For Postgres, use either disable, require or verify-full
|
| services.reposilite.settings.webThreadPool | Maximum amount of threads used by the core thread pool. (min: 5)
The web thread pool handles the first few steps of incoming HTTP connections, tasks are redirected as soon as possible to the IO thread pool.
|
| services.inadyn.settings.provider.<name>.password | Password for this DDNS provider
|
| services.sourcehut.settings."git.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.sourcehut.settings."man.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.sourcehut.settings."hub.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.slskd.settings.retention.files.complete | Lifespan of completely downloaded files in minutes.
|
| services.veilid.settings.logging.terminal.enabled | Events of type 'terminal' will be logged.
|
| services.sftpgo.settings.sftpd.bindings.*.address | Network listen address
|
| services.sftpgo.settings.httpd.bindings.*.address | Network listen address
|
| services.epgstation.settings.mirakurunPath | URL to connect to Mirakurun.
|
| services.opensearch.settings."discovery.type" | The type of discovery to use.
|
| services.misskey.settings.meilisearch.scope | The search scope.
|
| services.sabnzbd.secretFiles | Path to a list of ini file containing confidential settings such as credentials
|
| services.sourcehut.settings."lists.sr.ht".oauth-client-secret | lists.sr.ht's OAuth client secret for meta.sr.ht.
|
| services.sourcehut.settings."paste.sr.ht".oauth-client-secret | paste.sr.ht's OAuth client secret for meta.sr.ht.
|
| services.sourcehut.settings."pages.sr.ht".oauth-client-secret | pages.sr.ht's OAuth client secret for meta.sr.ht.
|
| services.headscale.settings.database.sqlite.path | Path to the sqlite3 database file.
|
| services.immichframe.settings.Accounts | Accounts configuration, multiple are permitted
|
| services.radicle.ci.broker.settings.triggers.*.filters | Trigger filter.
|
| services.nextcloud-spreed-signaling.settings | Declarative configuration
|
| services.radicle.ci.broker.settings.triggers.*.adapter | Adapter name.
|
| services.postfix.settings.main.mynetworks | List of trusted remote SMTP clients, that are allowed to relay mail
|
| services.waagent.settings.ResourceDisk.EnableSwap | If enabled, the agent creates a swap file (/swapfile) on the resource disk
and adds it to the system swap space
|
| services.anubis.defaultOptions.settings.POLICY_FNAME | The policy file to use
|
| services.invoiceplane.sites.<name>.settings | Structural InvoicePlane configuration
|
| services.wastebin.settings.WASTEBIN_HTTP_TIMEOUT | Maximum number of seconds a request can be processed until wastebin responds with 408
|
| services.wstunnel.servers.<name>.settings.restrict-to.*.port | The port.
|
| services.wstunnel.servers.<name>.settings.restrict-to.*.host | The hostname.
|
| services.grafana.settings.server.root_url | This is the full URL used to access Grafana from a web browser
|
| services.garage.settings.metadata_dir | The metadata directory, put this on a fast disk (e.g
|
| services.radicle.ci.broker.settings.report_dir | Directory where HTML and JSON report pages are written.
|
| services.waagent.settings.ResourceDisk.MountPoint | This option specifies the path at which the resource disk is mounted
|
| services.adguardhome.settings | AdGuard Home configuration
|
| services.glitchtip.settings.GLITCHTIP_DOMAIN | The URL under which GlitchTip is externally reachable.
|
| services.homebridge.settings.platforms.*.name | Name of the platform
|
| services.tor.settings.PublishHidServDescriptors | See torrc manual.
|
| services.misskey.settings.meilisearch.index | Meilisearch index to use.
|
| services.tor.settings.MaxAdvertisedBandwidth | See torrc manual.
|
| services.opensearch.settings."transport.port" | The port to listen on for transport traffic.
|
| services.ocsinventory-agent.settings.debug | Whether to enable debug mode.
|
| nix.settings.auto-optimise-store | If set to true, Nix automatically detects files in the store that have
identical contents, and replaces them with hard links to a single copy
|
| services.suricata.settings.logging.outputs.file.level | Loglevel for logs written to the logfile.
|
| services.libeufin.nexus.settings.nexus-ebics.PARTNER_ID | Partner ID of the EBICS subscriber
|
| services.epgstation.settings.encodeProcessNum | The maximum number of processes that EPGStation would allow to run
at the same time for encoding or streaming videos.
|
| services.mautrix-discord.settings.homeserver | fullDataDiration
|
| services.kanidm.server.settings.bindaddress | Address/port combination the webserver binds to.
|
| services.matrix-appservice-irc.settings.database | Configuration for the database
|
| security.loginDefs.settings.DEFAULT_HOME | Indicate if login is allowed if we can't cd to the home directory.
|
| services.szurubooru.server.settings.secretFile | File containing a secret used to salt the users' password hashes and generate filenames for static content.
|
| services.public-inbox.settings.publicinbox.css | The local path name of a CSS file for the PSGI web interface.
|
| services.karakeep.browser.enable | Enable the karakeep-browser service that runs a chromium instance in
the background with debugging ports exposed
|
| services.suwayomi-server.settings.server.downloadAsCbz | Download chapters as .cbz files.
|
| services.prowlarr.settings.log.analyticsEnabled | Send Anonymous Usage Data
|
| services.whisparr.settings.log.analyticsEnabled | Send Anonymous Usage Data
|
| services.opensnitch.settings.Server.Address | Unix socket path (unix:///tmp/osui.sock, the "unix:///" part is
mandatory) or TCP socket (192.168.1.100:50051).
|
| security.loginDefs.settings.TTYPERM | The terminal permissions: the login tty will be owned by the TTYGROUP group,
and the permissions will be set to TTYPERM
|
| services.minidlna.settings.enable_tivo | Support for streaming .jpg and .mp3 files to a TiVo supporting HMO.
|
| services.tinyproxy.settings.Anonymous | If an Anonymous keyword is present, then anonymous proxying is enabled
|
| services.botamusique.settings.bot.username | Name the bot should appear with.
|
| services.bitmagnet.settings.dht_server.port | DHT listen port
|
| services.tor.settings.FetchUselessDescriptors | See torrc manual.
|
| services.suricata.settings.vars.address-groups.ENIP_CLIENT | ENIP_CLIENT variable.
|
| services.tlsrpt.collectd.settings.socketmode | Permissions on the UNIX socket.
|
| services.suricata.settings.vars.address-groups.ENIP_SERVER | ENIP_SERVER variable.
|
| services.szurubooru.server.settings.data_dir | Path to the static files.
|
| services.swapspace.settings.freetarget | Percentage of free space swapspace should aim for when adding swapspace
|
| services.wgautomesh.settings.interface | Wireguard interface to manage (it is NOT created by wgautomesh, you
should use another NixOS option to create it such as
networking.wireguard.interfaces.wg0 = {...};).
|
| services.wgautomesh.settings.peers.*.endpoint | Bootstrap endpoint for connecting to this Wireguard peer if no
other address is known or none are working.
|
| services.draupnir.settings.homeserverUrl | Base URL of the Matrix homeserver that provides the Client-Server API.
|
| services.sourcehut.settings.objects.s3-upstream | Configure the S3-compatible object storage service.
|
| services.sourcehut.settings."meta.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.sourcehut.settings."todo.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.mautrix-discord.settings.appservice | Appservice configuration
|
| services.headscale.settings.oidc.pkce.enabled | Enable or disable PKCE (Proof Key for Code Exchange) support
|
| services.sourcehut.settings."builds.sr.ht::worker".timeout | Max build duration
|
| services.gitlab-runner.services.<name>.cloneUrl | Overwrite the URL for the GitLab instance
|
| services.anuko-time-tracker.settings.defaultCurrency | Defines a default currency symbol for new groups
|
| services.openvpn.servers.<name>.config | Configuration of this OpenVPN instance
|
| services.szurubooru.server.settings.data_url | Full URL to the data endpoint.
|
| services.warpgate.settings.recordings.enable | Whether to enable session recording.
|
| services.simplesamlphp.<name>.settings | Configuration options used by SimpleSAMLphp
|
| services.tor.settings.ExitPolicyRejectLocalInterfaces | See torrc manual.
|
| services.tor.settings.ConnDirectionStatistics | See torrc manual.
|
| services.kanidm.unix.settings.hsm_pin_path | Path to a HSM pin.
|
| services.omnom.settings.activitypub.privkey | ActivityPub private key
|
| <imports = [ pkgs.php.services.default ]>.php-fpm.settings.log_level | Error log level.
|
| hardware.bluetooth.settings | Set configuration for system-wide bluetooth (/etc/bluetooth/main.conf)
|
| services.pgbackrest.stanzas.<name>.settings | An attribute set of options as described in:
https://pgbackrest.org/configuration.html
All options can be used
|
| services.szurubooru.server.settings.show_sql | Whether to show SQL in server logs.
|
| services.tlsrpt.collectd.settings.socketname | Path at which the UNIX socket will be created.
|
| services.stash.settings.scrapers_path | Path to scrapers
|
| services.stash.settings.blobs_storage | Where to store blobs
|
| services.reposilite.settings.keyPassword | Plaintext password used to unlock the Java KeyStore set in services.reposilite.settings.keyPath
|
| services.anubis.defaultOptions.settings.SERVE_ROBOTS_TXT | Whether to serve a default robots.txt that denies access to common AI bots by name and all other
bots by wildcard.
|
| security.auditd.plugins.<name>.settings | Plugin-specific config file to link to /etc/audit/.conf
|
| services.saunafs.chunkserver.settings.DATA_PATH | Directory for chunck meta data
|
| services.geoipupdate.settings.EditionIDs | List of database edition IDs
|
| services.parsedmarc.settings.imap.password | The IMAP server password
|
| services.parsedmarc.settings.smtp.password | The SMTP server password
|
| services.nextcloud.package | Which package to use for the Nextcloud instance.
|
| services.nitter.preferences.theme | Instance theme.
|
| services.stash.settings.stash.*.excludevideo | Whether to exclude video files from being scanned into Stash
|
| services.stash.settings.stash.*.excludeimage | Whether to exclude image files from being scanned into Stash
|
| services.suricata.settings.vars.address-groups.DC_SERVERS | DC_SERVERS variable.
|
| services.tor.settings.GuardfractionFile | See torrc manual.
|
| programs.openvpn3.netcfg.settings | Options stored in /etc/openvpn3/netcfg.json configuration file
|
| services.anubis.defaultOptions.settings.BIND_NETWORK | The network family that Anubis should bind to
|
| services.postfix.settings.main.smtp_tls_CAfile | File containing CA certificates of root CAs trusted to sign either remote SMTP server certificates or intermediate CA certificates
|
| services.waagent.settings.ResourceDisk.FileSystem | The file system type for the resource disk
|
| services.matrix-synapse.settings.listeners | List of ports that Synapse should listen on, their purpose and their configuration
|
| services.suricata.settings.stats.decoder-events-prefix | Decoder event prefix in stats
|
| services.watchdogd.settings.loadavg.critical | The critical watermark level
|
| services.watchdogd.settings.meminfo.critical | The critical watermark level
|
| services.sourcehut.settings.mail.pgp-privkey | An absolute file path (which should be outside the Nix-store)
to an OpenPGP private key
|
| services.keycloak.settings.http-relative-path | The path relative to / for serving
resources.
In versions of Keycloak using Wildfly (<17),
this defaulted to /auth
|
| services.prometheus.exporters.ping.settings | Configuration for ping_exporter, see
https://github.com/czerwonk/ping_exporter
for supported values.
|
| services.waagent.settings.AutoUpdate.UpdateToLatestVersion | Whether or not to enable auto-update of the Extension Handler.
|
| services.nitter.sessionsFile | Path to the session tokens file
|
| services.bonsaid.settings.*.transitions | List of transitions out of this state
|
| services.rosenpass.settings.public_key | Path to a file containing the public key of the local Rosenpass peer
|
| services.rosenpass.settings.secret_key | Path to a file containing the secret key of the local Rosenpass peer
|
| services.geoipupdate.settings.LicenseKey | A file containing the MaxMind license key
|
| services.sourcehut.settings."builds.sr.ht".oauth-client-secret | builds.sr.ht's OAuth client secret for meta.sr.ht.
|
| services.moosefs.chunkserver.settings.DATA_PATH | Directory for lock files and other runtime data.
|
| services.snapserver.settings.tcp-control.enabled | Whether to enable the TCP JSON-RPC.
|
| services.thelounge.public | Make your The Lounge instance public
|
| services.paperless.enable | Whether to enable Paperless-ngx
|
| services.nezha-agent.settings.report_delay | The interval between system status reportings
|
| services.snapserver.settings.tcp-streaming.port | Port to listen on for snapclient connections.
|
| services.warpgate.settings.http.certificate | Path to HTTPS listener certificate.
|
| services.angrr.settings.temporary-root-policies.<name>.ignore-prefixes | List of path prefixes to ignore
|
| services.hickory-dns.settings.zones.*.zone_type | One of:
- "Primary" (the master, authority for the zone).
- "Secondary" (the slave, replicated from the primary).
- "External" (a cached zone that queries other nameservers)
|
| services.gitlab.pages.settings.internal-gitlab-server | Internal GitLab server used for API requests, useful
if you want to send that traffic over an internal load
balancer
|
| services.listmonk.database.settings.smtp.*.tls_type | Type of TLS authentication with the SMTP server
|
| services.bitmagnet.settings.postgres.password | Password for database user
|
| services.suricata.settings.vars.address-groups.AIM_SERVERS | AIM_SERVERS variable.
|
| services.suricata.settings.vars.address-groups.DNS_SERVERS | DNS_SERVERS variable.
|
| services.suricata.settings.vars.address-groups.SQL_SERVERS | SQL_SERVERS variable.
|
| services.stash.settings.preview_audio | Include audio stream in previews
|
| services.pantalaimon-headless.instances.<name>.homeserver | The URI of the homeserver that the pantalaimon proxy should
forward requests to, without the matrix API path but including
the http(s) schema.
|
| services.sourcehut.settings."pages.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.sourcehut.settings."lists.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.sourcehut.settings."paste.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.suricata.settings.logging.outputs.file.format | Logformat for logs written to the logfile.
|
| services.radicle.ci.broker.settings.adapters.<name>.command | Adapter command to run.
|
| services.suricata.settings.logging.outputs.file.enable | Whether to enable logging to file.
|
| services.suricata.settings.logging.outputs.syslog.type | Type of logs send to syslog.
|
| services.matrix-synapse.settings.listeners.*.path | Unix domain socket path to bind this listener to.
|
| services.mautrix-meta.instances.<name>.registrationServiceUnit | The registration service that generates the registration file
|
| services.sourcehut.settings."git.sr.ht::api".internal-ipnet | Set of IP subnets which are permitted to utilize internal API
authentication
|
| services.firewalld.settings.NftablesCounters | Whether to add a counter to every nftables rule.
|
| services.opengfw.settings.workers.tcpMaxBufferedPagesTotal | TCP max total buffered pages.
|
| services.quickwit.settings.rest.listen_port | The port to listen on for HTTP REST traffic.
|
| services.spacecookie.settings.hostname | The hostname the service is reachable via
|
| services.libeufin.nexus.settings.nexus-ebics.BANK_PUBLIC_KEYS_FILE | Filesystem location where Nexus should store the bank public keys.
|
| services.opensnitch.settings.Audit.AudispSocketPath | Configure audit socket path
|
| services.sourcehut.settings."sr.ht".service-key | An absolute file path (which should be outside the Nix-store)
to a key used for encrypting session cookies
|
| services.suricata.settings.outputs | Configure the type of alert (and other) logging you would like
|
| services.amule.settings.ExternalConnect.ECPassword | MD5 hash of the password, obtainaible with echo "<password>" | md5sum | cut -d ' ' -f 1
|
| services.suricata.settings.dpdk.interfaces | See upstream docs: docs/capture-hardware/dpdk and docs/configuration/suricata-yaml.html#data-plane-development-kit-dpdk.
|
| security.agnos.settings.accounts.*.email | Email associated with this account.
|
| services.canaille.settings.CANAILLE.SMTP.PASSWORD | SMTP Password
|
| services.opengfw.settings.workers.tcpMaxBufferedPagesPerConn | TCP max total bufferd pages per connection.
|
| services.wastebin.settings.WASTEBIN_DATABASE_PATH | Path to the sqlite3 database file
|
| services.tor.settings.ClientRejectInternalAddresses | See torrc manual.
|
| services.sabnzbd.settings.misc.cache_limit | Size of the RAM cache, in bytes (prefixes supported)
|
| services.etebase-server.settings.global.media_root | The media directory.
|
| services.crowdsec-firewall-bouncer.settings.api_url | URL of the local API.
|
| services.draupnir.settings.rawHomeserverUrl | Public base URL of the Matrix homeserver that provides the Client-Server API when using the Draupnir's
Report forwarding feature.
When using Pantalaimon, do not set this to the Pantalaimon URL!
|
| services.matrix-synapse.settings.presence.enabled | Whether to enable presence tracking
|
| services.waagent.settings.ResourceDisk.MountOptions | This option specifies disk mount options to be passed to the mount -o command
|
| boot.initrd.systemd.settings.Manager | Options for the global systemd service manager used in initrd
|
| services.suricata.settings.logging.default-log-level | The default log level: can be overridden in an output section
|
| services.canaille.settings.CANAILLE_OIDC.JWT.PRIVATE_KEY | JWT private key
|
| services.healthchecks.settings.SECRET_KEY_FILE | Path to a file containing the secret key.
|
| services.evdevremapkeys.settings | config.yaml for evdevremapkeys
|
| services.grafana.settings.security.admin_user | Default admin username.
|
| services.tor.settings.DoSRefuseSingleHopClientRendezvous | See torrc manual.
|
| services.suricata.settings.vars.address-groups.SMTP_SERVERS | SMTP_SERVERS variable.
|
| services.suricata.settings.vars.address-groups.HTTP_SERVERS | HTTP_SERVERS variable.
|
| services.libeufin.nexus.settings.nexus-ebics.BANK_DIALECT | Name of the following combination: EBICS version and ISO20022
recommendations that Nexus would honor in the communication with the
bank
|
| services.ferretdb.settings.FERRETDB_TELEMETRY | Enable or disable basic telemetry
|
| services.transmission.settings.utp-enabled | Whether to enable Micro Transport Protocol (µTP).
|
| services.stash.settings.calculate_md5 | Whether to calculate MD5 checksums for scene video files
|
| services.sourcehut.settings."meta.sr.ht::api".internal-ipnet | Set of IP subnets which are permitted to utilize internal API
authentication
|
| services.reposilite.settings.defaultFrontend | Whether to enable the default included frontend with a dashboard.
|
| services.glitchtip.redis.createLocally | Whether to enable and configure a local Redis instance.
|
| services.dendrite.settings.sync_api.search.enabled | Whether to enable Dendrite's full-text search engine.
|
| services.routinator.settings.repository-dir | The path where the collected RPKI data is stored.
|
| services.slskd.settings.soulseek.description | The user description for the Soulseek network.
|
| services.slskd.settings.soulseek.listen_port | The port on which to listen for incoming connections.
|
| services.warpgate.settings.mysql.certificate | Path to MySQL listener certificate.
|
| services.movim.podConfig.description | General description of the instance
|
| services.oncall.settings.db.conn.require_auth | Whether authentication is required to access the web app.
|
| services.tor.settings.ClientDNSRejectInternalAddresses | See torrc manual.
|
| services.tor.settings.DisableDebuggerAttachment | See torrc manual.
|
| services.tor.settings.DormantTimeoutDisabledByIdleStreams | See torrc manual.
|
| services.pid-fan-controller.settings.fans.*.heatPressureSrcs | Heat pressure sources affected by the fan.
|
| services.stash.settings.stash_boxes.*.endpoint | URL to the Stash Box graphql api
|
| services.wstunnel.servers.<name>.settings.restrict-to | Restrictions on the connections that the server will accept
|
| services.transmission.settings.umask | Sets transmission's file mode creation mask
|
| services.rosenpass.settings.peers.*.public_key | Path to a file containing the public key of the remote Rosenpass peer.
|
| services.syncthing.settings.options.relaysEnabled | When true, relays will be connected to and potentially used for device to device connections.
|
| services.pid-fan-controller.settings.heatSources.*.pidParams.P | K_p of PID controller.
|
| services.pid-fan-controller.settings.heatSources.*.pidParams.D | K_d of PID controller.
|
| services.pid-fan-controller.settings.heatSources.*.pidParams.I | K_i of PID controller.
|
| users.mysql.pam | Settings for pam_mysql
|
| services.sourcehut.settings."builds.sr.ht::worker".bind-address | HTTP bind address for serving local build information/monitoring.
|
| services.grafana.settings.smtp.from_address | Address used when sending out emails.
|
| services.crowdsec.settings.lapi.credentialsFile | The LAPI credential file to use.
|
| services.crowdsec.settings.capi.credentialsFile | The CAPI credential file to use.
|
| services.waagent.settings.ResourceDisk.Format | If set to true, waagent formats and mounts the resource disk that the platform provides,
unless the file system type in `ResourceDisk
|
| services.taler.exchange.settings.exchange.CURRENCY | The currency which the exchange will operate with
|
| services.zeronsd.servedNetworks.<name>.settings.wildcard | Whether to serve a wildcard record for ZeroTier Nodes.
|
| services.suricata.settings.vars.address-groups.MODBUS_CLIENT | MODBUS_CLIENT variable
|
| services.suricata.settings.vars.address-groups.MODBUS_SERVER | MODBUS_SERVER variable.
|
| services.syncthing.settings.folders.<name>.devices | The devices this folder should be shared with
|
| services.ocsinventory-agent.settings.local | If specified, the OCS Inventory Agent will run in offline mode
and the resulting inventory file will be stored in the specified path.
|
| services.suricata.settings.logging.default-log-format | The default output format
|
| services.sourcehut.settings."builds.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.sourcehut.settings."meta.sr.ht::billing".stripe-public-key | Public key for Stripe
|
| services.suwayomi-server.settings.server.systemTrayEnabled | Whether to enable a system tray icon, if possible.
|
| services.sftpgo.settings.webdavd.bindings.*.address | Network listen address
|
| services.angrr.settings.temporary-root-policies.<name>.ignore-prefixes-in-home | Path prefixes to ignore under home directory
|
| services.tlsrpt.reportd.settings.http_script | Call to an HTTPS client, that accepts the URL on the commandline and the request body from stdin.
|
| services.sourcehut.settings."sr.ht".environment | Values other than "production" adds a banner to each page.
|
| services.angrr.settings.temporary-root-policies.<name>.enable | Whether to enable this angrr policy.
|
| services.sabnzbd.settings.misc.enable_https | Whether to enable HTTPS for the web UI
|
| services.sabnzbd.settings.misc.email_server | SMTP server for email alerts (server:host)
|
| services.slskd.settings.global.upload.speed_limit | Total upload speed limit.
|
| services.firewalld.settings.NftablesTableOwner | If enabled, the generated nftables rule set will be owned exclusively by firewalld
|
| services.maubot.settings.database_opts | Additional arguments for asyncpg.create_pool() or sqlite3.connect()
|
| services.suwayomi-server.settings.server.basicAuthUsername | The username value that you have to provide when authenticating.
|
| services.journald.upload.settings.Upload.ServerKeyFile | SSL key in PEM format
|
| services.pretix.database.createLocally | Whether to automatically set up the database on the local DBMS instance
|
| services.headscale.settings.database.postgres.user | Database user.
|
| services.headscale.settings.database.postgres.name | Database name.
|
| services.transmission.settings.message-level | Set verbosity of transmission messages.
|
| services.maubot.settings.server.ui_base_path | The base path for the UI.
|
| security.pam.u2f.settings.origin | By default pam-u2f module sets the origin
to pam://$HOSTNAME
|
| services.transmission.settings.download-dir | Directory where to download torrents.
|
| services.nvme-rs.settings.email.smtp_username | SMTP username
|
| security.loginDefs.settings.TTYGROUP | The terminal permissions: the login tty will be owned by the TTYGROUP group,
and the permissions will be set to TTYPERM
|
| services.anuko-time-tracker.settings.defaultLanguage | Defines Anuko Time Tracker default language
|
| services.sourcehut.settings."pages.sr.ht::api".internal-ipnet | Set of IP subnets which are permitted to utilize internal API
authentication
|
| services.grafana.settings.database.cache_mode | For sqlite3 only.
Shared cache setting used for connecting to the database.
|
| services.nextcloud-spreed-signaling.settings.mcu.type | The type of MCU to use
|
| services.headscale.settings.database.postgres.host | Database host address.
|
| services.headscale.settings.database.postgres.port | Database host port.
|
| services.moosefs.cgiserver.settings.GUISERV_LISTEN_PORT | Port for GUI server to listen on.
|
| services.angrr.settings.temporary-root-policies.<name>.period | Retention period for the GC roots matched by this policy.
|
| services.angrr.settings.temporary-root-policies.<name>.path-regex | Regex pattern to match the GC root path.
|
| services.scrutiny.collector.settings.api.endpoint | Scrutiny app API endpoint for sending metrics to.
|
| services.tandoor-recipes.enable | Enable Tandoor Recipes
|
| services.suricata.settings.vars.address-groups.EXTERNAL_NET | EXTERNAL_NET variable.
|
| services.waagent.settings.Provisioning.Agent | Which provisioning agent to use.
|
| services.suwayomi-server.settings.server.basicAuthEnabled | Whether to enable basic access authentication for Suwayomi-Server
|
| i18n.inputMethod.fcitx5.settings.globalOptions | The global options in config file in ini format.
|
| services.angrr.settings.profile-policies.<name>.keep-booted-system | Whether to keep the last booted system generation
|
| services.crab-hole.settings.blocklist.allow_list | List of allowlists
|
| services.transmission.settings.rpc-bind-address | Where to listen for RPC connections
|
| services.mchprs.settings.auto_redpiler | Use redpiler automatically
|
| services.warpgate.settings.database_url | Database connection string
|
| services.grafana.settings.database.password | The database user's password (not applicable for sqlite3)
|
| services.hercules-ci-agent.settings.clusterJoinTokenPath | Location of the cluster-join-token.key file
|
| services.netbird.server.dashboard.settings | An attribute set that will be used to substitute variables when building the dashboard
|
| services.engelsystem.settings | Options to be added to config.php, as a nix attribute set
|
| services.mjolnir.pantalaimon | pantalaimon options (enables E2E Encryption support)
|
| services.teamspeak3.fileTransferIP | IP on which the server instance will listen for incoming file transfer connections
|
| services.grafana-image-renderer.settings.rendering.args | List of CLI flags passed to chromium.
|
| services.ocsinventory-agent.settings.server | The URI of the OCS Inventory server where to send the inventory file
|
| services.bitmagnet.settings.http_server.port | HTTP server listen port
|
| services.bluesky-pds.settings.PDS_BLOBSTORE_DISK_LOCATION | Store blobs at this location, set to null to use e.g
|
| services.dependency-track.settings."alpine.ldap.enabled" | Defines if LDAP will be used for user authentication
|
| services.suricata.settings.pcap-file.checksum-checks | Possible values are:
- yes: checksum validation is forced
- no: checksum validation is disabled
- auto: Suricata uses a statistical approach to detect when
checksum off-loading is used. (default)
Warning: 'checksum-validation' must be set to yes to have checksum tested.
|
| services.suricata.settings.logging.outputs.syslog.format | Logformat for logs send to syslog.
|
| services.suricata.settings.logging.outputs.syslog.enable | Whether to enable logging to syslog.
|
| services.moosefs.cgiserver.settings.GUISERV_LISTEN_HOST | IP address to bind GUI server to (* means any).
|
| services.pretix.settings.pretix.registration | Whether to allow registration of new admin users.
|
| services.syncthing.settings.options.localAnnouncePort | The port on which to listen and send IPv4 broadcast announcements to.
|
| services.hostapd.radios.<name>.networks.<name>.settings | Extra configuration options to put at the end of this BSS's defintion in the
hostapd.conf for the associated interface
|
| services.grafana.settings.server.socket_mode | Mode where the socket should be set when protocol=socket
|
| services.angrr.settings.temporary-root-policies.<name>.filter | External filter program to further filter GC roots matched by this policy.
|
| services.reposilite.settings.bypassExternalCache | Add cache bypass headers to responses from /api/* to avoid issues with proxies such as Cloudflare.
|
| services.healthchecks.settings.ALLOWED_HOSTS | The host/domain names that this site can serve.
|
| services.dependency-track.settings."alpine.database.url" | Specifies the JDBC URL to use when connecting to the database.
|
| services.pretalx.settings.files.upload_limit | Maximum file upload size in MiB.
|
| services.homebridge.settings.accessories | Homebridge Accessories
|
| boot.initrd.systemd.tmpfiles.settings | Similar to systemd.tmpfiles.settings but the rules are
only applied by systemd-tmpfiles before initrd-switch-root.target
|
| security.loginDefs.settings.ENCRYPT_METHOD | This defines the system default encryption algorithm for encrypting passwords.
|
| services.nextcloud.settings.mail_domain | The return address that you want to appear on emails sent by the Nextcloud server, for example nc-admin@example.com, substituting your own domain, of course.
|
| security.krb5.settings.includedir | Directories containing files to include in the Kerberos configuration.
|
| services.listmonk.database.settings.smtp.*.max_conns | Maximum number of simultaneous connections, defaults to 1
|
| services.sourcehut.settings."hg.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.dendrite.settings.media_api.base_path | Storage path for uploaded media.
|
| services.transmission.settings.watch-dir-enabled | Whether to enable the
services.transmission.settings.watch-dir.
|
| services.dependency-track.settings."alpine.oidc.client.id" | Defines the client ID to be used for OpenID Connect
|
| services.dependency-track.settings."alpine.oidc.enabled" | Defines if OpenID Connect will be used for user authentication
|
| services.opensnitch.settings.InterceptUnknown | Whether to intercept spare connections.
|
| services.tor.settings.BridgeAuthoritativeDir | See torrc manual.
|
| services.zeronsd.servedNetworks.<name>.settings.log_level | Log Level.
|
| services.maubot.settings.plugin_databases | Plugin database settings
|
| services.epgstation.settings.clientSocketioPort | Socket.io port that the web client is going to connect to
|
| services.firewalld.settings.FirewallBackend | The firewall backend implementation
|
| services.suricata.settings.logging.default-output-filter | A regex to filter output
|
| services.transmission.settings.peer-port-random-on-start | Randomize the peer port.
|
| services.umurmur.settings.channel_links | Channel tree definitions.
|
| services.mchprs.settings.view_distance | Maximal distance (in chunks) between players and loaded chunks
|
| services.suwayomi-server.settings.server.extensionRepos | URL of repositories from which the extensions can be installed.
|
| services.sslh.settings.verbose-connections | Where to log connections information
|
| services.sourcehut.settings."meta.sr.ht::billing".stripe-secret-key | An absolute file path (which should be outside the Nix-store)
to a secret key for Stripe
|
| services.taler.exchange.settings.exchange.MASTER_PUBLIC_KEY | Used by the exchange to verify information signed by the offline system.
|
| services.sourcehut.settings."hub.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.sourcehut.settings."git.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.sourcehut.settings."man.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.transmission.settings.peer-port-random-low | The minimal peer port to listen to for incoming connections
when services.transmission.settings.peer-port-random-on-start is enabled.
|
| services.matrix-synapse.settings.database.args.database | Name of the database when using the psycopg2 backend,
path to the database location when using sqlite3.
|
| services.grafana.settings.server.socket_gid | GID where the socket should be set when protocol=socket
|
| services.suricata.settings.vars.address-groups.TELNET_SERVERS | TELNET_SERVERS variable.
|
| nix.settings.substituters | List of binary cache URLs used to obtain pre-built binaries
of Nix packages
|
| services.nextcloud.settings.loglevel | Log level value between 0 (DEBUG) and 4 (FATAL).
-
0 (debug): Log all activity.
-
1 (info): Log activity such as user logins and file activities, plus warnings, errors, and fatal errors.
-
2 (warn): Log successful operations, as well as warnings of potential problems, errors and fatal errors.
-
3 (error): Log failed operations and fatal errors.
-
4 (fatal): Log only fatal errors that cause the server to stop.
|
| services.dependency-track.settings."alpine.oidc.issuer" | Defines the issuer URL to be used for OpenID Connect
|
| services.grafana.provision.alerting.rules.settings | Grafana rules configuration in Nix
|
| services.anuko-time-tracker.settings.exportDecimalDuration | Defines whether time duration values are decimal in CSV and XML data
exports (1.25 vs 1:15).
|
| services.nextcloud-spreed-signaling.settings.nats.url | URL of one or more NATS backends to use
|
| services.suricata.settings.dpdk | Data Plane Development Kit is a framework for fast packet processing in data plane applications running on a wide variety of CPU architectures
|
| services.listmonk.database.settings.messengers | List of messengers, see: https://github.com/knadh/listmonk/blob/master/models/settings.go#L64-L74 for options.
|
| services.sabnzbd.settings.servers.<name>.displayname | Human-friendly description of the server
|
| services.scrutiny.influxdb.enable | Enables InfluxDB on the host system using the services.influxdb2 NixOS module
with default options
|
| services.sourcehut.settings."builds.sr.ht::worker".buildlogs | Path to write build logs.
|
| services.slskd.settings.directories.downloads | Directory where downloaded files are stored.
|
| services.suricata.settings.logging.outputs.file.filename | Filename of the logfile.
|
| programs.openvpn3.log-service.settings | Options stored in /etc/openvpn3/log-service.json configuration file
|
| networking.wireless.iwd.settings | Options passed to iwd
|
| services.matrix-appservice-irc.settings.database.engine | Which database engine to use
|
| services.immichframe.settings.Accounts.*.ApiKeyFile | File containing an API key to talk to the Immich server
|
| services.grafana-image-renderer.settings.rendering.width | Width of the PNG used to display the alerting graph.
|
| services.sabnzbd.settings.servers.<name>.connections | Number of parallel connections permitted by
the server.
|
| services.slskd.settings.retention.files.incomplete | Lifespan of incomplete downloading files in minutes.
|
| services.suwayomi-server.settings.server.basicAuthPasswordFile | The password file containing the value that you have to provide when authenticating.
|
| services.angrr.settings.profile-policies.<name>.keep-current-system | Whether to keep the current system generation
|
| services.matrix-synapse.settings.report_stats | Whether or not to report anonymized homeserver usage statistics.
|
| services.pinnwand.settings.database_uri | Database URI compatible with SQLAlchemy
|
| services.sourcehut.settings."meta.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.sourcehut.settings."todo.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.tlsrpt.reportd.settings.contact_info | Contact information embedded into the reports.
|
| services.librenms.enableLocalBilling | Enable billing Cron-Jobs on the local instance
|
| services.transmission.settings.peer-port-random-high | The maximum peer port to listen to for incoming connections
when services.transmission.settings.peer-port-random-on-start is enabled.
|
| services.etebase-server.settings.global.static_root | The directory for static files.
|
| services.ferretdb.settings.FERRETDB_POSTGRESQL_URL | PostgreSQL URL for 'pg' handler
|
| services.listmonk.database.settings."bounce.mailboxes" | List of bounce mailboxes
|
| services.matrix-appservice-irc.settings.ircService.servers | IRC servers to connect to
|
| services.armagetronad.servers.<name>.settings | Armagetron Advanced server rules configuration
|
| services.your_spotify.settings.MONGO_ENDPOINT | The endpoint of the Mongo database.
|
| services.canaille.settings.CANAILLE_SQL.DATABASE_URI | The SQL server URI
|
| services.matrix-appservice-irc.settings.homeserver | Homeserver configuration
|
| services.nextcloud-spreed-signaling.settings.https.key | Path to the private key used for the HTTPS listener
|
| services.firewalld.settings.StrictForwardPorts | If enabled, the generated destination NAT (DNAT) rules will NOT accept traffic that was DNAT'd by other entities, e.g. docker
|
| services.matrix-appservice-discord.settings | config.yaml configuration as a Nix attribute set
|
| services.headscale.settings.tls_key_path | Path to key for already created certificate.
|
| services.swapspace.settings.max_swapsize | Greatest allowed size for individual swapfiles
|
| services.swapspace.settings.min_swapsize | Smallest allowed size for individual swapfiles
|
| services.sabnzbd.settings.misc.email_endjob | Whether to send emails on job completion
|
| services.syncthing.settings.devices.<name>.autoAcceptFolders | Automatically create or share folders that this device advertises at the default path
|
| services.wgautomesh.settings.gossip_port | wgautomesh gossip port, this MUST be the same number on all nodes in
the wgautomesh network.
|
| services.tuned.settings.dynamic_tuning | Whether to enable dynamic tuning.
|
| services.sabnzbd.settings.servers.<name>.ssl_verify | Level of TLS verification
|
| services.lasuite-meet.livekit.keyFile | LiveKit key file holding one or multiple application secrets
|
| services.pid-fan-controller.settings.fans.*.wildcardPath | Wildcard path of the hwmon pwm file
|
| services.pid-fan-controller.settings.heatSources.*.pidParams.setPoint | Set point of the controller in °C.
|
| services.suricata.settings.logging.outputs.console.enable | Whether to enable logging to console.
|
| services.syncthing.settings.options.urAccepted | Whether the user has accepted to submit anonymous usage data
|
| services.reposilite.settings.databaseThreadPool | Maximum amount of concurrent connections to the database. (one per thread)
Embedded databases (sqlite, h2) do not support truly concurrent connections, so the value will always be 1 if they are used.
|
| services.immichframe.settings.Accounts.*.ApiKey | API key to talk to the Immich server
|
| services.snapserver.settings.tcp-streaming.enabled | Whether to enable streaming via TCP.
|
| services.matrix-synapse.settings.log_config | The file that holds the logging configuration.
|
| services.libeufin.nexus.settings.nexus-ebics.CLIENT_PRIVATE_KEYS_FILE | Filesystem location where Nexus should store the subscriber private keys.
|
| services.umurmur.settings.max_bandwidth | Maximum bandwidth (in bits per second) that clients may send
speech at.
|
| services.olivetin.settings.ListenAddressSingleHTTPFrontend | The address to listen on for the internal "microproxy" frontend.
|
| services.firewalld.settings.IndividualCalls | Whether to use individual -restore calls to apply changes to the firewall
|
| services.pretalx.database.createLocally | Whether to automatically set up the database on the local DBMS instance
|
| security.agnos.settings.accounts | A list of ACME accounts
|
| services.libeufin.bank.settings.libeufin-bank.CURRENCY | The currency under which the libeufin-bank should operate
|
| services.homebridge.settings.accessories.*.name | Name of the accessory
|
| services.grafana.settings.server.enable_gzip | Set this option to true to enable HTTP compression, this can improve transfer speed and bandwidth utilization
|
| services.grafana.settings.security.admin_email | The email of the default Grafana Admin, created on startup.
|
| services.matrix-synapse.settings.listeners.*.resources | List of HTTP resources to serve on this listener.
|
| services.grafana.settings.users.hidden_users | This is a comma-separated list of usernames
|
| services.matrix-synapse.settings.server_name | The domain name of the server, with optional explicit port
|
| services.omnom.settings.server.secure_cookie | Whether to limit cookies to a secure channel.
|
| services.stash.settings.parallel_tasks | Number of parallel tasks to start during scan/generate
|
| services.anubis.defaultOptions.settings.DIFFICULTY | The difficulty required for clients to solve the challenge
|
| services.sourcehut.settings."pages.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.sourcehut.settings."paste.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.sourcehut.settings."lists.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.etebase-server.settings.global.secret_file | The path to a file containing the secret
used as django's SECRET_KEY.
|
| services.grafana.settings.database.log_queries | Set to true to log the sql calls and execution times
|
| services.homebridge.settings.platforms.*.platform | Platform type
|
| services.grafana-image-renderer.settings.rendering.height | Height of the PNG used to display the alerting graph.
|
| services.tuned.settings.sleep_interval | Interval in which the TuneD daemon is waken up and checks for events (in seconds).
|
| services.your_spotify.settings.SPOTIFY_PUBLIC | The public client ID of your Spotify application
|
| services.logind.settings.Login.KillUserProcesses | Specifies whether the processes of a user should be killed
when the user logs out
|
| services.your_spotify.enableLocalDB | Whether to enable a local mongodb instance.
|
| services.matrix-tuwunel.settings.global.server_name | The server_name is the name of this server
|
| services.matrix-conduit.settings.global.server_name | The server_name is the name of this server
|
| services.prometheus.exporters.process.settings.process_names | All settings expressed as an Nix attrset
|
| services.dendrite.settings.global.server_name | The domain name of the server, with optional explicit port
|
| services.tuned.settings.reapply_sysctl | Whether to enable the reapplying of global sysctls after TuneD sysctls are applied.
|
| services.nextcloud.settings."profile.enabled" | Makes user-profiles globally available under nextcloud.tld/u/user.name
|
| services.borgmatic.settings.repositories.*.path | Path to the repository
|
| services.minidlna.settings.friendly_name | Name that the server presents to clients.
|
| services.epgstation.settings.concurrentEncodeNum | The maximum number of encoding jobs that EPGStation would run at the
same time.
|
| services.system76-scheduler.settings.cfsProfiles.enable | Tweak CFS latency parameters when going on/off battery
|
| services.tor.relay.onionServices.<name>.settings.HiddenServiceSingleHopMode | See torrc manual.
|
| services.sourcehut.settings.webhooks.private-key | An absolute file path (which should be outside the Nix-store)
to a base64-encoded Ed25519 key for signing webhook payloads
|
| services.postsrsd.settings.unprivileged-user | Unprivileged user to drop privileges to.
Our systemd unit never runs postsrsd as a privileged process, so this option is read-only.
|
| services.nextcloud-spreed-signaling.settings.grpc.listen | IP and port to listen on for GRPC requests
|
| services.syncthing.settings.options.limitBandwidthInLan | Whether to apply bandwidth limits to devices in the same broadcast domain as the local device.
|
| services.slskd.settings.global.download.speed_limit | Total upload download limit
|
| services.grafana.provision.dashboards.settings | Grafana dashboard configuration in Nix
|
| services.grafana-image-renderer.settings.service.logging.level | The log-level of the grafana-image-renderer.service-unit.
|
| services.journald.remote.settings.Remote.ServerKeyFile | A path to a SSL secret key file in PEM format
|
| services.dependency-track.settings."alpine.database.driver" | Specifies the JDBC driver class to use.
|
| services.warpgate.settings.sso_providers | Configure OIDC single sign-on providers.
|
| services.ncps.cache.lock.backend | Lock backend to use: 'local' (single instance), 'redis'
(distributed), 'postgres' (distributed, requires PostgreSQL)
|
| hardware.tuxedo-drivers.settings.fn-lock | Enables or disables the laptop keyboard's Function (Fn) lock at boot
|
| services.angrr.settings.profile-policies.<name>.profile-paths | Paths to the Nix profile
|
| services.nextcloud.settings.enabledPreviewProviders | The preview providers that should be explicitly enabled.
|
| services.tor.relay.onionServices.<name>.settings.HiddenServiceMaxStreams | See torrc manual.
|
| services.grafana.settings.paths.provisioning | Folder that contains provisioning config files that grafana will apply on startup and while running
|
| hardware.nvidia.datacenter.settings | Additional configuration options for fabricmanager.
|
| services.filesender.settings.admin_email | Email address of FileSender administrator(s)
|
| services.netbird.server.management.settings | Configuration of the netbird management server
|
| services.omnom.settings.app.disable_signup | Whether to enable restricting user creation.
|
| services.anubis.defaultOptions.settings.WEBMASTER_EMAIL | If set, shows a contact email address when rendering error pages
|
| services.dendrite.settings.sync_api.search.language | The language most likely to be used on the server - used when indexing, to
ensure the returned results match expectations
|
| services.nextcloud-spreed-signaling.settings.app.debug | Set to "true" to install pprof debug handlers
|
| services.jitsi-meet.videobridge.enable | Jitsi Videobridge instance and configure it to connect to Prosody
|
| services.lidarr.settings.update.automatically | Automatically download and install updates.
|
| services.hddfancontrol.settings.<drive-bay-name>.extraArgs | Extra commandline arguments for hddfancontrol
|
| services.radarr.settings.update.automatically | Automatically download and install updates.
|
| services.suricata.settings.logging.outputs.syslog.facility | Facility to log to.
|
| services.sonarr.settings.update.automatically | Automatically download and install updates.
|
| services.anubis.defaultOptions.settings.METRICS_BIND_NETWORK | The network family that the metrics server should bind to
|
| services.grafana.provision.alerting.rules.settings.groups | List of rule groups to import or update.
|
| services.grafana.settings.smtp.ehlo_identity | Name to be used as client identity for EHLO in SMTP dialog.
|
| services.postfix.settings.main.relay_domains | List of domains delivered via the relay transport.
https://www.postfix.org/postconf.5.html#relay_domains
|
| services.tor.settings.ServerTransportPlugin.transports | List of pluggable transports.
|
| services.draupnir.settings.managementRoom | The room ID or alias where moderators can use the bot's functionality
|
| services.prometheus.exporters.lnd.lndHost | lnd instance gRPC address:port.
|
| services.dendrite.settings.global.private_key | The path to the signing private key file, used to sign
requests and events.
nix-shell -p dendrite --command "generate-keys --private-key matrix_key.pem"
|
| services.sourcehut.settings."builds.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.buffyboard.settings.input.touchscreen | Enable or disable the use of the touchscreen.
|
| services.warpgate.settings.postgres.certificate | Path to PostgreSQL listener certificate.
|
| services.borgmatic.settings.repositories.*.label | Label to the repository
|
| services.tor.settings.CookieAuthentication | See torrc manual.
|
| services.headscale.settings.dns.nameservers.global | List of nameservers to pass to Tailscale clients.
|
| services.postfixadmin.extraConfig | Extra configuration for the postfixadmin instance, see postfixadmin's config.inc.php for available options.
|
| services.nextcloud-spreed-signaling.settings.http.listen | IP and port to listen on for HTTP requests, in the format of ip:port
|
| services.slskd.settings.directories.incomplete | Directory where incomplete downloading files are stored.
|
| services.immichframe.settings.Accounts.*.ImmichServerUrl | The URL of your Immich server.
|
| services.mackerel-agent.settings.host_status.on_stop | Host status after agent shutdown.
|
| services.postfix.settings.master.<name>.wakeupUnusedComponent | If set to false the component will only be woken
up if it is used
|
| services.headscale.settings.oidc.extra_params | Custom query parameters to send with the Authorize Endpoint request.
|
| services.your_spotify.settings.CLIENT_ENDPOINT | The endpoint of your web application
|
| services.matrix-appservice-irc.settings.homeserver.url | The URL to the home server for client-server API calls
|
| services.firewalld.settings.NftablesFlowtable | This may improve forwarded traffic throughput by enabling nftables flowtable
|
| services.prometheus.exporters.fritz.settings.devices | Fritz!-devices to monitor using the exporter.
|
| services.syncthing.settings.folders.<name>.versioning.type | The type of versioning
|
| services.suricata.settings.app-layer.protocols.<name>.enabled | The option "enabled" takes 3 values - "yes", "no", "detection-only".
"yes" enables both detection and the parser, "no" disables both, and
"detection-only" enables protocol detection only (parser disabled).
|
| nix.settings.sandbox | If set, Nix will perform builds in a sandboxed environment that it
will set up automatically for each build
|
| services.matrix-appservice-irc.settings.ircService.mediaProxy.bindPort | Port that the media proxy binds to.
|
| services.sabnzbd.settings.servers.<name>.expire_date | If Notifications are enabled and an expiry date is
set, warn 5 days before expiry
|
| services.headscale.settings.dns.base_domain | Defines the base domain to create the hostnames for MagicDNS
|
| services.navidrome.settings.EnableInsightsCollector | Enable anonymous usage data collection, see https://www.navidrome.org/docs/getting-started/insights/ for details.
|
| services.syncthing.settings.folders.<name>.versioning | How to keep changed/deleted files with Syncthing
|
| services.veilid.settings.core.capabilities.disable | A list of capabilities to disable (for example, DHTV to say you cannot store DHT information).
|
| services.warpgate.settings.ssh.external_port | The SSH listener is reachable via this port externally.
|
| services.nextcloud-spreed-signaling.settings.grpc.targets | For target type static: List of GRPC targets to connect to for clustering mode.
|
| services.warpgate.settings.sso_providers.*.name | Internal identifier of SSO provider.
|
| services.kanidm.serverSettings.domain | The domain that Kanidm manages
|
| services.grafana.settings.security.secret_key | Secret key used for signing
|
| services.grafana.settings.users.password_hint | Text used as placeholder text on login page for password input.
|
| services.automysqlbackup.settings | automysqlbackup configuration
|
| services.veilid.settings.core.table_store.directory | The filesystem directory to store your table store within.
|
| services.veilid.settings.core.block_store.directory | The filesystem directory to store blocks for the block store.
|
| services.matrix-synapse.settings.listeners.*.resources.*.names | List of resources to host on this listener.
|
| services.nextcloud-spreed-signaling.settings.turn.servers | A list of TURN servers to use
|
| services.taler.exchange.settings.exchange.CURRENCY_ROUND_UNIT | Smallest amount in this currency that can be transferred using the underlying RTGS
|
| services.grafana.settings.users.default_theme | Sets the default UI theme. system matches the user's system theme.
|
| services.mpd.settings.bind_to_address | The address for the daemon to listen on
|
| services.your_spotify.settings.API_ENDPOINT | The endpoint of your server
This api has to be reachable from the device you use the website from not from the server
|
| services.hddfancontrol.settings.<drive-bay-name>.disks | Drive(s) to get temperature from
Can also use command substitution to automatically grab all matching drives; such as all scsi (sas) drives
|
| services.hercules-ci-agent.settings.staticSecretsDirectory | This is the default directory to look for statically configured secrets like cluster-join-token.key
|
| services.invidious.serviceScale | How many invidious instances to run
|
| services.grafana.provision.alerting.rules.settings.groups.*.name | Name of the rule group
|
| services.grafana.settings.database.ca_cert_path | The path to the CA certificate to use.
|
| services.readarr.settings.update.automatically | Automatically download and install updates.
|
| services.sourcehut.settings."hg.sr.ht".changegroup-script | A changegroup script which is installed in every mercurial repo
|
| services.headscale.settings.tls_cert_path | Path to already created certificate.
|
| services.sharkey.settings.fulltextSearch.provider | Which provider to use for full text search
|
| services.syncthing.settings.options.localAnnounceEnabled | Whether to send announcements to the local LAN, also use such announcements to find other devices.
|
| services.angrr.settings.temporary-root-policies.<name>.filter.program | Path to the external filter program.
|
| services.dendrite.settings.sync_api.search.index_path | The path the search index will be created in.
|
| services.warpgate.settings.http.external_port | The HTTP listener is reachable via this port externally.
|
| services.grafana.provision.alerting.rules.settings.apiVersion | Config file version.
|
| services.kanidm.server.settings.online_backup.path | Path to the output directory for backups.
|
| services.pid-fan-controller.settings.heatSources.*.wildcardPath | Path of the heat source's hwmon temp_input file
|
| services.libeufin.bank.settings.libeufin-bankdb-postgres.CONFIG | The database connection string for the libeufin-bank database.
|
| services.grafana.provision.alerting.muteTimings.settings | Grafana mute timings configuration in Nix
|
| services.nextcloud-spreed-signaling.settings.turn.apikeyFile | The path to the file containing the value for turn.apikey
|
| services.nextcloud-spreed-signaling.settings.turn.secretFile | The path to the file containing the value for turn.secret
|
| services.grafana.settings.server.read_timeout | Sets the maximum time using a duration format (5s/5m/5ms)
before timing out read of an incoming request and closing idle connections.
0 means there is no timeout for reading the request.
|
| services.slskd.settings.retention.transfers.upload.errored | Lifespan of errored upload tasks.
|
| services.prometheus.exporters.fritz.settings.devices.*.name | Name to use for the device.
|
| services.synapse-auto-compressor.settings.levels | Sizes of each new level in the compression algorithm, as a comma-separated list
|
| services.nextcloud.settings.mail_smtpport | This depends on mail_smtpmode
|
| services.lldap.settings.ldap_user_email | Admin email.
|
| services.sabnzbd.settings.misc.bandwidth_max | Maximum bandwidth in bytes(!)/sec (supports prefixes)
|
| services.chhoto-url.settings.hash_algorithm | The hash algorithm to use for passwords and API keys
|
| services.grafana.provision.alerting.rules.settings.deleteRules | List of alert rule UIDs that should be deleted.
|
| services.opentelemetry-collector.settings | Specify the configuration for Opentelemetry Collector in Nix
|
| services.tor.settings.AuthoritativeDirectory | See torrc manual.
|
| services.ncdns.identity.hostname | The hostname of this ncdns instance, which defaults to the machine
hostname
|
| services.crowdsec-firewall-bouncer.settings.api_key | API key to authenticate with a local crowdsec API
|
| services.nextcloud.settings.mail_smtpname | This depends on mail_smtpauth
|
| services.angrr.settings.temporary-root-policies.<name>.priority | Priority of this policy
|
| services.suricata.settings.logging.stacktrace-on-signal | Requires libunwind to be available when Suricata is configured and built
|
| services.prometheus.alertmanager-ntfy.settings | Configuration of alertmanager-ntfy
|
| services.dependency-track.settings."alpine.oidc.teams.claim" | Defines the name of the claim that contains group memberships or role assignments in the provider's userinfo endpoint
|
| services.dependency-track.settings."alpine.data.directory" | Defines the path to the data directory
|
| services.grafana.provision.datasources.settings | Grafana datasource configuration in Nix
|
| services.veilid.settings.client_api.ipc_enabled | veilid-server will respond to Python and other JSON client requests.
|
| services.mackerel-agent.settings.host_status.on_start | Host status after agent startup.
|
| services.nitter.preferences.replaceYouTube | Replace YouTube links with links to this instance (blank to disable).
|
| services.nextcloud.settings.mail_smtpauth | This depends on mail_smtpmode
|
| services.warpgate.settings.sso_providers.*.label | SSO provider name displayed on login page.
|
| services.postfix.settings.main.mydestination | List of domain names intended for local delivery using /etc/passwd and /etc/aliases.
Do not include virtual domains in this list.
https://www.postfix.org/postconf.5.html#mydestination
|
| services.nvme-rs.settings.thresholds.wear_warning | Wear warning threshold (%)
|
| services.grafana.provision.alerting.policies.settings | Grafana notification policies configuration in Nix
|
| services.warpgate.settings.mysql.external_port | The MySQL listener is reachable via this port externally.
|
| services.matrix-appservice-irc.settings.ircService.mediaProxy.publicUrl | URL under which the media proxy is publicly acccessible.
|
| services.livekit.settings.rtc.port_range_end | End of UDP port range for WebRTC
|
| services.lasuite-docs.collaborationServer.settings | Configuration options of collaboration server
|
| services.dependency-track.settings."alpine.oidc.username.claim" | Defines the name of the claim that contains the username in the provider's userinfo endpoint
|
| services.tuned.settings.update_interval | Update interval for dynamic tuning (in seconds).
|
| services.lldap.settings.jwt_secret_file | Path to a file containing the JWT secret.
|
| services.nvme-rs.settings.thresholds.temp_warning | Temperature warning threshold (°C)
|
| services.grafana.settings.users.allow_sign_up | Set to false to prohibit users from being able to sign up / create user accounts
|
| services.waagent.settings.Provisioning.Enable | Whether to enable provisioning functionality in the agent
|
| services.tor.settings.V3AuthoritativeDirectory | See torrc manual.
|
| services.autosuspend.settings.suspend_cmd | The command to execute in case the host shall be suspended
|
| services.tor.relay.onionServices.<name>.settings.HiddenServiceExportCircuitID | See torrc manual.
|
| services.quickwit.settings.listen_address | Listen address of Quickwit.
|
| services.plausible.database.postgres.setup | Whether to enable creating a postgresql instance.
|
| services.prometheus.exporters.script.settings.scripts.*.name | Name of the script.
|
| services.headscale.settings.dns.extra_records | Extra DNS records to expose to clients.
|
| services.dependency-track.settings."alpine.oidc.teams.default" | Defines one or more team names that auto-provisioned OIDC users shall be added to
|
| services.grafana.provision.alerting.rules.settings.deleteRules.*.uid | Unique identifier for the rule
|
| services.dependency-track.settings."alpine.database.username" | Specifies the username to use when authenticating to the database.
|
| services.listmonk.database.settings."privacy.exportable" | List of fields which can be exported through an automatic export request
|
| services.suricata.settings.exception-policy | Define a common behavior for all exception policies
|
| services.openssh.settings.AuthorizedPrincipalsFile | Specifies a file that lists principal names that are accepted for certificate authentication
|
| services.prometheus.exporters.script.settings | Free-form configuration for script_exporter, expressed as a Nix attrset and rendered to YAML.
Migration note:
The previous format using script = "sleep 5" is no longer supported
|
| services.anubis.defaultOptions.settings.OG_PASSTHROUGH | Whether to enable Open Graph tag passthrough
|
| services.grafana.provision.alerting.rules.settings.deleteRules.*.orgId | Organization ID, default = 1
|
| services.taler.exchange.settings.exchangedb-postgres.CONFIG | Database connection URI.
|
| services.taler.merchant.settings.merchantdb-postgres.CONFIG | Database connection URI.
|
| services.prowlarr.settings.update.automatically | Automatically download and install updates.
|
| services.whisparr.settings.update.automatically | Automatically download and install updates.
|
| services.tor.relay.onionServices.<name>.settings.HiddenServiceAllowUnknownPorts | See torrc manual.
|
| services.kanidm.provision.acceptInvalidCerts | Whether to allow invalid certificates when provisioning the target instance
|
| services.autosuspend.settings.wakeup_cmd | The command to execute for scheduling a wake up of the system
|
| services.headscale.settings.oidc.allowed_users | Users allowed to authenticate even if not in allowedDomains.
|
| services.nextcloud-spreed-signaling.settings.https.listen | IP and port to listen on for HTTPS requests, in the format of ip:port
|
| boot.kernelPackages | This option allows you to override the Linux kernel used by
NixOS
|
| services.grafana.provision.dashboards.settings.apiVersion | Config file version.
|
| services.nextcloud-spreed-signaling.settings.backend.timeout | Timeout in seconds for requests to the backend
|
| services.kerberos_server.settings.module | Modules to obtain Kerberos configuration from.
|
| services.kerberos_server.settings.realms | The realm(s) to serve keys for.
|
| services.factorio.mods-dat | Mods settings can be changed by specifying a dat file, in the mod
settings file
format.
|
| services.opensearch.settings."plugins.security.disabled" | Whether to enable the security plugin,
plugins.security.ssl.transport.keystore_filepath or
plugins.security.ssl.transport.server.pemcert_filepath and
plugins.security.ssl.transport.client.pemcert_filepath
must be set for this plugin to be enabled.
|
| services.tor.relay.onionServices.<name>.settings.HiddenServiceDirGroupReadable | See torrc manual.
|
| services.hddfancontrol.settings.<drive-bay-name>.pwmPaths | PWM filepath(s) to control fan speed (under /sys), followed by initial and fan-stop PWM values
Can also use command substitution to ensure the correct hwmonX is selected on every boot
|
| services.journald.upload.settings.Upload.NetworkTimeoutSec | When network connectivity to the server is lost, this option
configures the time to wait for the connectivity to get restored
|
| services.sabnzbd.settings.misc.bandwidth_perc | Percentage of bandwidth_max that sabnzbd is allowed to use.
0 means no limit.
|
| services.minidlna.settings.root_container | Use a different container as the root of the directory tree presented to clients.
|
| services.grafana.provision.alerting.contactPoints.settings | Grafana contact points configuration in Nix
|
| services.dependency-track.settings."alpine.database.mode" | Defines the database mode of operation
|
| documentation.man.mandoc.settings | Configuration for man.conf(5)
|
| services.simplesamlphp.<name>.phpfpmPool | The PHP-FPM pool that serves SimpleSAMLphp instance.
|
| services.chhoto-url.settings.redirect_method | The redirect method to use.
|
| services.headscale.settings.dns.extra_records.*.type | DNS record type.
|
| services.headscale.settings.dns.extra_records.*.name | DNS record name.
|
| services.nextcloud-spreed-signaling.settings.etcd.endpoints | List of static etcd endpoints to connect to.
|
| services.lasuite-docs.collaborationServer.settings.PORT | Port used by collaboration server to listen to
|
| services.sabnzbd.settings.ntfosd.ntfosd_enable | Whether to enable NotifyOSD alerts
|
| services.sourcehut.settings."lists.sr.ht::worker".reject-mimetypes | Comma-delimited list of Content-Types to reject
|
| services.grafana.provision.alerting.muteTimings.settings.muteTimes | List of mute time intervals to import or update.
|
| services.grafana.provision.alerting.rules.settings.groups.*.folder | Name of the folder the rule group will be stored in
|
| services.libeufin.nexus.settings.libeufin-nexusdb-postgres.CONFIG | The database connection string for the libeufin-nexus database.
|
| services.suricata.settings.classification-file | Suricata classification configuration file.
|
| services.grafana.provision.alerting.templates.settings | Grafana templates configuration in Nix
|
| services.suricata.settings.dpdk.interfaces.*.interface | See upstream docs: docs/capture-hardware/dpdk and docs/configuration/suricata-yaml.html#data-plane-development-kit-dpdk.
|
| services.prometheus.exporters.fritz.settings.log_level | Log level to use for the exporter.
|
| services.nipap.settings.auth.default_backend | Name of auth backend to use by default.
|
| services.nitter.preferences.replaceReddit | Replace Reddit links with links to this instance (blank to disable).
|
| services.postfix-tlspol.settings.server.socket-permissions | Permissions to the UNIX socket, if configured.
Due to hardening on the systemd unit the socket can never be created world readable/writable.
|
| virtualisation.cri-o.settings | Configuration for cri-o, see
https://github.com/cri-o/cri-o/blob/master/docs/crio.conf.5.md.
|
| services.archisteamfarm.settings | The ASF.json file, all the options are documented here
|
| services.grafana.provision.datasources.settings.prune | When true, provisioned datasources from this file will be deleted
automatically when removed from
services.grafana.provision.datasources.settings.datasources.
|
| services.wgautomesh.settings.lan_discovery | Enable discovery of peers on the same LAN using UDP broadcast.
|
| services.kmonad.keyboards.<name>.extraGroups | Extra permission groups to attach to the KMonad instance for
this keyboard
|
| services.matrix-appservice-irc.settings.homeserver.domain | The 'domain' part for user IDs on this home server
|
| services.headscale.settings.prefixes.allocation | Strategy used for allocation of IPs to nodes, available options:
- sequential (default): assigns the next free IP from the previous given IP.
- random: assigns the next free IP from a pseudo-random IP generator (crypto/rand).
|
| services.bonsaid.settings.*.delay_duration | Nanoseconds to wait after the previous state change before performing this transition
|
| services.public-inbox.settings.publicinbox.wwwlisting | Controls which lists (if any) are listed for when the root
public-inbox URL is accessed over HTTP.
|
| services.transmission.settings.script-torrent-done-enabled | Whether to run
services.transmission.settings.script-torrent-done-filename
at torrent completion.
|
| services.crowdsec.settings.console.configuration | Attributes inside the console.yaml file.
|
| services.matrix-synapse.settings.enable_metrics | Enable collection and rendering of performance metrics
|
| services.warpgate.settings.http.cookie_max_age | How long until logged in cookie expires.
|
| services.lifecycled.cloudwatchStream | Write logs to a specific Cloudwatch Logs stream
|
| security.pam.u2f.settings.interactive | Set to prompt a message and wait before testing the presence of a U2F device
|
| services.akkoma.config.":pleroma"."Pleroma.Web.Endpoint".url.host | Domain name of the instance.
|
| services.prometheus.exporters.nginxlog.settings.consul | Consul integration options
|
| security.googleOsLogin.enable | Whether to enable Google OS Login
|
| services.prometheus.alertmanager-ntfy.settings.http.addr | The address to listen on.
|
| services.pgbouncer.settings.pgbouncer.listen_port | Which port to listen on
|
| services.transmission.settings.incomplete-dir | When enabled with
services.transmission.home
services.transmission.settings.incomplete-dir-enabled,
new torrents will download the files to this directory
|
| services.grafana.settings.database.max_open_conn | The maximum number of open connections to the database.
|
| services.tlsrpt.reportd.settings.sender_address | Sender address used for reports.
|
| services.matrix-synapse.settings.listeners.*.x_forwarded | Use the X-Forwarded-For (XFF) header as the client IP and not the
actual client IP.
|
| services.transmission.settings.incomplete-dir-enabled | |
| services.kerberos_server.settings.include | Files to include in the Kerberos configuration.
|
| services.hydra.useSubstitutes | Whether to use binary caches for downloading store paths
|
| services.matrix-continuwuity.settings.global.address | Addresses (IPv4 or IPv6) to listen on for connections by the reverse proxy/tls terminator
|
| services.maubot.settings.crypto_database | Separate database URL for the crypto database
|
| services.grafana.settings.security.cookie_secure | Set to true if you host Grafana behind HTTPS.
|
| services.grafana.settings.database.max_idle_conn | The maximum number of connections in the idle connection pool.
|
| services.slskd.settings.retention.transfers.download.errored | Lifespan of errored download tasks.
|
| services.system76-scheduler.settings.cfsProfiles.default.latency | sched_latency_ns.
|
| services.mpd.settings.music_directory | The directory or URI where MPD reads music from
|
| services.umurmur.settings.default_channel | The channel in which users will appear in when connecting.
|
| services.mchprs.settings.block_in_hitbox | Allow placing blocks inside of players
(hitbox logic is simplified)
|
| services.headscale.settings.dns.extra_records.*.value | DNS record value (IP address).
|
| services.matrix-appservice-irc.settings.ircService.mediaProxy.signingKeyPath | Path to the signing key file for authenticated media.
|
| services.matrix-synapse.settings.public_baseurl | The public-facing base URL for the client API (not including _matrix/...)
|
| services.system76-scheduler.settings.cfsProfiles.default.preempt | Preemption mode.
|
| services.transmission.settings.script-torrent-done-filename | Executable to be run at torrent completion.
|
| services.parsedmarc.settings.elasticsearch.ssl | Whether to use an encrypted SSL/TLS connection.
|
| services.system76-scheduler.settings.cfsProfiles.default.nr-latency | sched_nr_latency.
|
| services.n8n.environment.GENERIC_TIMEZONE | The n8n instance timezone
|
| services.grafana.provision.alerting.muteTimings.settings.apiVersion | Config file version.
|
| services.prometheus.exporters.script.settings.scripts.*.script | Shell script to execute when metrics are requested.
|
| services.kerberos_server.settings.realms.<name>.acl | The privileges granted to a user.
|
| programs.openvpn3.log-service.settings.journald | Use systemd-journald
|
| services.hddfancontrol.settings.<drive-bay-name>.logVerbosity | Verbosity of the log level
|
| services.nvme-rs.settings.thresholds.wear_critical | Wear critical threshold (%)
|
| services.tor.settings.UseMicrodescriptors | See torrc manual.
|
| services.matrix-appservice-irc.settings.ircService.mediaProxy.ttlSeconds | Lifetime in seconds, that generated URLs stay valid
|
| services.slskd.settings.retention.transfers.upload.cancelled | Lifespan of cancelled upload tasks.
|
| services.slskd.settings.retention.transfers.upload.succeeded | Lifespan of succeeded upload tasks.
|
| services.system76-scheduler.settings.processScheduler.enable | Tweak scheduling of individual processes in real time.
|
| services.nextcloud-spreed-signaling.settings.backend.allowall | Allow any hostname as backend endpoint
|
| services.transmission.settings.trash-original-torrent-files | Whether to delete torrents added from the
services.transmission.settings.watch-dir.
|
| services.pgbouncer.settings.pgbouncer.pool_mode | Specifies when a server connection can be reused by other clients.
session
Server is released back to pool after client disconnects
|
| services.parsedmarc.settings.elasticsearch.user | Username to use when connecting to Elasticsearch, if
required.
|
| services.simplesamlphp.<name>.localDomain | The domain serving your SimpleSAMLphp instance
|
| services.nvme-rs.settings.thresholds.temp_critical | Temperature critical threshold (°C)
|
| services.nvme-rs.settings.thresholds.spare_warning | Available spare warning threshold (%)
|
| services.victorialogs.basicAuthUsername | Basic Auth username used to protect VictoriaLogs instance by authorization
|
| services.grafana.provision.alerting.muteTimings.settings.muteTimes.*.name | Name of the mute time interval, must be unique
|
| services.grafana.provision.alerting.policies.settings.apiVersion | Config file version.
|
| services.geoipupdate.settings.DatabaseDirectory | The directory to store the database files in
|
| services.grafana.provision.datasources.settings.apiVersion | Config file version.
|
| services.warpgate.settings.sso_providers.*.provider | SSO provider configurations.
|
| services.grafana.settings.database.query_retries | This setting applies to sqlite3 only and controls the number of times the system retries a query when the database is locked.
|
| services.homebridge.settings.accessories.*.accessory | Accessory type
|
| services.nextcloud.settings.mail_smtphost | This depends on mail_smtpmode
|
| services.nitter.preferences.replaceTwitter | Replace Twitter links with links to this instance (blank to disable).
|
| services.angrr.settings.temporary-root-policies.<name>.filter.arguments | Extra command-line arguments pass to the external filter program.
|
| services.syncthing.settings.folders.<name>.copyOwnershipFromParent | On Unix systems, tries to copy file/folder ownership from the parent directory (the directory it’s located in)
|
| services.headscale.settings.dns.search_domains | Search domains to inject to Tailscale clients.
|
| virtualisation.podman.defaultNetwork.settings | Settings for podman's default network.
|
| nix.settings.trusted-substituters | List of binary cache URLs that non-root users can use (in
addition to those specified using
nix.settings.substituters) by passing
--option binary-caches to Nix commands.
|
| services.grafana.settings.server.enforce_domain | Redirect to correct domain if the host header does not match the domain
|
| services.stash.settings.preview_segments | Number of segments in a preview file
|
| services.stash.settings.sound_on_preview | Enable sound on mouseover previews
|
| services.tor.relay.onionServices.<name>.settings.HiddenServiceMaxStreamsCloseCircuit | See torrc manual.
|
| services.libretranslate.domain | The domain serving your LibreTranslate instance
|
| services.nextcloud.settings.mail_smtpdebug | Enable SMTP class debugging.
loglevel will likely need to be adjusted too.
See docs.
|
| services.prometheus.exporters.script.settings.scripts.*.timeout | Optional timeout for the script in seconds.
|
| services.parsedmarc.settings.elasticsearch.hosts | A list of Elasticsearch hosts to push parsed reports
to.
|
| services.warpgate.settings.postgres.external_port | The PostgreSQL listener is reachable via this port externally.
|
| services.grafana.provision.alerting.rules.settings.groups.*.interval | Interval that the rule group should be evaluated at
|
| services.grafana.provision.dashboards.settings.providers | List of dashboards to insert/update.
|
| services.mollysocket.settings.allowed_uuids | UUIDs of Signal accounts that may use this server
|
| services.kanidm.server.settings.online_backup.schedule | The schedule for backups in cron format.
|
| services.listmonk.database.settings."app.notify_emails" | Administrator emails for system notifications
|
| networking.networkmanager.settings | Configuration added to the generated NetworkManager.conf, note that you can overwrite settings with this
|
| services.keycloak.settings.hostname-backchannel-dynamic | Enables dynamic resolving of backchannel URLs,
including hostname, scheme, port and context path
|
| services.mediagoblin.settings.mediagoblin.plugins | Plugins to enable
|
| services.grafana.provision.alerting.muteTimings.settings.deleteMuteTimes | List of mute time intervals that should be deleted.
|
| services.grafana.settings.server.router_logging | Set to true for Grafana to log all HTTP requests (not just errors)
|
| services.matrix-synapse.package | Reference to the matrix-synapse wrapper with all extras
(e.g. for oidc or saml2) added to the PYTHONPATH of all executables
|
| services.syncthing.settings.options.maxFolderConcurrency | This option controls how many folders may concurrently be in I/O-intensive operations such as syncing or scanning
|
| services.dovecot2.pluginSettings | Plugin settings for dovecot in general, e.g. sieve, sieve_default, etc
|
| services.mpdscribble.passwordFile | File containing the password for the mpd daemon
|
| services.misskey.meilisearch.createLocally | Create and use a local Meilisearch instance
|
| services.prometheus.exporters.fritz.settings.devices.*.username | Username to authenticate with the target device.
|
| services.prometheus.exporters.fritz.settings.devices.*.hostname | Hostname under which the target device is reachable.
|
| services.grafana.provision.alerting.contactPoints.settings.apiVersion | Config file version.
|
| security.pam.u2f.settings.authfile | By default pam-u2f module reads the keys from
$XDG_CONFIG_HOME/Yubico/u2f_keys (or
$HOME/.config/Yubico/u2f_keys if XDG variable is
not set)
|
| services.simplesamlphp.<name>.settings.baseurlpath | URL where SimpleSAMLphp can be reached.
|
| services.omnom.settings.app.results_per_page | Number of results per page.
|
| services.grafana.provision.alerting.policies.settings.policies | List of contact points to import or update.
|
| services.warpgate.settings.config_provider | Source of truth of users
|
| services.matrix-conduit.settings.global.database_path | Path to the conduit database, the directory where conduit will save its data
|
| services.openldap.configDir | Use this config directory instead of generating one from the
settings option
|
| services.journald.upload.settings.Upload.ServerCertificateFile | SSL CA certificate in PEM format
|
| services.glitchtip.settings.ENABLE_USER_REGISTRATION | When true, any user will be able to register
|
| services.borgmatic.settings.repositories | A required list of local or remote repositories with paths and
optional labels (which can be used with the --repository flag to
select a repository)
|
| services.firefox-syncserver.settings.tokenserver.enabled | Whether to enable the token service as well.
|
| services.veilid.settings.client_api.ipc_directory | IPC directory where file sockets are stored.
|
| services.synapse-auto-compressor.settings.chunk_size | The number of state groups to work on at once
|
| services.openssh.settings.PasswordAuthentication | Specifies whether password authentication is allowed.
|
| services.firewalld.settings.IPv6_rpfilter | Performs reverse path filtering (RPF) on IPv6 packets as per RFC 3704
|
| services.chhoto-url.settings.disable_frontend | Whether to disable the frontend.
|
| programs.openvpn3.log-service.settings.log_level | How verbose should the logging be
|
| services.grafana.provision.alerting.templates.settings.apiVersion | Config file version.
|
| services.victorialogs.basicAuthPasswordFile | File that contains the Basic Auth password used to protect VictoriaLogs instance by authorization
|
| services.prometheus.exporters.pihole.timeout | Controls the timeout to connect to a Pi-Hole instance
|
| services.wordpress.sites.<name>.extraConfig | Any additional text to be appended to the wp-config.php
configuration file
|
| services.grafana.provision.alerting.muteTimings.settings.deleteMuteTimes.*.orgId | Organization ID, default = 1.
|
| services.veilid.settings.core.network.dht.min_peer_count | Minimum number of nodes to keep in the peer table.
|
| services.prometheus.alertmanagerIrcRelay.settings | Configuration for Alertmanager IRC Relay as a Nix attribute set
|
| services.matrix-synapse.settings.listeners.*.resources.*.compress | Whether synapse should compress HTTP responses to clients that support it
|
| services.kanidm.server.settings.online_backup.versions | Number of backups to keep
|
| services.hercules-ci-agent.settings.concurrentTasks | Number of tasks to perform simultaneously
|
| services.grafana.provision.dashboards.settings.providers.*.type | Dashboard provider type.
|
| services.grafana.provision.dashboards.settings.providers.*.name | A unique provider name.
|
| services.nezha-agent.settings.skip_procs_count | Do not monitor the number of processes.
|
| services.auto-epp.settings.Settings.epp_state_for_AC | energy_performance_preference when on plugged in
See available epp states by running:
cat /sys/devices/system/cpu/cpu0/cpufreq/energy_performance_available_preferences
|
| services.journald.upload.settings.Upload.TrustedCertificateFile | SSL CA certificate
|
| services.kea.dhcp-ddns.configFile | Kea DHCP-DDNS configuration as a path, see https://kea.readthedocs.io/en/kea-3.0.2/arm/ddns.html
|
| services.matrix-synapse.settings.max_upload_size | The largest allowed upload size in bytes
|
| services.warpgate.settings.http.session_max_age | How long until a logged in session expires.
|
| systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.mode | The file access mode to use when creating this file or directory.
|
| services.plausible.database.clickhouse.setup | Whether to enable creating a clickhouse instance.
|
| services.kanidm.server.settings.ldapbindaddress | Address and port the LDAP server is bound to
|
| services.auto-epp.settings.Settings.epp_state_for_BAT | energy_performance_preference when on battery
See available epp states by running:
cat /sys/devices/system/cpu/cpu0/cpufreq/energy_performance_available_preferences
|
| services.chhoto-url.settings.try_longer_slugs | Whether to try a longer UID upon collision.
|
| programs.openvpn3.log-service.settings.timestamp | Add timestamp log file
|
| services.matrix-appservice-irc.settings.database.connectionString | The database connection string
|
| services.slskd.settings.retention.transfers.download.cancelled | Lifespan of cancelled download tasks.
|
| services.slskd.settings.retention.transfers.download.succeeded | Lifespan of succeeded download tasks.
|
| services.nextcloud-spreed-signaling.backends.<name>.urls | List of URLs of the Nextcloud instance
|
| services.taler.merchant.settings.merchant.LEGAL_PRESERVATION | How long to keep data in the database for tax audits after the transaction has completed.
|
| services.journald.remote.settings.Remote.ServerCertificateFile | A path to a SSL certificate file in PEM format
|
| services.pixelfed.secretFile | A secret file to be sourced for the .env settings
|
| services.pgbouncer.settings.pgbouncer.listen_addr | Specifies a list (comma-separated) of addresses where to listen for TCP connections
|
| services.grafana.provision.alerting.muteTimings.settings.deleteMuteTimes.*.name | Name of the mute time interval, must be unique
|
| services.veilid.settings.core.network.routing_table.node_id | Base64-encoded public key for the node, used as the node's ID.
|
| services.kerberos_server.settings.realms.<name>.acl.*.target | The principals that 'access' applies to.
|
| services.tlsrpt.reportd.settings.sendmail_script | Path to a sendmail-compatible executable for delivery reports.
|
| services.syncthing.settings.folders.<name>.ignorePatterns | Syncthing can be configured to ignore certain files in a folder using ignore patterns
|
| services.slskd.settings.flags.force_share_scan | Force a rescan of shares on every startup.
|
| services.mobilizon.settings.":mobilizon"."Mobilizon.Web.Endpoint".http.port | The port to run the server
|
| networking.wireless.interfaces | The interfaces wpa_supplicant will use
|
| services.sharkey.setupMeilisearch | Whether to automatically set up a local Meilisearch instance and configure Sharkey to use it
|
| services.mobilizon.settings.":mobilizon"."Mobilizon.Web.Endpoint".http.ip | The IP address to listen on
|
| services.parsedmarc.settings.general.save_forensic | Save forensic report data to Elasticsearch and/or Splunk.
|
| services.livekit.settings.rtc.use_external_ip | When set to true, attempts to discover the host's public IP via STUN
|
| services.grafana.provision.alerting.policies.settings.resetPolicies | List of orgIds that should be reset to the default policy.
|
| virtualisation.xen.store.settings | The OCaml-based Xen Store Daemon configuration
|
| services.nextcloud.settings.trusted_proxies | Trusted proxies, to provide if the nextcloud installation is being
proxied to secure against e.g. spoofing.
|
| services.nextcloud.settings.trusted_domains | Trusted domains, from which the nextcloud installation will be
accessible
|
| services.uwsgi.capabilities | Grant capabilities to the uWSGI instance
|
| services.system76-scheduler.settings.cfsProfiles.default.bandwidth-size | sched_cfs_bandwidth_slice_us.
|
| services.beesd.filesystems.<name>.spec | Description of how to identify the filesystem to be duplicated by this
instance of bees
|
| services.firezone.server.settingsSecret.TOKENS_SALT | A file containing a unique base64 encoded secret for the
TOKENS_SALT
|
| services.livekit.settings.rtc.port_range_start | Start of UDP port range for WebRTC
|
| services.kea.ctrl-agent.configFile | Kea Control Agent configuration as a path, see https://kea.readthedocs.io/en/kea-3.0.2/arm/agent.html
|
| services.nextcloud-spreed-signaling.settings.sessions.hashkeyFile | The path to the file containing the value for sessions.hashkey
|
| services.swapspace.settings.lower_freelimit | Lower free-space threshold: if the percentage of free space drops below this number, additional swapspace is allocated
|
| services.grafana.provision.alerting.contactPoints.settings.contactPoints | List of contact points to import or update.
|
| services.sabnzbd.settings.misc.inet_exposure | Restrictions for access from non-local IP addresses
|
| services.adguardhome.settings.schema_version | Schema version for the configuration
|
| services.nextcloud.settings.mail_smtpmode | Which mode to use for sending mail
|
| services.radicale.config | Radicale configuration, this will set the service
configuration file
|
| services.glitchtip.settings.ENABLE_ORGANIZATION_CREATION | When false, only superusers will be able to create new organizations after the first
|
| services.discourse.siteSettings | Discourse site settings
|
| services.prometheus.exporters.chrony.user | User name under which the chrony exporter shall be run
|
| services.tuned.settings.recommend_command | Whether to enable recommend functionality.
|
| services.quickwit.settings.grpc_listen_port | The port to listen on for gRPC traffic.
|
| services.ergochat.configFile | Path to configuration file
|
| services.prometheus.exporters.fritz.settings.devices.*.host_info | Enable extended host info for this device. Warning: This will heavily increase scrape time.
|
| services.swapspace.settings.upper_freelimit | Upper free-space threshold: if the percentage of free space exceeds this number, swapspace will attempt to free up swapspace
|
| services.biboumi.settings.policy_directory | A directory that should contain the policy files,
used to customize Botan’s behaviour
when negotiating the TLS connections with the IRC servers.
|
| services.matrix-continuwuity.settings.global.server_name | The server_name is the name of this server
|
| services.minidlna.settings.enable_subtitles | Enable subtitle support on unknown clients.
|
| virtualisation.xen.store.settings.pidFile | Path to the Xen Store Daemon PID file.
|
| services.nextcloud-spreed-signaling.settings.https.certificate | Path to the certificate used for the HTTPS listener
|
| services.mediagoblin.settings.mediagoblin.sql_engine | Database to use.
|
| services.system76-scheduler.settings.cfsProfiles.responsive.latency | sched_latency_ns.
|
| security.apparmor.enable | Whether to enable the AppArmor Mandatory Access Control system
|
| services.mobilizon.settings.":mobilizon"."Mobilizon.Storage.Repo".database | Name of the database
|
| services.system76-scheduler.settings.cfsProfiles.responsive.preempt | Preemption mode.
|
| services.firezone.server.settingsSecret.TOKENS_KEY_BASE | A file containing a unique base64 encoded secret for the
TOKENS_KEY_BASE
|
| services.firezone.server.settingsSecret.SECRET_KEY_BASE | A file containing a unique base64 encoded secret for the
SECRET_KEY_BASE
|
| services.grafana.provision.alerting.templates.settings.templates | List of templates to import or update.
|
| services.system76-scheduler.settings.cfsProfiles.responsive.nr-latency | sched_nr_latency.
|
| services.kerberos_server.settings.includedir | Directories containing files to include in the Kerberos configuration.
|
| services.maubot.settings.plugin_databases.sqlite | The directory where SQLite plugin databases should be stored.
|
| services.librenms.useDistributedPollers | Enables distributed pollers
for this LibreNMS instance
|
| systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.age | Delete a file when it reaches a certain age
|
| services.minidlna.settings.notify_interval | The interval between announces (in seconds)
|
| services.system76-scheduler.settings.processScheduler.useExecsnoop | Use execsnoop (otherwise poll the precess list periodically).
|
| services.prometheus.exporters.nginxlog.settings.namespaces | Namespaces to collect the metrics for
|
| services.mobilizon.settings.":mobilizon"."Mobilizon.Storage.Repo".username | User used to connect to the database
|
| services.journald.remote.settings.Remote.TrustedCertificateFile | A path to a SSL CA certificate file in PEM format, or all
|
| services.grafana.provision.alerting.contactPoints.settings.contactPoints.*.name | Name of the contact point
|
| services.prometheus.exporters.chrony.group | Group under which the chrony exporter shall be run
|
| services.nextcloud-spreed-signaling.settings.stats.allowed_ips | List of IP addresses that are allowed to access the debug, stats and metrics endpoints
|
| services.headscale.settings.oidc.allowed_domains | Allowed principal domains. if an authenticated user's domain
is not in this list authentication request will be rejected.
|
| services.nextcloud-spreed-signaling.settings.sessions.blockkeyFile | The path to the file containing the value for sessions.blockkey
|
| services.nextcloud.settings.mail_smtpsecure | This depends on mail_smtpmode
|
| services.filebeat.settings.output.elasticsearch.hosts | The list of Elasticsearch nodes to connect to
|
| services.postfix.settings.main.mynetworks_style | The method used for generating the default value for mynetworks, if that option is unset.
https://www.postfix.org/postconf.5.html#mynetworks_style
|
| services.matrix-conduit.settings.global.trusted_servers | Servers trusted with signing server keys.
|
| services.snapserver.settings.tcp.bind_to_address | Address to listen on for snapclient connections.
|
| services.grafana.settings.users.allow_org_create | Set to false to prohibit users from creating new organizations.
|
| services.warpgate.settings.http.sni_certificates | Certificates for additional domains.
|
| services.mbpfan.settings.general.polling_interval | The polling interval.
|
| systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.user | The user of the file
|
| services.public-inbox.settings.publicinboxmda.spamcheck | If set to spamc, public-inbox-watch(1) will filter spam
using SpamAssassin.
|
| services.hickory-dns.configFile | Path to an existing toml file to configure hickory-dns with
|
| services.matrix-synapse.settings.media_store_path | Directory where uploaded images and attachments are stored.
|
| services.matrix-synapse.settings.max_image_pixels | Maximum number of pixels that will be thumbnailed
|
| services.matrix-synapse.settings.signing_key_path | Path to the signing key to sign messages with.
|
| services.grafana.settings.database.client_key_path | The path to the client key
|
| users.mysql.nss | Settings for libnss-mysql
|
| services.grafana.settings.server.static_root_path | Root path for static assets.
|
| services.snapserver.settings.http.bind_to_address | Address to listen on for snapclient connections.
|
| services.grafana.settings.users.auto_assign_org | Set to true to automatically add new users to the main organization (id 1)
|
| services.tor.settings.VersioningAuthoritativeDirectory | See torrc manual.
|
| services.parsedmarc.settings.general.save_aggregate | Save aggregate report data to Elasticsearch and/or Splunk.
|
| services.jibri.xmppEnvironments.<name>.control.login.domain | The domain part of the JID for this Jibri instance.
|
| services.nvme-rs.settings.thresholds.error_threshold | Error count warning threshold
|
| services.swapspace.settings.cache_elasticity | Percentage of cache space considered to be "free"
|
| services.grafana.settings.security.admin_password | Default admin password
|
| services.grafana.provision.alerting.templates.settings.templates.*.name | Name of the template, must be unique
|
| services.grafana.provision.alerting.contactPoints.settings.deleteContactPoints | List of receivers that should be deleted.
|
| services.system76-scheduler.settings.processScheduler.refreshInterval | Process list poll interval, in seconds
|
| services.matrix-synapse.settings.listeners.*.bind_addresses | IP addresses to bind the listener to.
|
| services.warpgate.settings.http.sni_certificates.*.key | Path to private key.
|
| services.grafana.settings.users.default_language | This setting configures the default UI language, which must be a supported IETF language tag, such as en-US.
|
| services.veilid.settings.core.network.routing_table.bootstrap | Host name of existing well-known Veilid bootstrap servers for the network to connect to.
|
| boot.loader.generic-extlinux-compatible.enable | Whether to generate an extlinux-compatible configuration file
under /boot/extlinux.conf
|
| services.parsedmarc.settings.elasticsearch.password | The password to use when connecting to Elasticsearch,
if required
|
| services.grafana.settings.users.viewers_can_edit | Viewers can access and use Explore and perform temporary edits on panels in dashboards they have access to
|
| virtualisation.xen.store.settings.quota.maxSize | Size limit for transactions.
|
| systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.group | The group of the file
|
| services.parsedmarc.settings.elasticsearch.cert_path | The path to a TLS certificate bundle used to verify
the server's certificate.
|
| systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.type | The type of operation to perform on the file
|
| virtualisation.xen.store.settings.quota.maxPath | Path limit for the quota system.
|
| nix.checkAllErrors | If enabled, checks the nix.conf parsing for any kind of error
|
| services.grafana.settings.database.isolation_level | Only the MySQL driver supports isolation levels in Grafana
|
| services.postgresql.settings.log_line_prefix | A printf-style string that is output at the beginning of each log line
|
| services.system76-scheduler.settings.processScheduler.pipewireBoost.enable | Boost Pipewire client priorities.
|
| services.matrix-appservice-irc.settings.ircService.passwordEncryptionKeyPath | Location of the key with which IRC passwords are encrypted
for storage
|
| services.searx.limiterSettings | Limiter settings for SearXNG.
|
| services.kerberos_server.settings.realms.<name>.acl.*.principal | Which principal the rule applies to
|
| services.veilid.settings.core.protected_store.directory | The filesystem directory to store your protected store in.
|
| services.hickory-dns.settings.listen_addrs_ipv4 | List of ipv4 addresses on which to listen for DNS queries.
|
| services.hickory-dns.settings.listen_addrs_ipv6 | List of ipv6 addresses on which to listen for DNS queries.
|
| services.grafana.provision.datasources.settings.datasources | List of datasources to insert/update.
|
| services.grafana.provision.alerting.contactPoints.settings.deleteContactPoints.*.uid | Unique identifier for the receiver
|
| services.headscale.settings.derp.update_frequency | Frequency to update DERP maps.
|
| virtualisation.docker.daemon.settings | Configuration for docker daemon
|
| services.victoriatraces.basicAuthUsername | Basic Auth username used to protect VictoriaTraces instance by authorization
|
| services.tor.relay.onionServices.<name>.settings.HiddenServiceNumIntroductionPoints | See torrc manual.
|
| services.grafana.provision.dashboards.settings.providers.*.options.path | Path grafana will watch for dashboards
|
| services.grafana.provision.alerting.contactPoints.settings.deleteContactPoints.*.orgId | Organization ID, default = 1.
|
| services.snapserver.settings.stream.bind_to_address | Address to listen on for snapclient connections.
|
| services.kerberos_server.settings.realms.<name>.acl.*.access | The changes the principal is allowed to make.
The "all" permission does not imply the "get-keys" permission
|
| services.grafana.provision.alerting.templates.settings.deleteTemplates | List of alert rule UIDs that should be deleted.
|
| services.jibri.xmppEnvironments.<name>.control.muc.nickname | The nickname for this Jibri instance in the MUC.
|
| services.prometheus.exporters.ecoflow.prefix | The prefix that will be added to all metrics
|
| services.grafana.provision.datasources.settings.datasources.*.url | Url of the datasource.
|
| services.firezone.server.settingsSecret.RELEASE_COOKIE | A file containing a unique secret identifier for the Erlang
cluster
|
| documentation.man.mandoc.settings.output.style | Path to the file used for an external style-sheet
|
| services.maubot.configMutable | Whether maubot should write updated config into extraConfigFile. This will make your Nix module settings have no effect besides the initial config, as extraConfigFile takes precedence over NixOS settings!
|
| services.nextcloud.settings.mail_smtptimeout | This depends on mail_smtpmode
|
| virtualisation.xen.store.settings.quota.maxWatch | Maximum number of watches by the Xenstore Watchdog.
|
| security.agnos.settings.accounts.*.certificates | Certificates for agnos to issue or renew.
|
| virtualisation.xen.store.settings.enableMerge | Whether to enable transaction merge support.
|
| services.openssh.settings.KbdInteractiveAuthentication | Specifies whether keyboard-interactive authentication is allowed.
|
| services.headscale.settings.database.postgres.password_file | A file containing the password corresponding to
database.user.
|
| services.maubot.settings.plugin_databases.postgres | The connection URL for plugin database
|
| services.grafana.provision.datasources.settings.datasources.*.name | Name of the datasource
|
| services.grafana.provision.datasources.settings.datasources.*.type | Datasource type
|
| services.undervolt.useTimer | Whether to set a timer that applies the undervolt settings every 30s
|
| virtualisation.xen.store.settings.quota.enable | Whether to enable the quota system.
|
| services.grafana.provision.alerting.templates.settings.deleteTemplates.*.orgId | Organization ID, default = 1.
|
| services.matrix-conduit.settings.global.allow_federation | Whether this server federates with other servers.
|
| services.matrix-tuwunel.settings.global.allow_federation | Whether this server federates with other servers.
|
| services.biboumi.settings.realname_from_jid | Whether the realname and username of each biboumi
user will be extracted from their JID
|
| boot.initrd.systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.mode | The file access mode to use when creating this file or directory.
|
| services.parsedmarc.provision.grafana.dashboard | Whether the official parsedmarc grafana dashboard should
be provisioned to the local grafana instance.
|
| services.system76-scheduler.settings.cfsProfiles.responsive.bandwidth-size | sched_cfs_bandwidth_slice_us.
|
| services.firezone.server.settingsSecret.LIVE_VIEW_SIGNING_SALT | A file containing a unique base64 encoded secret for the
LIVE_VIEW_SIGNING_SALT
|
| services.headscale.settings.noise.private_key_path | Path to noise private key file, generated automatically if it does not exist.
|
| services.filesender.settings.log_facilities | Defines where FileSender logging is sent
|
| virtualisation.xen.store.settings.perms.enable | Whether to enable the node permission system.
|
| documentation.man.mandoc.settings.output.toc | Whether to enable printing a table of contents near the beginning of the HTML output
of mandoc(1) if an input file contains at least two
non-standard sections
.
|
| virtualisation.xen.store.settings.quota.maxEntity | Entity limit for transactions.
|
| services.maubot.settings.plugin_directories | Plugin directory paths
|
| services.nextcloud-spreed-signaling.settings.backend.backendtype | Type of backend configuration
|
| services.grafana.provision.alerting.templates.settings.deleteTemplates.*.name | Name of the template, must be unique
|
| services.grafana.settings.database.client_cert_path | The path to the client cert
|
| services.system76-scheduler.settings.processScheduler.pipewireBoost.profile.nice | Niceness.
|
| services.matrix-tuwunel.settings.global.trusted_servers | Servers listed here will be used to gather public keys of other servers
(notary trusted key servers)
|
| services.grafana.settings.security.disable_gravatar | Set to true to disable the use of Gravatar for user profile images.
|
| services.matrix-conduit.settings.global.max_request_size | Max request size in bytes
|
| services.matrix-tuwunel.settings.global.max_request_size | Max request size in bytes
|
| services.snapserver.settings.tcp-control.bind_to_address | Address to listen on for snapclient connections.
|
| services.victoriatraces.basicAuthPasswordFile | File that contains the Basic Auth password used to protect VictoriaTraces instance by authorization
|
| hardware.tuxedo-drivers.settings.charging-priority | These options manage the trade-off between battery charging and CPU performance when the USB-C power supply cannot provide sufficient power for both simultaneously:
charge_battery prioritizes battery charging (driver default)
performance prioritizes maximum CPU performance
|
| services.system76-scheduler.settings.cfsProfiles.default.wakeup-granularity | sched_wakeup_granularity_ns.
|
| hardware.tuxedo-drivers.settings.charging-profile | The maximum charge level to help reduce battery wear:
high_capacity charges to 100% (driver default)
balanced charges to 90%
stationary charges to 80% (maximum lifespan)
Note: Regardless of the configured charging profile, the operating system will always report the battery as being charged to 100%.
|
| services.grafana.settings.security.allow_embedding | When false, the HTTP header X-Frame-Options: deny will be set in Grafana HTTP responses
which will instruct browsers to not allow rendering Grafana in a <frame>, <iframe>, <embed> or <object>
|
| services.firezone.server.settingsSecret.COOKIE_SIGNING_SALT | A file containing a unique base64 encoded secret for the
COOKIE_SIGNING_SALT
|
| services.system76-scheduler.settings.processScheduler.pipewireBoost.profile.prio | CPU scheduler priority.
|
| services.tlsrpt.reportd.settings.organization_name | Name of the organization sending out the reports.
|
| services.omnom.settings.smtp.connection_timeout | Connection timeout duration in seconds.
|
| services.grafana.provision.datasources.settings.datasources.*.uid | Custom UID which can be used to reference this datasource in other parts of the configuration, if not specified will be generated automatically.
|
| services.grafana.provision.datasources.settings.datasources.*.jsonData | Extra data for datasource plugins.
|
| services.nipap.settings.auth.auth_cache_timeout | Seconds to store cached auth entries for.
|
| services.system76-scheduler.settings.processScheduler.pipewireBoost.profile.ioPrio | IO scheduler priority.
|
| services.sftpgo.settings.httpd.bindings.*.enable_web_admin | Enable the built-in web admin for this interface binding.
|
| services.nvme-rs.settings.email.smtp_password_file | File containing SMTP password
|
| services.swapspace.settings.buffer_elasticity | Percentage of buffer space considered to be "free"
|
| services.omnom.settings.smtp.tls_allow_insecure | Whether to enable Whether to allow insecure TLS..
|
| services.grafana.provision.datasources.settings.deleteDatasources | List of datasources that should be deleted from the database.
|
| virtualisation.containerd.settings | Verbatim lines to add to containerd.toml
|
| services.matrix-tuwunel.settings.global.allow_encryption | Whether new encrypted rooms can be created
|
| services.matrix-conduit.settings.global.allow_encryption | Whether new encrypted rooms can be created
|
| services.livekit.ingress.settings.rtc_config.port_range_end | End of UDP port range for WebRTC
|
| services.grafana.settings.database.server_cert_name | The common name field of the certificate used by the mysql or postgres server
|
| services.system76-scheduler.settings.processScheduler.pipewireBoost.profile.class | CPU scheduler class.
|
| services.nezha-agent.settings.disable_send_query | Disable sending TCP/ICMP/HTTP requests.
|
| services.mpd.settings.playlist_directory | The directory where MPD stores playlists
|
| services.system76-scheduler.settings.processScheduler.pipewireBoost.profile.ioClass | IO scheduler class.
|
| services.grafana.provision.alerting.templates.settings.templates.*.template | Alerting with a custom text template
|
| services.searx.faviconsSettings | Favicons settings for SearXNG.
|
| services.matrix-continuwuity.settings.global.database_path | Path to the continuwuity database, the directory where continuwuity will save its data
|
| services.dependency-track.settings."alpine.oidc.user.provisioning" | Specifies if mapped OpenID Connect accounts are automatically created upon successful
authentication
|
| services.grafana.provision.datasources.settings.datasources.*.access | Access mode. proxy or direct (Server or Browser in the UI)
|
| services.grafana.provision.datasources.settings.deleteDatasources.*.orgId | Organization ID of the datasource to delete.
|
| services.grafana.provision.datasources.settings.deleteDatasources.*.name | Name of the datasource to delete.
|
| services.headscale.settings.derp.server.private_key_path | Path to derp private key file, generated automatically if it does not exist.
|
| services.nextcloud.settings.mail_from_address | FROM address that overrides the built-in sharing-noreply and lostpassword-noreply FROM addresses
|
| boot.initrd.systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.age | Delete a file when it reaches a certain age
|
| services.mediagoblin.settings.mediagoblin.email_debug_mode | Disable email debug mode to start sending outgoing mails
|
| systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.argument | An argument whose meaning depends on the type of operation
|
| services.maubot.settings.plugin_directories.load | The directories from which plugins should be loaded
|
| services.grafana.settings.security.cookie_samesite | Sets the SameSite cookie attribute and prevents the browser from sending this cookie along with cross-site requests
|
| services.victoriametrics.basicAuthUsername | Basic Auth username used to protect VictoriaMetrics instance by authorization
|
| services.nvme-rs.settings.check_interval_secs | Check interval in seconds
|
| services.public-inbox.settings.publicinboxwatch.watchspam | If set, mail in this maildir will be trained as spam and
deleted from all watched inboxes
|
| services.nextcloud.settings.skeletondirectory | The directory where the skeleton files are located
|
| boot.initrd.systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.user | The user of the file
|
| services.postfix.settings.main.message_size_limit | Maximum size of an email message in bytes.
https://www.postfix.org/postconf.5.html#message_size_limit
|
| services.headscale.settings.database.sqlite.write_ahead_log | Enable WAL mode for SQLite
|
| services.public-inbox.settings.publicinboxwatch.spamcheck | If set to spamc, public-inbox-watch(1) will filter spam
using SpamAssassin.
|
| services.maubot.settings.plugin_directories.upload | The directory where uploaded new plugins should be stored.
|
| services.snapserver.settings.tcp-streaming.bind_to_address | Address to listen on for snapclient connections.
|
| virtualisation.xen.store.settings.quota.maxWatchEvents | Maximum number of outstanding watch events per watch.
|
| services.matrix-tuwunel.settings.global.unix_socket_perms | The default permissions (in octal) to create the UNIX socket with.
|
| services.stash.settings.gallery_cover_regex | Regex used to identify images as gallery covers
|
| services.stash.settings.preview_exclude_end | Duration of start of video to exclude when generating previews
|
| services.maubot.settings.plugin_directories.trash | The directory where old plugin versions and conflicting plugins should be moved
|
| services.etebase-server.settings.allowed_hosts.allowed_host1 | The main host that is allowed access.
|
| services.parsedmarc.provision.grafana.datasource | Whether the automatically provisioned Elasticsearch
instance should be added as a grafana datasource
|
| services.nextcloud.settings.mail_sendmailmode | For smtp, the sendmail binary is started with the parameter -bs: Use the SMTP protocol on standard input and output
|
| services.matrix-tuwunel.settings.global.unix_socket_path | Listen on a UNIX socket at the specified path
|
| boot.initrd.systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.group | The group of the file
|
| boot.initrd.systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.type | The type of operation to perform on the file
|
| services.grafana.provision.datasources.settings.datasources.*.editable | Allow users to edit datasources from the UI.
|
| services.grafana.settings.security.x_xss_protection | Set to true to enable the X-XSS-Protection header,
which tells browsers to stop pages from loading when they detect reflected cross-site scripting (XSS) attacks.
Note: this is the default in Grafana, it's turned off here
since it's recommended to not use this header anymore.
|
| virtualisation.xen.store.settings.quota.maxRequests | Maximum number of requests per transaction.
|
| services.warpgate.settings.ssh.inactivity_timeout | How long can user be inactive until Warpgate terminates the connection.
|
| services.snipe-it.nginx | With this option, you can customize the nginx virtualHost settings.
|
| services.sftpgo.settings.httpd.bindings.*.enable_web_client | Enable the built-in web client for this interface binding.
|
| services.victoriametrics.basicAuthPasswordFile | File that contains the Basic Auth password used to protect VictoriaMetrics instance by authorization
|
| services.mollysocket.settings.allowed_endpoints | List of UnifiedPush servers
|
| services.mobilizon.settings.":mobilizon"."Mobilizon.Storage.Repo".socket_dir | Path to the postgres socket directory
|
| services.system76-scheduler.settings.processScheduler.pipewireBoost.profile.matchers | Process matchers.
|
| services.prometheus.exporters.fritz.settings.devices.*.password_file | Path to a file which contains the password to authenticate with the target device
|
| services.warpgate.settings.ssh.keepalive_interval | If nothing is received from the client for this amount of time, server will send a keepalive message.
|
| services.jitsi-videobridge.nat.harvesterAddresses | Addresses of public STUN services to use to automatically find
the public and local addresses of this Jitsi-Videobridge instance
without the need for manual configuration
|
| documentation.man.mandoc.settings.output.width | The ASCII and UTF-8 output width, default is 78
|
| services.nextcloud.settings.overwriteprotocol | Force Nextcloud to always use HTTP or HTTPS i.e. for link generation
|
| services.stash.settings.sequential_scanning | Modifies behaviour of the scanning functionality to generate support files (previews/sprites/phash) at the same time as fingerprinting/screenshotting
|
| security.agnos.settings.accounts.*.certificates.*.domains | Domains the certificate represents
|
| services.prometheus.exporters.deluge.exportPerTorrentMetrics | Enable per-torrent metrics
|
| services.dnscrypt-proxy2.configFile | Path to TOML config file
|
| services.prometheus.alertmanager-ntfy.settings.ntfy.notification.tags | Tags to add to ntfy.sh messages
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.enable | Boost foreground process priorities.
(And de-boost background ones)
|
| services.parsedmarc.provision.elasticsearch | Whether to set up and use a local instance of Elasticsearch.
|
| services.cgit.<name>.repos | cgit repository settings, see cgitrc(5)
|
| services.matrix-synapse.settings.turn_shared_secret | The shared secret used to compute passwords for the TURN server
|
| services.listmonk.database.settings."privacy.domain_blocklist" | E-mail addresses with these domains are disallowed from subscribing.
|
| services.system76-scheduler.settings.cfsProfiles.responsive.wakeup-granularity | sched_wakeup_granularity_ns.
|
| virtualisation.xen.store.settings.persistent | Whether to activate the filed base backend.
|
| virtualisation.xen.store.settings.ringScanInterval | Perodic scanning for all the rings as a safenet for lazy clients
|
| documentation.man.mandoc.settings.manpath | Override the default search path for man(1),
apropos(1), and makewhatis(8)
|
| services.dendrite.settings.mscs.database.connection_string | Database for exerimental MSC's.
|
| services.grafana.settings.database.conn_max_lifetime | Sets the maximum amount of time a connection may be reused
|
| services.borgmatic.settings.source_directories | List of source directories and files to backup
|
| services.prometheus.alertmanager-ntfy.settings.ntfy.notification.tags.*.tag | The tag to add
|
| services.grafana.settings.users.auto_assign_org_id | Set this value to automatically add new users to the provided org
|
| virtualisation.docker.daemon.settings.live-restore | Allow dockerd to be restarted without affecting running container
|
| virtualisation.xen.store.settings.xenstored.log.file | Path to the Xen Store log file.
|
| services.zitadel.extraSettingsPaths | A list of paths to extra settings files
|
| services.doh-server.settings.ecs_use_precise_ip | If ECS is added to the request, let the full IP address or cap it to 24 or 128 mask
|
| documentation.man.mandoc.settings.output.man | A template for linked manuals (usually via the Xr macro) in HTML
output
|
| virtualisation.containers.storage.settings | storage.conf configuration
|
| virtualisation.docker.rootless.daemon.settings | Configuration for docker daemon
|
| services.redsocks.redsocks.*.redirectCondition | Conditions to make outbound packets go through this redsocks
instance
|
| services.headscale.settings.oidc.strip_email_domain | Whether the domain part of the email address should be removed when generating namespaces.
|
| console.useXkbConfig | If set, configure the virtual console keymap from the xserver
keyboard settings.
|
| services.crab-hole.settings.blocklist.include_subdomains | Whether to enable Include subdomains.
|
| virtualisation.xen.store.settings.xenstored.log.level | Logging level for the Xen Store.
|
| services.livekit.ingress.settings.rtc_config.use_external_ip | When set to true, attempts to discover the host's public IP via STUN
|
| services.headscale.settings.oidc.client_secret_path | Path to OpenID Connect client secret file
|
| services.xray.enable | Whether to run xray server
|
| security.agnos.settings.dns_listen_addr | Address for agnos to listen on
|
| documentation.man.mandoc.settings.output.includes | A string of relative path used as a template for the output path of
linked header files (usually via the In macro) in HTML output
|
| services.buffyboard.configFile | Path to an INI format configuration file to provide Buffyboard
|
| services.firezone.server.settingsSecret.COOKIE_ENCRYPTION_SALT | A file containing a unique base64 encoded secret for the
COOKIE_ENCRYPTION_SALT
|
| services.matrix-conduit.settings.global.allow_registration | Whether new users can register on this server.
|
| services.monica.nginx | With this option, you can customize the nginx virtualHost settings.
|
| services.nextcloud-spreed-signaling.settings.clients.internalsecretFile | The path to the file containing the value for clients.internalsecret
|
| services.livekit.ingress.settings.rtc_config.port_range_start | Start of UDP port range for WebRTC
|
| services.grafana.provision.datasources.settings.datasources.*.secureJsonData | Datasource specific secure configuration
|
| services.lldap.settings.ldap_user_pass_file | Path to a file containing the default admin password
|
| services.warpgate.settings.http.sni_certificates.*.certificate | Path to certificate.
|
| services.libeufin.bank.settings.libeufin-bank.SUGGESTED_WITHDRAWAL_EXCHANGE | Exchange that is suggested to wallets when withdrawing
|
| services.matrix-synapse.settings.enable_registration | Enable registration for new users.
|
| networking.usePredictableInterfaceNames | Whether to assign predictable names to network interfaces
|
| virtualisation.docker.rootless.setSocketVariable | Point DOCKER_HOST to rootless Docker instance for
normal users by default.
|
| services.matrix-synapse.settings.dynamic_thumbnails | Whether to generate new thumbnails on the fly to precisely match
the resolution requested by the client
|
| services.matrix-synapse.settings.trusted_key_servers | The trusted servers to download signing keys from.
|
| services.acme-dns.settings.api.disable_registration | Whether to disable the HTTP registration endpoint.
|
| documentation.man.mandoc.settings.output.indent | Number of blank characters at the left margin for normal text,
default of 5 for mdoc(7) and 7 for
man(7)
|
| services.postfix.settings.main.recipient_delimiter | Set of characters used as the delimiters for address extensions
|
| services.grafana.settings.analytics.reporting_enabled | When enabled Grafana will send anonymous usage statistics to stats.grafana.org
|
| services.minio.configDir | The config directory, for the access keys and other settings.
|
| boot.initrd.systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.argument | An argument whose meaning depends on the type of operation
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.background.nice | Niceness.
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.foreground.nice | Niceness.
|
| documentation.man.mandoc.settings.output.fragment | Whether to omit the declaration and the , , and
elements and only emit the subtree below the element in HTML
output of mandoc(1)
|
| services.chhoto-url.settings.cache_control_header | The Cache-Control header to send.
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.background.prio | CPU scheduler priority.
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.foreground.prio | CPU scheduler priority.
|
| services.matrix-continuwuity.settings.global.allow_federation | Whether this server federates with other servers.
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.background.ioPrio | IO scheduler priority.
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.foreground.ioPrio | IO scheduler priority.
|
| services.pgbouncer.settings.pgbouncer.default_pool_size | How many server connections to allow per user/database pair
|
| services.matrix-synapse.settings.url_preview_enabled | Is the preview URL API enabled? If enabled, you must specify an
explicit url_preview_ip_range_blacklist of IPs that the spider is
denied from accessing.
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.background.class | CPU scheduler class.
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.foreground.class | CPU scheduler class.
|
| services.matrix-continuwuity.settings.global.trusted_servers | Servers listed here will be used to gather public keys of other servers
(notary trusted key servers)
|
| services.matrix-continuwuity.settings.global.max_request_size | Max request size in bytes
|
| services.maubot.settings.plugin_databases.postgres_opts | Overrides for the default database_opts when using a non-default postgres connection URL.
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.foreground.ioClass | IO scheduler class.
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.background.ioClass | IO scheduler class.
|
| services.cross-seed.useGenConfigDefaults | Whether to use the option defaults from the configuration generated by
cross-seed gen-config
|
| virtualisation.xen.store.settings.xenstored.accessLog.file | Path to the Xen Store access log file.
|
| services.dendrite.settings.sync_api.database.connection_string | Database for the Sync API.
|
| documentation.man.mandoc.settings.output.paper | This option is for generating PostScript and PDF output
|
| services.headscale.settings.derp.auto_update_enabled | Whether to automatically update DERP maps on a set frequency.
|
| services.grafana.settings.analytics.check_for_updates | When set to false, disables checking for new versions of Grafana from Grafana's GitHub repository
|
| services.prometheus.alertmanager-ntfy.settings.ntfy.notification.topic | Note: when using ntfy.sh and other public instances
it is recommended to set this option to an empty string and set the actual topic via
services.prometheus.alertmanager-ntfy.extraConfigFiles since
the topic in ntfy.sh is essentially a password
|
| services.lasuite-docs.collaborationServer.settings.COLLABORATION_SERVER_ORIGIN | Origins allowed to connect to the collaboration server
|
| services.matrix-tuwunel.settings.global.allow_registration | Whether new users can register on this server
|
| services.prometheus.alertmanager-ntfy.settings.ntfy.notification.priority | The ntfy.sh message priority (see https://docs.ntfy.sh/publish/#message-priority for more information)
|
| services.matrix-continuwuity.settings.global.allow_encryption | Whether new encrypted rooms can be created
|
| services.lasuite-docs.collaborationServer.settings.COLLABORATION_BACKEND_BASE_URL | URL to the backend server base
|
| services.movim.secretFile | The secret file to be sourced for the .env settings.
|
| services.prometheus.exporters.ecoflow.ecoflowDevicesFile | File must contain one line, example: R3300000,R3400000,NC430000,...
|
| services.matrix-synapse.settings.macaroon_secret_key | Secret key for authentication tokens
|
| virtualisation.xen.store.settings.quota.transaction | Maximum number of transactions.
|
| services.peertube.settings.video_transcription.enabled | Enable automatic transcription of videos.
|
| virtualisation.tpm.provisioning | Script to provision the TPM before control is handed off to the VM.
TPM2TOOLS_TCTI will be provided to configure tpm2-tools to use the
swtpm instance transparently.
TCTI is also provided as a generic value, consumer is expected to
re-export it however it may need (TPM2OPENSSL_TCTI, TPM2_PKCS11_TCTI,
...).
|
| security.auditd.settings.space_left | If the free space in the filesystem containing log_file drops below this value, the audit daemon takes the action specified by
space_left_action
|
| services.nextcloud.settings.mail_template_class | Replaces the default mail template layout
|
| services.invidious.extraSettingsFile | A file including Invidious settings
|
| services.grafana.settings.plugins.preinstall_disabled | When set to true, disables the Background Plugin Installer, which runs before Grafana starts
|
| services.dendrite.settings.media_api.database.connection_string | Database for the Media API.
|
| services.dendrite.settings.relay_api.database.connection_string | Database for the Relay Server.
|
| services.stash.settings.notifications_enabled | If we should send notifications to the desktop
|
| services.grafana.settings.users.verify_email_enabled | Require email validation before sign up completes.
|
| services.dependency-track.settings."alpine.oidc.team.synchronization" | This option will ensure that team memberships for OpenID Connect users are dynamic and
synchronized with membership of OpenID Connect groups or assigned roles
|
| services.cgit.<name>.gitHttpBackend.enable | Whether to bypass cgit and use git-http-backend for HTTP clones
|
| services.grafana.settings.database.transaction_retries | This setting applies to sqlite3 only and controls the number of times the system retries a transaction when the database is locked.
|
| services.prometheus.alertmanager-ntfy.settings.ntfy.notification.tags.*.condition | The condition under which this tag should be added
|
| services.pipewire.wireplumber.extraConfig | Additional configuration for the WirePlumber daemon when run in
single-instance mode (the default in nixpkgs and currently the only
supported way to run WirePlumber configured via extraConfig)
|
| services.stash.settings.preview_exclude_start | Duration of end of video to exclude when generating previews
|
| services.prometheus.alertmanager-ntfy.settings.ntfy.notification.templates.title | The ntfy.sh message title template.
|
| services.jellyfin.forceEncodingConfig | Whether to overwrite Jellyfin's encoding.xml configuration file on each service start
|
| services.prometheus.scrapeConfigs.*.ec2_sd_configs.*.region | The AWS Region
|
| services.pgbouncer.settings.pgbouncer.max_client_conn | Maximum number of client connections allowed
|
| virtualisation.xen.store.settings.perms.enableWatch | Whether to enable the watch permission system
|
| programs.rush.global | The global statement defines global settings.
|
| services.synapse-auto-compressor.settings.chunks_to_compress | chunks_to_compress chunks of size chunk_size will be compressed
|
| virtualisation.xen.store.settings.quota.maxOutstanding | Maximum outstanding requests, i.e. in-flight requests / domain.
|
| services.grafana.settings.server.serve_from_sub_path | Serve Grafana from subpath specified in the root_url setting
|
| services.grafana.settings.users.auto_assign_org_role | The role new users will be assigned for the main organization (if the auto_assign_org setting is set to true).
|
| services.matrix-continuwuity.settings.global.unix_socket_perms | The default permissions (in octal) to create the UNIX socket with.
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.background.matchers | Process matchers.
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.foreground.matchers | Process matchers.
|
| services.nezha-agent.settings.skip_connection_count | Do not monitor the number of connections.
|
| services.matrix-synapse.settings.tls_private_key_path | PEM encoded private key for TLS
|
| services.chhoto-url.settings.allow_capital_letters | Whether to allow capital letters in slugs.
|
| services.nezha-agent.settings.use_ipv6_country_code | Use ipv6 countrycode to report location.
|
| services.szurubooru.server.settings.delete_source_files | Whether to delete thumbnails and source files on post delete.
|
| services.quorum.genesis | Blockchain genesis settings.
|
| services.litellm.settings.environment_variables | Environment variables to pass to the Lite
|
| services.dendrite.settings.key_server.database.connection_string | Database for the Key Server (for end-to-end encryption).
|
| services.xonotic.settings.sv_termsofservice_url | URL for the Terms of Service for playing on your server.
|
| services.prometheus.scrapeConfigs.*.ec2_sd_configs.*.filters | Filters can be used optionally to filter the instance list by other criteria.
|
| services.cloud-init.config | raw cloud-init configuration
|
| virtualisation.containers.containersConf.settings | containers.conf configuration
|
| services.buffyboard.settings.quirks.fbdev_force_refresh | If true and using the framebuffer backend, this triggers a display refresh after every draw operation
|
| services.dependency-track.database.type | h2 database is not recommended for a production setup.
postgresql this settings it recommended for production setups.
manual the module doesn't handle database settings.
|
| services.gatus.configFile | Path to the Gatus configuration file
|
| services.prometheus.scrapeConfigs.*.gce_sd_configs.*.filter | Filter can be used optionally to filter the instance list by other
criteria Syntax of this filter string is described here in the filter
query parameter section: https://cloud.google.com/compute/docs/reference/latest/instances/list.
|
| services.dendrite.settings.room_server.database.connection_string | Database for the Room Server.
|
| services.kmscon.useXkbConfig | Whether to configure keymap from xserver keyboard settings.
|
| services.doh-server.settings.log_guessed_client_ip | Enable log IP from HTTPS-reverse proxy header: X-Forwarded-For or X-Real-IP
Note: http uri/useragent log cannot be controlled by this config
|
| services.matrix-continuwuity.settings.global.unix_socket_path | Listen on a UNIX socket at the specified path
|
| services.matrix-synapse.settings.tls_certificate_path | PEM encoded X509 certificate for TLS
|
| virtualisation.xen.store.settings.conflict.burstLimit | Limits applied to domains whose writes cause other domains' transaction
commits to fail
|
| services.grafana.settings.security.csrf_trusted_origins | List of additional allowed URLs to pass by the CSRF check
|
| services.nextcloud.settings.default_phone_region | An ISO 3166-1
country code which replaces automatic phone-number detection
without a country code
|
| programs.openvpn3.netcfg.settings.systemd_resolved | Whether to use systemd-resolved integration
|
| services.stash.settings.write_image_thumbnails | Write image thumbnails to disk when generating on the fly
|
| services.rmfakecloud.extraSettings | Extra settings in the form of a set of key-value pairs
|
| services.slskd.settings.remote_file_management | Whether to enable modification of share contents through the web ui.
|
| services.warpgate.settings.ssh.host_key_verification | Specify host key verification action when connecting to a SSH target with unknown/differing host key.
|
| services.fediwall.nginx | Allows customizing the nginx virtualHost settings
|
| services.postfix.settings.main.smtpd_tls_chain_files | List of paths to the server private keys and certificates.
The order of items matters and a private key must always be followed by the corresponding certificate.
https://www.postfix.org/postconf.5.html#smtpd_tls_chain_files
|
| services.peertube.settings.video_transcription.engine_path | Custom engine path for local transcription.
|
| services.nextcloud-spreed-signaling.settings.backend.connectionsperhost | Maximum number of concurrent backend connections per host
|
| security.pam.rssh.settings.auth_key_file | Path to file with trusted public keys in OpenSSH's authorized_keys format
|
| services.agorakit.nginx | With this option, you can customize the nginx virtualHost settings.
|
| services.librenms.nginx | With this option, you can customize the nginx virtualHost settings.
|
| services.scrutiny.settings.web.influxdb.tls.insecure_skip_verify | Whether to enable skipping TLS verification when connecting to InfluxDB.
|
| services.biboumi.settings.persistent_by_default | Whether all rooms will be persistent by default:
the value of the “persistent” option in the global configuration of each
user will be “true”, but the value of each individual room will still
default to false
|
| services.matrix-synapse.settings.trusted_key_servers.*.server_name | Hostname of the trusted server.
|
| services.jitsi-meet.config | Client-side web application settings that override the defaults in config.js
|
| virtualisation.xen.store.settings.conflict.maxHistorySeconds | Limits applied to domains whose writes cause other domains' transaction
commits to fail
|
| services.artalk.allowModify | allow Artalk store the settings to config file persistently
|
| programs.openvpn3.log-service.settings.log_dbus_details | Add D-Bus details in log file/syslog
|
| services.matrix-continuwuity.settings.global.allow_registration | Whether new users can register on this server
|
| services.biboumi.settings.realname_customization | Whether the users will be able to use
the ad-hoc commands that lets them configure
their realname and username.
|
| services.cgit.<name>.gitHttpBackend.checkExportOkFiles | Whether git-http-backend should only export repositories that contain a git-daemon-export-ok file
|
| services.movim.h2o.tls.recommendations | By default, H2O, without prejudice, will use as many TLS versions &
cipher suites as it & the TLS library (OpenSSL) can support
|
| services.mobilizon.settings.":mobilizon"."Mobilizon.Web.Endpoint".has_reverse_proxy | Whether you use a reverse proxy
|
| services.maubot.settings.server.override_resource_path | Override path from where to load UI resources.
|
| security.auditd.settings.admin_space_left | This is a numeric value in mebibytes (MiB) that tells the audit daemon when to perform a configurable action because the system is running
low on disk space
|
| services.mediagoblin.settings.mediagoblin.allow_registration | Whether to enable user self registration
|
| services.prometheus.scrapeConfigs.*.honor_labels | Controls how Prometheus handles conflicts between labels
that are already present in scraped data and labels that
Prometheus would attach server-side ("job" and "instance"
labels, manually configured target labels, and labels
generated by service discovery implementations)
|
| services.h2o.hosts.<name>.tls.recommendations | By default, H2O, without prejudice, will use as many TLS versions &
cipher suites as it & the TLS library (OpenSSL) can support
|
| services.pgbouncer.settings.pgbouncer.max_db_connections | Do not allow more than this many server connections per database (regardless of user)
|
| services.prometheus.alertmanager-ntfy.settings.ntfy.notification.templates.description | The ntfy.sh message description template.
|
| services.tuned.ppdSettings | Settings for TuneD's power-profiles-daemon compatibility service.
|
| services.h2o.defaultTLSRecommendations | By default, H2O, without prejudice, will use as many TLS versions &
cipher suites as it & the TLS library (OpenSSL) can support
|
| services.nsd.zones | Define your zones here
|
| services.geoclue2.appConfig | Specify extra settings per application.
|
| services.nezha-agent.settings.disable_command_execute | Disable executing the command from dashboard.
|
| services.nextcloud.settings.mail_smtpstreamoptions | This depends on mail_smtpmode
|
| services.jupyter.user | Name of the user used to run the jupyter service
|
| services.doh-server.configFile | The config file for the doh-server
|
| programs.clash-verge.tunMode | Whether to enable Setcap for TUN Mode
|
| services.dendrite.settings.federation_api.database.connection_string | Database for the Federation API.
|
| services.headscale.settings.tls_letsencrypt_listen | When HTTP-01 challenge is chosen, letsencrypt must set up a
verification endpoint, and it will be listening on:
:http = port 80.
|
| services.veilid.settings.core.network.detect_address_changes | Should veilid-core detect and notify on network address changes?
|
| services.anuko-time-tracker.nginx | With this option, you can customize the Nginx virtualHost settings.
|
| services.sourcehut.settings."hg.sr.ht".clone_bundle_threshold | .hg/store size (in MB) past which the nightly job generates clone bundles.
|
| services.tt-rss.auth.autoLogin | Automatically login user on remote or other kind of externally supplied
authentication, otherwise redirect to login form as normal
|
| services.bluemap.maps | Settings for files in maps/
|
| services.opendkim.keyPath | The path that opendkim should put its generated private keys into
|
| services.dolibarr.h2o.tls.recommendations | By default, H2O, without prejudice, will use as many TLS versions &
cipher suites as it & the TLS library (OpenSSL) can support
|
| services.sabnzbd.configFile | Path to config file (deprecated, use settings instead and set this value to null)
|
| services.dendrite.settings.client_api.registration_disabled | Whether to disable user registration to the server
without the shared secret.
|
| security.agnos.settings.accounts.*.private_key_path | Path of the PEM-encoded private key for this account
|
| services.crab-hole.configFile | The config file of crab-hole
|
| services.newt.blueprint | Blueprint for declarative settings, see Newt Blueprint docs for more information.
|
| services.bookstack.nginx | With this option, you can customize the nginx virtualHost settings.
|
| services.strongswan-swanctl.swanctl.connections.<name>.children.<name>.if_id_in | XFRM interface ID set on inbound policies/SA
|
| services.grafana.settings.analytics.feedback_links_enabled | Set to false to remove all feedback links from the UI.
|
| services.dendrite.settings.app_service_api.database.connection_string | Database for the Appservice API.
|
| services.dendrite.settings.user_api.device_database.connection_string | Database for the User API, devices.
|
| services.stash.settings.preview_segment_duration | Preview segment duration, in seconds
|
| services.postfix.settings.main.smtp_tls_security_level | The client TLS security level.
Use dane with a local DNSSEC validating DNS resolver enabled.
https://www.postfix.org/postconf.5.html#smtp_tls_security_level
|
| services.grav.systemSettings | Settings written to user/config/system.yaml.
|
| services.timekpr.adminUsers | All listed users will become part of the timekpr group so they can manage timekpr settings without requiring sudo.
|
| services.mediagoblin.settings.mediagoblin.email_sender_address | Email address which notices are sent from.
|
| services.deepin.dde-daemon.enable | Whether to enable daemon for handling the deepin session settings.
|
| services.coturn.realm | The default realm to be used for the users when no explicit
origin/realm relationship was found in the database, or if the TURN
server is not using any database (just the commands-line settings
and the userdb file)
|
| services.chhoto-url.settings.custom_landing_directory | The path of a directory which contains a custom landing page.
|
| services.grafana.settings.security.x_content_type_options | Set to false to disable the X-Content-Type-Options response header
|
| services.longview.apiKey | Longview API key
|
| services.chhoto-url.settings.public_mode_expiry_delay | The maximum expiry delay in seconds to force in public mode.
|
| services.dendrite.settings.user_api.account_database.connection_string | Database for the User API, accounts.
|
| services.longview.apiKeyFile | A file containing the Longview API key
|
| services.mailman.webSettings | Overrides for the default mailman-web Django settings.
|
| services.strongswan-swanctl.swanctl.connections.<name>.children.<name>.if_id_out | XFRM interface ID set on outbound policies/SA
|
| services.filesender.settings.storage_filesystem_path | When using storage type filesystem this is the absolute path to the file system where uploaded files are stored until they expire
|
| services.pgbouncer.settings.pgbouncer.max_user_connections | Do not allow more than this many server connections per user (regardless of database)
|
| services.grafana.settings.security.csrf_additional_headers | List of allowed headers to be set by the user
|
| services.akkoma.config | Configuration for Akkoma
|
| services.factorio.saveName | The name of the savegame that will be used by the server
|
| services.bonsaid.configFile | Path to a .json file specifying the state transitions
|
| services.cyrus-imap.cyrusSettings | Cyrus configuration settings
|
| services.cyrus-imap.imapdSettings | IMAP configuration settings
|
| services.xandikos.nginx.enable | Configure the nginx reverse proxy settings.
|
| services.postfix.settings.main.smtpd_tls_security_level | The server TLS security level
|
| services.matrix-conduit.settings.global.allow_check_for_updates | Whether to allow Conduit to automatically contact
https://conduit.rs hourly to check for important Conduit news
|
| services.doh-server.settings.ecs_allow_non_global_ip | By default, non global IP addresses are never forwarded to upstream servers
|
| services.neo4j.extraServerConfig | Extra configuration for Neo4j Community server
|
| services.matrix-synapse.settings.app_service_config_files | A list of application service config file to use
|
| services.grafana.settings.security.content_security_policy | Set to true to add the Content-Security-Policy header to your requests
|
| services.headscale.settings.tls_letsencrypt_hostname | Domain name to request a TLS certificate for.
|
| services.kanidm.unix.settings.kanidm.pam_allowed_login_groups | Kanidm groups that are allowed to login using PAM.
|
| security.agnos.settings.accounts.*.certificates.*.key_output_file | Output path for the certificate private key
|
| services.strongswan-swanctl.swanctl.connections.<name>.children.<name>.mark_out | Netfilter mark and mask for output traffic
|
| services.journald.rateLimitBurst | Configures the rate limiting burst limit (number of messages per
interval) that is applied to all messages generated on the system
|
| virtualisation.xen.store.settings.conflict.rateLimitIsAggregate | If the conflict.rateLimitIsAggregate option is true, then after each
tick one point of conflict-credit is given to just one domain: the
one at the front of the queue
|
| services.prometheus.scrapeConfigs.*.scaleway_sd_configs.*.role | Role of the targets to retrieve
|
| services.bluemap.coreSettings | Settings for the core.conf file, see upstream docs.
|
| services.graphite.web.extraConfig | Graphite webapp settings
|
| services.strongswan-swanctl.swanctl.connections.<name>.children.<name>.mark_in | Netfilter mark and mask for input traffic
|
| services.cpupower-gui.enable | Enables dbus/systemd service needed by cpupower-gui
|
| services.prometheus.scrapeConfigs.*.gce_sd_configs.*.tag_separator | The tag separator used to separate concatenated GCE instance network tags
|
| services.postgresql.settings.shared_preload_libraries | List of libraries to be preloaded.
|
| services.nextcloud.settings.mail_send_plaintext_only | Email will be sent by default with an HTML and a plain text body
|
| services.bitlbee.extraSettings | Will be inserted in the Settings section of the config file.
|
| services.cloudlog.extraConfig | Any additional text to be appended to the config.php
configuration file
|
| services.sitespeed-io.runs | A list of run configurations
|
| services.nomad.extraSettingsPaths | Additional settings paths used to configure nomad
|
| services.trilium-server.nginx.enable | Configure the nginx reverse proxy settings.
|
| services.radicale.rights | Configuration for Radicale's rights file
|
| services.minetest-server.config | Settings to add to the minetest config file
|
| services.matrix-synapse.settings.url_preview_url_blacklist | Optional list of URL matches that the URL preview spider is
denied from accessing.
|
| services.syncthing.configDir | The path where the settings and keys will exist.
|
| services.kanidm.serverSettings | Settings for Kanidm, see
the documentation
and example configuration
for possible values.
|
| services.mattermost.environmentFile | Environment file (see systemd.exec(5)
"EnvironmentFile=" section for the syntax) which sets config options
for mattermost (see the Mattermost documentation)
|
| services.davis.database.urlFile | A file containing the database connection url
|
| services.warpgate.settings.http.trust_x_forwarded_headers | Trust X-Forwarded-* headers
|
| fonts.fontconfig.localConf | System-wide customization file contents, has higher priority than
defaultFonts settings.
|
| boot.isNspawnContainer | Whether the machine is running in an nspawn container
|
| services.github-runners.<name>.user | User under which to run the service
|
| programs.starship.presets | Presets files to be merged with settings in order.
|
| services.portunus.seedSettings | Seed settings for users and groups
|
| services.bluemap.webappSettings | Settings for the webapp.conf file, see upstream docs.
|
| services.logstash.extraSettings | Extra Logstash settings in YAML format.
|
| services.hardware.lcd.server.usbGroup | The group to use for settings permissions
|
| services.prometheus.scrapeConfigs.*.lightsail_sd_configs.*.region | The AWS region
|
| services.hardware.bolt.enable | Whether to enable Bolt, a userspace daemon to enable
security levels for Thunderbolt 3 on GNU/Linux
|
| services.buffyboard.settings.quirks.ignore_unused_terminals | If true, buffyboard won't automatically update the layout of a new terminal and
draw the keyboard, if the terminal is not opened by any process
|
| services.grafana.settings.analytics.check_for_plugin_updates | When set to false, disables checking for new versions of installed plugins from https://grafana.com
|
| services.freshrss.api.enable | Whether to enable API access for mobile apps and third-party clients (Google Reader API and Fever API)
|
| services.mediawiki.extraConfig | Any additional text to be appended to MediaWiki's
LocalSettings.php configuration file
|
| services.prometheus.scrapeConfigs.*.ec2_sd_configs.*.refresh_interval | Refresh interval to re-read the instance list
|
| services.prometheus.scrapeConfigs.*.gce_sd_configs.*.refresh_interval | Refresh interval to re-read the cloud instance list
|
| services.stash.settings.video_file_naming_algorithm | Hash algorithm to use for generated file naming
|
| services.prometheus.scrapeConfigs.*.linode_sd_configs.*.tag_separator | The string by which Linode Instance tags are joined into the tag label
|
| services.matrix-synapse.settings.registration_shared_secret | If set, allows registration by anyone who also has the shared
secret, even if registration is otherwise disabled
|
| services.grafana.settings.security.strict_transport_security | Set to true if you want to enable HTTP Strict-Transport-Security (HSTS) response header
|
| services.wgautomesh.settings.upnp_forward_external_port | Public port number to try to redirect to this machine's Wireguard
daemon using UPnP IGD.
|
| services.lldap.settings.force_ldap_user_pass_reset | Force reset of the admin password
|
| services.snipe-it.config | Snipe-IT configuration options to set in the
.env file
|
| services.veilid.settings.core.protected_store.allow_insecure_fallback | If we can't use system-provided secure storage, should we proceed anyway?
|
| services.apcupsd.configText | Contents of the runtime configuration file, apcupsd.conf
|
| services.olivetin.extraConfigFiles | Config files to merge into the settings defined in services.olivetin.settings
|
| services.mailman.enablePostfix | Enable Postfix integration
|
| services.btrbk.extraPackages | Extra packages for btrbk, like compression utilities for stream_compress.
Note: This option will get deprecated in future releases
|
| services.foundationdb.tls | FoundationDB Transport Security Layer (TLS) settings.
|
| services.openldap.mutableConfig | Whether to allow writable on-line configuration
|
| services.yarr.environmentFile | Environment file for specifying additional settings such as secrets
|
| services.tinc.networks.<name>.extraConfig | Extra lines to add to the tinc service configuration file
|
| services.jitsi-meet.interfaceConfig | Client-side web-app interface settings that override the defaults in interface_config.js
|
| services.schleuder.listDefaults | Default settings for lists (list-defaults.yml)
|
| services.matrix-continuwuity.settings.global.allow_announcements_check | If enabled, continuwuity will send a simple GET request periodically to
https://continuwuity.org/.well-known/continuwuity/announcements for any new announcements made.
|
| hardware.nvidia.nvidiaSettings | Whether to enable nvidia-settings, NVIDIA's GUI configuration tool
.
|
| services.gitlab-runner.configFile | Configuration file for gitlab-runner.
configFile takes precedence over services.
checkInterval and concurrent will be ignored too
|
| services.prometheus.scrapeConfigs.*.azure_sd_configs.*.refresh_interval | Refresh interval to re-read the instance list
|
| services.flexget.systemScheduler | When true, execute the runs via the flexget-runner.timer
|
| services.multipath.overrides | This section defines values for attributes that should override the
device-specific settings for all devices.
|
| services.pgbouncer.settings.pgbouncer.ignore_startup_parameters | By default, PgBouncer allows only parameters it can keep track of in startup packets:
client_encoding, datestyle, timezone and standard_conforming_strings
|
| services.grafana.settings.database.locking_attempt_timeout_sec | For mysql, if the migrationLocking feature toggle is set,
specify the time (in seconds) to wait before failing to lock the database for the migrations.
|
| services.librespeed.secrets | Attribute set of filesystem paths
|
| services.filebeat.inputs | Inputs specify how Filebeat locates and processes input data
|
| services.stash.settings.create_image_clip_from_videos | Create Image Clips from Video extensions when Videos are disabled in Library
|
| i18n.inputMethod.fcitx5.plasma6Support | Use qt6 versions of fcitx5 packages
|
| services.prometheus.remoteWrite.*.sigv4 | Configures AWS Signature Version 4 settings.
|
| services.grafana.settings.security.data_source_proxy_whitelist | Define a whitelist of allowed IP addresses or domains, with ports,
to be used in data source URLs with the Grafana data source proxy
|
| services.prometheus.scrapeConfigs.*.openstack_sd_configs.*.all_tenants | Whether the service discovery should list all instances for all projects
|
| services.postgresql.systemCallFilter | Configures the syscall filter for postgresql.service
|
| services.factorio.extraSettingsFile | File, which is dynamically applied to server-settings.json before
startup
|
| services.monica.config | monica configuration options to set in the
.env file
|
| services.libvirtd.autoSnapshot.vms | If specified only the list of VMs will be snapshotted else all existing one
|
| services.yggdrasil.configFile | A file which contains JSON or HJSON configuration for yggdrasil
|
| services.oink.domains | List of attribute sets containing configuration for each domain
|
| services.mattermost.preferNixConfig | If both mutableConfig and this option are set, the Nix configuration
will take precedence over any settings configured in the server
console.
|
| services.prosody.muc.*.tombstoneExpiry | This settings controls how long a tombstone is considered
valid
|
| services.komodo-periphery.extraSettings | Extra settings to add to the generated TOML config.
|
| services.packagekit.vendorSettings | Additional settings passed straight through to Vendor.conf
|
| services.bluemap.webserverSettings | Settings for the webserver.conf file, usually not required.
See upstream docs.
|
| services.asterisk.useTheseDefaultConfFiles | Sets these config files to the default content
|
| services.pufferpanel.environment | Environment variables to set for the service
|
| users.users.<name>.linger | Whether to enable or disable lingering for this user
|
| environment.wvdial.pppDefaults | Default ppp settings for wvdial.
|
| services.matrix-synapse.settings.url_preview_ip_range_blacklist | List of IP address CIDR ranges that the URL preview spider is denied
from accessing.
|
| services.matrix-synapse.settings.url_preview_ip_range_whitelist | List of IP address CIDR ranges that the URL preview spider is allowed
to access even if they are specified in url_preview_ip_range_blacklist.
|
| services.rathole.credentialsFile | Path to a TOML file to be merged with the settings
|
| services.headscale.settings.tls_letsencrypt_challenge_type | Type of ACME challenge to use, currently supported types:
HTTP-01 or TLS-ALPN-01.
|
| security.agnos.settings.accounts.*.certificates.*.fullchain_output_file | Output path for the full chain including the acquired certificate
|
| services.nginx.recommendedTlsSettings | Enable recommended TLS settings.
|
| services.foundationdb.locality | FoundationDB locality settings.
|
| services.netbird.useRoutingFeatures | Enables settings required for NetBird's routing features: Network Resources, Network Routes & Exit Nodes
|
| services.grafana.settings.security.disable_initial_admin_creation | Disable creation of admin user on first start of Grafana.
|
| services.dendrite.settings.global.trusted_third_party_id_servers | Lists of domains that the server will trust as identity
servers to verify third party identifiers such as phone
numbers and email addresses
|
| services.veilid.settings.core.protected_store.always_use_insecure_storage | Should we bypass any attempt to use system-provided secure storage?
|
| services.agorakit.config | Agorakit configuration options to set in the
.env file
|
| services.bookstack.config | BookStack configuration options to set in the
.env file
|
| hardware.cpu.amd.ryzen-smu.enable | Whether to enable ryzen_smu, a linux kernel driver that exposes access to the SMU (System Management Unit) for certain AMD Ryzen Processors
|
| programs.chromium.initialPrefs | Initial preferences are used to configure the browser for the first run
|
| services.librenms.environmentFile | File containing env-vars to be substituted into the final config
|
| users.extraUsers.<name>.linger | Whether to enable or disable lingering for this user
|
| services.prometheus.scrapeConfigs.*.openstack_sd_configs.*.refresh_interval | Refresh interval to re-read the instance list
|
| services.prometheus.scrapeConfigs.*.lightsail_sd_configs.*.refresh_interval | Refresh interval to re-read the instance list
|
| services.stash.settings.show_one_time_moved_notification | Whether a small notification to inform the user that Stash will no longer show a terminal window, and instead will be available in the tray
|
| services.sanoid.datasets.<name>.recursive | Whether to recursively snapshot dataset children
|
| services.clamav.clamonacc.enable | Whether to enable ClamAV on-access scanner
|
| services.karakeep.extraEnvironment | Environment variables to pass to Karakaeep
|
| services.metricbeat.modules | Metricbeat modules are responsible for reading metrics from the various sources
|
| services.nginx.recommendedGzipSettings | Enable recommended gzip settings
|
| hardware.openrazer.batteryNotifier | Settings for device battery notifications.
|
| services.filebeat.modules | Filebeat modules provide a quick way to get started
processing common log formats
|
| services.sunshine.applications | Configuration for applications to be exposed to Moonlight
|
| services.biboumi.credentialsFile | Path to a configuration file to be merged with the settings
|
| services.nginx.recommendedZstdSettings | Enable recommended zstd settings
|
| services.nginx.recommendedUwsgiSettings | Whether to enable recommended uwsgi settings if a vhost does not specify the option manually.
|
| services.nginx.recommendedProxySettings | Whether to enable recommended proxy settings if a vhost does not specify the option manually.
|
| services.discourse.backendSettings | Additional settings to put in the
discourse.conf file
|
| i18n.extraLocaleSettings | A set of additional system-wide locale settings other than LANG
which can be configured with i18n.defaultLocale
|
| services.privoxy.inspectHttps | Whether to configure Privoxy to inspect HTTPS requests, meaning all
encrypted traffic will be filtered as well
|
| services.dnscrypt-proxy2.upstreamDefaults | Whether to base the config declared in services.dnscrypt-proxy2.settings on the upstream example config (https://github.com/DNSCrypt/dnscrypt-proxy/blob/master/dnscrypt-proxy/example-dnscrypt-proxy.toml)
Disable this if you want to declare your dnscrypt config from scratch.
|
| services.akkoma.initDb.enable | Whether to automatically initialise the database on startup
|
| services.apache-kafka.configFiles.serverProperties | Kafka server.properties configuration file path
|
| services.nextcloud.configureRedis | Whether to configure Nextcloud to use the recommended Redis settings for small instances.
The Nextcloud system check recommends to configure either Redis or Memcache for file lock caching.
The notify_push app requires Redis to be configured
|
| services.headscale.settings.ephemeral_node_inactivity_timeout | Time before an inactive ephemeral node is deleted.
|
| services.prometheus.remoteRead.*.tls_config | Configures the remote read request's TLS settings.
|
| services.grafana.settings.users.user_invite_max_lifetime_duration | The duration in time a user invitation remains valid before expiring
|
| services.listmonk.database.mutableSettings | Database settings will be reset to the value set in this module if this is not enabled
|
| services.opencloud.environment | Extra environment variables to set for the service
|
| services.nginx.recommendedBrotliSettings | Enable recommended brotli settings
|
| services.opencloud.environmentFile | An environment file as defined in systemd.exec(5)
|
| services.grafana.settings.security.strict_transport_security_preload | Set to true to enable HSTS preloading option
|
| virtualisation.appvm.enable | This enables AppVMs and related virtualisation settings.
|
| services.mattermost.mutableConfig | Whether the Mattermost config.json is writeable by Mattermost
|
| services.displayManager.dms-greeter.configFiles | List of DankMaterialShell configuration files to copy into the greeter
data directory at /var/lib/dms-greeter
|
| services.stash.settings.dangerous_allow_public_without_auth | Learn more at https://docs.stashapp.cc/networking/authentication-required-when-accessing-stash-from-the-internet/
|
| services.crossfire-server.configFiles | Text to append to the corresponding configuration files
|
| services.prometheus.remoteWrite.*.tls_config | Configures the remote write request's TLS settings.
|
| services.weblate.configurePostgresql | Whether to enable and configure a local PostgreSQL server by creating a user and database for weblate
|
| services.dovecot2.imapsieve.mailbox.*.name | This setting configures the name of a mailbox for which administrator scripts are configured
|
| services.nginx.experimentalZstdSettings | Enable alpha quality zstd module with recommended settings
|
| services.yggdrasil.openMulticastPort | Whether to open the UDP port used for multicast peer discovery
|
| services.dysnomia.extraContainerProperties | An attribute set providing additional container settings in addition to the default properties
|
| services.crowdsec-firewall-bouncer.createRulesets | Whether to have the module create the appropriate firewall configuration
based on the bouncer settings
|
| services.prometheus.scrapeConfigs.*.tls_config | Configures the scrape request's TLS settings.
|
| services.tailscale.useRoutingFeatures | Enables settings required for Tailscale's routing features like subnet routers and exit nodes
|
| virtualisation.lxc.bridgeConfig | This is the config file for override lxc-net bridge default settings.
|
| services.archisteamfarm.ipcSettings | Settings to write to IPC.config
|
| services.grafana.settings.security.content_security_policy_report_only | Set to true to add the Content-Security-Policy-Report-Only header to your requests
|
| services.bitwarden-directory-connector-cli.ldap | Options to configure the LDAP connection
|
| services.bitwarden-directory-connector-cli.sync | Options to configure what gets synced
|
| services.centrifugo.environmentFiles | Files to load environment variables from
|
| services.xserver.displayManager.sx.enable | Whether to enable the "sx" pseudo-display manager, which allows users
to start manually via the "sx" command from a vt shell
|
| programs.ryzen-monitor-ng.enable | Whether to enable ryzen_monitor_ng, a userspace application for setting and getting Ryzen SMU (System Management Unit) parameters via the ryzen_smu kernel driver
|
| services.nginx.recommendedOptimisation | Enable recommended optimisation settings.
|
| services.grafana.settings.security.disable_brute_force_login_protection | Set to true to disable brute force login protection.
|
| services.grafana.settings.security.strict_transport_security_subdomains | Set to true to enable HSTS includeSubDomains option
|
| virtualisation.graphics | Whether to run QEMU with a graphics window, or in nographic mode
|
| services.qbittorrent.serverConfig | Free-form settings mapped to the qBittorrent.conf file in the profile
|
| services.firezone.server.provision.accounts | All accounts to provision
|
| services.transmission.credentialsFile | Path to a JSON file to be merged with the settings
|
| services.nghttpx.backends.*.params.affinity | If "ip" is given, client IP based session affinity is
enabled
|
| services.davis.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.davis.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.movim.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.slskd.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.slskd.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.movim.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.fluent-bit.configurationFile | Fluent Bit configuration
|
| services.snipe-it.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.snipe-it.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.akkoma.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.gancio.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.fluidd.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.fluidd.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.gancio.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.akkoma.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.matomo.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.matomo.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.monica.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.monica.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| networking.wireless.userControlled | Allow users of the wpa_supplicant group to control wpa_supplicant
through wpa_gui or wpa_cli
|
| services.grafana.settings.security.strict_transport_security_max_age_seconds | Sets how long a browser should cache HSTS in seconds
|
| services.prometheus.alertmanager-ntfy.extraConfigFiles | Config files to merge into the settings defined in services.prometheus.alertmanager-ntfy.settings
|
| virtualisation.rosetta.enable | Whether to enable Rosetta support
|
| virtualisation.libvirtd.onBoot | Specifies the action to be done to / on the guests when the host boots
|
| services.dolibarr.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.agorakit.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.librenms.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.kanboard.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.fediwall.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.librenms.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.kanboard.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.fediwall.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.agorakit.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.dolibarr.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.mainsail.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.pixelfed.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.pixelfed.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.mainsail.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| virtualisation.containerd.configFile | Path to containerd config file
|
| services.xserver.desktopManager.surf-display.screensaverSettings | Screensaver settings, see man 1 xset for possible options.
|
| services.radicle.httpd.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.radicle.httpd.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| networking.wireless.userControlled.enable | Allow normal users to control wpa_supplicant through wpa_gui or wpa_cli
|
| services.nginx.virtualHosts.<name>.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.nginx.virtualHosts.<name>.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.anuko-time-tracker.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.anuko-time-tracker.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.prometheus.exporters.ecoflow.scrapingInterval | Scrapping interval in seconds
|
| services.bookstack.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.bookstack.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| networking.networkmanager.enable | Whether to use NetworkManager to obtain an IP address and other
configuration for all network interfaces that are not manually
configured
|
| services.jirafeau.nginxConfig.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.jirafeau.nginxConfig.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.zabbixWeb.nginx.virtualHost.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.zabbixWeb.nginx.virtualHost.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.stash.settings.security_tripwire_accessed_from_public_internet | Learn more at https://docs.stashapp.cc/networking/authentication-required-when-accessing-stash-from-the-internet/
|
| services.fedimintd.<name>.nginx.config.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.fedimintd.<name>.nginx.config.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| programs.opengamepadui.powerstation.enable | Whether to enable Run PowerStation service for TDP control and performance settings.
.
|
| services.limesurvey.nginx.virtualHost.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.limesurvey.nginx.virtualHost.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.changedetection-io.environmentFile | Securely pass environment variables to changedetection-io
|
| virtualisation.oci-containers.containers.<name>.podman | Podman-specific settings in OCI containers
|
| services.misskey.reverseProxy.webserver.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.misskey.reverseProxy.webserver.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| virtualisation.lxd.recommendedSysctlSettings | Enables various settings to avoid common pitfalls when
running containers requiring many file operations
|
| services.prometheus.scrapeConfigs.*.http_sd_configs.*.tls_config | Configures the scrape request's TLS settings.
|
| qt.platformTheme | Selects the platform theme to use for Qt applications
|
| services.prometheus.scrapeConfigs.*.consul_sd_configs.*.tls_config | Configures the Consul request's TLS settings.
|
| networking.networkmanager.ensureProfiles.secrets.entries.*.matchType | NetworkManager connection type
The NetworkManager configuration settings reference roughly corresponds to connection types
|
| virtualisation.oci-containers.containers.<name>.capabilities | Capabilities to configure for the container
|
| services.hostapd.radios.<name>.networks.<name>.authentication.mode | Selects the authentication mode for this AP.
- "none": Don't configure any authentication
|
| networking.networkmanager.ensureProfiles.profiles | Declaratively define NetworkManager profiles
|