| systemd.automounts.*.enable | If set to false, this unit will be a symlink to
/dev/null
|
| services.tt-rss.registration.enable | Allow users to register themselves
|
| boot.loader.systemd-boot.memtest86.sortKey | systemd-boot orders the menu entries by their sort keys,
so if you want something to appear after all the NixOS entries,
it should start with o or onwards
|
| services.libretranslate.port | The the application should listen on.
|
| services.xserver.displayManager.xpra.desktop | Start a desktop environment instead of seamless mode
|
| services.quickwit.settings.rest.listen_port | The port to listen on for HTTP REST traffic.
|
| xdg.portal.wlr.settings | Configuration for xdg-desktop-portal-wlr
|
| services.dnsdist.dnscrypt.providerName | The name that will be given to this DNSCrypt resolver.
The provider name must start with 2.dnscrypt-cert..
|
| systemd.user.services.<name>.stopIfChanged | If set, a changed unit is restarted by calling
systemctl stop in the old configuration,
then systemctl start in the new one
|
| services.cyrus-imap.cyrusSettings.DAEMON | This section lists long running daemons to start before any SERVICES are spawned. master(8) will ensure that these processes are running, restarting any process which dies or forks
|
| services.stash.settings.parallel_tasks | Number of parallel tasks to start during scan/generate
|
| services.strongswan-swanctl.swanctl.connections.<name>.local_port | Local UDP port for IKE communication
|
| networking.wg-quick.interfaces.<name>.preUp | Commands called at the start of the interface setup.
|
| virtualisation.bios | An alternate BIOS (such as qboot) with which to start the VM
|
| networking.wireguard.interfaces.<name>.peers.*.dynamicEndpointRefreshRestartSeconds | When the dynamic endpoint refresh that is configured via
dynamicEndpointRefreshSeconds exits (likely due to a failure),
restart that service after this many seconds
|
| services.slskd.settings.soulseek.listen_port | The port on which to listen for incoming connections.
|
| services.firewalld.settings.IndividualCalls | Whether to use individual -restore calls to apply changes to the firewall
|
| services.tor.settings.ServerTransportPlugin.transports | List of pluggable transports.
|
| networking.wg-quick.interfaces.<name>.autostart | Whether to bring up this interface automatically during boot.
|
| services.transmission.openPeerPorts | Whether to enable opening of the peer port(s) in the firewall.
|
| systemd.units.<name>.wantedBy | Units that want (i.e. depend on) this unit
|
| systemd.mounts.*.wantedBy | Units that want (i.e. depend on) this unit
|
| systemd.paths.<name>.wantedBy | Units that want (i.e. depend on) this unit
|
| services.teeworlds.game.voteKickMinimumPlayers | The minimum amount of players required to start a kick vote.
|
| services.nsd.reuseport | Whether to enable SO_REUSEPORT on all used sockets
|
| virtualisation.incus.softDaemonRestart | Allow for incus.service to be stopped without affecting running instances.
|
| virtualisation.forwardPorts.*.host.port | The host port to be mapped.
|
| services.peertube.listenHttp | The port that the local PeerTube web server will listen on.
|
| services.fail2ban.bantime-increment.rndtime | "bantime.rndtime" is the max number of seconds using for mixing with random time
to prevent "clever" botnets calculate exact time IP can be unbanned again
|
| services.aria2.openPorts | Open listen and RPC ports found in settings.listen-port and
settings.rpc-listen-port options in the firewall.
|
| programs.pay-respects.runtimeRules | List of rules to be added to /etc/xdg/pay-respects/rules.
pay-respects will read the contents of these generated rules to recommend command corrections
|
| swapDevices.*.encrypted.keyFile | Path to a keyfile used to unlock the backing encrypted
device
|
| services.vwifi.server.ports.control | The control interface port
|
| services.offlineimap.install | Whether to install a user service for Offlineimap
|
| services.shairport-sync.settings | Configuration options for Shairport-Sync
|
| services.hadoop.hdfs.namenode.formatOnInit | Format HDFS namenode on first start
|
| services.gitlab.secrets.activeRecordPrimaryKeyFile | A file containing the secret used to encrypt some rails data
in the DB
|
| virtualisation.forwardPorts.*.guest.port | The guest port to be mapped.
|
| services.prometheus.exporters.mail.configuration.servers.*.port | Port to use for SMTP.
|
| systemd.slices.<name>.wantedBy | Units that want (i.e. depend on) this unit
|
| systemd.timers.<name>.wantedBy | Units that want (i.e. depend on) this unit
|
| services.prometheus.exporters.collectd.collectdBinary.port | Network address on which to accept collectd binary network packets.
|
| boot.loader.systemd-boot.netbootxyz.sortKey | systemd-boot orders the menu entries by their sort keys,
so if you want something to appear after all the NixOS entries,
it should start with o or onwards
|
| services.tlsrpt.reportd.settings.dbname | Path to the sqlite database.
|
| services.wgautomesh.settings.gossip_port | wgautomesh gossip port, this MUST be the same number on all nodes in
the wgautomesh network.
|
| fileSystems.<name>.encrypted.keyFile | Path to a keyfile used to unlock the backing encrypted
device
|
| systemd.user.units.<name>.wantedBy | Units that want (i.e. depend on) this unit
|
| systemd.user.paths.<name>.wantedBy | Units that want (i.e. depend on) this unit
|
| systemd.services.<name>.wantedBy | Units that want (i.e. depend on) this unit
|
| networking.nftables.extraDeletions | Extra deletion commands to be run on every firewall start, reload
and after stopping the firewall.
|
| services.home-assistant.configWritable | Whether to make configuration.yaml writable
|
| services.hitch.backend | The host and port Hitch connects to when receiving
a connection in the form [HOST]:PORT
|
| services.akkoma.dist.epmdPort | TCP port to bind Erlang Port Mapper Daemon to.
|
| networking.sits.<name>.encapsulation.port | Destination port when using UDP encapsulation.
|
| services.tarsnap.archives | Tarsnap archive configurations
|
| services.nextcloud.config.objectstore.s3.port | Required for some non-Amazon implementations.
|
| systemd.targets.<name>.wantedBy | Units that want (i.e. depend on) this unit
|
| systemd.sockets.<name>.wantedBy | Units that want (i.e. depend on) this unit
|
| systemd.user.slices.<name>.wantedBy | Units that want (i.e. depend on) this unit
|
| systemd.user.timers.<name>.wantedBy | Units that want (i.e. depend on) this unit
|
| services.kubernetes.scheduler.leaderElect | Whether to start leader election before executing main loop.
|
| services.mullvad-vpn.enableEarlyBootBlocking | This option activates an additional oneshot systemd service to ensure that the mullvad daemon
will start and block traffic before any network configuration will be applied
|
| services.nextcloud-spreed-signaling.settings.sessions.hashkeyFile | The path to the file containing the value for sessions.hashkey
|
| services.kanidm.provision.systems.oauth2.<name>.basicSecretFile | The basic secret to use for this service
|
| services.cassandra.maxHeapSize | Must be left blank or set together with heapNewSize
|
| systemd.user.services.<name>.wantedBy | Units that want (i.e. depend on) this unit
|
| services.portunus.ldap.tls | Whether to enable LDAPS protocol
|
| programs.uwsm.enable | Whether to enable uwsm, which wraps standalone Wayland compositors with a set
of Systemd units on the fly
|
| services.warpgate.settings.ssh.external_port | The SSH listener is reachable via this port externally.
|
| virtualisation.podman.networkSocket.port | TCP port number for receiving TLS connections.
|
| <imports = [ pkgs.php.services.default ]>.php-fpm.settings | PHP FPM configuration
|
| services.warpgate.settings.http.external_port | The HTTP listener is reachable via this port externally.
|
| services.nbd.server.listenPort | Port to listen on
|
| services.nextcloud.settings.mail_smtpport | This depends on mail_smtpmode
|
| systemd.user.sockets.<name>.wantedBy | Units that want (i.e. depend on) this unit
|
| systemd.user.targets.<name>.wantedBy | Units that want (i.e. depend on) this unit
|
| xdg.portal.enable | Whether to enable xdg desktop integration.
|
| services.warpgate.settings.mysql.external_port | The MySQL listener is reachable via this port externally.
|
| services.ax25.axports | Specification of one or more AX.25 ports.
|
| services.hadoop.yarn.resourcemanager.restartIfChanged | Automatically restart the service on config change
|
| virtualisation.docker.autoPrune.randomizedDelaySec | Add a randomized delay before each auto prune
|
| services.livekit.settings.rtc.port_range_end | End of UDP port range for WebRTC
|
| services.hitch.frontend | The port and interface of the listen endpoint in the
form [HOST]:PORT[+CERT].
|
| services.anuko-time-tracker.settings.reportFooter | Defines whether to use a footer on reports.
|
| services.mattermost.mutableConfig | Whether the Mattermost config.json is writeable by Mattermost
|
| services.i2pd.inTunnels.<name>.inPort | Service port
|
| services.firewalld.zones.<name>.forwardPorts.*.to-port | |
| services.synergy.client.serverAddress | The server address is of the form: [hostname][:port]
|
| services.prometheus.alertmanagerGotify.gotifyEndpoint.port | The port your gotify endpoint is running.
|
| services.prometheus.exporters.nginxlog.settings | All settings of nginxlog expressed as an Nix attrset
|
| services.paperless.exporter.settings | Settings to pass to the document exporter as CLI arguments.
|
| services.tinc.networks.<name>.hostSettings.<name>.rsaPublicKey | Legacy RSA public key of the host in PEM format, including start and
end markers
|
| services.tlsrpt.reportd.settings.fetchers | Comma-separated list of fetcher programs that retrieve collectd data.
|
| services.tor.settings.ServerTransportPlugin | See torrc manual.
|
| services.pgbouncer.settings.pgbouncer.listen_port | Which port to listen on
|
| services.archisteamfarm.web-ui.enable | Whether to start the web-ui
|
| boot.loader.systemd-boot.rebootForBitlocker | Enable EXPERIMENTAL BitLocker support
|
| services.firefly-iii-data-importer.settings | Options for firefly-iii data importer configuration
|
| services.cassandra.heapNewSize | Must be left blank or set together with heapNewSize
|
| virtualisation.vswitch.resetOnStart | Whether to reset the Open vSwitch configuration database to a default
configuration on every start of the systemd ovsdb.service.
|