| services.prosody.checkConfig | Check the configuration file with prosodyctl check config
|
| services.prosody.disco_items | List of discoverable items you want to advertise.
|
| services.minio.secretKey | Specify the Secret key of 8 to 40 characters in length that clients use to access the server
|
| services.mjpg-streamer.inputPlugin | Input plugin
|
| services.prometheus.scrapeConfigs.*.kubernetes_sd_configs.*.tls_config.server_name | ServerName extension to indicate the name of the server.
http://tools.ietf.org/html/rfc4366#section-3.1
|
| services.nsd.zones.<name>.dnssecPolicy.coverage | The length of time to ensure that keys will be correct; no action will be taken to create new keys to be activated after this time.
|
| services.openafsClient.inumcalc | Inode calculation method. compat is
computationally less expensive, but md5 greatly
reduces the likelihood of inode collisions in larger scenarios
involving multiple cells mounted into one AFS space.
|
| services.snipe-it.enable | Whether to enable snipe-it, a free open source IT asset/license management system.
|
| services.strongswan-swanctl.swanctl.connections.<name>.remote.<name>.id | IKE identity to expect for authentication round
|
| services.syncthing.settings.options | The options element contains all other global configuration options
|
| services.prometheus.exporters.exportarr-prowlarr.openFirewall | Open port in firewall for incoming connections.
|
| services.rumno.extraArgs | Extra command-line arguments to pass to the rumno daemon.
|
| services.prometheus.exporters.chrony.openFirewall | Open port in firewall for incoming connections.
|
| services.pdfding.consume.schedule | The cron schedule for the consume task to trigger
|
| services.prometheus.exporters.chrony.firewallRules | Specify rules for nftables to add to the input chain
when services.prometheus.exporters.chrony.openFirewall is true.
|
| services.nginx.virtualHosts.<name>.extraConfig | These lines go to the end of the vhost verbatim.
|
| services.thanos.sidecar.grpc-server-tls-key | TLS Key for the gRPC server, leave blank to disable TLS
|
| services.pretalx.enable | Whether to enable pretalx.
|
| services.nginx.virtualHosts.<name>.reuseport | Create an individual listening socket
|
| services.postfix.extraAliases | Additional entries to put verbatim into aliases file, cf. man-page aliases(8).
|
| services.tigerbeetle.cacheGridSize | The grid cache size
|
| services.syncthing.settings.folders.<name>.label | The label of the folder.
|
| services.taler.merchant.debug | Whether to enable debug logging.
|
| services.netdata.enableAnalyticsReporting | Enable reporting of anonymous usage statistics to Netdata Inc. via either
Google Analytics (in versions prior to 1.29.4), or Netdata Inc.'s
self-hosted PostHog (in versions 1.29.4 and later)
|
| services.physlock.lockOn.hibernate | Whether to lock screen with physlock just before hibernate.
|
| services.opengfw.rules.*.log | Whether to enable logging for the rule.
|
| services.prometheus.scrapeConfigs.*.digitalocean_sd_configs.*.authorization.type | Sets the authentication type
|
| services.opensearch.user | The user OpenSearch runs as
|
| services.prometheus.exporters.json.openFirewall | Open port in firewall for incoming connections.
|
| services.prometheus.exporters.varnish.port | Port to listen on.
|
| services.unclutter.excluded | Names of windows where unclutter should not apply
|
| services.rsync.jobs.<name>.user | The name of an existing user account under which the rsync process should run.
|
| services.prometheus.exporters.systemd.user | User name under which the systemd exporter shall be run.
|
| services.readarr.settings.update.automatically | Automatically download and install updates.
|
| services.prometheus.scrapeConfigs.*.marathon_sd_configs.*.oauth2.token_url | The URL to fetch the token from.
|
| services.sogo.vhostName | Name of the nginx vhost
|
| services.prometheus.exporters.exportarr-radarr.user | User name under which the exportarr-radarr exporter shall be run.
|
| services.monero.rpc.port | Port the RPC server will bind to.
|
| services.strongswan-swanctl.swanctl.connections.<name>.local.<name>.aaa_id | Server side EAP-Identity to expect in the EAP method
|
| services.photoprism.databasePasswordFile | Database password file.
|
| services.misskey.settings.redisForTimelines.host | The Redis host.
|
| services.prometheus.exporters.chrony.port | Port to listen on.
|
| services.radicle.httpd.nginx.acmeRoot | Directory for the ACME challenge, which is public
|
| services.movim.h2o | With this option, you can customize an H2O virtual host which already
has sensible defaults for Movim
|
| services.syncthing.key | Path to the key.pem file, which will be copied into Syncthing's
configDir.
|
| services.sks.extraDbConfig | Set contents of the files "KDB/DB_CONFIG" and "PTree/DB_CONFIG" within
the ${dataDir} directory
|
| services.redis.servers.<name>.port | The TCP port to accept connections
|
| services.quake3-server.port | UDP Port the server should listen on.
|
| services.printing.cups-pdf.instances.<name>.installPrinter | Whether to enable a CUPS printer queue for this instance
|
| services.slskd.nginx.listen | Listen addresses and ports for this virtual host
|
| services.thanos.query-frontend.tracing.config-file | Path to YAML file that contains tracing configuration
|
| services.mastodon.database.host | Database host address or unix socket.
|
| services.ncps.netrcFile | The path to netrc file for upstream authentication
|
| services.prometheus.scrapeConfigs.*.gce_sd_configs | List of Google Compute Engine service discovery configurations
|
| services.nginx.tailscaleAuth.group | Alias of services.tailscaleAuth.group.
|
| services.pomerium.secretsFile | Path to file containing secrets for Pomerium, in systemd
EnvironmentFile format
|
| services.rimgo.package | The rimgo package to use.
|
| services.prometheus.exporters.dnssec.extraFlags | Extra commandline options when launching Prometheus.
|
| services.tlsrpt.reportd.settings.contact_info | Contact information embedded into the reports.
|
| services.movim.domain | Fully-qualified domain name (FQDN) for the Movim instance.
|
| services.spamassassin.enable | Whether to enable the SpamAssassin daemon.
|
| services.maddy.ensureCredentials | List of user accounts which get automatically created if they don't
exist yet
|
| services.nullidentdmod.enable | Whether to enable the nullidentdmod identd daemon.
|
| services.onlyoffice.securityNonceFile | File holding nginx configuration that sets the nonce used to create secret links
|
| services.thanos.query.store.sd-files | Path to files that contain addresses of store API servers
|
| services.tor.settings.MaxAdvertisedBandwidth | See torrc manual.
|
| services.postgresql.settings.port | The port on which PostgreSQL listens.
|
| services.snipe-it.nginx.basicAuthFile | Basic Auth password file for a vhost
|
| services.mirakurun.channelSettings | Options which are added to channels.yml
|
| services.monica.mail.driver | Mail driver to use.
|
| services.thanos.query.http-address | Listen host:port for HTTP endpoints
|
| services.monero.extraConfig | Extra lines to be added verbatim to monerod configuration.
|
| services.rauc.dataDir | The state directory for RAUC.
|
| services.prometheus.exporters.dnssec.enable | Whether to enable the prometheus dnssec exporter.
|
| services.speedify.enable | This option enables Speedify daemon
|
| services.prometheus.scrapeConfigs.*.sample_limit | Per-scrape limit on number of scraped samples that will be accepted
|
| services.limesurvey.nginx.virtualHost.listen.*.extraParameters | Extra parameters of this listen directive.
|
| services.prometheus.exporters.sql.configuration.jobs.<name>.queries | SQL queries to run.
|
| services.prometheus.exporters.statsd.user | User name under which the statsd exporter shall be run.
|
| services.metabase.ssl.port | Listen port over SSL (https) for Metabase.
|
| services.ttyd.port | Port to listen on (use 0 for random port)
|
| services.multipath.defaults | This section defines default values for attributes which are used
whenever no values are given in the appropriate device or multipath
sections.
|
| services.navidrome.settings.EnableInsightsCollector | Enable anonymous usage data collection, see https://www.navidrome.org/docs/getting-started/insights/ for details.
|
| services.pleroma.configs | Pleroma public configuration
|
| services.postfix.settings.master.<name>.private | Whether the service's sockets and storage directory is restricted to
be only available via the mail system
|
| services.prometheus.exporters.smokeping.group | Group under which the smokeping exporter shall be run.
|
| services.nginx.config | Verbatim nginx.conf configuration
|
| services.prometheus.exporters.unpoller.log.debug | Whether to enable debug logging including line numbers, high resolution timestamps, per-device logs.
|
| services.slskd.settings.global.upload.slots | Limit of the number of concurrent upload slots.
|
| services.prometheus.scrapeConfigs.*.puppetdb_sd_configs.*.tls_config.key_file | Key file for client cert authentication to the server.
|
| services.prometheus.exporters.flow.asn | The ASN being monitored.
|
| services.prometheus.stateDir | Directory below /var/lib to store Prometheus metrics data
|
| services.thanos.store.log.format | Log format to use.
|
| services.sabnzbd.allowConfigWrite | By default we create the sabnzbd configuration read-only,
which keeps the nixos configuration as the single source
of truth
|
| services.opensmtpd.package | The opensmtpd package to use.
|
| services.radicle.httpd.nginx.default | Makes this vhost the default.
|
| services.slskd.nginx.serverName | Name of this virtual host
|
| services.prometheus.exporters.artifactory.artiPassword | Password for authentication against JFrog Artifactory API
|
| services.redmine.components.git | Whether to enable git integration..
|
| services.teeworlds.motd | The server's message of the day text.
|