| services.prosody.virtualHosts.<name>.ssl.cert | Path to the certificate file.
|
| services.peering-manager.enable | Enable Peering Manager
|
| services.limesurvey.httpd.virtualHost.enableUserDir | Whether to enable serving ~/public_html as
/~«username».
|
| services.mysql.galeraCluster.nodeAddresses | IP addresses or hostnames of all nodes in the cluster, including this node
|
| services.prometheus.exporters.rspamd.extraFlags | Extra commandline options to pass to the rspamd exporter.
|
| services.strongswan-swanctl.swanctl.connections.<name>.children.<name>.interface | Optional interface name to restrict outbound IPsec policies.
|
| services.prometheus.exporters.php-fpm.environmentFile | Environment file as defined in systemd.exec(5)
|
| services.mautrix-meta.instances.<name>.enable | Whether to enable Mautrix-Meta, a Matrix <-> Facebook and Matrix <-> Instagram hybrid puppeting/relaybot bridge.
|
| services.nixseparatedebuginfod2.substituters | nix substituter to fetch debuginfo from
|
| services.tor.settings.Address | See torrc manual.
|
| services.postfix.setgidGroup | How to call postfix setgid group (for postdrop)
|
| services.tor.settings.ControlPortFileGroupReadable | See torrc manual.
|
| services.mastodon.elasticsearch.preset | It controls the ElasticSearch indices configuration (number of shards and replica).
|
| services.postgresqlBackup.compressionLevel | The compression level used when compression is enabled.
gzip accepts levels 1 to 9. zstd accepts levels 1 to 19.
|
| services.suricata.settings.default-log-dir | The default logging directory
|
| services.pixelfed.nginx.basicAuthFile | Basic Auth password file for a vhost
|
| services.lldap.settings.http_url | The public URL of the server, for password reset links.
|
| services.nezha-agent.enable | Whether to enable Agent of Nezha Monitoring.
|
| services.prosody.modules.groups | Shared roster support
|
| services.pihole-ftl.enable | Whether to enable Pi-hole FTL.
|
| services.mbpfan.settings.general.high_temp | If temperature is above this, fan speed will gradually increase.
|
| services.postgrey.greylistAction | Response status for greylisted messages (see access(5))
|
| services.pgbouncer.user | The user pgbouncer is run as.
|
| services.mtr-exporter.extraFlags | Extra command line options to pass to MTR exporter.
|
| services.prometheus.exporters.dmarc.openFirewall | Open port in firewall for incoming connections.
|
| services.ntpd-rs.metrics.enable | Whether to enable ntpd-rs Prometheus Metrics Exporter.
|
| services.orthanc.stateDir | State directory of Orthanc.
|
| services.ocsinventory-agent.package | The ocsinventory-agent package to use.
|
| services.snipe-it.appURL | The root URL that you want to host Snipe-IT on
|
| services.mastodon.smtp.authenticate | Authenticate with the SMTP server using username and password.
|
| services.transfer-sh.secretFile | Path to file containing environment variables
|
| services.mollysocket.settings.port | Listening port of the web server
|
| services.prometheus.scrapeConfigs.*.marathon_sd_configs.*.follow_redirects | Configure whether HTTP requests follow HTTP 3xx redirects
|
| services.onlyoffice.package | The onlyoffice-documentserver package to use.
|
| services.prometheus.exporters.fritz.settings.log_level | Log level to use for the exporter.
|
| services.prometheus.enableReload | Reload prometheus when configuration file changes (instead of restart)
|
| services.prometheus.exporters.ipmi.openFirewall | Open port in firewall for incoming connections.
|
| services.nix-serve.openFirewall | Open ports in the firewall for nix-serve.
|
| services.reaction.settingsFiles | Configuration for reaction, see the wiki.
reaction supports JSON, YAML and JSONnet
|
| services.rabbitmq.dataDir | Data directory for rabbitmq.
|
| services.nextcloud-whiteboard-server.settings | Settings to configure backend server
|
| services.stalwart.package | The stalwart package to use.
|
| services.todesk.enable | Whether to enable ToDesk daemon.
|
| services.postfix.settings.main | The main.cf configuration file as key value set
|
| services.suricata.settings.af-xdp | Linux high speed af-xdp capture support, see
docs/capture-hardware/af-xdp.
|
| services.prometheus.exporters.knot.enable | Whether to enable the prometheus knot exporter.
|
| services.strongswan-swanctl.swanctl.connections.<name>.local.<name>.cert.<name>.file | Absolute path to the certificate to load
|
| services.suricata.enabledSources | List of sources that should be enabled
|
| services.prometheus.exporters.nginx.scrapeUri | Address to access the nginx status page
|
| services.tor.settings.IPv6Exit | See torrc manual.
|
| services.pretix.settings.pretix.cachedir | Directory for storing temporary files.
|
| services.openldap.configDir | Use this config directory instead of generating one from the
settings option
|
| services.saslauthd.enable | Whether to enable saslauthd, the Cyrus SASL authentication daemon.
|
| services.sharkey.setupRedis | Whether to automatically set up a local Redis cache and configure Sharkey to use it.
|
| services.restic.server.dataDir | The directory for storing the restic repository.
|
| services.unclutter-xfixes.timeout | Number of seconds before the cursor is marked inactive.
|
| services.udp-over-tcp.tcp2udp.<name>.threads | Sets the number of worker threads to use
|
| services.matrix-appservice-discord.enable | Whether to enable a bridge between Matrix and Discord.
|
| services.picom.menuOpacity | Opacity of dropdown and popup menu.
|
| services.umami.settings.APP_SECRET_FILE | A file containing a secure random string
|
| services.nagios.virtualHost.locations.<name>.extraConfig | These lines go to the end of the location verbatim.
|
| services.mediamtx.enable | Whether to enable MediaMTX.
|
| services.nagios.virtualHost.listen | Listen addresses and ports for this virtual host.
This option overrides addSSL, forceSSL and onlySSL
|
| services.nextcloud.settings.mail_send_plaintext_only | Email will be sent by default with an HTML and a plain text body
|
| services.moodle.virtualHost.servedFiles | This option provides a simple way to serve individual, static files.
This option has been deprecated and will be removed in a future
version of NixOS
|
| services.nominatim.package | The nominatim-api package to use.
|
| services.slurm.dbdserver.dbdHost | Hostname of the machine where slurmdbd
is running (i.e. name returned by hostname -s).
|
| services.slskd.nginx.locations.<name>.proxyPass | Adds proxy_pass directive and sets recommended proxy headers if
recommendedProxySettings is enabled.
|
| services.prometheus.scrapeConfigs.*.dns_sd_configs.*.names | A list of DNS SRV record names to be queried.
|
| services.matrix-alertmanager.package | The matrix-alertmanager package to use.
|
| services.matomo.nginx.listenAddresses | Listen addresses for this virtual host
|
| services.logrotate.checkConfig | Whether the config should be checked at build time
|
| services.rauc.slots.<name>.*.settings | Settings for this slot.
|
| services.tinc.networks | Defines the tinc networks which will be started
|
| services.pgmanage.sqlRoot | This tells pgmanage where to put the SQL file history
|
| services.scollector.extraConfig | Extra scollector configuration added to the end of scollector.toml
|
| services.prometheus.scrapeConfigs.*.marathon_sd_configs.*.tls_config.server_name | ServerName extension to indicate the name of the server.
http://tools.ietf.org/html/rfc4366#section-3.1
|
| services.step-ca.openFirewall | Whether to enable opening the certificate authority server port.
|
| services.szurubooru.server.settings.data_url | Full URL to the data endpoint.
|
| services.umurmur.settings.bindaddr | IPv4 address to bind to
|
| services.murmur.autobanTime | The amount of time an IP ban lasts (in seconds).
|
| services.prometheus.alertmanagerGotify.port | The local port the bridge is listening on.
|
| services.pgmanage.enable | Whether to enable PostgreSQL Administration for the web.
|
| services.udp-over-tcp.udp2tcp.<name>.fwmark | If given, sets the SO_MARK option on the TCP socket.
|
| services.postgresqlBackup.compression | The type of compression to use on the generated database dump.
|
| services.prometheus.scrapeConfigs.*.puppetdb_sd_configs.*.basic_auth.username | HTTP username
|
| services.lidarr.settings.log.analyticsEnabled | Send Anonymous Usage Data
|
| services.readarr.openFirewall | Open ports in the firewall for Readarr
|
| services.nats.serverName | Name of the NATS server, must be unique if clustered.
|
| services.mchprs.settings.block_in_hitbox | Allow placing blocks inside of players
(hitbox logic is simplified)
|
| services.opensearch.settings | OpenSearch configuration.
|
| services.postgres-websockets.environment.PGWS_HOST | Address the server will listen for websocket connections.
|
| services.prometheus.exporters.fastly.extraFlags | Extra commandline options to pass to the fastly exporter.
|
| services.prometheus.exporters.deluge.exportPerTorrentMetrics | Enable per-torrent metrics
|
| services.minecraft-server.whitelist | Whitelisted players, only has an effect when
services.minecraft-server.declarative is
true and the whitelist is enabled
via services.minecraft-server.serverProperties by
setting white-list to true
|
| services.tox-node.tcpConnectionLimit | Maximum number of active TCP connections relay can hold
|
| services.trafficserver.records | List of configurable variables used by Traffic Server
|
| services.prometheus.exporters.v2ray.group | Group under which the v2ray exporter shall be run.
|
| services.misskey.database.createLocally | Create the PostgreSQL database locally
|
| services.parsedmarc.settings.imap.port | The IMAP server port.
|