| services.gitlab-runner.services.<name>.buildsDir | Absolute path to a directory where builds will be stored
in context of selected executor (Locally, Docker, SSH).
|
| hardware.nvidia-container-toolkit.csv-files | The path to the list of CSV files to use when generating the CDI specification in CSV mode.
|
| services.gancio.nginx.sslCertificateKey | Path to server SSL certificate key.
|
| services.gitea.settings.mailer.SENDMAIL_PATH | Path to sendmail binary or script.
|
| services.ejabberd.imagemagick | Add ImageMagick to server's path; allows for image thumbnailing
|
| services.keycloak.database.host | Hostname of the database to connect to
|
| services.foundationdb.pidfile | Path to pidfile for fdbmonitor.
|
| services.akkoma.nginx.sslCertificateKey | Path to server SSL certificate key.
|
| services.fluidd.nginx.sslCertificateKey | Path to server SSL certificate key.
|
| services.borgbackup.repos | Serve BorgBackup repositories to given public SSH keys,
restricting their access to the repository only
|
| services.matomo.nginx.sslCertificateKey | Path to server SSL certificate key.
|
| services.public-inbox.settings.coderepo.<name>.dir | Path to a git repository
|
| services.thanos.rule.tracing.config | Tracing configuration
|
| services.matterbridge.configPath | The path to the matterbridge configuration file.
|
| services.monica.nginx.sslCertificateKey | Path to server SSL certificate key.
|
| services.taskserver.pki.manual.ca.cert | Fully qualified path to the CA certificate.
Setting this option will prevent automatic CA creation and handling.
|
| services.peering-manager.peeringdbApiKeyFile | Path to a file containing the PeeringDB API key.
|
| virtualisation.xen.qemu.pidFile | Path to the QEMU PID file.
|
| services.warpgate.settings.log.send_to | Path of UNIX socket of log forwarder
|
| services.gitlab.initialRootPasswordFile | File containing the initial password of the root account if
this is a new install
|
| services.gitlab.databasePasswordFile | File containing the GitLab database user password
|
| services.gitlab.secrets.otpFile | A file containing the secret used to encrypt secrets for OTP
tokens
|
| services.etesync-dav.sslCertificate | Path to server SSL certificate
|
| services.haven.environmentFile | Path to a file containing sensitive environment variables
|
| services.httpd.virtualHosts.<name>.documentRoot | The path of Apache's document root directory
|
| services.grafana.settings.server.socket | Path where the socket should be created when protocol=socket
|
| services.esphome.allowedDevices | A list of device nodes to which esphome has access to
|
| services.calibre-server.libraries | Make sure each library path is initialized before service startup
|
| boot.specialFileSystems.<name>.device | The device as passed to mount
|
| services.limesurvey.nginx.virtualHost.root | The path of the web root directory.
|
| services.netdata.extraNdsudoPackages | Extra packages to add to PATH to make available to ndsudo.
ndsudo has SUID privileges, be careful what packages you list here.
cfg.package must be built with withNdsudo = true
|
| services.opengfw.settings.ruleset.geosite | Path to geosite.dat.
|
| services.nullmailer.remotesFile | Path to the remotes control file
|
| services.mastodon.secretKeyBaseFile | Path to file containing the secret key base
|
| services.neo4j.ssl.policies.<name>.privateKey | The name of private PKCS #8 key file for this policy to be found
in the baseDirectory, or the absolute path to
the key file
|
| services.wyoming.satellite.sounds.awake | Path to audio file in WAV format to play when wake word is detected.
|
| services.blockbook-frontend.<name>.certFile | To enable SSL, specify path to the name of certificate files without extension
|
| networking.firewall.logReversePathDrops | Logs dropped packets failing the reverse path filter test if
the option networking.firewall.checkReversePath is enabled.
|
| services.photoprism.originalsPath | Storage path of your original media files (photos and videos).
|
| services.postgresqlBackup.location | Path of directory where the PostgreSQL database dumps will be placed.
|
| services.prefect.databasePasswordFile | path to a file containing e.g.:
DBPASSWORD=supersecret
stored outside the nix store, read by systemd as EnvironmentFile.
|
| services.warpgate.settings.postgres.key | Path to PostgreSQL listener private key.
|
| services.kubernetes.kubelet.cni.configDir | Path to Kubernetes CNI configuration directory.
|
| virtualisation.rootDevice | The path (inside the VM) to the device containing the root filesystem.
|
| services.multipath.devices.*.user_friendly_names | If set to "yes", using the bindings file /etc/multipath/bindings
to assign a persistent and unique alias to the multipath, in the
form of mpath
|
| services.strongswan-swanctl.swanctl.connections.<name>.local.<name>.pubkeys | List of raw public key candidates to use for
authentication
|
| services.sourcehut.settings."hg.sr.ht".repos | Path to mercurial repositories on disk
|
| services.keycloak.sslCertificate | The path to a PEM formatted certificate to use for TLS/SSL
connections.
|
| services.gerbil.environmentFile | Path to a file containing sensitive environment variables for Gerbil
|
| services.pgadmin.initialPasswordFile | Initial password file for the pgAdmin account
|
| services.thanos.store.tracing.config | Tracing configuration
|
| services.thanos.query.tracing.config | Tracing configuration
|
| services.postfix-tlspol.settings.server.cache-file | Path to the cache file.
|
| services.sabnzbd.secretFiles | Path to a list of ini file containing confidential settings such as credentials
|
| services.mattermost.database.host | Host to use for the database
|
| services.samba.settings.global."passwd program" | Path to a program that can be used to set UNIX user passwords.
|
| services.limesurvey.database.socket | Path to the unix socket file to use for authentication.
|
| services.misskey.meilisearch.keyFile | The path to a file containing the Meilisearch API key
|
| services.spiped.config.<name>.source | Address on which spiped should listen for incoming
connections
|
| services.typesense.settings.server.data-dir | Path to the directory where data will be stored on disk.
|
| services.netbird.server.coturn.passwordFile | The path to a file containing the password of the user used by netbird to connect to the coturn server.
|
| services.kubernetes.pki.caCertPathPrefix | Path-prefrix for the CA-certificate to be used for cfssl signing
|
| services.xserver.xkb.extraLayouts.<name>.typesFile | The path to the xkb types file
|
| services.vdirsyncer.jobs.<name>.config.statusPath | vdirsyncer's status path
|
| services.discourse.redis.passwordFile | File containing the Redis password
|
| services.limesurvey.virtualHost.sslServerKey | Path to server SSL certificate key.
|
| services.simplesamlphp.<name>.libDir | Path to the SimpleSAMLphp library directory.
|
| services.sourcehut.settings."git.sr.ht".repos | Path to git repositories on disk
|
| services.grafana.settings.smtp.cert_file | File path to a cert file.
|
| services.etesync-dav.sslCertificateKey | Path to server SSL certificate key
|
| hardware.nvidia-container-toolkit.mounts.*.hostPath | Host path.
|
| services.thanos.receive.objstore.config-file | Path to YAML file that contains object store configuration
|
| services.thanos.compact.objstore.config-file | Path to YAML file that contains object store configuration
|
| services.thanos.sidecar.objstore.config-file | Path to YAML file that contains object store configuration
|
| services.tsidp.environmentFile | Path to an environment file loaded for the tsidp service
|
| services.xserver.windowManager.qtile.configFile | Path to the qtile configuration file
|
| services.wastebin.secretFile | Path to file containing sensitive environment variables
|
| services.matrix-synapse.extraConfigFiles | Extra config files to include
|
| services.limesurvey.virtualHost.sslServerCert | Path to server SSL certificate.
|
| services.dokuwiki.sites.<name>.templates | List of path(s) to respective template(s) which are copied into the 'tpl' directory.
These templates need to be packaged before use, see example.
|
| security.pam.mount.additionalSearchPaths | Additional programs to include in the search path of pam_mount
|
| services.fwupd.daemonSettings.EspLocation | The EFI system partition (ESP) path used if UDisks is not available
or if this partition is not mounted at /boot/efi, /boot, or /efi
|
| services.forgejo.settings.server.STATIC_ROOT_PATH | Upper level of template and static files path.
|
| services.kasmweb.sslCertificateKey | The SSL certificate's key to be used for kasmweb
|
| services.maddy.tls.certificates.*.keyPath | Path to the private key used for TLS.
|
| services.mpd.credentials.*.passwordFile | Path to file containing the password.
|
| services.restic.backups.<name>.repositoryFile | Path to the file containing the repository location to backup to.
|
| services.mediawiki.httpd.virtualHost.sslServerKey | Path to server SSL certificate key.
|
| services.xserver.windowManager.mlvwm.configFile | Path to the mlvwm configuration file
|
| services.wordpress.sites.<name>.languages | List of path(s) to respective language(s) which are copied from the 'languages' directory.
|
| services.xserver.windowManager.bspwm.configFile | Path to the bspwm configuration file
|
| services.grafana.settings.server.serve_from_sub_path | Serve Grafana from subpath specified in the root_url setting
|
| services.sourcehut.settings."hg.sr.ht".srhtext | Path to the srht mercurial extension
(defaults to where the hgsrht code is)
|
| services.dashy.settings | Settings serialized into user-data/conf.yml before build
|
| image.repart.partitions.<name>.contents.<name>.source | Path of the source file.
|
| security.pam.u2f.enable | Enables U2F PAM (pam-u2f) module
|
| services.buildkite-agents.<name>.privateSshKeyPath | OpenSSH private key
A run-time path to the key file, which is supposed to be provisioned
outside of Nix store.
|
| programs.hyprland.systemd.setPath.enable | Set environment path of systemd to include the current system's bin directory
|
| services.ghostunnel.servers.<name>.cacert | Path to CA bundle file (PEM/X509)
|
| services.keycloak.sslCertificateKey | The path to a PEM formatted private key to use for TLS/SSL
connections.
|